Full privacy notice — the Anyway platform and the TudatOS services
Version: v2026-08-01 · Effective from: 1 August 2026
This notice replaces the unified v2026-07-06 notice, as well as the v2026-05-01 extract previously seeded into the platform.
This notice has been prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Infotv.).
1. § The Controller — joint controllers (Article 26 GDPR)
(1) Personal data is processed by the following three Hungarian legal entities as joint controllers:
| Tudatos Diák Iskolaszövetkezet | Tudatos Dolgozók Szociális Szövetkezet | T-Digital Solutions Kft. | |
|---|---|---|---|
| Registered seat | 1117 Budapest, Dombóvári út 9., Hungary | 2161 Csomád, Kossuth Lajos út 103., Hungary | 1117 Budapest, Dombóvári út 9., Hungary |
| Company reg. no. | 01-02-054584 | 13-02-051561 | 01-09-428831 |
| Tax no. | 26777748-2-43 | 32644953-2-13 | 32526620-2-43 |
| Postal address | 1117 Budapest, Dombóvári út 9., Hungary | 2161 Csomád, Kossuth Lajos út 103., Hungary | 1117 Budapest, Dombóvári út 9., Hungary |
| [email protected] | [email protected] | [email protected] | |
| Represented by | Attila Zoltán Yilmaz | Leonárd Henrik Szabó | Attila Zoltán Yilmaz |
(2) The Controllers have entered into a joint controller arrangement under Article 26(1) GDPR. Its essence is as follows: T-Digital Solutions Kft. is responsible for fulfilling the administrative obligations relating to the joint processing; data subjects may exercise their rights against any of the joint controllers, through a single, unified point of contact. We send the essence of the arrangement on request.
(3) Single point of contact:
E-mail: [email protected] · Postal address: 1117 Budapest, Dombóvári út 9., Hungary · Phone: +36 1 815 8990
(4) Data Protection Officer: Gábor Varga — [email protected] (or [email protected], [email protected])
2. § The software operator — processor (Article 28 GDPR)
(1) The software concerned (tudatosdiak.hu, anyway.hu, app.tudatosdiak.hu, app.anyway.hu, office.tudatosdiak.hu, and the TudatOS Karrier / Partner / Staff mobile applications) is developed and operated on behalf of the Controller by the following company:
| T-Cloud Solutions Kft. | |
|---|---|
| Registered seat | 1117 Budapest, Dombóvári út 9., 4th floor, Hungary |
| Company reg. no. | 01-09-438601 |
| Tax no. | 32710148-2-43 |
| Activity | Software development, operation, infrastructure management, product support |
(2) T-Cloud Solutions Kft. processes personal data exclusively on the documented instructions of the Controller, under a written Data Processing Agreement (DPA). It also engages further sub-processors; the full list is set out in Section 12.
3. § Definitions
- Processing: any operation or set of operations performed on personal data.
- Controller: the natural or legal person that determines the purposes and means of the processing.
- Joint controller: a controller that jointly determines the processing under an arrangement pursuant to Article 26 GDPR.
- Processor: a person that processes personal data on behalf of, and on the instructions of, the controller.
- Sub-processor: a person engaged by the processor to carry out part of the task.
- Recipient: a person to whom we disclose the personal data.
- Data subject: the natural person whose personal data we process.
- Consent: a freely given, specific, informed and unambiguous indication of wishes.
- Personal data: information relating to an identified or identifiable natural person.
- Special category data: a category under Article 9 GDPR (e.g. health data).
- Profiling: automated evaluation of personal data in order to predict certain characteristics.
- Cookie and local storage: a small data file placed on the user’s device, or data stored in the browser.
- Personal data breach: a breach of the security of personal data.
- GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council.
