PRIVACY NOTICE
The purpose of this notice is to provide you with relevant information and to set out the data protection and data processing policy of Data-Vita Kft. (hereinafter: the “Company”). Our goal is to comply with applicable regulations in our data processing, so that every one of our clients can confidently entrust us with their data.
Data protection is extremely important to us, and we want to ensure transparency regarding how we collect your personal data and how we process it. Please read this notice, and if you have any questions, feel free to contact us at info@data-vita.com.
1) Definitions
- “Personal data”: any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
- “Data processing”: any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
- “Data controller”: the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
- “Data processor”: the natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.
- “The data subject’s consent”: any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.
- “Objection”: a statement by the data subject in which they object to the processing of their personal data and request that the processing be terminated and/or the processed data be erased.
- “Personal data breach”: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
- “Biometric data”: personal data resulting from specific technical processing relating to the physical, physiological, or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic (fingerprint) data.
- “Health data”: personal data related to the physical or mental health of a natural person, including the provision of healthcare services to that person, which reveal information about their health status.
2) Data processing principles
In processing your data, our Company follows the principles below:
- We process your personal data in accordance with this privacy notice and the applicable statutory provisions.
- We make every reasonable effort to keep the processing of your personal data transparent, and we are available at any time to answer any questions you may have.
- We collect personal data only for specified, explicit, and legitimate purposes, and do not process it in a manner incompatible with those purposes. The personal data we collect and process is adequate, relevant, and limited to what is necessary in relation to the purposes of the processing. We store personal data in a form which permits identification of you for no longer than is necessary for the purposes for which the personal data is processed.
- Our Company takes every reasonable step to ensure that the data we process is accurate and, where necessary, kept up to date; inaccurate personal data is erased or corrected without delay.
- Through the use of appropriate technical and organizational measures, we ensure adequate security of personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage.
3) Purpose and legal basis for processing personal data
Our Company processes your personal data as follows:
- On the basis of your prior, informed, and voluntary consent, and only to the extent necessary and always tied to a specific purpose — that is, we collect, record, organize, store, and use it accordingly;
- In certain cases, the processing of your data is based on statutory requirements and is mandatory; in such cases we specifically draw your attention to this fact;
- In certain other cases, the processing of your personal data is based on a legitimate interest of our Company or of a third party — for example, the operation, development, and security of our website;
- We do not knowingly collect any personal data from children under 18. If you are under 16, please do not provide any personal data through the app. If you have reason to believe that a child under 16 has provided us with personal data through the app, please contact us and request that we delete that child’s personal data from our records. We encourage parents and legal guardians to monitor their children’s internet use and to help enforce this privacy notice by instructing their children never to provide personal data through the app without their permission.
This Privacy Notice applies solely to the information/data collected in connection with our services.
4) Purpose of the processing
| Name of processing | Purpose of processing | Legal basis | Data processed | Data retention period |
| Registration, contact | Promotion, updates on the app (updates, new features or content), educational materials, and amendments to the Terms & Conditions / Privacy Notice | Data subject’s voluntary consent, GDPR Art. 6(1)(a) | Username, name, e-mail address, phone number, password | 2 years from the last contact |
| Newsletter | Marketing communications | Data subject’s voluntary consent, GDPR Art. 6(1)(a) | Name, e-mail address | Until the data subject unsubscribes |
| Downloading and using the app | Ensuring the usability and stability of the application in order to provide the service | GDPR Art. 6(1)(b) | IP address | Deleted 2 years after use of the app |
| Ensuring the usability and stability of the application | GDPR Art. 6(1)(f) | Deleted 2 years after use of the app | ||
| Social media | Contact requests, communication, tracking (e.g. interest/behavioral profiling, use of cookies), remarketing, reach measurement (e.g. access statistics, recognizing returning visitors) | GDPR Art. 6(1)(f) | Registration data (e.g. names, addresses), contact details (e-mail, phone numbers), content data (e.g. text posts, photos, videos), usage data (e.g. websites visited, content interests, access times), meta/communication data (e.g. device information, IP addresses) | |
| Data transfer: Facebook, Google Ads, Meta Ads, etc. | ||||
| Processing related to push messages | Using the app allows you to receive push notifications related to your account or to certain functions of the app | Data subject’s voluntary consent, GDPR Art. 6(1)(a) | Until consent is withdrawn | |
| Invoicing | Fulfillment of accounting obligations | Fulfillment of a legal obligation, GDPR Art. 6(1)(c) | Name, e-mail address, home address | 8 years |
Our Company may analyze anonymous and potentially aggregated data provided by customers. Typical customer purposes include: understanding and improving services, developing new services, and achieving other legitimate business purposes.
