Quivra Labs Limited Liability Company

Privacy Policy

Regarding the Legyen Zöld application ("Service")

Last modified: 26 June 2026

This privacy notice summarises the processing activities carried out by Quivra Labs Limited Liability Company as data controller ("Data Controller") in connection with the operation of the web and/or mobile application named Legyen Zöld ("Service"). The purpose of the Service is to enable users to receive personalised lawn care recommendations, a calendar function, reminders, calculators, weather information and AI-based support by providing data about their lawn area. Please read this privacy notice carefully, and if you have any questions regarding the processing of your personal data, please contact the Data Controller at the contact details provided below.

Data Controller

Data Controller:
Quivra Labs Korlátolt Felelősségű Társaság
Registered office:
1063 Budapest, Szinyei Merse Pál utca 21. 1. em. 5. ajtó
Postal address:
1063 Budapest, Szinyei Merse Pál utca 21. 1. em. 5. ajtó
Company registration number:
Cg.01-09-453528
Tax number:
32996542-2-42
Represented by:
Balogh Árpád, managing director, acting independently
Email:
office@quivralabs.com
Website / application:
App Store: Legyen Zöld!Google Play: Legyen Zöld!

The Data Controller acts as an independent data controller with respect to personal data relating to the provision of the Service, the management of user accounts, the provision of lawn care functions, the operation of the AI assistant, the management of subscriptions and its own marketing activities. The Data Controller may, based on users' separate consent, send direct marketing electronic messages to users in connection with the Legyen Zöld! application, services, functions, offers, promotions and lawn care related content. Based on the user's separate consent, the Data Controller may transfer the user's name and email address to Pitch System Kft. so that Pitch System Kft. may, in its own name, send direct marketing electronic messages to the user in connection with its own lawn care products, services, content, offers, workshops, newsletter or other marketing communications. Pitch System Kft. acts as an independent data controller with respect to its own marketing communications, which means that it independently determines the manner and means of processing the personal data transferred to it for its own marketing purposes, and bears independent data protection responsibility for this activity. Pitch System Kft. provides detailed information about its own data processing in its own privacy notice. The legal basis for direct marketing processing is the data subject's consent pursuant to Article 6(1)(a) of the GDPR. The provision of consent is voluntary; its refusal or withdrawal does not affect the use of the basic functions of the Legyen Zöld! application. The data subject may withdraw consent at any time, without justification, in particular via the unsubscribe link in marketing messages or at the contact details of the sending data controller. Data processed: name, email address, fact, timestamp and source of consent, version of the consent statement, and fact and timestamp of unsubscribing.

