| Registration and user account creation | Natural persons registering for the Service | Creating a user account, identifying the user, providing access to the Service, communication in connection with the account. | Performance of a contract or pre-contractual steps pursuant to Article 6(1)(b) GDPR. | Name, email address, user identifier, registration timestamp, account status. | Hosting provider, application developer / IT operator, authentication provider if such service is used. | Until the user account exists; data is deleted upon account deletion, unless retention is required by legal obligation, legitimate interest or enforcement of legal claims. |
| Email address verification with confirmation code | Registering users | Verifying that the email address provided during registration is under the control of the user. | Performance of a contract / pre-contractual steps pursuant to Article 6(1)(b) GDPR; legitimate interest in preventing abuse pursuant to Article 6(1)(f) GDPR. | Email address, 6-digit confirmation code sent by email, timestamp of code generation and validity, verification status. | Email sending provider, hosting provider, IT operator. | The confirmation code is retained until the validity period expires; in technical logs for a short period necessary for security purposes. |
| Login, authentication and session management | Registered users | Secure login, maintaining active sessions, preventing unauthorised access. | Performance of a contract pursuant to Article 6(1)(b) GDPR; legitimate interest for security logging pursuant to Article 6(1)(f) GDPR. | Email address, user identifier, technical hash of password, session identifier, tokens, IP address, device and browser data, login timestamps, failed login attempts. | Hosting provider, authentication provider, IT operator, security provider. | Session data until end of session; security logs for a proportionate period necessary for the purpose, typically no more than a few months, except in the event of an incident or dispute. |
| Prevention of abusive repeated use of the trial period | Former users who used the trial period or deleted their accounts | Preventing the same user from obtaining unlimited new trial periods after deleting their account. | Legitimate interest of the Data Controller pursuant to Article 6(1)(f) GDPR. Legitimate interest: preventing abusive use of the Service and protecting the business model. | Email address, trial period activation timestamp, trial period status. From a data minimisation perspective, applying a one-way irreversible hash identifier instead of the actual email address is recommended where technically suitable. | Hosting provider, IT operator. | For the predetermined period necessary to prevent trial period abuse, substantiated in the legitimate interest balancing test. The retention period must be specified as a concrete duration. |
| Lawn area / garden profile creation and management | Users who create a lawn area or garden profile in the Service | Creating a profile for the lawn area, providing personalised lawn care recommendations, calendar entries, reminders and AI support. | Performance of a contract pursuant to Article 6(1)(b) GDPR. | Municipality-level location data, address / garden address, or GPS coordinates / precise geolocation, area size, lawn installation date, lawn type (seeded lawn / turf), grass seed type, soil type, sun exposure, cultivation method, mowing method, irrigation method, other lawn data provided by the user. | Hosting provider, application developer / IT operator, AI provider if the data is processed by AI. | Until the user account exists or until the user deletes the given lawn area / garden profile. |
| Retrieval of weather and soil temperature information based on location | Users who create a lawn area and use the weather function | Displaying weather, forecast and soil temperature information related to the user's lawn area. | Performance of a contract pursuant to Article 6(1)(b) GDPR. | Municipality location data, address / garden address, or GPS coordinates / precise geolocation, location settings linked to lawn area, technical data of weather queries. | Weather data sources: HungaroMet Nonprofit Zrt., Norwegian Meteorological Institute. | Location data until the lawn area exists; weather query logs for a short period necessary for technical operation. |
| Personalised lawn care recommendations and profiling | Registered users | Generating personalised lawn care suggestions, tasks and reminders based on the user's lawn data, location, calendar data and activity log. | Performance of a contract pursuant to Article 6(1)(b) GDPR. If the recommendations also serve personalisation for marketing or product sales, a separate legal basis and notice are required. Based on current information, the processing does not involve solely automated decision-making within the meaning of Article 22 GDPR that produces legal effects or similarly significant effects. | Lawn area data, municipality location data, address / garden address, or GPS coordinates / precise geolocation, calendar data, activity log, dashboard data, relevant data provided during AI chat. | Hosting provider, application developer / IT operator, AI provider. | Until the user account exists or until the given lawn area is deleted. |