If you have any questions regarding the data processing, you may request further information at info@data-vita.com or by post at our mailing address. We will send our response, where possible, within 1 week (but no later than within 1 month) to the contact details you provided.
5) Information about the website – cookies and tracking
What are cookies?
Cookies are small data files (hereinafter: “cookies”) that reach your computer through the website, as it is used, in such a way that your internet browser saves and stores them on your computer’s hard drive. The main purpose of cookies is to identify users and thereby create customized web pages, or to save the website’s login data so that you can conveniently log in again later. Most commonly used internet browsers (Chrome, Firefox, etc.) accept and allow the downloading and use of cookies by default; it is up to you whether you refuse or disable them by changing your browser settings, and you can also delete cookies already stored on your computer. More information on the use of cookies is available in the “help” section of each browser, and further information can be found at http://www.cookiecentral.com. There are cookies that do not require your prior consent. You will receive brief information about these upon your first visit to the website — examples include multimedia-player, load-balancing, or user-centered security cookies. Regarding cookies that require consent — where the processing already begins upon visiting the site — you are informed and asked for your consent when you first visit. Accepting cookies is not mandatory, but without allowing cookies, websites may not function as expected.
Use of Google Analytics and Google AdWords
Google Analytics is primarily used to generate statistics, including measuring the effectiveness of campaigns. Using Analytics makes it possible to obtain information about how many visitors have visited the website and how much time visitors spent on it. The program recognizes the visitor’s IP address, so it can track whether a visitor is a returning or a new visitor, and it can also track the path the visitor took through the website and where they entered.
Google AdWords is an advertising service for businesses that want to display ads on Google and on Google’s advertising network. Remarketing is an AdWords service that allows marketers to show ads to users who have previously visited their website. In advertising campaigns, it is common to measure ad effectiveness using Google AdWords, in which case Google AdWords data is collected in addition to the usual Google Analytics data. According to Google, these cookies only record information that is unsuitable for personal identification. We inform you that the settings and use of Google Analytics and Google AdWords fully comply with the requirements of the data protection authority. Further information can be found here: Google’s privacy policy. Users have the option to disable future cookie data recording and storage at any time, as described below.
Disabling cookies
If you would like to manage, modify, or disable cookie settings, you can do so from your own computer in your browser. Cookie settings can be found depending on your browser’s toolbar (Internet Explorer here, Google Chrome here, Mozilla Firefox here, Safari here). Through these links you can set which tracking functions are allowed/disabled on your computer. Website visitors who do not want Google Analytics to report on their visit can install the Google Analytics opt-out browser add-on. This add-on instructs Google Analytics JavaScript scripts (ga.js, analytics.js, and dc.js) not to send visit information to Google. In addition, visitors who have installed the opt-out browser add-on will also not take part in content experiments. If you would like to disable Analytics’ web activity tracking, visit the Google Analytics opt-out page and install the add-on for your browser. For further information on installing and removing the add-on, please refer to the help section of your particular browser.
6) Data occurring in the app
If you use our application, we may also store the following information, provided you choose to grant us access or permission to it:
- Geolocation: In order to provide certain location-based services, we may request access or permission to track location-based information from your mobile device, either continuously or while using our app. If you would like to change our access or permissions, you can do so in your device settings.
- Device access: We may request access or permission to certain features of your mobile device, including your device’s Bluetooth, calendar, contacts, microphone, reminders, and other functions. If you would like to change our access or permissions, you can do so in your device settings.
- Device information: We automatically collect information about the device (such as the mobile device identifier, model, and manufacturer), the operating system used, version information and system configuration information, device and application ID numbers, browser type and version, hardware model, internet service provider and/or mobile carrier. If you use our app, we may collect information about the mobile network associated with your device, the mobile device’s operating system or platform, the type of mobile device used, your mobile device’s unique device identifier and related information, and the features of the app that you use.
- Push notifications: You may request push notifications related to your account or to certain functions of the app. If you wish to unsubscribe from receiving this type of notification, you can turn them off in your device settings. This information is required primarily to maintain the security and functioning of the app, for troubleshooting, and for our internal analysis and reporting purposes.
All personal data you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal data.
7) Data transfer
We may only transfer your data within the framework defined by law, and in the case of our data processors, we ensure — by stipulating contractual terms — that they may not use your personal data for purposes contrary to your consent. Further information can be found in Section 9. Our Company may only transfer data abroad in accordance with the relevant provisions of the GDPR and the Hungarian Information Act (Infotv.). Courts, prosecutors’ offices, and other authorities (e.g., the police, the tax authority, the National Authority for Data Protection and Freedom of Information) may contact our Company requesting information, disclosure of data, or provision of documents. In such cases, we must fulfill our data-disclosure obligations, but only to the extent strictly necessary to achieve the purpose of the request.
