K klubtár

Privacy Policy

Effective from: [DATE]

Draft: the bracketed [DETAILS] must be filled in, and the text requires legal review before publication — until then it is not a binding document.

This English translation is provided for convenience only — the Hungarian version prevails.

1. The data controller

The data controller is the operator of the Klubtár platform: [COMPANY NAME] (registered office: [ADDRESS]; tax number: [TAX NUMBER]); e-mail: [PRIVACY E-MAIL]. No data protection officer has been appointed / the data protection officer is: [NAME, CONTACT].

2. Data processed and purposes

Partner registration and contact: the contact person's name, e-mail address and password (stored irreversibly hashed), and the organisation's company details. Legal basis: performance of a contract (GDPR Art. 6(1)(b)). Retention: [5] years after the contract ends (general limitation period).

Invoicing: the data required to issue invoices. Legal basis: legal obligation (GDPR Art. 6(1)(c); Hungarian Accounting Act). Retention: 8 years.

Card payments: the Provider never sees or stores card data; payments are handled by OTP Mobil Kft. (SimplePay) under its own privacy policy. Only the data necessary to identify the transaction is transferred.

Visitor analytics: the Platform uses server-side, cookie-free statistics producing aggregated data unsuitable for identification. Legal basis: the Provider's legitimate interest (GDPR Art. 6(1)(f)) — improving the service.

3. Customer data on partner sites

For customer data provided on the partner clubs' websites and web shops, the data controller is the given partner club; the Provider acts as data processor under the data processing agreement concluded with the partner. Customers should exercise their data subject rights primarily with the club concerned.

4. Processors and recipients

Hosting and operations: [HOSTING PROVIDER NAME, ADDRESS]. Online payments: OTP Mobil Kft. (SimplePay). Invoicing: [INVOICING PROVIDER, e.g. Billingo Technologies Zrt.]. E-mail delivery: [E-MAIL PROVIDER].

Data is not transferred to third countries. / [If it is: recipient and safeguards of the transfer.]

5. Data security

The Provider transmits personal data over encrypted connections (HTTPS), stores passwords irreversibly hashed, keeps partners' data logically separated from each other, applies access control and logging, and makes regular backups.

6. Data subject rights

Data subjects may request access to, rectification or erasure of their data, restriction of processing, data portability, and may object to processing based on legitimate interest. The controller responds without undue delay, at the latest within one month. Contact: [PRIVACY E-MAIL].

7. Remedies

Complaints may be lodged with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH — 1055 Budapest, Falk Miksa utca 9–11.; ugyfelszolgalat@naih.hu; www.naih.hu), and data subjects may also turn to the competent regional court.

8. Cookies

The central site only uses cookies strictly necessary for operation (session identifier, security/CSRF cookie); there are no marketing or tracking cookies. Visitor analytics is cookie-free.

9. Changes to this policy

The Provider may amend this policy; the current version is always available on this page. Partners are notified of material changes by e-mail.