Privacy policy

Privacy Policy

Effective from: 12 August 2026

Version: 2.2


Introduction

AVEROLS-MANDO Kft. (registered seat: Nyugati tér 7, 1055 Budapest, Hungary; company registration number: 01 09 375298; VAT number: 28819763-2-41; registry court: Company Registry Court of the Budapest-Capital Regional Court; hereinafter: the Controller or the Service Provider), as the operator of the oi75.com online store available under the OI75 brand (together with other domains redirected to it, such as oimatcha.hu), of the Tevello-based community platform and of the OI75 mobile application, is committed to the protection of personal data.

This Privacy Policy (hereinafter: the Policy) sets out in detail what personal data the Controller processes in the course of providing its services, for what purpose, on what legal basis and for how long, to whom it transfers such data, and what rights data subjects may exercise in relation to their personal data.

The Policy has been prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter: GDPR), and with Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Infotv.).

The Policy covers all services provided by the Service Provider: online store purchases, the OI75 Club monthly digital subscription, the 75-day Challenge system and its Reward, email marketing activity, use of the Tevello community platform, and use of the OI75 mobile application (Apple App Store / Google Play).


DELETING YOUR ACCOUNT AND DATA

You may delete your OI75 account and the data belonging to it at any time. Steps to request deletion:

1. From the app (fastest)

Open the OI75 app and choose: Me tab → Settings → Delete account. Deletion starts immediately and cannot be undone.

2. By email

If you cannot access the app, write to hello@oi75.com with the subject "Delete account", from the email address your account uses. After identification, we fulfil the request within 30 days at the latest.

What we delete

your account and profile (name, email address, profile picture);
your logs: meals, body weight, workouts, challenge progress;
your community content: posts, comments, reactions, own recipes;
your uploaded images;
your push notification identifiers.

What we retain, and for how long

billing and order data for the period prescribed by law (accounting documents: 8 years, Section 169 of the Accounting Act) — these relate to the purchase of club membership, not to the app account;
documents relating to consumer complaints for 5 years (Section 17/A(7) of the Consumer Protection Act);
content already deleted may remain in backups for up to 30 days, after which it also falls out of the backups.

Important: deleting your OI75 account does not automatically cancel your club membership (OI75 Club subscription). Membership must be cancelled separately.

The detailed rules on the right to erasure are set out in Section 7.3 of this Policy.


1. Details of the Controller

Company name

AVEROLS-MANDO Korlátolt Felelősségű Társaság

Short company name

AVEROLS-MANDO Kft.

Registered seat

Nyugati tér 7, 1055 Budapest, Hungary

Company registration number

01 09 375298

VAT number

28819763-2-41

Registry court

Company Registry Court of the Budapest-Capital Regional Court

Authorised representative

Olivia Sütő (managing director)

Email

hello@oi75.com

Phone

+36 70 320 00 52

Customer service hours

Monday to Friday, 9:00–17:00 (CET/CEST)

Website

https://oi75.com

The Controller has not appointed a dedicated Data Protection Officer (DPO), as the conditions for mandatory appointment under Article 37 GDPR are not met.


2. Scope, purpose, legal basis and retention period of the personal data processed

The Controller processes the personal data of data subjects in connection with the following activities:

2.1. Online store purchase (physical products)

Data processed

surname, first name, email address, phone number, billing address, shipping address, details of the products ordered, order identifier, time of purchase, payment method

Purpose of processing

fulfilment of the order (delivery, returns handling), issuing invoices, keeping in contact with the customer

Legal basis

Article 6(1)(b) GDPR — performance of a contract; in respect of accounting data, Article 6(1)(c) GDPR — compliance with a legal obligation (accounting)

Retention period

until performance of the contract + 5 years based on the general limitation period under civil law (Section 6:22 of the Civil Code); accounting documents are retained for 8 years (Section 169 of the Accounting Act)

2.2. Registration (customer account)

Data processed

name, email address, password (stored in encrypted form by the Shopify system), time of registration, order and subscription history linked to the account

Purpose of processing

operating the customer account, enabling sign-in, keeping a record of order history