8) Data processors
The Controller is entitled to engage data processors in carrying out its activities. Data processors do not make independent decisions; they are only authorized to act in accordance with the contract concluded with the Controller and the instructions received. The Controller supervises the work of the data processors. Data processors may only engage further sub-processors with the Controller’s consent.
Data processors used by the Controller:
DATA PROCESSING ACTIVITY RELATED TO WEB HOSTING SERVICES
Data processor’s name:
Rackhost Zrt.
Data processor’s registered office:
6722 Szeged, Tisza Lajos körút 41.
Tax number:
25333572-2-06
Data processor’s phone number:
+36 1 445 1200
Data processor’s e-mail address:
info@rackhost.hu
Processing of all personal data provided by the data subject on the website, for the purpose of ensuring the proper operation of the website.
Duration of processing / data deletion deadline: Lasts until the agreement between the Service Provider and the Hosting Provider is terminated, or until the data subject submits a deletion request to the Hosting Provider.
DATA PROCESSING ACTIVITY RELATED TO GOOGLE ANALYTICS AGGREGATE DATA ANALYSIS
Data processor’s name:
Google, Mountain View, California, United States
Data processor’s registered office:
Ireland, Dublin, Barrow Street 4
Based on the agreement concluded with the Controller, the Processor uses the Google Analytics service, which helps both the Controller and the Processor gain a more accurate picture of their visitors’ activities.
Data processor’s name:
SalesAutopilot Kft.
Data processor’s registered office:
1016 Budapest, Zsolt utca 6/A. V. em. 1.
Data processor’s tax number:
25743500-2-41
Data processor’s phone number:
(+36) 1 490-0172
Data processor’s e-mail address:
info@salesautopilot.hu
Data processing for promotional purposes, informing users about new features and content of the application.
Data processor’s name:
FireBase (Google LLC)
Data processor’s registered office:
1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Data processor’s tax number:
770493581
Data processor’s phone number:
(+800) 829-4933
Data processor’s e-mail address:
privacyofficer@google.com
Provides online storage for the mobile application.
Data processor’s name:
RudderStack Inc.
Data processor’s registered office:
548 Market St Pmb 48141, San Francisco, California, 94104-5401, US
Data processor’s phone number:
(+669) 292-6948
Data processor’s e-mail address:
contact@rudderstack.com
All data collected during tracking is sent to the RudderStack data platform. Identification is carried out using an anonymous UUID; there is no logged-in user, since the app does not (currently) manage user accounts. If the user deletes the app, a new identifier is generated if they download the app again.
The data arriving here is analyzed or used through the following additional platforms/providers:
Data processor’s name:
AppsFlyer Inc.
Data processor’s registered office:
100 First Street, Suite 2500, San Francisco, CA, 94105, USA
Data processor’s tax number:
471748089
Data processor’s phone number:
(+415) 636-94301
Data processor’s e-mail address:
privacy@appsflyer.com
A cloud-based mobile attribution and marketing analytics tool, allowing us to measure the performance of our advertising campaigns.
Data processor’s name:
Mixpanel Inc.
Data processor’s registered office:
USA, San Francisco, One Front Street, 1 Front St 28th Floor
Data processor’s tax number:
270231379
Data processor’s phone number:
(+888) 510-2370
Data processor’s e-mail address:
support@mixpanel.com
A product analytics platform that allows us to better understand customer behavior in the app and on the website. Among other things, we use it to measure customer activity, customer value, and customer engagement. Mixpanel applies GDPR-compliant data protection standards and allows users to review the data Mixpanel collects about them.
9) Data security
Our Company’s associates and employees involved in data processing and handling are authorized — subject to a duty of confidentiality — to access your personal data only to a predetermined extent.
We protect your personal data with appropriate technical and other measures, and we ensure the security and availability of the data, safeguarding it against unauthorized access, alteration, damage, disclosure, and any other unauthorized use.
As part of our organizational measures, we continuously train our employees. In our office, we control physical access and keep paper-based documents securely locked away. As part of our technical measures, we use encryption, password protection, and anti-virus software. However, we draw your attention to the fact that data transmission over the internet cannot be considered completely secure. Our Company makes every effort to make these processes as secure as possible; however, we cannot accept full responsibility for data transmission through our website, though with regard to data received by our Company, we adhere to strict rules to ensure the security of your data and to prevent unlawful access.
10) Rights related to data processing
- The right to request information: Any person may, through the contact details provided, request information about which of their data the organization processes, on what legal basis, for what purpose, from what source, and for how long. Upon such a request, the information must be sent to the contact details provided without delay, but within 30 days at the latest.