| Calendar function, activity log and automatic scheduling | Users using the calendar function | Recording, scheduling, tracking lawn care tasks and sending reminders. | Performance of a contract pursuant to Article 6(1)(b) GDPR. | Completed or planned tasks and their dates, including mowing, blade sharpening, spraying, irrigation, fertilisation, assessment, renovation; user notes; automatic scheduling settings. | Hosting provider, application developer / IT operator, push / notification provider. | Until the user account exists or until the given calendar entry / log item is deleted. |
| Dashboard and lawn status tracking | Registered users | Aggregating lawn care activities, status tracking, displaying lawn care performance and maintenance data. | Performance of a contract pursuant to Article 6(1)(b) GDPR. | Applied nutrients, number of mowings, mowed area in m², blade condition, related dates and activity statuses. | Hosting provider, application developer / IT operator, AI provider if the data is also used to personalise AI responses. | Until the user account exists or until the given log data is deleted. |
| Use of the calculator function | Users using the calculator function | Performing indicative calculations related to area, product category or selected product. | Performance of a contract pursuant to Article 6(1)(b) GDPR where data is linked to the user account; for solely temporary, unsaved calculations, the processing is of a limited technical nature. | Area size in m², category, selected product, calculation result. Data is linked to the user account if the user saves the calculation or the result is displayed in the profile / history. | Hosting provider, application developer / IT operator. | If data is saved, until the user account exists or until the given calculation is deleted; for temporary, unsaved calculations, until the end of the session. |
| Text chat with the AI assistant | Users using the AI assistant | Answering user questions, providing lawn care advice and personalised support using an AI assistant. | Performance of a contract pursuant to Article 6(1)(b) GDPR where the AI assistant is a function of the Service. | Questions and messages submitted in chat, message timestamps, user identifier, lawn data relevant to providing responses, AI responses. | Gemini API / Google service is used as the AI provider under the Data Controller's own account; hosting provider; IT operator. | In the Data Controller's systems, chat history is retained until the user account exists or until chat history is deleted. Logging and retention by the AI provider is governed by the service provider settings and contractual terms applied, which must be documented separately. |
| AI-based photo analysis | Users uploading photos in the AI assistant | AI-based analysis of the lawn's condition, issues or the content of a photo uploaded by the user, and providing a lawn care response. | Performance of a contract pursuant to Article 6(1)(b) GDPR. Photo upload is voluntary; the basic functions of the Service can be used without the photo analysis function. | Uploaded photo, image file metadata, question associated with the image, AI analysis result. Users are requested not to upload photos showing persons, home addresses, licence plates or other unnecessary personal data. | AI provider, hosting provider, IT operator. Logging, retention, use for model training or exclusion thereof by the AI provider must be documented through contractual and technical settings. | If the photo is saved, until the chat history / user account exists or until deletion; if only temporary analysis is performed, for the duration necessary for the analysis. The exact retention period matching actual operation must be recorded. |
| Personalisation of AI responses based on background data | Registered users using the AI assistant | Using the user's lawn data and logged activities so that the AI assistant provides responses tailored to the user's own lawn area. | Performance of a contract pursuant to Article 6(1)(b) GDPR. | Lawn area data, municipality location data, address / garden address, or GPS coordinates / precise geolocation, logged activities, dashboard data, calendar entries, chat messages. | Gemini API / Google service, hosting provider, IT operator. The scope of background data transferred to the AI provider must be limited to data actually necessary for providing responses from a data minimisation perspective. | In line with the underlying data: until the user account, the given lawn area, calendar entry or chat history exists. AI provider retention and exclusion of possible model training must be documented separately. |