4. § Scope of this notice
| Service | Surface |
|---|---|
| Marketing and recruiting website (visitor-facing part) | tudatosdiak.hu — governed by the layer-1 notice |
| Student and job-seeker platform | app.tudatosdiak.hu, tudatosdiak.hu/karrier |
| Partner and ATS platform (candidate and recruitment management) | app.tudatosdiak.hu, app.anyway.hu |
| School cooperative and payroll back-office system | office.tudatosdiak.hu |
| TudatOS Karrier mobile application (student) | iOS App Store, Google Play |
| TudatOS Partner mobile application (employer) | iOS App Store, Google Play |
| TudatOS Staff mobile application (internal) | iOS App Store, Google Play |
| Messaging channels | e-mail (Mailjet), SMS (SeeMe / smsapi.hu), push (Google FCM / Apple APNs) |
| External recruitment channels | Profession.hu, Facebook, LinkedIn |
| AI processing layer | Anthropic Claude, Google Gemini |
5. § Purposes, legal bases, data processed and retention
5.1. Registration and account management
- Mandatory data: last name, first name, e-mail address, password (stored hashed only, in a non-reversible form).
- Optional data: phone number, language, newsletter consent, gender, nationality, source of registration (UTM parameters, referrer, landing page).
- Purpose: identification of the user, account management, communication.
- Legal basis: Article 6(1)(b) GDPR — conclusion and performance of the account agreement.
- Retention: until the account is terminated; where the e-mail address is not confirmed, automatic deletion after 90 days; automatic deletion after 2 years of inactivity.
5.2. Detailed job-seeker and membership profile
- Data: address, place and date of birth, mother’s maiden name, nationality, student-ID number, tax-ID, TAJ (social-security) number, bank-account number, e-mail address of the legal guardian (parent), languages, work experience, qualifications, interests, driving licence.
- Purpose: job application, preparation of the cooperative membership relationship, fulfilment of statutory notification obligations.
- Legal basis: Article 6(1)(b) GDPR — contract; for the financial and tax fields Article 6(1)(c) — legal obligation (Act CXVII of 1995 on Personal Income Tax (Szja tv.), Act CXXII of 2019 on Social Security Contributions (Tbj.), Act X of 2006 on Cooperatives).
- Retention: until membership is established or the profile is deleted; in the case of membership, the duration of the relationship + a 5-year limitation period (accounting and payroll data: see 5.6.).
5.3. Student ID and enrolment certificate photographs
- Data: photograph of the front and back of the student ID, student or pupil enrolment certificate.
- Purpose: verification of cooperative membership eligibility and of pupil/student status.
- Legal basis: Article 6(1)(c) GDPR — legal obligation (Act X of 2006 on Cooperatives).
- Retention: automatically deleted from both the file storage and the database within 7 days of the date of the employment notification to the tax authority (NAV); immediately upon rejection.
- Recipients: the joint controllers; official student-status verification (KEF-IF / NEAK).
5.4. Occupational health data — special category data under Article 9 GDPR
- Data: date of the examination, examining physician, place of the examination, fitness statement (PDF), validity, FEOR code, job position.
- Purpose: statutory certification of occupational health fitness.
- Legal basis: Article 9(2)(b) GDPR — employment-law obligation; Act XCIII of 1993 on Labour Safety (Mvt.) §§ 49–55; Decree 33/1998 (VI. 24.) NM.
- Retention: 30 years after the employment relationship ends (Mvt. § 64(1)).
- Recipients: the occupational health service provider, the joint controllers, T-Cloud Solutions Kft.
- Note: we do not process the specific medical result (diagnosis) of the examination — only the fit / not fit / fit with conditions rating and the validity period.
5.5. Employment, work performance, attendance
- Data: individual assignment agreements, job position and FEOR code, place of work, hours worked, timesheet, shift schedule, absence, certificate of performance.
- Purpose: performance of the employment, settlement towards the partner, statutory record-keeping.
- Legal basis: Article 6(1)(b) and (c) GDPR (Act I of 2012 on the Labour Code (Mt.), Act X of 2006 on Cooperatives, Act C of 2000 on Accounting (Szvt.)).
- Retention: end of the relationship + 5 years; pay-related vouchers as set out in 5.6.
- The check-in function of the mobile application records a timestamp only; it does not record GPS coordinates.
5.6. Cooperative membership contract and payroll settlement
- Data: natural-person identification data, address, tax-ID, TAJ number, bank-account number; the data required for family and personal tax allowances (number of children, number of children under 16, child with a disability, single parent, date of first marriage, recent-graduate status); payslips, payments.
- Purpose: creation and performance of the membership contract, payroll accounting, tax and contribution returns, payment.