- The right to rectification: Any person may, through the contact details provided, request the correction of any of their data. This must be arranged without delay upon request, but within 30 days at the latest, and information must be sent to the contact details provided.
- The right to erasure: Any person may, through the contact details provided, request the deletion of their data. Upon request, this must be done without delay, but within 30 days at the latest, and information must be sent to the contact details provided.
- Data that we are required to retain due to a legal, statutory, or contractual obligation for the purposes of maintaining commercial records will, instead of being deleted, be restricted (locked) to prevent their use for any other purpose.
- The right to restriction: Any person may, through the contact details provided, request the restriction of their data. The restriction lasts as long as the stated reason makes retention of the data necessary. This must be done without delay upon request, but within 30 days at the latest, and information must be sent to the contact details provided.
- The right to object: Any person may, through the contact details provided, object to the processing of their data. The objection must be examined within the shortest possible time from submission of the request, but within 15 days at the latest; a decision must be made on its merits, and the decision communicated to the contact details provided.
Upon your request, we will inform you about:
- your data processed by us or processed by us (or by our appointed data processor);
- the source of that data;
- the purpose and legal basis of the processing;
- its duration, or, if that is not possible, the criteria used to determine that duration;
- the name, address, and data-processing-related activities of our data processors;
- he circumstances and effects of any data protection incidents, and the measures taken to remedy and prevent them; and
- in the case of transfer of your personal data, the legal basis and recipient of the transfer.
We will provide this information within the shortest possible time from submission of the request, where possible within 1 week (but no later than within 1 month). The information is provided free of charge, except where you have already submitted a request for information regarding the same set of data in the current year. Any cost reimbursement you have already paid will be refunded if we processed the data unlawfully or if the request for information led to a correction. We may only refuse to provide information in cases specified by law, citing the relevant legal provision, and informing you of the possibility of judicial remedy or of turning to the Authority. Our Company will notify you, as well as all those to whom the data was previously transferred for processing purposes, of any rectification, restriction, marking, or deletion of personal data, unless such notification would not infringe your legitimate interest by its omission.
If we do not fulfill your request for rectification, restriction, or erasure, we will, within 1 week of receiving the request (but no later than within 1 month), communicate the reasons for our refusal in writing or — with your consent — electronically, and inform you of the possibility of judicial remedy and of turning to the Authority. If you object to the processing of your personal data, we will examine the objection within the shortest possible time from submission of the request, within 1 week (but no later than within 1 month), and inform you of our decision in writing. If we determine that your objection is well-founded, we will terminate the processing — including any further data collection and transfer — and restrict (lock) the data, and we will notify all those to whom the personal data concerned by the objection was previously transferred, and who are obliged to take action to give effect to the right to object, of the objection and the measures taken as a result.
We will refuse to comply with the request if we can demonstrate that the processing is justified by compelling legitimate grounds which override your interests, rights, and freedoms, or which relate to the establishment, exercise, or defense of legal claims. If you disagree with our decision, or if we fail to meet the deadline, you may turn to a court within 30 days of the communication of the decision or of the last day of the deadline.
Data protection litigation falls within the jurisdiction of the regional court (törvényszék); the action may, at the choice of the data subject, be brought before the regional court of the data subject’s place of residence or stay. Foreign nationals may also file a complaint with the supervisory authority competent for their place of residence. We ask that, before turning to the supervisory authority or a court with your complaint, you first contact our Company — in the interest of consultation and the fastest possible resolution of any issue that has arisen.
11) Legal remedies related to data processing
National Authority for Data Protection and Freedom of Information (NAIH)
- Postal address: 1530 Budapest, Pf.: 5.
- Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c
- Phone: +36 (1) 391-1400
- Fax: +36 (1) 391-1410
- E-mail: ugyfelszolgalat@naih.hu
- Web: https://naih.hu
12) Main legislation governing our activities
- Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data (GDPR)
- Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information (“Infotv.”)
- Act V of 2013 on the Civil Code (“Ptk.”)
- Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services (“Eker tv.”)
- Act C of 2003 on Electronic Communications (“Ehtv”)
- Act CLV of 1997 on Consumer Protection (“Fogyv tv.”)
- Act CLXV of 2013 on Complaints and Public Interest Disclosures (“Pktv.”)
- Act XLVIII of 2008 on the Basic Conditions and Certain Limitations of Commercial Advertising Activity (“Grtv.”)
On matters not covered by this notice, the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), as well as those of Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information (“Infotv.”), shall govern.
13) Review of the Privacy Notice
This Privacy Notice will be reviewed as necessary. Our Company reserves the right to amend the Notice, and will inform data subjects accordingly in an appropriate manner.
Date of publication:
Szeged, December 1, 2023.