| Processing of physical characteristics provided in the profile | Users who provide height and/or weight in their profile | Calculating and displaying estimated calorie expenditure related to lawn care activities. | Consent of the data subject pursuant to Article 6(1)(a) GDPR. The fields are optional; providing them is not a condition of using the basic functions of the Service. | Height in cm, weight in kg, estimated calorie value calculated therefrom. | Hosting provider, application developer / IT operator. | Until consent is withdrawn, the data is deleted by the user, or the user account is deleted. |
| Management of push notifications and notification preferences | Users who enable push notifications | Sending notifications related to lawn care tasks, calendar entries, automatic scheduling or Service functions. | Performance of a contract pursuant to Article 6(1)(b) GDPR for service notifications; consent pursuant to Article 6(1)(a) GDPR for marketing push notifications. | Push/device token, notification settings, notification preferences by task type, automatic scheduling settings, device technical data. | Push notification provider, in particular Apple Push Notification service and/or Google Firebase Cloud Messaging / Google Cloud service, IT operator. | Until notifications are disabled, the token expires or the setting is deleted; the user can disable notifications at any time. |
| Subscription and in-app payment (Apple / Google IAP) | Users using paid or subscription features | Creating a subscription, technical processing of payments, verification of subscription entitlement. | Performance of a contract pursuant to Article 6(1)(b) GDPR; legal obligation pursuant to Article 6(1)(c) GDPR for accounting data. | User identifier, subscription plan, subscription status, transaction identifier, payment confirmation. The Data Controller does not see or store card data in the IAP model. | Apple Distribution International Ltd. / Apple group, Google Ireland Limited / Google group, app stores, hosting provider, accountant / billing provider if applicable. | Until the subscription exists, then until the end of the limitation period for claims; for accounting records, 8 years from the date of issue. |
| Web payment, checkout and invoicing | Users initiating payment or subscription through the web interface | Preparing the payment process, processing payment, issuing invoices, managing subscription entitlement. | Performance of a contract pursuant to Article 6(1)(b) GDPR; legal obligation pursuant to Article 6(1)(c) GDPR for invoicing. | Name, billing address, email address, subscription plan, transaction identifier, payment status, invoice data. Card data is generally processed by the payment provider. | Barion Payment Zártkörűen Működő Részvénytársaság, billing provider, accountant, hosting provider. | Subscription data until the subscription exists, then until the end of the limitation period; for accounting records, 8 years from the date of issue. |
| Sending marketing emails by the Data Controller | Users who give marketing consent | Sending newsletters, offers, promotions, product and service information in connection with the Service or related services. | Consent of the data subject pursuant to Article 6(1)(a) GDPR, also taking into account the rules on commercial advertising activity. | Name, email address, fact and timestamp of consent, source and version of consent, fact and timestamp of unsubscribing. | Newsletter sending provider, CRM provider, marketing agency, hosting provider. | Until consent is withdrawn; data necessary to prove consent for a period matching the relevant enforcement / regulatory proceedings risk. |
| Sending marketing emails by Pitch System Kft. | Users who give separate consent to Pitch System Kft.'s own marketing communications | Sending Pitch System Kft.'s own offers, promotions or marketing messages. | Separate consent of the data subject pursuant to Article 6(1)(a) GDPR. Consent must be requested separately from the Data Controller's own marketing consent. | Name, email address, fact and timestamp of consent, text / version of consent, fact and timestamp of unsubscribing. | Pitch System Kft. (registered office: 9515 Pápoc, Sárvár utca 2.; company registration number: Cg. 18-09-115092; email: info@mrpitch.hu) as an independent data controller for its own marketing communications. Pitch System Kft. provides detailed information in its own privacy notice. | Until consent is withdrawn; data necessary to prove consent for a period matching the relevant enforcement / regulatory proceedings risk. |
