Privacy Notice
Version: v2026-07-06 · Effective from: 6 July 2026
The previous versions (the v2026-05-01 unified notice, as well as 2025-08-01 on tudatosdiak.hu and 2025-05-01 on anyway.hu) are superseded by this notice.
This privacy notice describes the personal-data-processing activities carried out by the joint controllers named in Section 1 (collectively: the “Controller”) in connection with the use of tudatosdiak.hu, anyway.hu, office.tudatosdiak.hu, and the TudatOS Karrier / Partner / Staff mobile applications. This is a single, umbrella notice: the listed legal entities act as joint controllers under Article 26 GDPR, on shared infrastructure and under unified rules. No separate privacy notice applies to any of these services.
This notice has been prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and Act CXII of 2011 on Informational Self-Determination and Freedom of Information (“Privacy Act”).
1. § The Controller — Joint Controllers (Article 26 GDPR)
(1) Personal data is processed by the following three Hungarian legal entities as joint controllers:
| Tudatos Diák Iskolaszövetkezet | Tudatos Dolgozók Szociális Szövetkezet | T-Digital Solutions Kft. | |
|---|---|---|---|
| Registered seat | 1117 Budapest, Dombóvári út 9. | 2161 Csomád, Kossuth Lajos út 103. | 1117 Budapest, Dombóvári út 9. |
| Company reg. no. | 01-02-054584 | 13-02-051561 | 01-09-428831 |
| Tax no. | 26777748-2-43 | 32644953-2-13 | 32526620-2-43 |
| Postal address | 1117 Budapest, Dombóvári út 9. | 2161 Csomád, Kossuth Lajos út 103. | 1117 Budapest, Dombóvári út 9. |
| [email protected] | [email protected] | [email protected] | |
| Represented by | Attila Zoltán Yilmaz | Leonárd Henrik Szabó | Attila Zoltán Yilmaz |
(2) The Controllers have entered into a joint controller arrangement under Article 26(1) GDPR. Its essence is as follows: in the course of the joint processing, T-Digital Solutions Kft. is responsible for fulfilling the administrative obligations relating to the joint processing; data subjects may exercise their rights against any of the joint controllers through a single, unified point of contact.
(3) Single point of contact:
E-mail: [email protected]
Postal address: 1117 Budapest, Dombóvári út 9.
Phone: +36 1 815 8990
(4) Contact details of the Controllers’ Data Protection Officer:
Name: Gábor Varga
E-mail: [email protected] / [email protected] / [email protected]
2. § The Software Operator — Processor (Article 28 GDPR)
(1) The software concerned (the tudatosdiak.hu marketing and recruiting website, the anyway.hu ATS platform, the office.tudatosdiak.hu back-office system and the TudatOS Karrier / Partner / Staff mobile applications) is developed and operated on behalf of the Controller by the following company:
| T-Cloud Solutions Kft. | |
|---|---|
| Registered seat | 1117 Budapest, Dombóvári út 9. 4th floor |
| Company reg. no. | 01 09 438601 |
| Tax no. | 32710148243 |
| Activity | Software development, software operation, infrastructure management, technical support |
(2) T-Cloud Solutions Kft. processes personal data exclusively on the documented instructions of the Controller, under a written Data Processing Agreement (DPA). T-Cloud Solutions Kft. also engages further sub-processors; the full list is set out in Section 11.
3. § Definitions
- Processing: any operation or set of operations performed on personal data.
- Controller: the natural or legal person that determines the purposes and means of the processing of personal data.
- Joint controller: a controller jointly determining processing under an arrangement pursuant to Article 26 GDPR.
- Processor: a person that processes personal data on behalf of the controller.
- Data transfer: making personal data accessible to a third party (recipient).
- Data subject: the natural person whose personal data is processed by the Controller.
- Consent: a freely given, specific, informed and unambiguous indication of the data subject’s wishes.
- Personal data: information relating to an identified or identifiable natural person.