Jelenleg amúgy appon belüli lokális notifikáció van, ami nem ugyan az mint a push értesítés. Nem tudom arról kell-e írni. Pl. napi idézetet megjeleníti a telefon ha valaki beállítja az appon belül.
PRIVACY NOTICE
The purpose of this notice is to provide you with relevant information and to set out the data protection and data processing policy of Data-Vita Kft. (hereinafter: the “Company”). Our goal is to comply with applicable regulations in our data processing, so that every one of our clients can confidently entrust us with their data.
Data protection is extremely important to us, and we want to ensure transparency regarding how we collect your personal data and how we process it. Please read this notice, and if you have any questions, feel free to contact us at info@data-vita.com.
1) Definitions
- “Personal data”: any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
- “Data processing”: any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
- “Data controller”: the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
- “Data processor”: the natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.
- “The data subject’s consent”: any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.
- “Objection”: a statement by the data subject in which they object to the processing of their personal data and request that the processing be terminated and/or the processed data be erased.
- “Personal data breach”: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
- “Biometric data”: personal data resulting from specific technical processing relating to the physical, physiological, or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic (fingerprint) data.
- “Health data”: personal data related to the physical or mental health of a natural person, including the provision of healthcare services to that person, which reveal information about their health status.
2) Data processing principles
In processing your data, our Company follows the principles below:
- We process your personal data in accordance with this privacy notice and the applicable statutory provisions.
- We make every reasonable effort to keep the processing of your personal data transparent, and we are available at any time to answer any questions you may have.
- We collect personal data only for specified, explicit, and legitimate purposes, and do not process it in a manner incompatible with those purposes. The personal data we collect and process is adequate, relevant, and limited to what is necessary in relation to the purposes of the processing. We store personal data in a form which permits identification of you for no longer than is necessary for the purposes for which the personal data is processed.
- Our Company takes every reasonable step to ensure that the data we process is accurate and, where necessary, kept up to date; inaccurate personal data is erased or corrected without delay.
- Through the use of appropriate technical and organizational measures, we ensure adequate security of personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage.
3) Purpose and legal basis for processing personal data
Our Company processes your personal data as follows:
- On the basis of your prior, informed, and voluntary consent, and only to the extent necessary and always tied to a specific purpose — that is, we collect, record, organize, store, and use it accordingly;
- In certain cases, the processing of your data is based on statutory requirements and is mandatory; in such cases we specifically draw your attention to this fact;
- In certain other cases, the processing of your personal data is based on a legitimate interest of our Company or of a third party — for example, the operation, development, and security of our website;
- We do not knowingly collect any personal data from children under 18. If you are under 16, please do not provide any personal data through the app. If you have reason to believe that a child under 16 has provided us with personal data through the app, please contact us and request that we delete that child’s personal data from our records. We encourage parents and legal guardians to monitor their children’s internet use and to help enforce this privacy notice by instructing their children never to provide personal data through the app without their permission.
This Privacy Notice applies solely to the information/data collected in connection with our services.
4) Purpose of the processing
| Name of processing | Purpose of processing | Legal basis | Data processed | Data retention period |
| Registration, contact | Promotion, updates on the app (updates, new features or content), educational materials, and amendments to the Terms & Conditions / Privacy Notice | Data subject’s voluntary consent, GDPR Art. 6(1)(a) | Username, name, e-mail address, phone number, password | 2 years from the last contact |
| Newsletter | Marketing communications | Data subject’s voluntary consent, GDPR Art. 6(1)(a) | Name, e-mail address | Until the data subject unsubscribes |
| Downloading and using the app | Ensuring the usability and stability of the application in order to provide the service | GDPR Art. 6(1)(b) | IP address | Deleted 2 years after use of the app |
| GDPR Art. 6(1)(f) | Deleted 2 years after use of the app | |||
| Social media | Contact requests, communication, tracking (e.g. interest/behavioral profiling, use of cookies), remarketing, reach measurement (e.g. access statistics, recognizing returning visitors) | GDPR Art. 6(1)(f) | Registration data (e.g. names, addresses), contact details (e-mail, phone numbers), content data (e.g. text posts, photos, videos), usage data (e.g. websites visited, content interests, access times), meta/communication data (e.g. device information, IP addresses) | |
| Data transfer: Facebook, Google Ads, Meta Ads, etc. | ||||
| Processing related to push messages | Using the app allows you to receive push notifications related to your account or to certain functions of the app | Data subject’s voluntary consent, GDPR Art. 6(1)(a) | Until consent is withdrawn | |
| Invoicing | Fulfillment of accounting obligations | Fulfillment of a legal obligation, GDPR Art. 6(1)(c) | Name, e-mail address, home address | 8 years |
Our Company may analyze anonymous and potentially aggregated data provided by customers. Typical customer purposes include: understanding and improving services, developing new services, and achieving other legitimate business purposes.