Legal basis

Article 6(1)(b) GDPR — performance of a contract

Retention period

for the active existence of the account and until the account is deleted; after 3 years of inactivity counted from the last sign-in, the Controller is entitled to delete the account

2.3. OI75 Club subscription (digital service)

Data processed

name, email address, subscription start date, payment history, identifier linked to the Tevello account, the tokenised payment reference for the monthly fee (through the Shopify system)

Purpose of processing

provision of the OI75 Club service, automatic collection of the monthly fee, provision of Tevello access, management of membership entitlements

Legal basis

Article 6(1)(b) GDPR — performance of a contract

Retention period

for the active existence of the subscription; for 5 years after the subscription ends (Section 6:22 of the Civil Code), and payment documents for 8 years

2.4. 75-day Challenge and Reward

Data processed

Tevello identifier, name, email address, the time and content of the daily check-in comments, the completion status of the Challenge, documents on the issuing and redemption of the Reward

Purpose of processing

tracking completion of the Challenge, establishing eligibility for the Reward, issuing the Reward, handling any complaints

Legal basis

Article 6(1)(b) GDPR — performance of a contract

Retention period

5 years from the closing of the Challenge (evidentiary need in case of a possible legal dispute)

2.5. Email marketing and newsletter

Data processed

name, email address, time and method of subscription, newsletter open and click statistics, the history of marketing communication with the recipient, interest segment (where relevant)

Purpose of processing

sending marketing newsletters and promotional offers, promoting the Controller's products and services, targeting personalised offers

Legal basis

Article 6(1)(a) GDPR — consent of the data subject; in the case of existing customers, legitimate interest may be applied to directly related products under Section 6(1) of Act XLVIII of 2008 on Business Advertising Activity (known as "soft opt-in"); in both cases this may be withdrawn at any time

Retention period

until consent is withdrawn (unsubscribe), or deleted after 2 years of inactivity counted from the last active communication

2.6. UGC — content published by the Member in the Community

Data processed

comments, posts, photos and videos published by the Member, the time of publication, the Member's Tevello / Facebook identifier

Purpose of processing

enabling community interaction, operating the Community, and presenting selected excerpts in the Controller's marketing communication, either anonymously or — subject to separate consent — in identifiable form

Legal basis

Article 6(1)(b) GDPR — performance of a contract (within the Community); for external use for marketing purposes, Article 6(1)(a) GDPR — consent of the data subject

Retention period

within the Community, for the duration of the membership relationship and thereafter in accordance with the operating rules of the platform; in the case of use for marketing purposes, until consent is withdrawn

2.7. Complaint handling, customer service

Data processed

name, email address, possibly phone number, the subject and content of the complaint or enquiry, the time of communication

Purpose of processing

investigating and answering the complaint or enquiry

Legal basis

Article 6(1)(c) GDPR — legal obligation (for consumer complaints, under Section 17/A of the Consumer Protection Act), and Article 6(1)(f) GDPR — legitimate interest (customer service enquiries in general)

Retention period

the Controller retains documents relating to consumer complaints for 5 years (Section 17/A(7) of the Consumer Protection Act)

2.8. Use of the OI75 mobile application (Apple App Store / Google Play)

Data processed

the Member's sign-in identifier (the email address used in the Online Store), name, App session data, the log data recorded in the App (meals and their calorie values, body weight, workout entries, challenge progress), photos uploaded by the Member, basic logs of content views within the App (for example which course chapter was opened), device identifier, operating system type and version, debugging logs

Purpose of processing

providing secure access through the App to the content of an already purchased Club membership, operating the logging and tracking functions (meal, body weight and workout log, challenge), ensuring the technical operation and stability of the App, troubleshooting

Legal basis

Article 6(1)(b) GDPR — performance of a contract (access to Club content and provision of the logging functions), and Article 6(1)(f) GDPR — legitimate interest (technical operation, security)

Retention period

log data for as long as the account exists, or until the account is deleted (see "Deleting your account and data"); session data for as long as required for the technical operation of the App; debugging logs for a maximum of 90 days

Payment in the App. Club membership can be purchased in two ways: in the Online Store (oi75.com), or as an in-app purchase through the payment system of the Apple App Store or Google Play. An in-app purchase takes place entirely on the store's own interface: the payment data (card number, billing details) is handled by Apple or Google as an independent controller — the Controller neither sees nor stores it. From the store, the Controller receives only whether a valid subscription belongs to the given user (the purchase receipt and its expiry date), and uses this solely to establish membership entitlement.

