Quivra Labs Limited Liability Company

Privacy Policy

Regarding the "Legyen zöld!" lawn condition analysis application ("Service")

Last modified: 28 July 2026

This privacy notice summarises the processing activities carried out by Quivra Labs Limited Liability Company as data controller ("Data Controller") in connection with the operation of the mobile application named Legyen Zöld ("Service"). The purpose of the Service is to enable users to receive personalised lawn care recommendations, a calendar function, reminders, calculators, weather information and AI-based support by providing data about their lawn area. Please read this privacy notice carefully, and if you have any questions regarding the processing of your personal data, please contact the Data Controller at the contact details provided below.

Data Controller

Data Controller:
Quivra Labs Korlátolt Felelősségű Társaság
Registered office:
1063 Budapest, Szinyei Merse Pál utca 21. 1. em. 5. ajtó
Postal address:
1063 Budapest, Szinyei Merse Pál utca 21. 1. em. 5. ajtó
Company registration number:
Cg.01-09-453528
Tax number:
32996542-2-42
Represented by:
Balogh Árpád, managing director, acting independently
Email:
office@quivralabs.com
Application:
App Store: Legyen Zöld!Google Play: Legyen Zöld!

The Data Controller acts as an independent data controller with respect to personal data relating to the provision of the Service, the management of user accounts, the provision of lawn care functions, the operation of the AI assistant, the management of subscriptions and its own marketing activities. The Data Controller may, based on users' separate consent, send direct marketing electronic messages to users in connection with the Legyen Zöld! application, services, functions, offers, promotions and lawn care related content. Based on the user's separate consent, the Data Controller may transfer the user's name and email address to Pitch System Kft. so that Pitch System Kft. may, in its own name, send direct marketing electronic messages to the user in connection with its own lawn care products, services, content, offers, workshops, newsletter or other marketing communications. Pitch System Kft. acts as an independent data controller with respect to its own marketing communications, which means that it independently determines the manner and means of processing the personal data transferred to it for its own marketing purposes, and bears independent data protection responsibility for this activity. Pitch System Kft. provides detailed information about its own data processing in its own privacy notice. The legal basis for direct marketing processing is the data subject's consent pursuant to Article 6(1)(a) of the GDPR. The provision of consent is voluntary; its refusal or withdrawal does not affect the use of the basic functions of the Legyen Zöld! application. The data subject may withdraw consent at any time, without justification, in particular via the unsubscribe link in marketing messages or at the contact details of the sending data controller. Data processed: name, email address, fact, timestamp and source of consent, version of the consent statement, and fact and timestamp of unsubscribing.