- Legal basis: Article 6(1)(b) GDPR (contract) and Article 6(1)(c) GDPR (Szja tv., Tbj., Act C of 2000 on Accounting (Szvt.), Act X of 2006 on Cooperatives).
- Retention: accounting vouchers 8 years (Szvt. § 169); payroll source data 50 years from the last day of the calendar year following the end of the employment (Act LXXXI of 1997 on Social Security Pension Benefits (Tny.) § 99/A); other membership data 5 years (limitation period under Act V of 2013 on the Civil Code (Ptk.)).
- Recipients: the joint controllers, NAV, the payroll provider (Hessyn / RLB-60), the accountant, OTP Bank Nyrt., KBOSS.hu Kft. (Számlázz.hu).
5.7. Contracts and electronic signature
- Data: name at the time of signing, place and date of birth, mother’s name, address; the channel used to send the one-time passcode (OTP) for identity verification (e-mail / SMS), its recipient and the time of successful verification; IP address, browser identifier (user-agent); the handwritten signature image and its seal; RFC 3161 timestamp and hash.
- Purpose: provable electronic signature (PAdES) for contracts and for filings with the authorities.
- Legal basis: Article 6(1)(b) GDPR — contract; Regulation (EU) 910/2014 (eIDAS).
- Retention: until the limitation period of the relationship underpinned by the contract expires (generally 5 years); as an accounting voucher, 8 years.
- Recipients: the joint controllers; Wiredsign Zrt. (signature service); FreeTSA (timestamping).
5.8. Job application (ATS — the Anyway platform)
- Data: name, e-mail, phone, CV (PDF), cover letter, the content of the job-seeker profile, answers to the application questions, the time and status of the application, internal notes and evaluations relating to the process.
- Purpose: conducting the application procedure, forwarding the application to the employer partner.
- Legal basis: Article 6(1)(a) GDPR — explicit consent (the submission of the application).
- Retention: until the given vacancy is closed, and at most 60 days from the application; if you tick the CV Database (Open to Work) option, then as set out in 5.10.
- Recipients: the employer partner whose vacancy you applied for; the joint controllers; T-Cloud Solutions Kft.
5.9. AI-based CV analysis, scoring and match recommendation
- Data sent to the AI: the full text of the uploaded CV, name, e-mail, phone, date of birth, nationality, languages, work experience, qualifications, driving licence, the answers given to the application questions.
- Data NOT sent to the AI: TAJ number, tax-ID, mother’s name, bank-account number, family-tax-allowance data, occupational health data, password, and all pay data (hourly rate, gross and net pay, amounts paid out and transferred, payslips).
- Purpose: structured data extraction (you can edit the result yourself), scoring of the match to the job, preliminary categorisation, generation of report and text drafts, internal assistant.
- Legal basis: Article 6(1)(b) GDPR — efficient performance of the recruitment process.
- Retention: the AI output follows the retention period of the application or of the profile, as applicable; the log of AI conversations: 24 months.
- Providers used: Anthropic PBC (Claude), Google LLC (Gemini) — see Section 8 and Section 12.
5.10. CV Database (Open to Work) and partner access
- What it means: a voluntary option that you can switch on separately in your profile. If you switch it on, your profile is added to the CV Database, and our contracted employer partners can find you even when you have not applied for the given vacancy.
- What the partner sees: full name, e-mail address, phone number, date of birth, place of residence (town), qualifications, languages, work experience, the uploaded CV and the interests given in the profile.
- What the partner does NOT see: TAJ number, tax-ID, mother’s name, bank-account number, occupational health data, pay data, your applications running at other partners.
- Legal basis: Article 6(1)(a) GDPR — explicit, separate consent, which can be withdrawn at any time with a single toggle.
- Retention: until consent is withdrawn, and at most 2 years, after which we ask you again.
- Important: if a partner transfers your data into its own system, from that point on it acts as an independent controller in respect of that data. Our contract obliges the partner to inform you of this and to ensure your rights.
5.11. Communication (e-mail, SMS, push, newsletter)
- Data: e-mail address, phone number, push token, the content of the message and its delivery metadata (time, opens, clicks).
- Purpose: notifications about the process, reminders, job alerts, newsletter.