In connection with downloading, installing, reviewing and using an account in the stores (Apple App Store, Google Play), Apple Inc. and Google Ireland Ltd. / Google LLC process data about the Member in their own right, as independent controllers, in accordance with their own privacy policies; the Controller does not receive such data and is not responsible for its processing. (The privacy documentation of the stores is available on their websites.)

2.9. Cookies and tracking technologies

Details of the use of cookies and tracking technologies (analytics, marketing, functional) are set out in Section 11 of this Policy.


3. Source of the personal data

The Controller collects personal data from the following sources:

directly from the data subject — during registration, ordering, newsletter subscription, customer service enquiries and community interaction;
automatically — during use of the Online Store and the Tevello platform (IP address, device data, browsing data, cookies);
from service partners — from processors acting on behalf of the Service Provider (for example the parcel service regarding delivery confirmation, the payment provider regarding transaction status).

The Controller does not purchase personal data lists from third parties and does not use targeting data obtained from data brokers.


4. Special provisions relating to minors

The Controller does not target the OI75 services at minors. The Controller does not knowingly process the data of natural persons under 16 years of age; if the Controller becomes aware that it has collected data about a person under 16, it deletes that data without delay.

A data subject between 16 and 18 years of age may use the Controller's services only with the permission of their legal representative (parent or guardian).


5. Automated decision-making, profiling

The Controller does not take automated decisions based solely on algorithms in relation to data subjects that would produce legal effects concerning them or similarly significantly affect them (Article 22 GDPR).

The Controller does apply segmentation for marketing purposes (for example targeting relevant newsletter content based on purchase history or interests); however, this does not qualify as automated decision-making under Article 22 GDPR, as it does not produce a binding decision concerning the data subject.


6. Data security

In order to protect personal data, the Controller applies the following measures:

the Online Store and subscription management run on the infrastructure of the Shopify platform, which holds ISO/IEC 27001 certification and is PCI-DSS Level 1 compliant;
the Controller neither sees nor stores payment data (card numbers); these are handled by Shopify and its payment provider partners in accordance with the PCI-DSS standard;
sign-in data (username, password) is stored by the Shopify and Tevello platforms using encrypted technical solutions independent of the Controller; the Controller does not know and cannot come to know the password;
the Controller restricts data access narrowly among its staff, to the extent necessary for the task;
data communication takes place with HTTPS / TLS encryption;
the Controller makes regular backups.

The Controller applies the data security measures under Article 32 GDPR proportionately to the risks. Like any online service provider, the Controller cannot guarantee absolute security.

In the event of a personal data breach, the Controller notifies the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) without undue delay and no later than 72 hours after becoming aware of it, and — where the breach poses a high risk to the data subjects — also informs the data subjects.


7. Rights of the data subject

Under the GDPR, the data subject has the following rights in relation to the processing of their personal data:

7.1. Right of access (Article 15 GDPR)

The data subject may request information from the Controller about what personal data it processes about them, for what purpose, for how long, and to whom it transfers that data.

7.2. Right to rectification (Article 16 GDPR)

The data subject may request the rectification of inaccurate personal data concerning them and the completion of incomplete data.

7.3. Right to erasure / "right to be forgotten" (Article 17 GDPR)

In defined cases the data subject may request the erasure of their personal data, in particular:

where the data is no longer necessary for the original purpose;
where they withdraw their consent (and there is no other legal basis);
where the data is processed unlawfully.

The right to erasure is not unlimited: where a statutory obligation applies (for example the retention of accounting documents), the Controller may continue to process the relevant data.

The specific steps for deleting the OI75 account and the data belonging to it are set out in the "Deleting your account and data" section at the beginning of this Policy.