If you have any questions regarding the data processing, you may request further information at info@data-vita.com or by post at our mailing address. We will send our response, where possible, within 1 week (but no later than within 1 month) to the contact details you provided.
5) Information about the website – cookies and tracking
What are cookies?
Cookies are small data files (hereinafter: “cookies”) that reach your computer through the website, as it is used, in such a way that your internet browser saves and stores them on your computer’s hard drive. The main purpose of cookies is to identify users and thereby create customized web pages, or to save the website’s login data so that you can conveniently log in again later. Most commonly used internet browsers (Chrome, Firefox, etc.) accept and allow the downloading and use of cookies by default; it is up to you whether you refuse or disable them by changing your browser settings, and you can also delete cookies already stored on your computer. More information on the use of cookies is available in the “help” section of each browser, and further information can be found at http://www.cookiecentral.com. There are cookies that do not require your prior consent. You will receive brief information about these upon your first visit to the website — examples include multimedia-player, load-balancing, or user-centered security cookies. Regarding cookies that require consent — where the processing already begins upon visiting the site — you are informed and asked for your consent when you first visit. Accepting cookies is not mandatory, but without allowing cookies, websites may not function as expected.
Use of Google Analytics and Google AdWords
Google Analytics is primarily used to generate statistics, including measuring the effectiveness of campaigns. Using Analytics makes it possible to obtain information about how many visitors have visited the website and how much time visitors spent on it. The program recognizes the visitor’s IP address, so it can track whether a visitor is a returning or a new visitor, and it can also track the path the visitor took through the website and where they entered.
Google AdWords is an advertising service for businesses that want to display ads on Google and on Google’s advertising network. Remarketing is an AdWords service that allows marketers to show ads to users who have previously visited their website. In advertising campaigns, it is common to measure ad effectiveness using Google AdWords, in which case Google AdWords data is collected in addition to the usual Google Analytics data. According to Google, these cookies only record information that is unsuitable for personal identification. We inform you that the settings and use of Google Analytics and Google AdWords fully comply with the requirements of the data protection authority. Further information can be found here: Google’s privacy policy. Users have the option to disable future cookie data recording and storage at any time, as described below.
Disabling cookies
If you would like to manage, modify, or disable cookie settings, you can do so from your own computer in your browser. Cookie settings can be found depending on your browser’s toolbar (Internet Explorer here, Google Chrome here, Mozilla Firefox here, Safari here). Through these links you can set which tracking functions are allowed/disabled on your computer. Website visitors who do not want Google Analytics to report on their visit can install the Google Analytics opt-out browser add-on. This add-on instructs Google Analytics JavaScript scripts (ga.js, analytics.js, and dc.js) not to send visit information to Google. In addition, visitors who have installed the opt-out browser add-on will also not take part in content experiments. If you would like to disable Analytics’ web activity tracking, visit the Google Analytics opt-out page and install the add-on for your browser. For further information on installing and removing the add-on, please refer to the help section of your particular browser.
6) Data occurring in the app
If you use our application, we may also store the following information, provided you choose to grant us access or permission to it:
- Geolocation: In order to provide certain location-based services, we may request access or permission to track location-based information from your mobile device, either continuously or while using our app. If you would like to change our access or permissions, you can do so in your device settings.
- Device access: We may request access or permission to certain features of your mobile device, including your device’s Bluetooth, calendar, contacts, microphone, reminders, and other functions. If you would like to change our access or permissions, you can do so in your device settings.
- Device information: We automatically collect information about the device (such as the mobile device identifier, model, and manufacturer), the operating system used, version information and system configuration information, device and application ID numbers, browser type and version, hardware model, internet service provider and/or mobile carrier. If you use our app, we may collect information about the mobile network associated with your device, the mobile device’s operating system or platform, the type of mobile device used, your mobile device’s unique device identifier and related information, and the features of the app that you use.
- Push notifications: You may request push notifications related to your account or to certain functions of the app. If you wish to unsubscribe from receiving this type of notification, you can turn them off in your device settings. This information is required primarily to maintain the security and functioning of the app, for troubleshooting, and for our internal analysis and reporting purposes.
All personal data you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal data.
7) Data transfer
We may only transfer your data within the framework defined by law, and in the case of our data processors, we ensure — by stipulating contractual terms — that they may not use your personal data for purposes contrary to your consent. Further information can be found in Section 9. Our Company may only transfer data abroad in accordance with the relevant provisions of the GDPR and the Hungarian Information Act (Infotv.). Courts, prosecutors’ offices, and other authorities (e.g., the police, the tax authority, the National Authority for Data Protection and Freedom of Information) may contact our Company requesting information, disclosure of data, or provision of documents. In such cases, we must fulfill our data-disclosure obligations, but only to the extent strictly necessary to achieve the purpose of the request.