- Legal basis: for service-type (transactional) messages, Article 6(1)(b) GDPR; for marketing-type messages, Article 6(1)(a) — consent that can be withdrawn at any time, in line with Section 6 of Act XLVIII of 2008 on the Basic Requirements of and Certain Restrictions on Commercial Advertising Activity (Grt.).
- Retention: e-mail and SMS logs 24 months, then anonymised statistics; push: until delivery.
- Recipients: Mailjet SAS (e-mail), SeeMe Solutions Kft. / smsapi.hu (SMS), Google FCM and Apple APNs (push).
- Unsubscribing: a one-click unsubscribe link (RFC 8058) at the bottom of every marketing e-mail, and the notification settings in your profile.
5.12. Operational, security and audit logs
- Data: IP address, browser identifier (user-agent), the URL browsed, event type, session identifier, mobile application screen, application version, push opens; data-change audit (the old and the new value, who changed it and when).
- Purpose: troubleshooting, fraud and abuse prevention, accountability (Article 5(2) GDPR).
- Legal basis: Article 6(1)(f) GDPR — legitimate interest. The legitimate interest assessment (balancing test) is available on request.
- Right to object: at any time, at [email protected].
- Retention: detailed event log 90 days, then aggregate only; financial audit log 5 years; the session cookie at most 30 days. The sign-in log (the user identifier and the time of sign-in only — no IP address or browser identifier) is kept for 24 months, as it is the source of the monthly service-usage statistics.
5.13. Mobile device and app event data
- Data: device identifier, platform (iOS / Android), operating-system and application version, push token, screen-event history.
- Purpose: identifying the recipient of push notifications, measuring the stability of the application and feature usage, delivering application updates (OTA).
- Legal basis: for push delivery, Article 6(1)(b) GDPR; for analytics and update delivery, Article 6(1)(f) GDPR, with an opt-out option.
- Retention: push token for as long as the application is installed; mobile event log 90 days.
5.14. Employer partner — contact-person and corporate data
- Data: the contact person’s name, e-mail address, phone number and job position; the company’s name, registered seat, tax number, company-registry data, representative and basic financial data (from Cégadat / Opten queries).
- Purpose: contracting and performance, invoicing, management of the recruitment project, partner-risk checks.
- Legal basis: Article 6(1)(b) GDPR contract; Article 6(1)(c) GDPR for the customer due diligence required by Act LIII of 2017 on the Prevention and Combating of Money Laundering and Terrorist Financing (Pmt.); Article 6(1)(f) GDPR legitimate interest for the risk checks.
- Retention: the duration of the business relationship + 5 years; accounting vouchers 8 years.
6. § Cookies and data stored in the browser
On the platform (app.tudatosdiak.hu, app.anyway.hu, office.tudatosdiak.hu) we do not use any analytics or marketing cookies. We distinguish two groups.
6.1. Strictly necessary cookies
The service does not work without these, so no consent is required to set them (Section 155(4) of the Hungarian Electronic Communications Act, Article 5(3) of the ePrivacy Directive).
| Cookie | Purpose | Lifetime |
|---|---|---|
laravel_session | Login and session state | until the end of the session, max. 30 days |
XSRF-TOKEN | Protection against cross-site request forgery (CSRF) | until the end of the session |
remember_web_<hash> | The Remember me login persistence (optional) | 5 years |
__cf_bm | Cloudflare bot management | 30 minutes |
6.2. Functional (convenience) storage
These remember your settings. They are not strictly necessary, which is why we list them separately — saving the setting is your own choice and you can change it at any time in the interface. We do not use them for tracking and do not share them with third parties.
| Cookie | Purpose | Lifetime |
|---|---|---|
i18n_locale | Language selection | 1 year |
theme_preference | Light / dark theme | 1 year |
The analytics and marketing cookies used on the tudatosdiak.hu visitor-facing surface, together with the keys stored in the browser (td_cookie_consent, td_web_visitor_id, td_web_session_id, td_web_session_ts, td_web_landing, td_web_utm, td_lead_popup, td_active_promo, theme), are listed item by item in section 3 of the layer-1 notice. Those are loaded only after consent has been given, and consent can be changed at any time using the Cookie settings button in the footer.
The mobile applications do not use cookies and do not run marketing trackers; they keep the login token and the interface preferences in the device’s own, application-level storage.