- Special category data: a category under Article 9 GDPR (e.g. health data).
- Cookie: a small data file placed on the user’s device.
- Personal data breach: a breach of the security of personal data.
- GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council.
- Privacy Notice: this document.
4. § Scope of the Notice
(1) This umbrella notice covers the processing carried out by all of the following services; no separate privacy notice applies to any of them:
| Service | Surface |
|---|---|
| Marketing and recruiting website | tudatosdiak.hu |
| Student / job-seeker interface | tudatosdiak.hu/karrier, anyway.hu |
| ATS (applicant and recruitment tracking platform) | anyway.hu |
| Cooperative-membership and payroll back-office | office.tudatosdiak.hu |
| TudatOS Karrier mobile application | iOS App Store, Google Play |
| TudatOS Partner mobile application | iOS App Store, Google Play |
| TudatOS Staff mobile application (internal) | iOS App Store, Google Play |
| Messaging channels | e-mail (Mailjet), SMS (SeeMe), push (FCM / APNs) |
| External recruitment channels | Profession.hu, Facebook, LinkedIn |
| AI processing layer | Anthropic Claude, Google Gemini |
5. § Purposes, Legal Bases, Data Categories and Retention
5.1. Website Registration
Mandatory data: last name, first name, e-mail, password (hashed).
Optional data: phone, language, newsletter opt-in, gender, nationality, sign-up source (UTM, referrer, landing URL).
Purpose: identification of the registered user, account management, communication.
Legal basis: Art. 6(1)(b) GDPR — pre-contractual measures (account agreement).
Retention: until the registration is deleted; if the e-mail is not confirmed, automatic deletion after 90 days; automatic deletion after 2 years of inactivity.
5.2. Detailed Job-Seeker and Membership Profile
Data: address, place and date of birth, mother’s maiden name, nationality, student-ID number, tax-ID, TAJ (social-security) number, bank-account number, parent’s e-mail, languages, work experience, interests, driving licence.
Purpose: job application, preparation of the cooperative-membership relationship.
Legal basis: Art. 6(1)(b) GDPR — contract; for financial/tax fields Art. 6(1)(c) — legal obligation (PIT Act, Social Security Contributions Act).
Retention: until membership is established or the profile is deleted; duration of membership + 5-year limitation period.
5.3. Student ID and Enrolment Certificate Photographs
Data: photo of the front and back of the student ID, student enrolment certificate.
Purpose: verification of cooperative-membership eligibility, verification of student status.
Legal basis: Art. 6(1)(c) GDPR — legal obligation (Act X of 2006).
Retention: automatically deleted from the file storage and the database within 7 days of the announcement; immediately upon rejection.
Recipients: joint controllers; KEF-IF (NEAK / OEP) authority query.
5.4. Occupational-Health Data — Special Category under Article 9 GDPR
Data: examination date, examining physician, place of examination, fitness statement (PDF), validity, FEOR code, position.
Purpose: statutory certification of occupational-health fitness.
Legal basis: Art. 9(2)(b) GDPR — employment-law obligation; Act XCIII of 1993 (Labour Safety Act) §§ 49–55; Decree 33/1998 (VI. 24.) NM.
Retention: 30 years after the employment relationship ends (Labour Safety Act § 64(1)).
Recipients: occupational-health service provider, joint controllers, T-Cloud.
5.5. Cooperative-Membership Contract and Payroll
Data: natural-person identification data, address, tax-ID, TAJ number, bank-account number; data required for family and personal tax allowances (number of children, number of children under 16, child with a disability, single parent, date of first marriage, recent-graduate status).
Purpose: creation and performance of the membership contract, payroll, tax and contribution filings.
Legal basis: Art. 6(1)(b) GDPR (contract) and Art. 6(1)(c) (PIT Act, Social Security Contributions Act, Cooperatives Act, Act X of 2006).