8) Data processors
The Controller is entitled to engage data processors in carrying out its activities. Data processors do not make independent decisions; they are only authorized to act in accordance with the contract concluded with the Controller and the instructions received. The Controller supervises the work of the data processors. Data processors may only engage further sub-processors with the Controller’s consent.
Data processors used by the Controller:
DATA PROCESSING ACTIVITY RELATED TO WEB HOSTING SERVICES
Data processor’s name: Rackhost Zrt.
Data processor’s registered office: 6722 Szeged, Tisza Lajos körút 41.
Tax number: 25333572-2-06
Data processor’s phone number: +36 1 445 1200
Data processor’s e-mail address: info@rackhost.hu
Processing of all personal data provided by the data subject on the website, for the purpose of ensuring the proper operation of the website.
Duration of processing / data deletion deadline: Lasts until the agreement between the Service Provider and the Hosting Provider is terminated, or until the data subject submits a deletion request to the Hosting Provider.
DATA PROCESSING ACTIVITY RELATED TO GOOGLE ANALYTICS AGGREGATE DATA ANALYSIS
Data processor’s name: Google, Mountain View, California, United States
Data processor’s registered office: Ireland, Dublin, Barrow Street 4
Based on the agreement concluded with the Controller, the Processor uses the Google Analytics service, which helps both the Controller and the Processor gain a more accurate picture of their visitors’ activities.
Data processor’s name: SalesAutopilot Kft.
Data processor’s registered office: 1016 Budapest, Zsolt utca 6/A. V. em. 1.
Data processor’s tax number: 25743500-2-41
Data processor’s phone number: (+36) 1 490-0172
Data processor’s e-mail address: info@salesautopilot.hu
Data processing for promotional purposes, informing users about new features and content of the application.
Data processor’s name: FireBase (Google LLC)
Data processor’s registered office: 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Data processor’s tax number: 770493581
Data processor’s phone number: (+800) 829-4933
Data processor’s e-mail address: privacyofficer@google.com
Provides online storage for the mobile application.
Data processor’s name: RudderStack Inc.
Data processor’s registered office: 548 Market St Pmb 48141, San Francisco, California, 94104-5401, US
Data processor’s phone number: (+669) 292-6948
Data processor’s e-mail address: contact@rudderstack.com
All data collected during tracking is sent to the RudderStack data platform. Identification is carried out using an anonymous UUID; there is no logged-in user, since the app does not (currently) manage user accounts. If the user deletes the app, a new identifier is generated if they download the app again.
The data arriving here is analyzed or used through the following additional platforms/providers:
Data processor’s name: AppsFlyer Inc.
Data processor’s registered office: 100 First Street, Suite 2500, San Francisco, CA, 94105, USA
Data processor’s tax number: 471748089
Data processor’s phone number: (+415) 636-94301
Data processor’s e-mail address: privacy@appsflyer.com
A cloud-based mobile attribution and marketing analytics tool, allowing us to measure the performance of our advertising campaigns.
Data processor’s name: Mixpanel Inc.
Data processor’s registered office: USA, San Francisco, One Front Street, 1 Front St 28th Floor
Data processor’s tax number: 270231379
Data processor’s phone number: (+888) 510-2370
Data processor’s e-mail address: support@mixpanel.com
A product analytics platform that allows us to better understand customer behavior in the app and on the website. Among other things, we use it to measure customer activity, customer value, and customer engagement. Mixpanel applies GDPR-compliant data protection standards and allows users to review the data Mixpanel collects about them.
9) Data security
Our Company’s associates and employees involved in data processing and handling are authorized — subject to a duty of confidentiality — to access your personal data only to a predetermined extent.
We protect your personal data with appropriate technical and other measures, and we ensure the security and availability of the data, safeguarding it against unauthorized access, alteration, damage, disclosure, and any other unauthorized use.
As part of our organizational measures, we continuously train our employees. In our office, we control physical access and keep paper-based documents securely locked away. As part of our technical measures, we use encryption, password protection, and anti-virus software. However, we draw your attention to the fact that data transmission over the internet cannot be considered completely secure. Our Company makes every effort to make these processes as secure as possible; however, we cannot accept full responsibility for data transmission through our website, though with regard to data received by our Company, we adhere to strict rules to ensure the security of your data and to prevent unlawful access.
10) Rights related to data processing
- The right to request information: Any person may, through the contact details provided, request information about which of their data the organization processes, on what legal basis, for what purpose, from what source, and for how long. Upon such a request, the information must be sent to the contact details provided without delay, but within 30 days at the latest.