7. § Minors — data subjects under the age of 18
This chapter is for you if you are not yet 18 — and for your parent, too.
7.1. Age limits
| Age limit | What it means |
|---|---|
| 15 years | From this age you can apply for student employment and register. |
| 16 years | From this age you can give consent on your own to the processing operations that are based on consent (cookies, newsletter, CV Database, marketing contact). This follows from Article 8(1) GDPR and Section 6(3) of Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Infotv.): Hungary applies the age limit of 16. |
| 18 years | From this age you are of full legal age: you can sign contracts on your own, and no involvement of a legal guardian is required. |
7.2. Under the age of 16: parental approval
If you are not yet 16, the approval of your parent or other legal guardian is required for processing based on consent.
This works as follows:
- During registration we ask for your date of birth.
- If you are under 16, you must enter your legal guardian’s e-mail address (in the system:
parent_email). - We send a message to that address informing your parent about what data we process and asking for their approval.
- We record the fact and time of the approval and the confirmation data — this is our evidence that we act lawfully (Article 8(2) and Article 7(1) GDPR).
- Until approval is given, the features based on consent (newsletter, CV Database, marketing contact) are not available.
Important: under the age of 18, we send official notices (contract, employment notification to the tax authority (NAV), occupational health appointment) exclusively to your legal guardian’s e-mail address.
7.3. What we NEVER do with a minor
- We do not build a marketing profile of a minor.
- We do not send them consent-based marketing contact (newsletter, offers, remarketing).
- We do not pass their data to a partner that may not employ minors.
- Under the age of 16, the CV Database (Open to Work) can only be switched on with valid parental approval.
7.4. Employment under the age of 18
The law prescribes an age limit of 18 for certain job positions. If you apply for such a vacancy, the system may automatically reject your application on the basis of your date of birth. This is an automated decision, and therefore:
- we always state the reason for the rejection;
- you can ask for a human to review it — using the Request human review function, or at [email protected] (Article 22(3) GDPR);
- we continue to recommend other job opportunities that have no age limit.
7.5. Plain language and parental rights
Under Article 12(1) GDPR, information addressed to minors must be clear and intelligible. If there is anything you do not understand, write to [email protected] and we will explain it in simpler terms.
As a parent, you can at any time request access to, rectification of or erasure of your child’s data, or withdraw approval previously given — at the same address. After withdrawal we cease the processing based on consent; processing based on a legal obligation (pay, employment notification, occupational health) remains in place until the statutory retention period expires.
8. § AI processing and automated decision-making (Article 22 GDPR)
(1) To speed up the recruitment and application process, we use large language models (LLMs) and vector-embedding models. These run at external providers, under a processor agreement and EU–US DPF certification.
| Provider | Model family | What we use it for |
|---|---|---|
| Anthropic PBC | Claude | CV analysis (fallback route), student-ID recognition, report and text generation, internal assistant |
| Google LLC | Gemini (Pro, Flash, Embedding) | CV analysis (primary), embedding-based job matching, translation, ad-copy generation |
(2) No decision based solely on automated processing and producing legal effects concerning the data subject may be taken. The AI score is a ranking aid; the final HR decision is in all cases taken by a natural-person staff member.
(3) An exception that we name explicitly: for vacancies subject to a statutory age limit, the system may automatically reject the application on the basis of the date of birth (see 7.4.). In such a case you have the full benefit of your rights under Article 22(3) GDPR — human intervention, expressing your point of view, and contesting the decision.
(4) Your rights in relation to AI processing:
- Requesting human review — using the Request human review function available on the screens that display the AI result, or at [email protected].
- Disabling AI processing in the profile settings.
- Requesting an explanation of a given AI output, in human language.
- Rectification or erasure of the data extracted by the AI, in the profile.
- Objecting at any time, at [email protected].
(5) Anthropic and Google provide contractual guarantees that data submitted via the API is not used for model training. At the providers, the data is stored temporarily for abuse-investigation purposes (typically for up to 30 days), after which it is automatically deleted.
(6) Guest CV analysis: if you upload a CV for analysis without logging in, the content of the file is sent to the AI provider for the duration of the analysis; we do not store the file itself, and we do not link the result of the analysis to any account.