7.4. Right to restriction of processing (Article 18 GDPR)

In defined cases (for example where the accuracy of data is contested, or where a legal claim is being pursued) the data subject may request the restriction of processing.

7.5. Right to data portability (Article 20 GDPR)

The data subject has the right to receive the personal data concerning them which they have provided, in a structured, commonly used, machine-readable format, or to request its direct transmission to another controller (where technically feasible).

7.6. Right to object (Article 21 GDPR)

The data subject has the right to object to processing based on legitimate interest, in particular to processing for direct marketing purposes. In the latter case the Controller must cease the processing for that purpose without delay.

7.7. Right to withdraw consent (Article 7(3) GDPR)

Where the legal basis of processing is consent (for example the newsletter, or the use of UGC for marketing), the data subject may withdraw their consent at any time, without giving reasons, with effect for the future. Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.

7.8. Right to lodge a complaint (Article 77 GDPR)

The data subject has the right to lodge a complaint with the supervisory authority, which in Hungary is the Hungarian National Authority for Data Protection and Freedom of Information (details in Section 12).

7.9. How to exercise these rights

The data subject may exercise the above rights using the following contact details:

email: hello@oi75.com
postal address: Nyugati tér 7, 1055 Budapest, Hungary

The Controller answers the request without undue delay and within 1 month at the latest. Where that deadline needs to be extended because of the complexity or the large number of requests, the Controller may extend it by a further 2 months, notifying the data subject at the same time.

In order to verify the identity of the data subject, the Controller is entitled to request identifying data from them (for example confirmation of the email address used for the order). This is necessary in order to prevent abuse.

The exercise of these rights is free of charge for the data subject, unless the request is manifestly unfounded or excessive, in particular because of its repetitive character (in which case the Controller may charge a reasonable fee or refuse to act on the request).


7.10. Prohibition of discrimination, and choices regarding targeted advertising

The Controller does not discriminate against a data subject for having exercised any of the rights listed in this Section: neither the quality nor the price of the service changes because those rights are exercised.

A data subject may at any time request that the Controller not share information about them for the purpose of ad targeting based on their online activity across different merchants and websites. This can be done by changing the cookie settings on the Website, or by sending a request to hello@oi75.com. In some countries and states (in particular in certain states of the United States of America) local law may grant the data subject an additional, separate right to opt out of the "sale" or "sharing" of personal data; that right may be exercised through the same contact details.


8. Newsletter unsubscription and management of marketing communication

The data subject may unsubscribe from marketing email communication:

by clicking the "Unsubscribe" link at the bottom of any marketing email; or
by sending a request to the email address hello@oi75.com.

The Controller fulfils unsubscription requests without delay.

Unsubscription applies to communication for marketing purposes. The data subject may still receive transactional emails relating to the performance of the contract (for example order confirmation, notice of the collection of the monthly Club fee, challenge completion feedback), as the legal basis for these is the performance of the contract, not consent.


9. Processors

The Controller engages processor partners for certain operations involving personal data. Processors act on behalf of and on the instructions of the Controller, under a written data processing agreement in accordance with Article 28 GDPR.

9.1. Hosting and online store provider

Name

Shopify International Ltd.

Registered seat

Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland

Role

hosting of the Online Store, management of the ordering process, management of the customer account and OI75 Club subscriptions, operation of Shopify's built-in payment system

Transfer to a third country

yes (see Section 10)

Privacy documentation

https://www.shopify.com/legal/privacy

In respect of certain enhanced features that Shopify itself develops (for example cross-merchant personalisation and the related ad targeting), Shopify acts not as a processor but as an INDEPENDENT CONTROLLER. Data subjects may exercise their rights in relation to that processing directly with Shopify at the following address: https://privacy.shopify.com/en

9.2. Community and education platform

Name

Tevello (a service running on Shopify infrastructure as a Shopify application)

Role

operating the OI75 Community interface, providing courses and educational content, recording the daily Challenge check-in comments

Privacy documentation

the privacy policy of Tevello as in force from time to time

9.3. Payment provider

Name

Shopify Payments (a payment service operated by Shopify International Ltd.)