Retention: accounting vouchers: 8 years (Accounting Act § 169); payroll source data: 50 years from the last day of the calendar year following the end of employment (Pension Act § 99/A); other membership data: 5 years (Civil Code).
Recipients: joint controllers, NAV (Online Invoice), payroll provider (Hessyn / RLB), accountant, OTP Bank, Számlázz.hu.
5.6. Signing Identity — Electronic Signature
Data: name at signing, place and date of birth, mother’s name, address; OTP-authentication channel (e-mail / SMS) and recipient; IP address, user-agent; handwritten signature image and seal; RFC 3161 timestamp, hash.
Purpose: provable electronic signature (PAdES) for contracts and authority filings.
Legal basis: Art. 6(1)(b) GDPR — contract + Regulation (EU) 910/2014 (eIDAS).
Retention: limitation period of the relationship underpinned by the contract (generally 5 years, as an accounting voucher 8 years).
Recipients: joint controllers; FreeTSA (timestamping); Wiredsign Zrt.
5.7. Job Application (ATS — Anyway platform)
Data: name, e-mail, phone, CV (PDF), cover letter, content of the job-seeker profile, answers to application questions, time of application.
Purpose: conducting the recruitment procedure, forwarding to the employer partner.
Legal basis: Art. 6(1)(a) GDPR — explicit consent.
Retention: until the given application is closed, up to 60 days from the application; with an “Open to Work” mark (CV-pool opt-in), up to 2 years or until withdrawal.
Recipients: the employer partner selected by the data subject; joint controllers; T-Cloud.
5.8. AI-Based CV Analysis, Application Scoring and Matching
Data sent to the AI: the full text of the CV uploaded by the data subject (PDF), name, e-mail, phone, date of birth, nationality, languages, work experience, driving licence, application answers.
Data NOT sent to the AI: TAJ number, tax-ID, mother’s name, bank-account number, family-tax-allowance data, occupational-health data, password, salary.
Purpose: structured data extraction (editable by the user), scoring of the match to the job, preliminary categorisation (pass / borderline / fail), embedding-based semantic matching.
Legal basis: Art. 6(1)(b) GDPR — efficient performance of the recruitment process.
Automated decision (Article 22 GDPR): no decision producing legal effects concerning the data subject is taken solely on the basis of automated processing; the AI score is merely a ranking aid, and the final HR decision is always taken by a natural-person staff member. The data subject may at any time request that the AI result be disregarded and that an exclusively human evaluation be carried out, using the “Request human review” function available on the interface or by writing to [email protected].
Providers used: Anthropic PBC (Claude), Google LLC (Gemini) — see Section 11.
5.9. Recruitment Communication (e-mail, SMS, push)
Data: e-mail, phone, push token, message content and delivery metadata (time, opens, clicks).
Purpose: notifications about the recruitment process, reminders, job alerts, newsletter.
Legal basis: for service-type messages Art. 6(1)(b) GDPR; for marketing-type messages Art. 6(1)(a) — revocable consent.
Retention: mail and SMS logs: 24 months, then anonymised statistics; push: only until delivery.
Recipients: Mailjet (e-mail), SeeMe / smsapi.hu (SMS), Google FCM and Apple APNs (push).
5.10. Operational, Security and Audit Logs
Data: IP address, user-agent, browsed URL and Laravel route, event type, session ID, mobile app screen, app version, push opens; data-change audit (old and new value, who and when).
Purpose: error handling, fraud and abuse prevention, accountability (Art. 5(2) GDPR).
Legal basis: Art. 6(1)(f) GDPR — legitimate interest.
Right to object: at any time, at [email protected].
Retention: detailed event log: 90 days, then aggregate; financial audit log: 5 years; login and session data: up to 30 days.
5.11. Mobile-Device and App-Event Data
Data: device ID, platform (iOS / Android), OS version, app version, push token, screen-event history.
Purpose: recipient identification for push delivery, measurement of app stability and feature usage.
