Privacy Policy
Effective from: 12 August 2026
Version: 2.2
Introduction
AVEROLS-MANDO Kft. (registered seat: Nyugati tér 7, 1055 Budapest, Hungary; company registration number: 01 09 375298; VAT number: 28819763-2-41; registry court: Company Registry Court of the Budapest-Capital Regional Court; hereinafter: the Controller or the Service Provider), as the operator of the oi75.com online store available under the OI75 brand (together with other domains redirected to it, such as oimatcha.hu), of the Tevello-based community platform and of the OI75 mobile application, is committed to the protection of personal data.
This Privacy Policy (hereinafter: the Policy) sets out in detail what personal data the Controller processes in the course of providing its services, for what purpose, on what legal basis and for how long, to whom it transfers such data, and what rights data subjects may exercise in relation to their personal data.
The Policy has been prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter: GDPR), and with Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Infotv.).
The Policy covers all services provided by the Service Provider: online store purchases, the OI75 Club monthly digital subscription, the 75-day Challenge system and its Reward, email marketing activity, use of the Tevello community platform, and use of the OI75 mobile application (Apple App Store / Google Play).
DELETING YOUR ACCOUNT AND DATA
You may delete your OI75 account and the data belonging to it at any time. Steps to request deletion:
1. From the app (fastest)
Open the OI75 app and choose: Me tab → Settings → Delete account. Deletion starts immediately and cannot be undone.
2. By email
If you cannot access the app, write to hello@oi75.com with the subject "Delete account", from the email address your account uses. After identification, we fulfil the request within 30 days at the latest.
What we delete
your account and profile (name, email address, profile picture);
your logs: meals, body weight, workouts, challenge progress;
your community content: posts, comments, reactions, own recipes;
your uploaded images;
your push notification identifiers.
What we retain, and for how long
billing and order data for the period prescribed by law (accounting documents: 8 years, Section 169 of the Accounting Act) — these relate to the purchase of club membership, not to the app account;
documents relating to consumer complaints for 5 years (Section 17/A(7) of the Consumer Protection Act);
content already deleted may remain in backups for up to 30 days, after which it also falls out of the backups.
Important: deleting your OI75 account does not automatically cancel your club membership (OI75 Club subscription). Membership must be cancelled separately.
The detailed rules on the right to erasure are set out in Section 7.3 of this Policy.
1. Details of the Controller
Company name
AVEROLS-MANDO Korlátolt Felelősségű Társaság
Short company name
AVEROLS-MANDO Kft.
Registered seat
Nyugati tér 7, 1055 Budapest, Hungary
Company registration number
01 09 375298
VAT number
28819763-2-41
Registry court
Company Registry Court of the Budapest-Capital Regional Court
Authorised representative
Olivia Sütő (managing director)
Email
hello@oi75.com
Phone
+36 70 320 00 52
Customer service hours
Monday to Friday, 9:00–17:00 (CET/CEST)
Website
https://oi75.com
The Controller has not appointed a dedicated Data Protection Officer (DPO), as the conditions for mandatory appointment under Article 37 GDPR are not met.
2. Scope, purpose, legal basis and retention period of the personal data processed
The Controller processes the personal data of data subjects in connection with the following activities:
2.1. Online store purchase (physical products)
Data processed
surname, first name, email address, phone number, billing address, shipping address, details of the products ordered, order identifier, time of purchase, payment method
Purpose of processing
fulfilment of the order (delivery, returns handling), issuing invoices, keeping in contact with the customer
Legal basis
Article 6(1)(b) GDPR — performance of a contract; in respect of accounting data, Article 6(1)(c) GDPR — compliance with a legal obligation (accounting)
Retention period
until performance of the contract + 5 years based on the general limitation period under civil law (Section 6:22 of the Civil Code); accounting documents are retained for 8 years (Section 169 of the Accounting Act)
2.2. Registration (customer account)
Data processed
name, email address, password (stored in encrypted form by the Shopify system), time of registration, order and subscription history linked to the account
Purpose of processing
operating the customer account, enabling sign-in, keeping a record of order history
Legal basis
Article 6(1)(b) GDPR — performance of a contract
Retention period
for the active existence of the account and until the account is deleted; after 3 years of inactivity counted from the last sign-in, the Controller is entitled to delete the account
2.3. OI75 Club subscription (digital service)
Data processed
name, email address, subscription start date, payment history, identifier linked to the Tevello account, the tokenised payment reference for the monthly fee (through the Shopify system)
Purpose of processing
provision of the OI75 Club service, automatic collection of the monthly fee, provision of Tevello access, management of membership entitlements