Role

processing card transactions, collecting the monthly subscription fee (recurring payment)

Data processed

for the Service Provider: transaction identifier, amount, status; the Service Provider does not see the card data

9.4. Delivery partner

Name

Magyar Posta Zrt. (MPL)

Registered seat

Dunavirág u. 2-6, 1138 Budapest, Hungary

Role

delivery of ordered products

Data processed

recipient's name, shipping address, phone number, email address, parcel identifier, weight data

9.5. Invoicing system

Name

Billingo Technologies Zrt. (registered seat: Árbóc utca 6, 1133 Budapest, Hungary)

Role

issuing electronic invoices, storing invoice data

Data processed

billing name, address, VAT number (for companies), products ordered, amount, payment method

9.6. Email marketing system

Name

Sendinblue SAS (trading as Brevo; registered seat: 106 boulevard Haussmann, 75008 Paris, France)

Role

sending newsletters and automated email campaigns, collecting statistics

Data processed

name, email address, subscription date, email open and click statistics

9.7. Social media platform

Name

Meta Platforms Ireland Ltd.

Registered seat

Merrion Road, Dublin 4, D04 X2K5, Ireland

Role

operating the Facebook group, and ad targeting and measurement through the Meta Pixel placed on the Online Store — see Section 11

Privacy documentation

https://www.facebook.com/privacy/policy

9.8. Web analytics and marketing pixels

Name

Google Ireland Ltd. (registered seat: Gordon House, Barrow Street, Dublin 4, Ireland) — Google Analytics 4

Role

anonymised traffic analysis, collecting statistics on the use of the Online Store

Name

TikTok Information Technologies UK Ltd. (registered seat: WeWork, 125 Shaftesbury Avenue, London, WC2H 8AD, United Kingdom) — TikTok Pixel

Role

ad targeting and measurement, feeding conversions from the Online Store (purchase, add to cart, page view) back into TikTok's advertising system

Privacy documentation

https://www.tiktok.com/legal/privacy-policy

9.9. Technical publisher of the OI75 mobile application

Name

Griff Webshop Kft.

Registered seat

Nyugati tér 7, 1055 Budapest, Hungary

Company registration number

01 09 321829

Role

technical publication of the OI75 mobile application in the Apple App Store and Google Play stores, and maintaining the developer relationship with the stores. The App publisher is not a contracting party to the Club contract between the Member and the Controller, and does not sell any product or service. The App publisher processes the Member's personal data on the instructions of the Controller, under an agreement concluded with the Controller.

Data processed

the data listed in Section 2.8 that is necessary for the technical operation of the App

9.10. The app stores (as independent controllers)

The following organisations are not processors of the Controller; they process the Member's data collected by them in their own right, as independent controllers, in accordance with their own privacy policies:

Name

Apple Inc. (and Apple Distribution International Ltd.)

Role

downloading, installing and updating the OI75 mobile application through the Apple App Store; processing relating to the Apple account

Privacy documentation

https://www.apple.com/legal/privacy/

Name

Google Ireland Ltd. / Google LLC

Role

downloading, installing and updating the OI75 mobile application through the Google Play store; processing relating to the Google account

Privacy documentation

https://policies.google.com/privacy

The Controller does not receive the data collected by the above store operators and is not responsible for its processing.

9.11. Artificial intelligence (AI) provider

Name

Anthropic PBC (registered seat: United States of America) — provider of the "Claude" language model

Role

estimating the nutritional value of food recorded by the user in the app (based on entered text and photographs), producing the written analysis of the daily nutrition summary, and machine translation of community posts

Data processed

the description of the food provided by the user; the food photograph taken by the user; for the daily analysis, the nutrition, water and step data recorded for that day, and — if the user has recorded them — body weight, sleep duration and mood; the text of the community post, comment or recipe

The Service Provider transfers NO identifying data to the AI provider: no name, no email address, no user or device identifier. The app does not connect directly to the AI provider, but through the Service Provider's own server. The Service Provider does not store the text of the requests.