Legal basis: for push delivery: Art. 6(1)(b) GDPR; for analytics: Art. 6(1)(f) — with an opt-out option.
Retention: push token: as long as the app is installed; mobile event log: 90 days.
5.12. Employer Partner (Company) — Contact and Corporate Data
Data: contact name, e-mail, phone, role; company name, registered seat, tax-ID, company-registry data, representative, basic financial data (from Cégadat / Opten queries).
Purpose: contracting and performance, invoicing, recruitment-project management, partner-risk checks.
Legal basis: Art. 6(1)(b) GDPR contract, Art. 6(1)(c) AML Act, Art. 6(1)(f) legitimate interest.
Retention: duration of the business relationship + 5 years; accounting vouchers 8 years.
6. § Cookies and Website Tracking
On the tudatosdiak.hu, anyway.hu and office.tudatosdiak.hu surfaces we use the following cookies. Consent to non-essential cookies is managed by our own cookie-settings banner(your choice is stored in your browser’s local storage under the td_cookie_consent key); consent can be changed at any time via the “Cookie settings” button placed in the footer.
Strictly necessary cookies
| Cookie | Source | Purpose | Lifetime |
|---|---|---|---|
| laravel_session | tudatosdiak.hu / anyway.hu / office.tudatosdiak.hu | Storing login and session state | until end of session or max. 30 days |
| XSRF-TOKEN | as above | Protection against CSRF attacks | until end of session |
| remember_web_<hash> | as above | "Remember me" login persistence | 5 years (opt-in) |
| td_cookie_consent | tudatosdiak.hu (localStorage) | Recording cookie settings (consent) | 12 months |
| NEXT_LOCALE | tudatosdiak.hu | Remembering the chosen language (Hungarian / English) | 1 year |
Functional cookies
| Cookie | Source | Purpose | Lifetime |
|---|---|---|---|
| i18n_locale | tudatosdiak.hu / anyway.hu | Language selection | 1 year |
| theme_preference | anyway.hu | Light / dark theme | 1 year |
Statistical (analytics) cookies
| Cookie | Source | Purpose | Lifetime |
|---|---|---|---|
| _ga | Google Analytics 4 | Unique visitor ID | 2 years |
| _ga_<container-id> | Google Analytics 4 | Session state | 2 years |
| _gid | Google Analytics | Session ID | 24 hours |
| _clck / _clsk | Microsoft Clarity | Anonymous behaviour analytics, heatmaps (with consent) | 1 year / session |
| td_web_visitor_id, td_session_id | tudatosdiak.hu (localStorage) → TudatOS | Visit attribution (source, UTM) — only with analytics consent | 1 year |
The analytics and marketing tools (Google Analytics 4, Google Tag Manager, Microsoft Clarity, the Meta Pixel, and the TudatOS visitor-attribution tracker) are loaded only after the relevant consent has been given; Google Tag Manager is the container through which we manage these tags.
Bot and abuse screening
| Cookie | Source | Purpose | Lifetime |
|---|---|---|---|
| _GRECAPTCHA | Google reCAPTCHA | Bot and abuse screening on forms | 6 months |
| __cf_bm | Cloudflare | Bot management | 30 minutes |
Marketing cookies are placed only where the marketing category has been explicitly accepted. Currently we use Google Ads conversion measurement (Enhanced Conversions): with consent, certain data entered when submitting a form (e.g. e-mail, phone number, name) is transmitted to Google for the purpose of matching conversions. In addition, we run a Meta (Facebook) Pixel via Google Tag Manager (provider: Meta Platforms Ireland Ltd.) for remarketing and ad-performance measurement. The Meta Pixel is activated only after the marketing cookie category has been accepted; through its Advanced Matching feature, certain contact data provided by the user (e-mail address, phone number) may be transmitted to Meta in hashed form for the purpose of matching conversions. Meta may also use the data received in accordance with its own privacy policy (facebook.com/privacy/policy); the transfer of data to Meta Platforms, Inc. (USA) takes place under the EU–US Data Privacy Framework (DPF) (see Section 9). We do not currently run any LinkedIn pixel. The on-site chat assistant is loaded from our own system (app.tudatosdiak.hu); the handling of conversations is governed by Section 7 (AI).