9. § Mobile application permissions
We operate three mobile applications. Permissions can be revoked at any time at the operating-system level (iOS → Settings → Privacy; Android → App permissions). None of the applications uses geolocation or the contact list.
TudatOS Karrier (student, job seeker) — hu.tudatosdiak.career
| Permission | Purpose | Mandatory? |
|---|---|---|
| Internet | Connection to the server | yes |
| Notifications (push) | Job alerts, interview and occupational health reminders | no |
| Camera | Student-ID photograph, profile picture (7-day automatic deletion) | no |
| Apple / Google sign-in | Quick login | no |
| Biometrics (Face ID / Touch ID) | Quick login — stays local, never leaves the device | no |
| Phone call (tel: link) | Calling the workplace contact person | no |
| Local storage | Login token, interface preferences | yes |
TudatOS Partner (employer) — hu.tudatosdiak.partner
| Permission | Purpose | Mandatory? |
|---|---|---|
| Internet | Connection to the server | yes |
| Notifications (push) | New application, interview slot, contract status | no |
| Biometrics | Quick login | no |
| Phone call (tel:) | Calling the candidate | no |
| Local storage | Login token, company switcher, interface preferences | yes |
TudatOS Staff (internal, for staff members) — hu.tudatosdiak.staff
| Permission | Purpose | Mandatory? |
|---|---|---|
| Internet | Connection to the server | yes |
| Notifications (push) | Check-in reminder, tickets, sales and recruitment events | no |
| Biometrics | Quick login | no |
| Phone call (tel:) | Calling a partner or a candidate from the CRM | no |
| Local storage | Login token, role, call log | yes |
Application updates (OTA) are delivered by the Capgo service; for this, an application-level device identifier and the application version number are transmitted. The applications carry out no marketing tracking.
10. § Data transfers to third countries
Some processors are established outside the European Economic Area. Such transfers always take place with appropriate safeguards:
| Recipient | Data | Country | Legal basis |
|---|---|---|---|
| DigitalOcean, LLC (105 Edgeview Drive, Suite 425, Broomfield, CO 80021) | Hosting, file storage (Spaces) | USA | EU–US DPF, supplementary SCC |
| Cloudflare, Inc. | DNS, content delivery, WAF | USA | EU–US DPF |
| Anthropic PBC | AI (Claude) | USA | EU–US DPF |
| Google LLC | AI (Gemini), FCM, OAuth, Maps, Analytics, reCAPTCHA | USA | EU–US DPF |
| Microsoft Corporation | Clarity behaviour analytics (website only, with consent) | USA | EU–US DPF |
| Meta Platforms, Inc. | Meta Pixel (website only, with marketing consent) | USA | EU–US DPF |
| Apple Inc. | App Store, Sign In, APNs | USA | EU–US DPF |
| Canva Pty Ltd. | Marketing materials | Australia | Adequacy decision |
| Capgo | Mobile application updates (OTA): device identifier, application and OS version | Being confirmed | Data processing agreement; the seat and the legal basis of the transfer are being confirmed |
The status of the certifications can be checked at dataprivacyframework.gov. The standard contractual clauses under EU 2021/914 (SCC) are available to the data subject on request at [email protected].
11. § Domestic data transfers
| Recipient | Data | Legal basis |
|---|---|---|
| NAV (National Tax and Customs Administration) | Tax data, invoices, employment notifications | Legal obligation |
| Oktatási Hivatal (Educational Authority) / NEAK (KEF-IF) | Verification of pupil and student status | Legal obligation |
| Court, prosecution service, investigating authority | The data specified in the request | Legal obligation |
| Employer partner (the vacancy applied for) | Name, contact details, CV, application answers | Consent of the data subject |
| Employer partner (CV Database) | The data set listed in 5.10. | Separate consent of the data subject |
| Occupational health service provider | Occupational health data | Legal obligation (Mvt.) |
| OTP Bank Nyrt. | Bank-account and payment data | Performance of contract |
| Hessyn Szoftver Informatikai Kft. / RLB-60 Bt. | Payroll settlement data | Processor (DPA) |
| KBOSS.hu Kft. (Számlázz.hu) | Invoicing data | Processor (DPA) |
12. § Processors and sub-processors
T-Cloud Solutions Kft. (as the Controller’s processor) engages the following sub-processors. It notifies the Controller before engaging a new sub-processor.