Personal Data Processed

Processing activityCategories of data subjectsPurpose of processingLegal basisData processedTransfers / processorsRetention period
Registration and user account creationNatural persons registering for the ServiceCreating a user account, identifying the user, providing access to the Service, communication in connection with the account.Performance of a contract or pre-contractual steps pursuant to Article 6(1)(b) GDPR.Name, email address, user identifier, registration timestamp, account status.Hosting provider, lawn care professional partner, authentication and user account management provider.Until the user account exists; data is deleted upon account deletion, unless retention is required by legal obligation, legitimate interest or enforcement of legal claims.
Maintenance of inactive user accounts and enabling reactivationRegistered natural person users whose trial period expired without a subscription being concluded, or whose paid subscription has terminated or expired, but who have not deleted their user account.Limited maintenance of the user account, enabling repeated login to the account, displaying the status of the trial period or subscription, and facilitating the later reactivation of the Service without the user having to register again and re-enter the necessary data.Legitimate interest of the Data Controller in the continuity of user accounts, in serving returning users and in ensuring simple reactivation of the Service, pursuant to Article 6(1)(f) GDPR.Name, email address, user identifier, registration timestamp, account status, expiry date of the trial period or subscription, timestamp of last login, and the data strictly necessary for the later reactivation of the Service and the restoration of previous user settings.Hosting provider, authentication and user account management provider.Until the user deletes the user account, but no longer than 12 months following the expiry of the trial period or the subscription or - if later - the user's last login. Upon expiry of this period, the personal data linked to the account is deleted or - where possible - irreversibly anonymised, unless further retention of certain data is justified by a legal obligation or the establishment, exercise or defence of legal claims.
Email address verification with confirmation codeRegistering usersVerifying that the email address provided during registration is under the control of the user.Performance of a contract / pre-contractual steps pursuant to Article 6(1)(b) GDPR; legitimate interest in preventing abuse pursuant to Article 6(1)(f) GDPR.Email address, 6-digit confirmation code sent by email, timestamp of code generation and validity, verification status.Email sending provider, hosting provider.The confirmation code is valid for no more than 15 minutes from its generation, or until successful verification - whichever occurs earlier - after which it is deleted or permanently invalidated. Technical and security log data relating to the generation, sending and use of the code, to verification attempts and to their outcome is retained by the Data Controller for 90 days.
Login, authentication and session managementRegistered usersSecure login, maintaining active sessions, preventing unauthorised access.Performance of a contract pursuant to Article 6(1)(b) GDPR; legitimate interest for security logging pursuant to Article 6(1)(f) GDPR.Email address, user identifier, technical hash of password, session identifier, tokens, IP address, device and browser data, login timestamps, failed login attempts.Hosting provider, authentication and user account management provider, security provider.Login data - in particular the email address, the user identifier and the secure technical hash of the password - is retained until the user account exists. Session identifiers and authentication tokens are processed until logout, until their technical expiry or revocation, but no longer than 30 days from the last activity. Technical and security log data relating to logins, failed login attempts and other security events is retained by the Data Controller for 90 days. In the event of a security incident or dispute, the log data necessary for that purpose may be retained separately until the investigation of the incident or the enforceability of the legal claim is concluded, at most until the end of the applicable limitation period.
Prevention of abusive repeated use of the trial periodFormer users who used the trial period or deleted their accountsPreventing the same user from obtaining unlimited new trial periods after deleting their account.Legitimate interest of the Data Controller pursuant to Article 6(1)(f) GDPR. Legitimate interest: preventing abusive use of the Service and protecting the business model.Email address; upon deletion of the account, a cryptographic hash generated from the email address in a one-way manner using a secret key; the fact of previous use of the trial period.Hosting provider.For the predetermined period necessary to prevent trial period abuse, substantiated in the legitimate interest balancing test. Upon deletion of the account, the raw email address is deleted, and thereafter only the cryptographic hash generated from the email address in a one-way manner using a secret key, together with the fact of previous use of the trial period, is retained for 5 years from the deletion of the account. Upon expiry of this period, the Data Controller deletes the cryptographic hash and the data relating to the use of the trial period.