We use Google Analytics 4 with IP anonymisation; the Google Signals advertising features are disabled. Data is transferred under the EU–US Data Privacy Framework (DPF) (see Section 9).
7. § AI Processing and Automated Decision-Making
(1) To speed up the recruitment and application process, we use large language models (LLMs) and vector-embedding models. These models run at external providers, within a processor relationship with the Controller and under EU–US DPF certification.
| Provider | Model family | Purpose |
|---|---|---|
| Anthropic PBC | Claude Sonnet 4.x, Claude Haiku | CV analysis (fallback), student-ID OCR, report generation, e-mail-text generation, internal assistant |
| Google LLC | Gemini 2.5 Pro, Flash, Embedding | CV analysis (primary), embedding-based job matching, translation, ad-copy generation |
(2) No decision producing legal effects concerning the data subject is taken solely on the basis of automated processing. The AI score is a ranking aid; the final HR decision is in all cases taken by a natural-person staff member.
(3) The data subject’s rights in relation to AI processing (Article 22 GDPR):
- Request human review — the “Request human review” function is available on every AI-related screen;
- Fully disable AI processing in the profile settings;
- Request an explanation of an AI decision in human language;
- Delete / modify AI-extracted data in the profile;
- Object at any time at [email protected].
(4) Anthropic and Google provide contractual guarantees that data submitted via the API is not used for model training (zero-retention API mode). At the providers, data is stored temporarily for abuse-investigation purposes (typically for up to 30 days), after which it is automatically deleted.
8. § Mobile Application Permissions
The TudatOS Group operates three mobile applications. Application permissions can be revoked at any time at the operating-system level (iOS → Settings → Privacy; Android → App permissions). Neither application uses geolocation or contacts.
TudatOS Karrier (job-seeker) — hu.tudatosdiak.career
| Permission | Purpose | Mandatory? |
|---|---|---|
| Internet | API connection | yes |
| Notifications (push) | Job alerts, interview and occupational-health reminders | no |
| Camera | Student-ID photo, profile avatar (7-day auto-delete) | no (only on use) |
| Apple Sign-In / Google Sign-In | Quick login | no |
| Biometric (Face ID / Touch ID) | Quick login (local, never leaves the device) | no |
| Phone call (tel: link) | Calling a job contact | no |
| Local storage (Capacitor Preferences) | Login token, UI preferences | yes |
TudatOS Partner (employer) — hu.tudatosdiak.partner
| Permission | Purpose | Mandatory? |
|---|---|---|
| Internet | API connection | yes |
| Notifications (push) | New application, interview slot, contract status | no |
| Biometric | Quick login | no |
| Phone call (tel:) | Calling an applicant | no |
| Local storage | Login token, multi-company switcher, UI | yes |
TudatOS Staff (internal) — hu.tudatosdiak.staff
| Permission | Purpose | Mandatory? |
|---|---|---|
| Internet | API connection | yes |
| Notifications (push) | Check-in reminder, tickets, sales/recruiter events | no |
| Biometric | Quick login | no |
| Phone call (tel:) | Calling a partner / applicant from the CRM | no |
| Local storage | Login token, role-override, call log | yes |
The check-in feature records only a timestamp; it does not record GPS coordinates.