| Recording of consents and unsubscribes | Users who give or withdraw marketing consent | Proving the existence of consents, managing consent withdrawals, preventing further unsolicited contact. | Fulfilment of legal obligation pursuant to Article 6(1)(c) GDPR, or legitimate interest of the Data Controller pursuant to Article 6(1)(f) GDPR. | Email address, name, timestamp of consent and withdrawal, version of consent text, IP address or other technical evidence, suppression list status. | Newsletter sending provider, CRM provider, marketing agency, hosting provider. | During the existence of the consent; after withdrawal, minimum data necessary for suppression list and evidence purposes for a proportionate period. |
| Aggregate analysis and application development | Service users | Improving the application's operation, functions, accuracy and user experience, preparing statistical analyses. | Legitimate interest of the Data Controller pursuant to Article 6(1)(f) GDPR. Legitimate interest: developing the Service and its safe, efficient operation. In the event of actual anonymisation, the anonymised results are no longer personal data. | Registration and usage data, lawn area data, calendar data, application usage events; data from AI chat only in non-identifiable aggregate or anonymised form, where technically feasible and necessary for the development purpose. | Application developer, data analytics provider, hosting provider, AI provider if involved. | For personal data, for a limited period necessary for the development purpose; aggregated / anonymised statistics may be retained longer subject to exclusion of identification. |
| Background analytics, feature usage measurement and marketing profiling | Service users and visitors | Measuring feature usage, improving the Service, measuring marketing effectiveness. Marketing profiling may only be carried out if supported by the final technical operation and an appropriate legal basis. | Legitimate interest pursuant to Article 6(1)(f) GDPR for necessary technical analytics; consent pursuant to Article 6(1)(a) GDPR for non-essential analytics / marketing tools. | Feature usage events, device and browser data, cookie or similar identifiers, IP address, campaign parameters. The exact scope of data to be finalised based on cookie and SDK audit. | Analytics provider, marketing technology provider, cookie consent management platform, hosting provider. | For the lifetime of the given cookie / SDK / analytics tool, or until consent is withdrawn; exact duration to be finalised based on tool audit. |
| Technical logging, debugging and IT security | Service visitors and users | Ensuring secure, stable operation of the application, identifying errors, preventing abuse and unauthorised access, investigating incidents. | Legitimate interest of the Data Controller pursuant to Article 6(1)(f) GDPR. | IP address, device identifiers, browser data, operating system data, access timestamps, error logs, session identifiers, user identifier, system events. | Hosting provider, application developer, monitoring / log management provider, IT security provider. | For a limited period necessary for technical and security purposes; in the event of an incident or dispute, until the matter is resolved. |
| Handling of customer service, user and complaint enquiries | Users, prospective users and complainants contacting the Data Controller | Handling and documenting user questions, complaints, technical issues, subscription or billing enquiries. | Performance of a contract pursuant to Article 6(1)(b) GDPR; legal obligation pursuant to Article 6(1)(c) GDPR for consumer complaints; legitimate interest pursuant to Article 6(1)(f) GDPR for other enquiries. | Name, email address, content of enquiry, related account data, subscription status, responses, attachments, technical error descriptions. | Customer service system provider, hosting provider, application developer / technical support, accountant or payment provider if the enquiry relates to payment. | For a period corresponding to the legal claims limitation period after the matter is resolved; for consumer complaints, 3 years from the date of the response pursuant to Section 17/A(7) of Act CLV of 1997 on Consumer Protection. |
| Enforcement of legal claims and defence in disputes | Users, former users, complainants, contact persons of contractual partners | Submitting, enforcing and defending the Data Controller's contractual, payment, consumer, data protection or other legal claims; participating in administrative or judicial proceedings. | Legitimate interest of the Data Controller pursuant to Article 6(1)(f) GDPR. | Account data, subscription data, payment status, communication data, customer service enquiries, log data, consent logs, other data relevant to the dispute. | Lawyer, accountant, debt collector, authorities, courts, hosting provider. | Until the end of the enforcement / limitation period, or in the event of pending proceedings, until their final conclusion. |