Lawn area / garden profile creation and managementUsers who create a lawn area or garden profile in the ServiceCreating a profile for the lawn area, providing personalised lawn care recommendations, calendar entries, reminders and AI support.Performance of a contract pursuant to Article 6(1)(b) GDPR.Municipality-level location data, address / garden address, or GPS coordinates / precise geolocation, area size, lawn installation date, lawn type (seeded lawn / turf), grass seed type, soil type, sun exposure, cultivation method, mowing method, irrigation method, other lawn data provided by the user.Hosting provider, lawn care professional partner, AI provider if the data is processed by AI.Until the user account exists or until the user deletes the given lawn area / garden profile.
Retrieval of weather and soil temperature information based on location dataUsers who create a lawn area and use the weather functionDisplaying weather, forecast and soil temperature information related to the user's lawn area.Performance of a contract pursuant to Article 6(1)(b) GDPR. Access to the device's location data takes place solely on the basis of the permission granted by the user in the device settings.The municipality or garden address provided by the user, or - if the user permits it - the GPS coordinates or precise location data determined by the device, location settings linked to the lawn area, technical data of weather queries.Weather data is retrieved from external data sources; however, no data attributable to the user is transferred to those providers.Location data until the lawn area or the user account exists, or until the user modifies or deletes the location data; technical log data of weather queries is retained by the Data Controller for 90 days from the query, after which it is deleted or irreversibly anonymised; aggregated statistical data that cannot be linked to the data subject may be retained without time limitation.
Personalised lawn care recommendations, dashboard indicators and automatic task schedulingRegistered usersGenerating personalised lawn care suggestions, tasks, reminders, dashboard indicators and automatically generated log files based on the user's lawn data, location, calendar data and activity log, and on the weather / soil temperature information related to the given lawn area.Performance of a contract pursuant to Article 6(1)(b) GDPR. If the recommendations also serve personalisation for marketing or product sales, a separate legal basis and notice are required. The processing does not involve solely automated decision-making within the meaning of Article 22 GDPR that produces legal effects or similarly significant effects.Lawn area data, municipality location data, address / garden address, or GPS coordinates / precise geolocation, garden data, calendar data, activity log, completed or planned lawn care tasks, applied nutrients, number of mowings, mowed area in m², blade condition, related dates and activity statuses, as well as the dashboard indicators and automatically generated calendar tasks derived therefromHosting provider.Until the user account exists, or until the given lawn area is deleted, or until the data underlying a calendar entry, log data or dashboard indicator is deleted.
Calendar function, activity log and automatic schedulingUsers using the calendar functionRecording, scheduling, tracking lawn care tasks and sending reminders.Performance of a contract pursuant to Article 6(1)(b) GDPR.Completed or planned tasks and their dates, including mowing, blade sharpening, spraying, irrigation, fertilisation, assessment, renovation; user notes; automatic scheduling settings.Hosting provider, push / notification provider.Until the user account exists or until the given calendar entry / log item is deleted.
Use of the calculator functionUsers using the calculator functionPerforming indicative calculations related to area, product category or selected product.Performance of a contract pursuant to Article 6(1)(b) GDPR where data is linked to the user account; for solely temporary, unsaved calculations, the processing is of a limited technical nature.Area size in m², category, selected product, calculation result. Data is linked to the user account if the user saves the calculation or the result is displayed in the profile / history.No data transfer.Until the end of the session.
Text chat with the AI assistant and AI-based lawn care supportUsers using the AI assistantAnswering user questions, providing lawn care advice and personalised support using an AI assistant. When providing responses, the AI assistant may also take into account the lawn data, calendar and log data relevant to the given question, as well as the weather / soil temperature information related thereto, so that the response is tailored to the user's own lawn area.Performance of a contract pursuant to Article 6(1)(b) GDPR where the AI assistant is a function of the Service.Questions and messages submitted in chat, message timestamps, user identifier, lawn data relevant to providing responses (for example calendar entries, logged lawn care activities, relevant data underlying dashboard indicators, weather / soil temperature information related to the given lawn area), AI responses.Gemini API / Google service is used as the AI provider under the Data Controller's own account; hosting provider.In the Data Controller's systems, chat history is retained until the user account exists or until chat history is deleted. The AI provider caches repeated questions for 24 hours in order to provide faster responses, and stores the questions, responses and the related context for no more than 30 days for the purpose of monitoring abuse.