Personal Data Processed

Processing activityCategories of data subjectsPurpose of processingLegal basisData processedTransfers / processorsRetention period
Registration and user account creationNatural persons registering for the ServiceCreating a user account, identifying the user, providing access to the Service, communication in connection with the account.Performance of a contract or pre-contractual steps pursuant to Article 6(1)(b) GDPR.Name, email address, user identifier, registration timestamp, account status.Hosting provider, application developer / IT operator, authentication provider if such service is used.Until the user account exists; data is deleted upon account deletion, unless retention is required by legal obligation, legitimate interest or enforcement of legal claims.
Email address verification with confirmation codeRegistering usersVerifying that the email address provided during registration is under the control of the user.Performance of a contract / pre-contractual steps pursuant to Article 6(1)(b) GDPR; legitimate interest in preventing abuse pursuant to Article 6(1)(f) GDPR.Email address, 6-digit confirmation code sent by email, timestamp of code generation and validity, verification status.Email sending provider, hosting provider, IT operator.The confirmation code is retained until the validity period expires; in technical logs for a short period necessary for security purposes.
Login, authentication and session managementRegistered usersSecure login, maintaining active sessions, preventing unauthorised access.Performance of a contract pursuant to Article 6(1)(b) GDPR; legitimate interest for security logging pursuant to Article 6(1)(f) GDPR.Email address, user identifier, technical hash of password, session identifier, tokens, IP address, device and browser data, login timestamps, failed login attempts.Hosting provider, authentication provider, IT operator, security provider.Session data until end of session; security logs for a proportionate period necessary for the purpose, typically no more than a few months, except in the event of an incident or dispute.
Prevention of abusive repeated use of the trial periodFormer users who used the trial period or deleted their accountsPreventing the same user from obtaining unlimited new trial periods after deleting their account.Legitimate interest of the Data Controller pursuant to Article 6(1)(f) GDPR. Legitimate interest: preventing abusive use of the Service and protecting the business model.Email address, trial period activation timestamp, trial period status. From a data minimisation perspective, applying a one-way irreversible hash identifier instead of the actual email address is recommended where technically suitable.Hosting provider, IT operator.For the predetermined period necessary to prevent trial period abuse, substantiated in the legitimate interest balancing test. The retention period must be specified as a concrete duration.
Lawn area / garden profile creation and managementUsers who create a lawn area or garden profile in the ServiceCreating a profile for the lawn area, providing personalised lawn care recommendations, calendar entries, reminders and AI support.Performance of a contract pursuant to Article 6(1)(b) GDPR.Municipality-level location data, address / garden address, or GPS coordinates / precise geolocation, area size, lawn installation date, lawn type (seeded lawn / turf), grass seed type, soil type, sun exposure, cultivation method, mowing method, irrigation method, other lawn data provided by the user.Hosting provider, application developer / IT operator, AI provider if the data is processed by AI.Until the user account exists or until the user deletes the given lawn area / garden profile.
Retrieval of weather and soil temperature information based on locationUsers who create a lawn area and use the weather functionDisplaying weather, forecast and soil temperature information related to the user's lawn area.Performance of a contract pursuant to Article 6(1)(b) GDPR.Municipality location data, address / garden address, or GPS coordinates / precise geolocation, location settings linked to lawn area, technical data of weather queries.Weather data sources: HungaroMet Nonprofit Zrt., Norwegian Meteorological Institute.Location data until the lawn area exists; weather query logs for a short period necessary for technical operation.
Personalised lawn care recommendations and profilingRegistered usersGenerating personalised lawn care suggestions, tasks and reminders based on the user's lawn data, location, calendar data and activity log.Performance of a contract pursuant to Article 6(1)(b) GDPR. If the recommendations also serve personalisation for marketing or product sales, a separate legal basis and notice are required. Based on current information, the processing does not involve solely automated decision-making within the meaning of Article 22 GDPR that produces legal effects or similarly significant effects.Lawn area data, municipality location data, address / garden address, or GPS coordinates / precise geolocation, calendar data, activity log, dashboard data, relevant data provided during AI chat.Hosting provider, application developer / IT operator, AI provider.Until the user account exists or until the given lawn area is deleted.
Calendar function, activity log and automatic schedulingUsers using the calendar functionRecording, scheduling, tracking lawn care tasks and sending reminders.Performance of a contract pursuant to Article 6(1)(b) GDPR.Completed or planned tasks and their dates, including mowing, blade sharpening, spraying, irrigation, fertilisation, assessment, renovation; user notes; automatic scheduling settings.Hosting provider, application developer / IT operator, push / notification provider.Until the user account exists or until the given calendar entry / log item is deleted.
Dashboard and lawn status trackingRegistered usersAggregating lawn care activities, status tracking, displaying lawn care performance and maintenance data.Performance of a contract pursuant to Article 6(1)(b) GDPR.Applied nutrients, number of mowings, mowed area in m², blade condition, related dates and activity statuses.Hosting provider, application developer / IT operator, AI provider if the data is also used to personalise AI responses.Until the user account exists or until the given log data is deleted.