Legal basis
Article 6(1)(b) GDPR — performance of a contract
Retention period
for the active existence of the subscription; for 5 years after the subscription ends (Section 6:22 of the Civil Code), and payment documents for 8 years
2.4. 75-day Challenge and Reward
Data processed
Tevello identifier, name, email address, the time and content of the daily check-in comments, the completion status of the Challenge, documents on the issuing and redemption of the Reward
Purpose of processing
tracking completion of the Challenge, establishing eligibility for the Reward, issuing the Reward, handling any complaints
Legal basis
Article 6(1)(b) GDPR — performance of a contract
Retention period
5 years from the closing of the Challenge (evidentiary need in case of a possible legal dispute)
2.5. Email marketing and newsletter
Data processed
name, email address, time and method of subscription, newsletter open and click statistics, the history of marketing communication with the recipient, interest segment (where relevant)
Purpose of processing
sending marketing newsletters and promotional offers, promoting the Controller's products and services, targeting personalised offers
Legal basis
Article 6(1)(a) GDPR — consent of the data subject; in the case of existing customers, legitimate interest may be applied to directly related products under Section 6(1) of Act XLVIII of 2008 on Business Advertising Activity (known as "soft opt-in"); in both cases this may be withdrawn at any time
Retention period
until consent is withdrawn (unsubscribe), or deleted after 2 years of inactivity counted from the last active communication
2.6. UGC — content published by the Member in the Community
Data processed
comments, posts, photos and videos published by the Member, the time of publication, the Member's Tevello / Facebook identifier
Purpose of processing
enabling community interaction, operating the Community, and presenting selected excerpts in the Controller's marketing communication, either anonymously or — subject to separate consent — in identifiable form
Legal basis
Article 6(1)(b) GDPR — performance of a contract (within the Community); for external use for marketing purposes, Article 6(1)(a) GDPR — consent of the data subject
Retention period
within the Community, for the duration of the membership relationship and thereafter in accordance with the operating rules of the platform; in the case of use for marketing purposes, until consent is withdrawn
2.7. Complaint handling, customer service
Data processed
name, email address, possibly phone number, the subject and content of the complaint or enquiry, the time of communication
Purpose of processing
investigating and answering the complaint or enquiry
Legal basis
Article 6(1)(c) GDPR — legal obligation (for consumer complaints, under Section 17/A of the Consumer Protection Act), and Article 6(1)(f) GDPR — legitimate interest (customer service enquiries in general)
Retention period
the Controller retains documents relating to consumer complaints for 5 years (Section 17/A(7) of the Consumer Protection Act)
2.8. Use of the OI75 mobile application (Apple App Store / Google Play)
Data processed
the Member's sign-in identifier (the email address used in the Online Store), name, App session data, the log data recorded in the App (meals and their calorie values, body weight, workout entries, challenge progress), photos uploaded by the Member, basic logs of content views within the App (for example which course chapter was opened), device identifier, operating system type and version, debugging logs
Purpose of processing
providing secure access through the App to the content of an already purchased Club membership, operating the logging and tracking functions (meal, body weight and workout log, challenge), ensuring the technical operation and stability of the App, troubleshooting
Legal basis
Article 6(1)(b) GDPR — performance of a contract (access to Club content and provision of the logging functions), and Article 6(1)(f) GDPR — legitimate interest (technical operation, security)
Retention period
log data for as long as the account exists, or until the account is deleted (see "Deleting your account and data"); session data for as long as required for the technical operation of the App; debugging logs for a maximum of 90 days
Payment in the App. Club membership can be purchased in two ways: in the Online Store (oi75.com), or as an in-app purchase through the payment system of the Apple App Store or Google Play. An in-app purchase takes place entirely on the store's own interface: the payment data (card number, billing details) is handled by Apple or Google as an independent controller — the Controller neither sees nor stores it. From the store, the Controller receives only whether a valid subscription belongs to the given user (the purchase receipt and its expiry date), and uses this solely to establish membership entitlement.
In connection with downloading, installing, reviewing and using an account in the stores (Apple App Store, Google Play), Apple Inc. and Google Ireland Ltd. / Google LLC process data about the Member in their own right, as independent controllers, in accordance with their own privacy policies; the Controller does not receive such data and is not responsible for its processing. (The privacy documentation of the stores is available on their websites.)