AI-based photo analysisUsers uploading photos in the AI assistantAI-based analysis of the lawn's condition, issues or the content of a photo uploaded by the user, and providing a lawn care response.Performance of a contract pursuant to Article 6(1)(b) GDPR. Photo upload is voluntary; the basic functions of the Service can be used without the photo analysis function.Uploaded photo; the EXIF and other metadata of the image file solely within the framework of technical processing until their automatic removal; the question associated with the image; the AI analysis result. Users are requested not to upload photos showing persons, home addresses, licence plates or other unnecessary personal data.AI provider, hosting provider.The photo is stored until the chat history / user account exists or until deletion. As a general rule, the AI provider does not permanently retain input and output data; such data may be cached for no more than 24 hours for performance purposes and logged for no more than 30 days for the purpose of detecting abuse. The AI provider does not use the data to train its models.
Processing of physical characteristics provided in the profileUsers who provide height and/or weight in their profileCalculating and displaying estimated calorie expenditure related to lawn care activities.Consent of the data subject pursuant to Article 6(1)(a) GDPR and - in view of the health-related nature of the data - pursuant to Article 9(2)(a) GDPR. The fields are optional; providing them is not a condition of using the basic functions of the Service.Height in cm, weight in kg, estimated calorie value calculated therefrom.Hosting provider.Until consent is withdrawn, the data is deleted by the user, or the user account is deleted.
Management of push notifications and notification preferencesUsers who enable push notificationsSending notifications related to lawn care tasks, calendar entries, automatic scheduling or Service functions.Performance of a contract pursuant to Article 6(1)(b) GDPR for service notifications; consent pursuant to Article 6(1)(a) GDPR for marketing push notifications.Push/device token, notification settings, notification preferences by task type, automatic scheduling settings, device technical data.Push notification provider, in particular Apple Push Notification service and/or Google Firebase Cloud Messaging / Google Cloud service.Until notifications are disabled, the token expires or the setting is deleted; the user can disable notifications at any time.
Subscription and in-app payment (Apple / Google IAP)Users using paid or subscription featuresCreating a subscription, technical processing of payments, verification of subscription entitlement.Performance of a contract pursuant to Article 6(1)(b) GDPR; legal obligation pursuant to Article 6(1)(c) GDPR for accounting data.User identifier, subscription plan, subscription status, transaction identifier, payment confirmation. The Data Controller does not see or store card data in the IAP model.Apple Distribution International Ltd. / Apple group, Google Ireland Limited / Google group, app stores, hosting provider, accountant / billing provider if applicable.Until the subscription exists, then until the end of the limitation period for claims; for accounting records, 8 years from the date of issue.
Sending marketing emails by the Data ControllerUsers who give marketing consentSending newsletters, offers, promotions, product and service information in connection with the Service or related services.Consent of the data subject pursuant to Article 6(1)(a) GDPR, also taking into account the rules on commercial advertising activity.Name, email address, fact and timestamp of consent, source and version of consent, fact and timestamp of unsubscribing.Newsletter sending provider, hosting provider.Until consent is withdrawn; data necessary to prove consent for a period matching the relevant enforcement / regulatory proceedings risk.
Sending marketing emails by Pitch System Kft.Users who give separate consent to Pitch System Kft.'s own marketing communicationsSending Pitch System Kft.'s own offers, promotions or marketing messages.Separate consent of the data subject pursuant to Article 6(1)(a) GDPR. Consent must be requested separately from the Data Controller's own marketing consent.Name, email address, fact and timestamp of consent, text / version of consent, fact and timestamp of unsubscribing.Pitch System Kft. (registered office: 9515 Pápoc, Sárvár utca 2.; company registration number: Cg. 18-09-115092; email: info@mrpitch.hu) as an independent data controller for its own marketing communications. Pitch System Kft. provides detailed information in its own privacy notice.Until consent is withdrawn; data necessary to prove consent for a period matching the relevant enforcement / regulatory proceedings risk.