Use of the calculator functionUsers using the calculator functionPerforming indicative calculations related to area, product category or selected product.Performance of a contract pursuant to Article 6(1)(b) GDPR where data is linked to the user account; for solely temporary, unsaved calculations, the processing is of a limited technical nature.Area size in m², category, selected product, calculation result. Data is linked to the user account if the user saves the calculation or the result is displayed in the profile / history.Hosting provider, application developer / IT operator.If data is saved, until the user account exists or until the given calculation is deleted; for temporary, unsaved calculations, until the end of the session.
Text chat with the AI assistantUsers using the AI assistantAnswering user questions, providing lawn care advice and personalised support using an AI assistant.Performance of a contract pursuant to Article 6(1)(b) GDPR where the AI assistant is a function of the Service.Questions and messages submitted in chat, message timestamps, user identifier, lawn data relevant to providing responses, AI responses.Gemini API / Google service is used as the AI provider under the Data Controller's own account; hosting provider; IT operator.In the Data Controller's systems, chat history is retained until the user account exists or until chat history is deleted. Logging and retention by the AI provider is governed by the service provider settings and contractual terms applied, which must be documented separately.
AI-based photo analysisUsers uploading photos in the AI assistantAI-based analysis of the lawn's condition, issues or the content of a photo uploaded by the user, and providing a lawn care response.Performance of a contract pursuant to Article 6(1)(b) GDPR. Photo upload is voluntary; the basic functions of the Service can be used without the photo analysis function.Uploaded photo, image file metadata, question associated with the image, AI analysis result. Users are requested not to upload photos showing persons, home addresses, licence plates or other unnecessary personal data.AI provider, hosting provider, IT operator. Logging, retention, use for model training or exclusion thereof by the AI provider must be documented through contractual and technical settings.If the photo is saved, until the chat history / user account exists or until deletion; if only temporary analysis is performed, for the duration necessary for the analysis. The exact retention period matching actual operation must be recorded.
Personalisation of AI responses based on background dataRegistered users using the AI assistantUsing the user's lawn data and logged activities so that the AI assistant provides responses tailored to the user's own lawn area.Performance of a contract pursuant to Article 6(1)(b) GDPR.Lawn area data, municipality location data, address / garden address, or GPS coordinates / precise geolocation, logged activities, dashboard data, calendar entries, chat messages.Gemini API / Google service, hosting provider, IT operator. The scope of background data transferred to the AI provider must be limited to data actually necessary for providing responses from a data minimisation perspective.In line with the underlying data: until the user account, the given lawn area, calendar entry or chat history exists. AI provider retention and exclusion of possible model training must be documented separately.
Processing of physical characteristics provided in the profileUsers who provide height and/or weight in their profileCalculating and displaying estimated calorie expenditure related to lawn care activities.Consent of the data subject pursuant to Article 6(1)(a) GDPR. The fields are optional; providing them is not a condition of using the basic functions of the Service.Height in cm, weight in kg, estimated calorie value calculated therefrom.Hosting provider, application developer / IT operator.Until consent is withdrawn, the data is deleted by the user, or the user account is deleted.
Management of push notifications and notification preferencesUsers who enable push notificationsSending notifications related to lawn care tasks, calendar entries, automatic scheduling or Service functions.Performance of a contract pursuant to Article 6(1)(b) GDPR for service notifications; consent pursuant to Article 6(1)(a) GDPR for marketing push notifications.Push/device token, notification settings, notification preferences by task type, automatic scheduling settings, device technical data.Push notification provider, in particular Apple Push Notification service and/or Google Firebase Cloud Messaging / Google Cloud service, IT operator.Until notifications are disabled, the token expires or the setting is deleted; the user can disable notifications at any time.
Subscription and in-app payment (Apple / Google IAP)Users using paid or subscription featuresCreating a subscription, technical processing of payments, verification of subscription entitlement.Performance of a contract pursuant to Article 6(1)(b) GDPR; legal obligation pursuant to Article 6(1)(c) GDPR for accounting data.User identifier, subscription plan, subscription status, transaction identifier, payment confirmation. The Data Controller does not see or store card data in the IAP model.Apple Distribution International Ltd. / Apple group, Google Ireland Limited / Google group, app stores, hosting provider, accountant / billing provider if applicable.Until the subscription exists, then until the end of the limitation period for claims; for accounting records, 8 years from the date of issue.
Web payment, checkout and invoicingUsers initiating payment or subscription through the web interfacePreparing the payment process, processing payment, issuing invoices, managing subscription entitlement.Performance of a contract pursuant to Article 6(1)(b) GDPR; legal obligation pursuant to Article 6(1)(c) GDPR for invoicing.Name, billing address, email address, subscription plan, transaction identifier, payment status, invoice data. Card data is generally processed by the payment provider.Barion Payment Zártkörűen Működő Részvénytársaság, billing provider, accountant, hosting provider.Subscription data until the subscription exists, then until the end of the limitation period; for accounting records, 8 years from the date of issue.