2.9. Cookies and tracking technologies
Details of the use of cookies and tracking technologies (analytics, marketing, functional) are set out in Section 11 of this Policy.
3. Source of the personal data
The Controller collects personal data from the following sources:
directly from the data subject — during registration, ordering, newsletter subscription, customer service enquiries and community interaction;
automatically — during use of the Online Store and the Tevello platform (IP address, device data, browsing data, cookies);
from service partners — from processors acting on behalf of the Service Provider (for example the parcel service regarding delivery confirmation, the payment provider regarding transaction status).
The Controller does not purchase personal data lists from third parties and does not use targeting data obtained from data brokers.
4. Special provisions relating to minors
The Controller does not target the OI75 services at minors. The Controller does not knowingly process the data of natural persons under 16 years of age; if the Controller becomes aware that it has collected data about a person under 16, it deletes that data without delay.
A data subject between 16 and 18 years of age may use the Controller's services only with the permission of their legal representative (parent or guardian).
5. Automated decision-making, profiling
The Controller does not take automated decisions based solely on algorithms in relation to data subjects that would produce legal effects concerning them or similarly significantly affect them (Article 22 GDPR).
The Controller does apply segmentation for marketing purposes (for example targeting relevant newsletter content based on purchase history or interests); however, this does not qualify as automated decision-making under Article 22 GDPR, as it does not produce a binding decision concerning the data subject.
6. Data security
In order to protect personal data, the Controller applies the following measures:
the Online Store and subscription management run on the infrastructure of the Shopify platform, which holds ISO/IEC 27001 certification and is PCI-DSS Level 1 compliant;
the Controller neither sees nor stores payment data (card numbers); these are handled by Shopify and its payment provider partners in accordance with the PCI-DSS standard;
sign-in data (username, password) is stored by the Shopify and Tevello platforms using encrypted technical solutions independent of the Controller; the Controller does not know and cannot come to know the password;
the Controller restricts data access narrowly among its staff, to the extent necessary for the task;
data communication takes place with HTTPS / TLS encryption;
the Controller makes regular backups.
The Controller applies the data security measures under Article 32 GDPR proportionately to the risks. Like any online service provider, the Controller cannot guarantee absolute security.
In the event of a personal data breach, the Controller notifies the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) without undue delay and no later than 72 hours after becoming aware of it, and — where the breach poses a high risk to the data subjects — also informs the data subjects.
7. Rights of the data subject
Under the GDPR, the data subject has the following rights in relation to the processing of their personal data:
7.1. Right of access (Article 15 GDPR)
The data subject may request information from the Controller about what personal data it processes about them, for what purpose, for how long, and to whom it transfers that data.
7.2. Right to rectification (Article 16 GDPR)
The data subject may request the rectification of inaccurate personal data concerning them and the completion of incomplete data.
7.3. Right to erasure / "right to be forgotten" (Article 17 GDPR)
In defined cases the data subject may request the erasure of their personal data, in particular:
where the data is no longer necessary for the original purpose;
where they withdraw their consent (and there is no other legal basis);
where the data is processed unlawfully.
The right to erasure is not unlimited: where a statutory obligation applies (for example the retention of accounting documents), the Controller may continue to process the relevant data.
The specific steps for deleting the OI75 account and the data belonging to it are set out in the "Deleting your account and data" section at the beginning of this Policy.
7.4. Right to restriction of processing (Article 18 GDPR)
In defined cases (for example where the accuracy of data is contested, or where a legal claim is being pursued) the data subject may request the restriction of processing.
7.5. Right to data portability (Article 20 GDPR)
The data subject has the right to receive the personal data concerning them which they have provided, in a structured, commonly used, machine-readable format, or to request its direct transmission to another controller (where technically feasible).
7.6. Right to object (Article 21 GDPR)
The data subject has the right to object to processing based on legitimate interest, in particular to processing for direct marketing purposes. In the latter case the Controller must cease the processing for that purpose without delay.
7.7. Right to withdraw consent (Article 7(3) GDPR)
Where the legal basis of processing is consent (for example the newsletter, or the use of UGC for marketing), the data subject may withdraw their consent at any time, without giving reasons, with effect for the future. Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
7.8. Right to lodge a complaint (Article 77 GDPR)
The data subject has the right to lodge a complaint with the supervisory authority, which in Hungary is the Hungarian National Authority for Data Protection and Freedom of Information (details in Section 12).