Recording of consents and unsubscribesUsers who give or withdraw marketing consentProving the existence of consents, managing consent withdrawals, preventing further unsolicited contact.Fulfilment of legal obligation pursuant to Article 6(1)(c) GDPR, or legitimate interest of the Data Controller pursuant to Article 6(1)(f) GDPR.Email address, name, timestamp of consent and withdrawal, version of consent text, IP address or other technical evidence, suppression list status.Newsletter sending provider, hosting provider.The Data Controller processes the data related to consent during the existence of the consent. If consent is withdrawn, the data subject's data is deleted from the marketing records without delay. The minimum data necessary to prove the granting and withdrawal of consent, to handle legal claims and to prevent further unsolicited contact is retained by the Data Controller in a separate evidentiary and suppression list record for 5 years from the withdrawal of consent or - if later - from the sending of the last marketing message, after which it is deleted or irreversibly anonymised.
Aggregate analysis and application developmentService usersImproving the application's operation, functions, accuracy and user experience, preparing statistical analyses.Legitimate interest of the Data Controller pursuant to Article 6(1)(f) GDPR. Legitimate interest: developing the Service and its safe, efficient operation. In the event of actual anonymisation, the anonymised results are no longer personal data.Registration and usage data, lawn area data, calendar data, application usage events; data from AI chat only in non-identifiable aggregate or anonymised form, where technically feasible and necessary for the development purpose.Data analytics provider, hosting provider.The Data Controller processes personal or pseudonymised data contained in the development data set for no more than 14 months from the first use of the data for this purpose, but at most until the end of the retention period applicable to the original processing purpose of the underlying data. Thereafter, the data is deleted or irreversibly anonymised. Genuinely anonymised aggregated statistics that can no longer be linked to data subjects may be retained without time limitation.
Background analytics and feature usage measurementService users and visitorsMeasuring feature usage, improving the Service, measuring marketing effectiveness.Legitimate interest pursuant to Article 6(1)(f) GDPR for necessary technical analytics; consent pursuant to Article 6(1)(a) GDPR for non-essential analytics / marketing tools.Application usage events (e.g. screen views, feature usage, subscription events), device identifiers, application identifiers, operating system, device type, IP address (to the extent processed by Google for the provision of the service), campaign identifiers and attribution data.Analytics provider, lawn care professional partner, hosting provider.For the lifetime of the given SDK / analytics tool, or until consent is withdrawn. The retention period for user- and event-level data processed by Google Analytics for Firebase is 14 months. Following the withdrawal of consent, no further analytics or marketing data is collected or transferred. Statistical data that is solely aggregated and can no longer be linked to the data subject may be retained for a longer period.
Technical logging, debugging and IT securityService visitors and usersEnsuring secure, stable operation of the application, identifying errors, preventing abuse and unauthorised access, investigating incidents.Legitimate interest of the Data Controller pursuant to Article 6(1)(f) GDPR.IP address, device identifiers, browser data, operating system data, access timestamps, error logs, session identifiers, user identifier, system events.Hosting provider, monitoring / log management provider, issue tracking provider.The Data Controller retains technical, error and security log data for 90 days from its creation. If a security incident, abuse or dispute arises during this period, the log data necessary to investigate and handle the given matter may be retained separately until the conclusion of the proceedings or, in the event of a legal claim, until the end of the applicable limitation period - as a general rule five years for civil law claims. Thereafter, the data is deleted or irreversibly anonymised.
Handling of customer service, user and complaint enquiriesUsers, prospective users and complainants contacting the Data ControllerHandling and documenting user questions, complaints, technical issues, subscription or billing enquiries.Performance of a contract pursuant to Article 6(1)(b) GDPR; legal obligation pursuant to Article 6(1)(c) GDPR for consumer complaints; legitimate interest pursuant to Article 6(1)(f) GDPR for other enquiries.Name, email address, content of enquiry, related account data, subscription status, responses, attachments, technical error descriptions.Customer service system provider, hosting provider, accountant or payment provider if the enquiry relates to payment.For a period corresponding to the legal claims limitation period after the matter is resolved; for consumer complaints, 3 years from the date of the response pursuant to Section 17/A(7) of Act CLV of 1997 on Consumer Protection.
Enforcement of legal claims and defence in disputesUsers, former users, complainants, contact persons of contractual partnersSubmitting, enforcing and defending the Data Controller's contractual, payment, consumer, data protection or other legal claims; participating in administrative or judicial proceedings.Legitimate interest of the Data Controller pursuant to Article 6(1)(f) GDPR.Account data, subscription data, payment status, communication data, customer service enquiries, log data, consent logs, other data relevant to the dispute.Lawyer, accountant, debt collector, authorities, courts, hosting provider.Until the end of the enforcement / limitation period, or in the event of pending proceedings, until their final conclusion.