Sending marketing emails by the Data ControllerUsers who give marketing consentSending newsletters, offers, promotions, product and service information in connection with the Service or related services.Consent of the data subject pursuant to Article 6(1)(a) GDPR, also taking into account the rules on commercial advertising activity.Name, email address, fact and timestamp of consent, source and version of consent, fact and timestamp of unsubscribing.Newsletter sending provider, CRM provider, marketing agency, hosting provider.Until consent is withdrawn; data necessary to prove consent for a period matching the relevant enforcement / regulatory proceedings risk.
Sending marketing emails by Pitch System Kft.Users who give separate consent to Pitch System Kft.'s own marketing communicationsSending Pitch System Kft.'s own offers, promotions or marketing messages.Separate consent of the data subject pursuant to Article 6(1)(a) GDPR. Consent must be requested separately from the Data Controller's own marketing consent.Name, email address, fact and timestamp of consent, text / version of consent, fact and timestamp of unsubscribing.Pitch System Kft. (registered office: 9515 Pápoc, Sárvár utca 2.; company registration number: Cg. 18-09-115092; email: info@mrpitch.hu) as an independent data controller for its own marketing communications. Pitch System Kft. provides detailed information in its own privacy notice.Until consent is withdrawn; data necessary to prove consent for a period matching the relevant enforcement / regulatory proceedings risk.
Recording of consents and unsubscribesUsers who give or withdraw marketing consentProving the existence of consents, managing consent withdrawals, preventing further unsolicited contact.Fulfilment of legal obligation pursuant to Article 6(1)(c) GDPR, or legitimate interest of the Data Controller pursuant to Article 6(1)(f) GDPR.Email address, name, timestamp of consent and withdrawal, version of consent text, IP address or other technical evidence, suppression list status.Newsletter sending provider, CRM provider, marketing agency, hosting provider.During the existence of the consent; after withdrawal, minimum data necessary for suppression list and evidence purposes for a proportionate period.
Aggregate analysis and application developmentService usersImproving the application's operation, functions, accuracy and user experience, preparing statistical analyses.Legitimate interest of the Data Controller pursuant to Article 6(1)(f) GDPR. Legitimate interest: developing the Service and its safe, efficient operation. In the event of actual anonymisation, the anonymised results are no longer personal data.Registration and usage data, lawn area data, calendar data, application usage events; data from AI chat only in non-identifiable aggregate or anonymised form, where technically feasible and necessary for the development purpose.Application developer, data analytics provider, hosting provider, AI provider if involved.For personal data, for a limited period necessary for the development purpose; aggregated / anonymised statistics may be retained longer subject to exclusion of identification.
Background analytics, feature usage measurement and marketing profilingService users and visitorsMeasuring feature usage, improving the Service, measuring marketing effectiveness. Marketing profiling may only be carried out if supported by the final technical operation and an appropriate legal basis.Legitimate interest pursuant to Article 6(1)(f) GDPR for necessary technical analytics; consent pursuant to Article 6(1)(a) GDPR for non-essential analytics / marketing tools.Feature usage events, device and browser data, cookie or similar identifiers, IP address, campaign parameters. The exact scope of data to be finalised based on cookie and SDK audit.Analytics provider, marketing technology provider, cookie consent management platform, hosting provider.For the lifetime of the given cookie / SDK / analytics tool, or until consent is withdrawn; exact duration to be finalised based on tool audit.
Technical logging, debugging and IT securityService visitors and usersEnsuring secure, stable operation of the application, identifying errors, preventing abuse and unauthorised access, investigating incidents.Legitimate interest of the Data Controller pursuant to Article 6(1)(f) GDPR.IP address, device identifiers, browser data, operating system data, access timestamps, error logs, session identifiers, user identifier, system events.Hosting provider, application developer, monitoring / log management provider, IT security provider.For a limited period necessary for technical and security purposes; in the event of an incident or dispute, until the matter is resolved.
Handling of customer service, user and complaint enquiriesUsers, prospective users and complainants contacting the Data ControllerHandling and documenting user questions, complaints, technical issues, subscription or billing enquiries.Performance of a contract pursuant to Article 6(1)(b) GDPR; legal obligation pursuant to Article 6(1)(c) GDPR for consumer complaints; legitimate interest pursuant to Article 6(1)(f) GDPR for other enquiries.Name, email address, content of enquiry, related account data, subscription status, responses, attachments, technical error descriptions.Customer service system provider, hosting provider, application developer / technical support, accountant or payment provider if the enquiry relates to payment.For a period corresponding to the legal claims limitation period after the matter is resolved; for consumer complaints, 3 years from the date of the response pursuant to Section 17/A(7) of Act CLV of 1997 on Consumer Protection.
Enforcement of legal claims and defence in disputesUsers, former users, complainants, contact persons of contractual partnersSubmitting, enforcing and defending the Data Controller's contractual, payment, consumer, data protection or other legal claims; participating in administrative or judicial proceedings.Legitimate interest of the Data Controller pursuant to Article 6(1)(f) GDPR.Account data, subscription data, payment status, communication data, customer service enquiries, log data, consent logs, other data relevant to the dispute.Lawyer, accountant, debt collector, authorities, courts, hosting provider.Until the end of the enforcement / limitation period, or in the event of pending proceedings, until their final conclusion.