9. § International Data Transfers
Some processors are established outside the European Economic Area (EEA). Such transfers always take place with appropriate safeguards:
| Recipient | Data | Country | Legal basis |
|---|---|---|---|
| DigitalOcean LLC | Hosting, file storage (Spaces) | USA | EU–US DPF + SCC fallback |
| Cloudflare Inc. | DNS, CDN, WAF | USA | EU–US DPF |
| Anthropic PBC | AI (Claude) | USA | EU–US DPF |
| Google LLC | AI (Gemini), FCM, OAuth, Maps, Analytics | USA | EU–US DPF |
| Google reCAPTCHA (Google LLC) | Bot and abuse screening | USA | EU–US DPF |
| Meta Platforms, Inc. | Meta Pixel — remarketing, conversion measurement (hashed e-mail address, phone number) | USA | EU–US DPF |
| Apple Inc. | App Store, Sign In, APNs | USA | EU–US DPF |
| Canva Pty Ltd. | Marketing materials | Australia | Adequacy decision |
The status of the certifications can be checked at dataprivacyframework.gov. The EU 2021/914 standard data-protection contractual clauses (SCC) are available on request at [email protected].
10. § Domestic Data Transfers
| Recipient | Data | Legal basis |
|---|---|---|
| NAV (National Tax and Customs Administration) | Tax data, invoices, filings | Legal obligation |
| OH / NEAK / OEP (KEF-IF) | Student status verification | Legal obligation |
| Court, prosecutor, investigating authority | Data as per the request | Legal obligation |
| Employer partner (job applied for) | Name, contact, CV, application answers | Data subject consent |
| Occupational-health service provider | Occupational-health data | Legal obligation (Labour Safety Act) |
| OTP Bank | Bank account, payout data | Performance of contract |
| Hessyn / RLB | Payroll data | Processor (DPA) |
| Számlázz.hu | Invoicing data | Processor (DPA) |
11. § Processors and Sub-Processors
T-Cloud Solutions Kft. (as the Controller’s processor) engages the following sub-processors. It notifies the Controller before engaging a new sub-processor.
| # | Company | Seat | Activity |
|---|---|---|---|
| 1 | T-Cloud Solutions Kft. | 1117 Budapest, Dombóvári út 9. 4th floor | Software development, operation |
| 2 | DigitalOcean LLC | New York, USA | Hosting, storage (Spaces) |
| 3 | Cloudflare Inc. | San Francisco, USA | DNS, CDN, WAF |
| 4 | Anthropic PBC | San Francisco, USA | AI (Claude) |
| 5 | Google LLC | Mountain View, USA | AI (Gemini), FCM, OAuth, Maps, Analytics |
| 6 | Apple Inc. | Cupertino, USA | App Store, Sign In, APNs |
| 7 | Microsoft Ireland Operations Ltd. | Dublin, IE | Office 365 |
| 8 | Mailjet SAS (Sinch Group) | Paris, FR | Transactional and marketing e-mail |
| 9 | SeeMe Solutions Kft. (smsapi.hu) | Budapest | SMS gateway |
| 10 | Wiredsign Zrt. | Diósjenő | Electronic signature |
| 11 | FreeTSA | Germany | RFC 3161 timestamping |
| 12 | Hessyn Szoftver Informatikai Kft. | Budapest | Payroll software |
| 13 | RLB-60 Bt. | Hatvan | Payroll software |
| 14 | FireBird Foundation z.s. | Prague, CZ | Database software |
| 15 | KBOSS.hu Kft. (Számlázz.hu) | Budapest | Invoicing |
| 16 | OTP Bank Nyrt. | Budapest | Banking transactions (Elektra) |
| 17 | Cégadat API operator | Budapest | Company-registry query |
| 18 | Opten Kft. | Budapest | Company data / risk |
| 19 | Canva Pty Ltd. | Sydney, Australia | Design tool (marketing) |
| 20 | MiniCRM Zrt. | Budapest | Internal CRM |
| 21 | Profession.hu (DBH-Group) | Budapest | Recruitment channel |
| 22 | tárhely.eu kft. | Budapest | Static website hosting |
| 23 | Meta Platforms Ireland Ltd. | Dublin, IE | Meta Pixel — remarketing, conversion measurement, only with marketing consent |
12. § Retention Periods
| Data category | Period |
|---|---|
| Active membership | Relationship + 5-year limitation period |
| Accounting data | 8 years (Accounting Act § 169) |
| E-mail-unverified registration | 90 days |
| Student ID + enrolment certificate photo | 7 days after the announcement |
| Occupational-health data | End of employment + 30 years (Labour Safety Act) |
| Application (ATS) | 60 days / "Open to Work" pool: 2 years |
| Mail and SMS logs | 24 months |
| Detailed event log | 90 days |
| Login and session | 30 days |
| Financial audit log | 5 years |
| Signature image and signature metadata | Limitation period of the contract (5 years) / accounting (8 years) |
| Backup | 7 days |
| Cookies | Individual lifetime listed in the cookie table (see Section 6) |
13. § Data Security Measures
- Encryption: TLS 1.2+ (HTTPS) for all communication; AES-256 encryption at rest on the databases and the DigitalOcean Spaces storage.