Certain functions of the Service implement automated, deterministic personalisation in the sense that they provide personalised suggestions and responses, dashboard indicators, reminders and automatically generated calendar tasks based on the lawn data, location data, address / garden address, or GPS coordinates / precise geolocation data provided by the user, on calendar entries and activity logs, as well as on the weather and soil temperature information related to the given lawn area. The above personalisation takes place on the basis of a rule set and a proprietary algorithm determined by the Data Controller, and not through AI-based background personalisation. The AI assistant operates as a separate chat function, which serves solely to answer the questions raised by the user, within the framework of interactions initiated by the user. Based on current information, the Service does not make solely automated decisions within the meaning of Article 22 GDPR that produce legal effects or similarly significantly affect the data subject. If the Service's operation were to include such automated decision-making or AI-based personalisation in the future, the Data Controller will provide separate notice and, where necessary, carry out the required data protection risk assessment.

The Data Controller does not carry out profiling for marketing purposes. Simple conversion measurement serves solely to measure whether a subscription was concluded following the trial period; it does not give rise to the creation of user profiles, to audience segmentation or to personalised marketing activity.

When using the AI chat and photo upload functions, the user may provide free-text or image content. The Data Controller requests that the user does not provide special category data, personal data relating to third parties, home addresses, licence plates or other data not necessary for lawn care advice.

Data Processors and Data Transfers

CategoryProcessor / RecipientContact details
Hosting, server and data centre providerRender, Inc.525 Brannan Street, Suite 300, San Francisco, CA 94107, United StatesPrivacyDPA
Authentication and user account management providerClerk, Inc.660 King Street, Unit 345, San Francisco, CA 94107, USAPrivacyDPA
Hosting provider (photos)Amazon Web Services EMEA SARL (Amazon S3)38 Avenue John F. Kennedy, L-1855 Luxembourg, LuxembourgAWS Privacy
AI provider / generative AI modelGoogle Ireland Limited (Gemini API / Google AI)Gordon House, Barrow Street, Dublin 4, IrelandGoogle Privacy Policy
Newsletter sending providerMailerLite88 Harcourt Street, Dublin 2, D02 DK18, IrelandMailerLite Privacy Policy
Analytics providerGoogle Ireland Limited (Firebase Analytics and Google Analytics)Gordon House, Barrow Street, Dublin 4, IrelandGoogle Privacy Policy
Issue tracking providerSentry Software Netherlands B.V.Schiphol Boulevard 359, 1118 BJ Schiphol, Netherlandscompliance@sentry.io
Mobile application store and in-app paymentApple Distribution International Ltd. / Apple groupHollyhill Industrial Estate, Hollyhill, Cork, T23 YK84, IrelandApple Privacy Contact
Mobile application store and in-app paymentGoogle Ireland Limited / Google groupGordon House, Barrow Street, Dublin 4, IrelandGoogle Privacy Policy
Lawn care professional partner, marketing collaboratorPitch System Kft.9515 Pápoc Sárvár utca 2.
Push notification providerFirebase Cloud Messaging (Google Ireland Limited) and Apple Push Notification service (Apple Distribution International Ltd.)Apple: Hollyhill Industrial Estate, Hollyhill, Cork, T23 YK84, Ireland — Google: Gordon House, Barrow Street, Dublin 4, IrelandApple Privacy ContactGoogle Privacy Policy
Weather data sourceHungaroMet Nonprofit Zrt.www.met.hu
Weather data sourceNorwegian Meteorological Institutewww.yr.no
Legal representativeD. Szabó András Ügyvédi Iroda1116 Budapest, Fehérvári út 132-144. I. ép. fszt. 9.

The development and IT operation of the application is carried out by the Data Controller within its own organisation. Personal data may be accessed solely by the Data Controller's duly authorised employees, who are subject to confidentiality obligations, to the extent necessary for the performance of their duties.

Beyond the recipients listed above, the Data Controller may transfer personal data provided by you to a competent authority, court or applicant where required by an official or judicial request, or where justified to protect the rights and freedoms of the Data Controller or others.

Where personal data is transferred to a third country outside the European Economic Area, the Data Controller ensures the lawfulness of the transfer in accordance with Chapter V of the GDPR. Transfers to Render Services Inc. and Google LLC in the United States are based on the European Commission's adequacy decision on the EU-US Data Privacy Framework; these providers are participants in the framework with an active certification that also covers the processing of the personal data referred to in this notice. In the case of a recipient not covered by the EU-US Data Privacy Framework, or of a transfer to another third country not benefiting from an adequacy decision, the Data Controller applies the standard contractual clauses adopted by the European Commission and - where necessary - supplementary technical and organisational measures. Further information on the data transfer safeguards applied, or a copy thereof, may be requested at the Data Controller's contact details.

General Data Security Measures

The Data Controller assesses the risks arising from its processing activities and evaluates them in terms of the severity and likelihood of occurrence in order to guarantee an appropriate level of data security.