Certain functions of the Service may involve profiling in the sense that they provide personalised suggestions and responses based on the user's lawn data, location data, address / garden address, or GPS coordinates / precise geolocation, calendar entries and activity logs. Based on current information, the Service does not make solely automated decisions within the meaning of Article 22 GDPR that produce legal effects or similarly significantly affect the data subject. If the Service's operation were to include such automated decision-making in the future, the Data Controller will provide separate notice.

When using the AI chat and photo upload functions, the user may provide free-text or image content. The Data Controller requests that the user does not provide special category data, personal data relating to third parties, home addresses, licence plates or other data not necessary for lawn care advice.

Data Processors and Data Transfers

CategoryProcessor / RecipientContact details
Hosting, server and data centre providerVercel Inc.440 N Barranca Avenue #4133, Covina, CA 91723, United States
AI provider / generative AI modelGoogle service / Gemini API – Google Ireland Limited, Google LLCGordon House, Barrow Street, Dublin 4, Ireland
Mobile application store and in-app paymentApple Distribution International Ltd. / Apple groupHollyhill Industrial Estate, Hollyhill, Cork, Ireland
Mobile application store and in-app paymentGoogle Ireland Limited / Google groupGordon House, Barrow Street, Dublin 4, Ireland
Marketing partner / recipientPitch System Kft.9515 Pápoc, Sárvár utca 2.
Push notification providerApple Push Notification service / Google Firebase Cloud MessagingHollyhill Industrial Estate, Hollyhill, Cork, Ireland / Gordon House, Barrow Street, Dublin 4, Ireland
Weather data sourceHungaroMet Nonprofit Zrt.www.met.hu
Weather data sourceNorwegian Meteorological Institutewww.yr.no
Application developer / IT operatorQuivra Labs Kft.1063 Budapest, Szinyei Merse Pál utca 21. I. em. 5., info@quivralabs.com
Legal representativeDSZA Legal1116 Budapest, Fehérvári út 132-144. I. ép. fszt. 9.

Beyond the recipients listed above, the Data Controller may transfer personal data provided by you to a competent authority, court or applicant where required by an official or judicial request, or where justified to protect the rights and freedoms of the Data Controller or others.

Where personal data are transferred to a third country outside the European Economic Area, the Data Controller ensures appropriate data transfer safeguards in accordance with Chapter V of the GDPR, in particular through adequacy decisions, standard contractual clauses adopted by the European Commission, supplementary technical and organisational measures, and the applicable service provider data processing terms. For Vercel, Google / Gemini API and other external providers, the data transfer safeguards must be specified in the final privacy notice based on the actual contractual arrangements.

Web payment and in-app payment may involve different data flows. In the IAP model, card data is processed by Apple, Google or the relevant app store payment infrastructure; the Data Controller generally receives only the data necessary to verify subscription entitlement and transaction status. For web checkout, the exact details of the payment provider and billing provider must be provided before finalisation.

General Data Security Measures

The Data Controller assesses the risks arising from its processing activities and evaluates them in terms of the severity and likelihood of occurrence in order to guarantee an appropriate level of data security.