- Access control: role-based access control (RBAC), two-factor login on the staff interface, password hashing (bcrypt).
- Logging and audit: every material change is audit-logged, recording the old and new values.
- Backup: daily backup, 7-day recovery point; automatic overwrite; restoration only with the approval of an executive officer.
- WAF and DDoS protection: Cloudflare.
- Staff confidentiality obligation under contract; annual data-protection training for staff with access rights.
14. § Data-Subject Rights
Under the GDPR, the data subject has the following rights. The rights may be exercised at [email protected] or in the user account (“My Data → GDPR requests”). The data subject may exercise their rights against any of the joint controllers through the single point of contact. We provide our response within 1 month, extendable in justified cases by a further 2 months.
- Right of access (Article 15 GDPR) — self-service JSON/CSV data export available.
- Right to rectification (Article 16) — generally directly in the profile.
- Right to erasure / “right to be forgotten” (Article 17).
- Right to restriction of processing (Article 18).
- Right to data portability (Article 20) — JSON/CSV.
- Right to object (Article 21) — against processing based on legitimate interest.
- Right to withdraw consent (Article 7(3)) — at any time; withdrawal does not affect the lawfulness of processing before withdrawal.
- Rights related to automated decision-making (Article 22) — human review, expression of a point of view, contesting the decision. A “Request human review” button is available on every AI-related screen.
- Right to lodge a complaint with a supervisory authority (Article 77) — NAIH (see Section 16).
- Right to a judicial remedy (Article 79) — the regional court competent for the place of residence (birosag.hu/torvenyszekek).
- Rights of a deceased data subject — upon presentation of the death certificate and proof of identity, a close relative under the Civil Code may exercise the data-subject rights within 5 years of the death (Act LIII of 2018 §§ 25/G–25/J).
15. § Personal Data Breach
(1) Upon detecting a personal data breach, the Controller notifies NAIH without undue delay, but at the latest within 72 hours (Article 33 GDPR).
(2) Where the breach is likely to result in a high risk to the rights and freedoms of data subjects, we also notify the data subjects directly (Article 34 GDPR).
(3) We keep an internal register of breaches: categories and number of data subjects affected, time, circumstances, effects, and measures taken.
16. § Supervisory Authority
The data subject has the right to lodge a complaint with the supervisory authority:
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address: 1055 Budapest, Falk Miksa u. 9–11.
Postal address: 1363 Budapest, P.O. Box 9.
Phone: +36 1 391 1400
E-mail: [email protected]
Web: naih.hu
17. § Final Provisions — Version Control
(1) The Controller reserves the right to amend this notice unilaterally (in particular in the event of a change in legislation). We inform data subjects of material changes in advance through the main communication channel (e-mail, application login screen, website header).
(2) On their first login after a new version takes effect, the data subject confirms that they have read the new notice; the time, IP address and browser characteristics of this are recorded in the policy_acceptances log.
(3) Version v2026-07-06 of this Privacy Notice is effective from 6 July 2026.