7.9. How to exercise these rights
The data subject may exercise the above rights using the following contact details:
email: hello@oi75.com
postal address: Nyugati tér 7, 1055 Budapest, Hungary
The Controller answers the request without undue delay and within 1 month at the latest. Where that deadline needs to be extended because of the complexity or the large number of requests, the Controller may extend it by a further 2 months, notifying the data subject at the same time.
In order to verify the identity of the data subject, the Controller is entitled to request identifying data from them (for example confirmation of the email address used for the order). This is necessary in order to prevent abuse.
The exercise of these rights is free of charge for the data subject, unless the request is manifestly unfounded or excessive, in particular because of its repetitive character (in which case the Controller may charge a reasonable fee or refuse to act on the request).
7.10. Prohibition of discrimination, and choices regarding targeted advertising
The Controller does not discriminate against a data subject for having exercised any of the rights listed in this Section: neither the quality nor the price of the service changes because those rights are exercised.
A data subject may at any time request that the Controller not share information about them for the purpose of ad targeting based on their online activity across different merchants and websites. This can be done by changing the cookie settings on the Website, or by sending a request to hello@oi75.com. In some countries and states (in particular in certain states of the United States of America) local law may grant the data subject an additional, separate right to opt out of the "sale" or "sharing" of personal data; that right may be exercised through the same contact details.
8. Newsletter unsubscription and management of marketing communication
The data subject may unsubscribe from marketing email communication:
by clicking the "Unsubscribe" link at the bottom of any marketing email; or
by sending a request to the email address hello@oi75.com.
The Controller fulfils unsubscription requests without delay.
Unsubscription applies to communication for marketing purposes. The data subject may still receive transactional emails relating to the performance of the contract (for example order confirmation, notice of the collection of the monthly Club fee, challenge completion feedback), as the legal basis for these is the performance of the contract, not consent.
9. Processors
The Controller engages processor partners for certain operations involving personal data. Processors act on behalf of and on the instructions of the Controller, under a written data processing agreement in accordance with Article 28 GDPR.
9.1. Hosting and online store provider
Name
Shopify International Ltd.
Registered seat
Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland
Role
hosting of the Online Store, management of the ordering process, management of the customer account and OI75 Club subscriptions, operation of Shopify's built-in payment system
Transfer to a third country
yes (see Section 10)
Privacy documentation
https://www.shopify.com/legal/privacy
In respect of certain enhanced features that Shopify itself develops (for example cross-merchant personalisation and the related ad targeting), Shopify acts not as a processor but as an INDEPENDENT CONTROLLER. Data subjects may exercise their rights in relation to that processing directly with Shopify at the following address: https://privacy.shopify.com/en
9.2. Community and education platform
Name
Tevello (a service running on Shopify infrastructure as a Shopify application)
Role
operating the OI75 Community interface, providing courses and educational content, recording the daily Challenge check-in comments
Privacy documentation
the privacy policy of Tevello as in force from time to time
9.3. Payment provider
Name
Shopify Payments (a payment service operated by Shopify International Ltd.)
Role
processing card transactions, collecting the monthly subscription fee (recurring payment)
Data processed
for the Service Provider: transaction identifier, amount, status; the Service Provider does not see the card data
9.4. Delivery partner
Name
Magyar Posta Zrt. (MPL)
Registered seat
Dunavirág u. 2-6, 1138 Budapest, Hungary
Role
delivery of ordered products
Data processed
recipient's name, shipping address, phone number, email address, parcel identifier, weight data
9.5. Invoicing system
Name
Billingo Technologies Zrt. (registered seat: Árbóc utca 6, 1133 Budapest, Hungary)
Role
issuing electronic invoices, storing invoice data
Data processed
billing name, address, VAT number (for companies), products ordered, amount, payment method
9.6. Email marketing system
Name
Sendinblue SAS (trading as Brevo; registered seat: 106 boulevard Haussmann, 75008 Paris, France)
Role
sending newsletters and automated email campaigns, collecting statistics
Data processed
name, email address, subscription date, email open and click statistics
9.7. Social media platform
Name
Meta Platforms Ireland Ltd.