| # | Company | Registered seat | Activity |
|---|---|---|---|
| 1 | T-Cloud Solutions Kft. | 1117 Budapest, Dombóvári út 9., 4th floor | Software development, operation |
| 2 | DigitalOcean, LLC | Broomfield, CO, USA | Hosting, file storage (Spaces) |
| 3 | Cloudflare, Inc. | San Francisco, USA | DNS, CDN, WAF |
| 4 | Anthropic PBC | San Francisco, USA | AI (Claude) |
| 5 | Google LLC / Google Ireland Ltd. | Mountain View, USA / Dublin, IE | AI (Gemini), FCM, OAuth, Maps, Analytics, reCAPTCHA |
| 6 | Apple Inc. | Cupertino, USA | App Store, Sign In, APNs |
| 7 | Microsoft Ireland Operations Ltd. | Dublin, IE | Office 365 |
| 8 | Microsoft Corporation | Redmond, USA | Clarity behaviour analytics (website only, with consent) |
| 9 | Meta Platforms Ireland Ltd. | Dublin, IE | Meta Pixel (website only, with marketing consent) |
| 10 | Mailjet SAS (Sinch Group) | Paris, FR | Transactional and marketing e-mail |
| 11 | SeeMe Solutions Kft. (smsapi.hu) | Budapest | SMS gateway |
| 12 | Wiredsign Zrt. | Diósjenő | Electronic signature |
| 13 | FreeTSA | Germany | RFC 3161 timestamping |
| 14 | Hessyn Szoftver Informatikai Kft. | Budapest | Payroll software |
| 15 | RLB-60 Bt. | Hatvan | Payroll software |
| 16 | FireBird Foundation z.s. | Prague, CZ | Database software |
| 17 | KBOSS.hu Kft. (Számlázz.hu) | Budapest | Invoicing |
| 18 | OTP Bank Nyrt. | Budapest | Banking transactions |
| 19 | Operator of the Cégadat API | Budapest | Company-registry query |
| 20 | Opten Kft. | Budapest | Company data and risk information |
| 21 | Canva Pty Ltd. | Sydney, Australia | Design tool (marketing) |
| 22 | MiniCRM Zrt. | Budapest | Internal CRM |
| 23 | Profession.hu (DBH-Group) | Budapest | Recruitment channel |
| 24 | tárhely.eu Kft. | Budapest | Static website hosting |
| 25 | Capgo | Being confirmed | Mobile application updates (OTA) — in the student app |
13. § Retention periods — summary
| Data category | Period | Basis |
|---|---|---|
| Registration without e-mail address confirmation | 90 days | internal policy |
| Inactive account | 2 years | internal policy |
| Active membership, membership data | Relationship + 5 years | limitation period under the Civil Code (Ptk.) |
| Accounting vouchers | 8 years | Szvt. § 169 |
| Payroll source data | 50 years | Tny. § 99/A |
| Occupational health data | End of employment + 30 years | Mvt. § 64(1) |
| Student ID and enrolment certificate photograph | 7 days after the employment notification | internal policy |
| Application (ATS) | 60 days | internal policy |
| CV Database (Open to Work) | Until withdrawal, max. 2 years | consent |
| E-mail and SMS logs | 24 months | internal policy |
| Log of AI conversations | 24 months | internal policy |
| Detailed event log | 90 days | internal policy |
| Login and session | 30 days | internal policy |
| Financial audit log | 5 years | accountability |
| Signature image and signature metadata | 5 years / as an accounting voucher 8 years | Ptk. / Szvt. |
| Backup | 7 days | internal policy |
| Cookies and local storage | individual, see Section 6 | — |
14. § Data security measures
- Encryption: TLS 1.2+ for all communication; AES-256 encryption at rest on the databases and the file storage.
- Access control: role-based access control (RBAC), two-factor login on the staff interface, password hashing (bcrypt); private documents are accessible only through expiring, signed links.
- Logging and audit: every material change is audit-logged, recording the old and the new value.
- Backup: daily backup with a 7-day recovery point; restoration only with the approval of an executive officer.
- Network protection: Cloudflare WAF and DDoS protection, reCAPTCHA on forms, rate limiting.