- The right to rectification: Any person may, through the contact details provided, request the correction of any of their data. This must be arranged without delay upon request, but within 30 days at the latest, and information must be sent to the contact details provided.
- The right to erasure: Any person may, through the contact details provided, request the deletion of their data. Upon request, this must be done without delay, but within 30 days at the latest, and information must be sent to the contact details provided.
- Data that we are required to retain due to a legal, statutory, or contractual obligation for the purposes of maintaining commercial records will, instead of being deleted, be restricted (locked) to prevent their use for any other purpose.
- The right to restriction: Any person may, through the contact details provided, request the restriction of their data. The restriction lasts as long as the stated reason makes retention of the data necessary. This must be done without delay upon request, but within 30 days at the latest, and information must be sent to the contact details provided.
- The right to object: Any person may, through the contact details provided, object to the processing of their data. The objection must be examined within the shortest possible time from submission of the request, but within 15 days at the latest; a decision must be made on its merits, and the decision communicated to the contact details provided.
Upon your request, we will inform you about:
- your data processed by us or processed by us (or by our appointed data processor);
- the source of that data;
- the purpose and legal basis of the processing;
- its duration, or, if that is not possible, the criteria used to determine that duration;
- the name, address, and data-processing-related activities of our data processors;
- he circumstances and effects of any data protection incidents, and the measures taken to remedy and prevent them; and
- in the case of transfer of your personal data, the legal basis and recipient of the transfer.
We will provide this information within the shortest possible time from submission of the request, where possible within 1 week (but no later than within 1 month). The information is provided free of charge, except where you have already submitted a request for information regarding the same set of data in the current year. Any cost reimbursement you have already paid will be refunded if we processed the data unlawfully or if the request for information led to a correction. We may only refuse to provide information in cases specified by law, citing the relevant legal provision, and informing you of the possibility of judicial remedy or of turning to the Authority. Our Company will notify you, as well as all those to whom the data was previously transferred for processing purposes, of any rectification, restriction, marking, or deletion of personal data, unless such notification would not infringe your legitimate interest by its omission.
If we do not fulfill your request for rectification, restriction, or erasure, we will, within 1 week of receiving the request (but no later than within 1 month), communicate the reasons for our refusal in writing or — with your consent — electronically, and inform you of the possibility of judicial remedy and of turning to the Authority. If you object to the processing of your personal data, we will examine the objection within the shortest possible time from submission of the request, within 1 week (but no later than within 1 month), and inform you of our decision in writing. If we determine that your objection is well-founded, we will terminate the processing — including any further data collection and transfer — and restrict (lock) the data, and we will notify all those to whom the personal data concerned by the objection was previously transferred, and who are obliged to take action to give effect to the right to object, of the objection and the measures taken as a result.
We will refuse to comply with the request if we can demonstrate that the processing is justified by compelling legitimate grounds which override your interests, rights, and freedoms, or which relate to the establishment, exercise, or defense of legal claims. If you disagree with our decision, or if we fail to meet the deadline, you may turn to a court within 30 days of the communication of the decision or of the last day of the deadline.
Data protection litigation falls within the jurisdiction of the regional court (törvényszék); the action may, at the choice of the data subject, be brought before the regional court of the data subject’s place of residence or stay. Foreign nationals may also file a complaint with the supervisory authority competent for their place of residence. We ask that, before turning to the supervisory authority or a court with your complaint, you first contact our Company — in the interest of consultation and the fastest possible resolution of any issue that has arisen.
11) Legal remedies related to data processing
National Authority for Data Protection and Freedom of Information (NAIH)
- Postal address: 1530 Budapest, Pf.: 5.
- Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c
- Phone: +36 (1) 391-1400
- Fax: +36 (1) 391-1410
- E-mail: ugyfelszolgalat@naih.hu
- Web: https://naih.hu
12) Main legislation governing our activities
- Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data (GDPR)
- Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information (“Infotv.”)
- Act V of 2013 on the Civil Code (“Ptk.”)
- Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services (“Eker tv.”)
- Act C of 2003 on Electronic Communications (“Ehtv”)
- Act CLV of 1997 on Consumer Protection (“Fogyv tv.”)
- Act CLXV of 2013 on Complaints and Public Interest Disclosures (“Pktv.”)
- Act XLVIII of 2008 on the Basic Conditions and Certain Limitations of Commercial Advertising Activity (“Grtv.”)
On matters not covered by this notice, the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), as well as those of Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information (“Infotv.”), shall govern.
13) Review of the Privacy Notice
This Privacy Notice will be reviewed as necessary. Our Company reserves the right to amend the Notice, and will inform data subjects accordingly in an appropriate manner.
Date of publication:
Szeged, December 1, 2023.