Registered seat
Merrion Road, Dublin 4, D04 X2K5, Ireland
Role
operating the Facebook group, and ad targeting and measurement through the Meta Pixel placed on the Online Store — see Section 11
Privacy documentation
https://www.facebook.com/privacy/policy
9.8. Web analytics and marketing pixels
Name
Google Ireland Ltd. (registered seat: Gordon House, Barrow Street, Dublin 4, Ireland) — Google Analytics 4
Role
anonymised traffic analysis, collecting statistics on the use of the Online Store
Name
TikTok Information Technologies UK Ltd. (registered seat: WeWork, 125 Shaftesbury Avenue, London, WC2H 8AD, United Kingdom) — TikTok Pixel
Role
ad targeting and measurement, feeding conversions from the Online Store (purchase, add to cart, page view) back into TikTok's advertising system
Privacy documentation
https://www.tiktok.com/legal/privacy-policy
9.9. Technical publisher of the OI75 mobile application
Name
Griff Webshop Kft.
Registered seat
Nyugati tér 7, 1055 Budapest, Hungary
Company registration number
01 09 321829
Role
technical publication of the OI75 mobile application in the Apple App Store and Google Play stores, and maintaining the developer relationship with the stores. The App publisher is not a contracting party to the Club contract between the Member and the Controller, and does not sell any product or service. The App publisher processes the Member's personal data on the instructions of the Controller, under an agreement concluded with the Controller.
Data processed
the data listed in Section 2.8 that is necessary for the technical operation of the App
9.10. The app stores (as independent controllers)
The following organisations are not processors of the Controller; they process the Member's data collected by them in their own right, as independent controllers, in accordance with their own privacy policies:
Name
Apple Inc. (and Apple Distribution International Ltd.)
Role
downloading, installing and updating the OI75 mobile application through the Apple App Store; processing relating to the Apple account
Privacy documentation
https://www.apple.com/legal/privacy/
Name
Google Ireland Ltd. / Google LLC
Role
downloading, installing and updating the OI75 mobile application through the Google Play store; processing relating to the Google account
Privacy documentation
https://policies.google.com/privacy
The Controller does not receive the data collected by the above store operators and is not responsible for its processing.
9.11. Artificial intelligence (AI) provider
Name
Anthropic PBC (registered seat: United States of America) — provider of the "Claude" language model
Role
estimating the nutritional value of food recorded by the user in the app (based on entered text and photographs), producing the written analysis of the daily nutrition summary, and machine translation of community posts
Data processed
the description of the food provided by the user; the food photograph taken by the user; for the daily analysis, the nutrition, water and step data recorded for that day, and — if the user has recorded them — body weight, sleep duration and mood; the text of the community post, comment or recipe
The Service Provider transfers NO identifying data to the AI provider: no name, no email address, no user or device identifier. The app does not connect directly to the AI provider, but through the Service Provider's own server. The Service Provider does not store the text of the requests.
For the processing of the user's OWN logged data (food estimation from text and photograph, daily analysis, recipe macros), the app asks for the user's explicit, prior consent; until consent is given, no data is transferred to the AI provider in these functions. Consent can be withdrawn at any time on the Settings screen of the app.
There is a single exception to this: the machine translation into English of posts, comments and recipes PUBLISHED on the community interface. The Service Provider initiates this on the server side at the time of publication, so that members who are not native Hungarian speakers can also read the content. It applies exclusively to text that the user has already made public to the community, never to the private log. The result of the translation is stored together with the post and is deleted together with the post.
Privacy documentation
https://www.anthropic.com/legal/privacy
9.12. Operator of the app backend
Name
Cloudflare, Inc. (registered seat: 101 Townsend St., San Francisco, CA 94107, United States of America)
Role
operating the backend of the OI75 mobile application (application server, database, file storage, cache). The log, profile and community data recorded in the App is stored on this infrastructure.
Data processed
the data listed in Sections 2.6 and 2.8
Transfer to a third country
yes (see Section 10)
Privacy documentation
https://www.cloudflare.com/privacypolicy/
9.13. Transfer of data in the context of a business transaction
In the event of the Controller's transformation, merger, division, transfer of a business line or of assets, acquisition, liquidation or bankruptcy, personal data may pass to the legal successor or to the party acquiring the assets. In such a case the data may be used solely for the purposes set out in this Policy, and the Controller informs data subjects of the change in accordance with Section 13.
The Controller keeps an accurate and up-to-date list of the processors actually in use in its own records; the set of processors listed in this Section may change, of which the Controller gives notice by amending this Policy.
10. International data transfers
Certain processors engaged by the Controller (in particular Shopify International Ltd., Meta Platforms Ireland Ltd., Google Ireland Ltd., Anthropic PBC, Cloudflare, Inc. and TikTok Information Technologies UK Ltd.) may transfer personal data to countries outside the European Economic Area (EEA), primarily to the United States and Canada, and in the case of TikTok to servers operating in third countries outside China.