When operating its IT systems, the Data Controller provides the necessary access management, internal organisational and technical solutions to ensure that data can only be accessed by authorised persons, and that personal data cannot come into the possession of unauthorised persons or be deleted, exported from the system or modified by them.

The Data Controller also enforces data protection and data security requirements against its data processors through prior assessments and data processing agreements.

The Data Controller maintains a record of any data protection incidents and, where required under the GDPR, notifies the National Authority for Data Protection and Freedom of Information and the affected data subjects.

Internet communication between the Data Controller and persons visiting or using the application takes place via an encrypted connection using the https protocol.

The Data Controller applies password protection, access control, logging, rights management and technical protection measures proportionate to the risks on its IT devices.

AI chat and photo upload may present special data protection risks; therefore, the Data Controller strives to ensure that only data necessary for providing responses is transferred to the AI provider, and provides users with clear information about the risks of free-text and image content.

Rights of Data Subjects

The data subject may at any time request information by post, email or telephone at the contact details set out in this notice regarding the personal data we process about them.

Upon request, we will inform the data subject of:

  • the data processed,
  • the purpose of processing,
  • the legal basis,
  • the retention period,
  • who receives or has received their data and for what purpose.

The information will be provided in writing within one month of the request, by paper or electronic means depending on how the request was made.

The data subject may at any time object to the processing of their personal data. We will examine the objection and make a decision on its merits within the shortest possible time, but no later than one month, and notify the data subject of our decision.

The data subject may at any time request the erasure of personal data we process about them, or the rectification of incorrectly recorded personal data.

We will also restrict the data subject's personal data if they request it, or if available information suggests that erasure would prejudice the data subject's legitimate interests. Restricted data will be processed until the processing purpose or legitimate interest that precluded erasure ceases to exist.

The data subject may, through the contact details in this notice, request that the Data Controller restrict the processing of their personal data (with clear marking of the restricted nature and separate handling from other data) where:

  • the data subject contests the accuracy of the personal data (in which case the Data Controller will restrict processing for the period necessary to verify accuracy);
  • the processing is unlawful and the data subject opposes erasure and requests restriction of use instead;
  • the Data Controller no longer needs the personal data for processing purposes but the data subject requires it for the establishment, exercise or defence of legal claims; or
  • the data subject has objected to processing (in which case the restriction applies until it is determined whether the Data Controller's legitimate grounds override those of the data subject).

The data subject is entitled, through the contact details in this notice, to receive the personal data they have provided to the Data Controller in a structured, commonly used, machine-readable format, and to transmit those data to another data controller or processor without hindrance from the Data Controller.

We will comply with access, erasure, rectification, restriction, portability and locking requests as soon as possible, but within one month, and will notify the data subject. If we are unable to comply with a request, we will notify the data subject within one month.

Where data have been transferred to another party with the data subject's consent, we will also notify the recipient of the necessary steps.

Where we process personal data on the basis of the data subject's consent, the data subject may withdraw their consent at any time. Consent may be withdrawn by contacting the Data Controller at the details set out in this notice; where appropriate, the Data Controller will also provide simpler means of withdrawal.

If the data subject is visually impaired or elderly, they may request that the Data Controller provide the content of this Privacy Notice in Word (text) format or in large print, through the contact details set out in this notice.

The data subject is also entitled to lodge a complaint with the

National Authority for Data Protection and Freedom of Information

1055 Budapest, Falk Miksa utca 9-11.

www.naih.hu

+36 (1) 391-1400

ugyfelszolgalat@naih.hu

or to enforce their rights relating to the processing of personal data before a court with competent jurisdiction under Act CXXX of 2016 on the Code of Civil Procedure.

The competent court can be found at:

birosag.hu/birosag-kereso

The data subject may exercise the rights listed in this notice at any time by contacting the Data Controller by email or other written means. In connection with such a request, the Data Controller may ask the requesting person to identify themselves or provide other personal data to verify their entitlement. Requests will be handled in the manner set out under the contact section of this privacy notice.

The Data Controller may be contacted through the details set out in Section 1.

Quivra Labs Korlátolt Felelősségű Társaság – Data Controller