- Human factor: contractual confidentiality obligation, annual data-protection training for staff members who have access.
15. § Data-subject rights and how to exercise them
You have the following rights. You may exercise your rights against any of the joint controllers, through the single point of contact. We provide our response within 1 month; in justified cases this may be extended by a further 2 months, of which we notify you in advance. Fulfilling a request is free of charge; where a request is manifestly unfounded or excessive, we may charge a fee or refuse to act on it (Article 12(5) GDPR).
| Right | Article | How to exercise it |
|---|---|---|
| Access and a copy | 15 | [email protected]; a self-service data export (JSON) is also available in the TudatOS Karrier mobile application |
| Rectification | 16 | Most data can be corrected directly in the profile; otherwise [email protected] |
| Erasure (right to be forgotten) | 17 | Account deletion in the TudatOS Karrier mobile application (with signed confirmation), or [email protected] |
| Restriction of processing | 18 | [email protected] |
| Data portability | 20 | Machine-readable export (JSON) — as for access |
| Objection | 21 | [email protected] — against processing based on legitimate interest (5.12., 5.13., 5.14.) |
| Withdrawal of consent | Article 7(3) | In the profile settings (newsletter, CV Database, AI processing), using the unsubscribe link at the bottom of messages, or at [email protected]. Withdrawal does not affect the lawfulness of the earlier processing |
| Rights related to automated decision-making | 22 | The Request human review function, or [email protected] |
| Complaint to the supervisory authority | 77 | NAIH — see Section 17 |
| Judicial remedy | 79 | The regional court competent for your place of residence (birosag.hu/torvenyszekek) |
What happens on erasure: data subject to statutory retention (pay, accounting vouchers, occupational health certificates, employment notifications) must be retained by us until the statutory deadline — we store these separately, with restricted access, and use them exclusively for the statutory purpose. All other data is deleted or irreversibly anonymised, and the files (CV, documents) are physically deleted as well.
Suppression list after erasure: we add the deleted e-mail address — that single item of data, in technical form — to a suppression list. This is needed precisely so that we can give effect to your erasure request: without it, a later import or sign-up would bring your address back and you would receive mail again. The legal basis is Article 17(3) GDPR (limits on the right to erasure, for the establishment of legal claims and compliance with a legal obligation) together with Article 6(1)(c), read with Section 6(5) of the Hungarian Advertising Act (Grt.), which requires a register of advertising opt-outs. We use the suppression list for no other purpose, and on request we will confirm whether you are on it.
Deceased data subject: upon presentation of the death certificate and proof of identity, a close relative within the meaning of the Civil Code (Ptk.) may exercise the data-subject rights within 5 years of the death (Act LIII of 2018 §§ 25/G–25/J).
16. § Personal data breach
(1) On detecting a breach we inform NAIH without undue delay, but at the latest within 72 hours (Article 33 GDPR).
(2) Where the breach is likely to result in a high risk to the rights and freedoms of data subjects, we also notify the data subjects directly (Article 34 GDPR), describing in plain terms what happened and what they should do.
(3) We keep an internal register of breaches: the categories and number of data subjects affected, the time, the circumstances, the effects, and the measures taken.
(4) If a breach occurs at one of our processors, the contract obliges them to notify us without delay.
17. § Supervisory authority
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address: 1055 Budapest, Falk Miksa u. 9–11. · Postal address: 1363 Budapest, P.O. Box 9.
Phone: +36 1 391 1400 · E-mail: [email protected] · Web: naih.hu
Before you lodge a complaint, we are happy to help: [email protected].
18. § Final provisions — version control
(1) The Controller reserves the right to amend this notice unilaterally, in particular in the event of a change in legislation. We inform data subjects of material changes in advance, through the main communication channel (e-mail, the application login screen, the website header).
(2) On their first login after a new version takes effect, the user confirms that they have read the notice; the time of this, the version number, the IP address and the browser characteristics are logged. The notice is not to be accepted but to be read and understood — acceptance applies to the terms of service (ÁSZF).
(3) The earlier versions (v2026-07-06, v2026-05-01, 2025-08-01, 2025-05-01) are kept in an archive and are available on request.
(4) Version v2026-08-01 of this notice is effective from 1 August 2026.