The legal guarantees for international data transfers are the following:
the Standard Contractual Clauses (SCC) approved by the European Commission, which the processor partner has undertaken in its contract concluded with the Controller;
where available, the processor's certification under the EU-US Data Privacy Framework;
supplementary technical and organisational safeguards for the protection of personal data.
Further information on these guarantees is available in the privacy documentation of the given processor, or may be requested from the Controller in writing (hello@oi75.com).
11. Cookies and tracking technologies
11.1. What are cookies?
A cookie is a small text data file which the Website stores on the visitor's device through their browser. Cookies allow the Website to "remember" the visitor's preferences, to manage the signed-in state, or to collect statistics on the use of the Website.
11.2. Categories of cookies used
a) Strictly necessary cookies
These cookies are necessary for the basic operation of the Website (for example maintaining the signed-in state, preserving the contents of the cart during browsing). The visitor's consent is not required for these, as their legal basis is the Controller's legitimate interest in operating the service.
b) Preference cookies
These cookies remember the visitor's choices (for example language, display mode). The data subject's consent is required for their use.
c) Analytics cookies
These cookies provide anonymised statistics on the use of the Website (for example Google Analytics). The data subject's consent is required for their use.
d) Marketing / advertising cookies
These cookies display advertisements relevant to the visitor on other websites as well (for example Meta Pixel, Google Ads). The data subject's explicit, prior consent is required for their use.
11.3. Managing consent
On a first visit to the Website, the visitor can state through a cookie banner which categories of cookies they permit. Consent may be withdrawn at any time by reopening the cookie settings or by changing the relevant settings in the browser.
11.4. Blocking cookies
The visitor may block the use of cookies in their browser; this may however result in certain functions of the Website being unavailable or not working correctly.
11.5. Third-party websites and links
The Website and the App may contain links to websites or platforms operated by third parties (for example to scientific sources, to the privacy documentation of service partners, or to social media pages). If a data subject follows a link to a website that is not under the Controller's control, please read that website's own privacy terms and terms of use. The Controller accepts no responsibility for the data processing, security or content of such websites, and the placement of a link does not in itself constitute endorsement of them.
Information shared on a public or semi-public interface — such as the OI75 Community or third-party social platforms — may be visible to other users. Data subjects should carefully consider what personal data they publish on such interfaces.
12. Enforcement — lodging a complaint with the authority
12.1. Complaint to the Controller
If the data subject considers that the processing of their personal data infringes their rights, they may in the first instance contact the Controller at the email address hello@oi75.com or by post (Nyugati tér 7, 1055 Budapest, Hungary). The Controller investigates the complaint and provides a reasoned, written answer.
12.2. Complaint to the supervisory authority
The data subject may also lodge a complaint with the supervisory authority:
Name
Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH)
Address
Falk Miksa utca 9-11, 1055 Budapest, Hungary
Postal address
1363 Budapest, Pf.: 9, Hungary
Phone
+36 1 391 1400
Fax
+36 1 391 1410
Email
ugyfelszolgalat@naih.hu
Website
https://naih.hu
12.3. Recourse to the courts
In the event of an infringement of their rights, the data subject may turn to the regional court competent for their place of residence or for the registered seat of the Controller. At the data subject's choice, proceedings may also be brought before the regional court of their place of residence.
13. Amendment of this Policy
The Controller reserves the right to amend this Policy unilaterally. The Controller informs data subjects of any amendment:
by publishing the updated version on the Website;
by email notification sent to registered users and Members (in the case of a material change).
The amended Policy takes effect from the day of publication.
14. Entry into force
This Privacy Policy enters into force on 12 August 2026 and remains valid until withdrawn or until the next amendment enters into force. It replaces version 2.1 (effective from 29 July 2026).
Changes in version 2.2: a new Section 9.11 on the artificial intelligence (AI) provider (Anthropic PBC); a new Section 9.12 on the operator of the app backend (Cloudflare, Inc.); an extension of Section 2.8 covering in-app purchases; an extension of Section 9.1 covering Shopify's role as an independent controller; the addition of provisions previously present only in the online store's template policy (7.10 prohibition of discrimination and targeted advertising, 9.13 business transactions, 11.5 third-party websites); and a related extension of Section 10 (international data transfers).
Budapest, 12 August 2026
AVEROLS-MANDO Kft.
Controller
---
This Privacy Policy was originally drawn up in Hungarian. In the event of any discrepancy between the Hungarian and the English version, the Hungarian version prevails.