When operating its IT systems, the Data Controller provides the necessary access management, internal organisational and technical solutions to ensure that data can only be accessed by authorised persons, and that personal data cannot come into the possession of unauthorised persons or be deleted, exported from the system or modified by them.

The Data Controller also enforces data protection and data security requirements against its data processors through prior assessments and data processing agreements.

The Data Controller maintains a record of any data protection incidents and, where required under the GDPR, notifies the National Authority for Data Protection and Freedom of Information and the affected data subjects.

Internet communication between the Data Controller and persons visiting or using the application takes place via an encrypted connection using the https protocol.

The Data Controller applies password protection, access control, logging, rights management and technical protection measures proportionate to the risks on its IT devices.

AI chat and photo upload may present special data protection risks; therefore, the Data Controller strives to ensure that only data necessary for providing responses is transferred to the AI provider, and provides users with clear information about the risks of free-text and image content.

Rights of Data Subjects

The data subject may at any time request information by post, email or telephone at the contact details set out in this notice regarding the personal data we process about them.

Upon request, we will inform the data subject of:

  • the data processed,
  • the purpose of processing,
  • the legal basis,
  • the retention period,
  • who receives or has received their data and for what purpose.

The information will be provided in writing within one month of the request, by paper or electronic means depending on how the request was made.

The data subject may at any time object to the processing of their personal data. We will examine the objection and make a decision on its merits within the shortest possible time, but no later than one month, and notify the data subject of our decision.

The data subject may at any time request the erasure of personal data we process about them, or the rectification of incorrectly recorded personal data.

We will also restrict the data subject's personal data if they request it, or if available information suggests that erasure would prejudice the data subject's legitimate interests. Restricted data will be processed until the processing purpose or legitimate interest that precluded erasure ceases to exist.

The data subject may, through the contact details in this notice, request that the Data Controller restrict the processing of their personal data (with clear marking of the restricted nature and separate handling from other data) where:

  • the data subject contests the accuracy of the personal data (in which case the Data Controller will restrict processing for the period necessary to verify accuracy);
  • the processing is unlawful and the data subject opposes erasure and requests restriction of use instead;
  • the Data Controller no longer needs the personal data for processing purposes but the data subject requires it for the establishment, exercise or defence of legal claims; or
  • the data subject has objected to processing (in which case the restriction applies until it is determined whether the Data Controller's legitimate grounds override those of the data subject).

The data subject is entitled, through the contact details in this notice, to receive the personal data they have provided to the Data Controller in a structured, commonly used, machine-readable format, and to transmit those data to another data controller or processor without hindrance from the Data Controller.

We will comply with access, erasure, rectification, restriction, portability and locking requests as soon as possible, but within one month, and will notify the data subject. If we are unable to comply with a request, we will notify the data subject within one month.

Where data have been transferred to another party with the data subject's consent, we will also notify the recipient of the necessary steps.

Where we process personal data on the basis of the data subject's consent, the data subject may withdraw their consent at any time. Consent may be withdrawn by contacting the Data Controller at the details set out in this notice; where appropriate, the Data Controller will also provide simpler means of withdrawal.

If the data subject is visually impaired or elderly, they may request that the Data Controller provide the content of this Privacy Notice in Word (text) format or in large print, through the contact details set out in this notice.

The data subject is also entitled to lodge a complaint with the

National Authority for Data Protection and Freedom of Information

1055 Budapest, Falk Miksa utca 9-11.

www.naih.hu

+36 (1) 391-1400

ugyfelszolgalat@naih.hu

or to enforce their rights relating to the processing of personal data before a court with competent jurisdiction under Act CXXX of 2016 on the Code of Civil Procedure.

The competent court can be found at:

birosag.hu/birosag-kereso

The data subject may exercise the rights listed in this notice at any time by contacting the Data Controller by email or other written means. In connection with such a request, the Data Controller may ask the requesting person to identify themselves or provide other personal data to verify their entitlement.

The Data Controller may be contacted through the details set out in Section 1.

Quivra Labs Korlátolt Felelősségű Társaság – Data Controller