For the processing of the user's OWN logged data (food estimation from text and photograph, daily analysis, recipe macros), the app asks for the user's explicit, prior consent; until consent is given, no data is transferred to the AI provider in these functions. Consent can be withdrawn at any time on the Settings screen of the app.

There is a single exception to this: the machine translation into English of posts, comments and recipes PUBLISHED on the community interface. The Service Provider initiates this on the server side at the time of publication, so that members who are not native Hungarian speakers can also read the content. It applies exclusively to text that the user has already made public to the community, never to the private log. The result of the translation is stored together with the post and is deleted together with the post.

Privacy documentation

https://www.anthropic.com/legal/privacy

9.12. Operator of the app backend

Name

Cloudflare, Inc. (registered seat: 101 Townsend St., San Francisco, CA 94107, United States of America)

Role

operating the backend of the OI75 mobile application (application server, database, file storage, cache). The log, profile and community data recorded in the App is stored on this infrastructure.

Data processed

the data listed in Sections 2.6 and 2.8

Transfer to a third country

yes (see Section 10)

Privacy documentation

https://www.cloudflare.com/privacypolicy/

9.13. Transfer of data in the context of a business transaction

In the event of the Controller's transformation, merger, division, transfer of a business line or of assets, acquisition, liquidation or bankruptcy, personal data may pass to the legal successor or to the party acquiring the assets. In such a case the data may be used solely for the purposes set out in this Policy, and the Controller informs data subjects of the change in accordance with Section 13.

The Controller keeps an accurate and up-to-date list of the processors actually in use in its own records; the set of processors listed in this Section may change, of which the Controller gives notice by amending this Policy.


10. International data transfers

Certain processors engaged by the Controller (in particular Shopify International Ltd., Meta Platforms Ireland Ltd., Google Ireland Ltd., Anthropic PBC, Cloudflare, Inc. and TikTok Information Technologies UK Ltd.) may transfer personal data to countries outside the European Economic Area (EEA), primarily to the United States and Canada, and in the case of TikTok to servers operating in third countries outside China.

The legal guarantees for international data transfers are the following:

the Standard Contractual Clauses (SCC) approved by the European Commission, which the processor partner has undertaken in its contract concluded with the Controller;
where available, the processor's certification under the EU-US Data Privacy Framework;
supplementary technical and organisational safeguards for the protection of personal data.

Further information on these guarantees is available in the privacy documentation of the given processor, or may be requested from the Controller in writing (hello@oi75.com).


11. Cookies and tracking technologies

11.1. What are cookies?

A cookie is a small text data file which the Website stores on the visitor's device through their browser. Cookies allow the Website to "remember" the visitor's preferences, to manage the signed-in state, or to collect statistics on the use of the Website.

11.2. Categories of cookies used

a) Strictly necessary cookies

These cookies are necessary for the basic operation of the Website (for example maintaining the signed-in state, preserving the contents of the cart during browsing). The visitor's consent is not required for these, as their legal basis is the Controller's legitimate interest in operating the service.

b) Preference cookies

These cookies remember the visitor's choices (for example language, display mode). The data subject's consent is required for their use.

c) Analytics cookies

These cookies provide anonymised statistics on the use of the Website (for example Google Analytics). The data subject's consent is required for their use.

d) Marketing / advertising cookies

These cookies display advertisements relevant to the visitor on other websites as well (for example Meta Pixel, Google Ads). The data subject's explicit, prior consent is required for their use.

11.3. Managing consent

On a first visit to the Website, the visitor can state through a cookie banner which categories of cookies they permit. Consent may be withdrawn at any time by reopening the cookie settings or by changing the relevant settings in the browser.

11.4. Blocking cookies

The visitor may block the use of cookies in their browser; this may however result in certain functions of the Website being unavailable or not working correctly.


11.5. Third-party websites and links

The Website and the App may contain links to websites or platforms operated by third parties (for example to scientific sources, to the privacy documentation of service partners, or to social media pages). If a data subject follows a link to a website that is not under the Controller's control, please read that website's own privacy terms and terms of use. The Controller accepts no responsibility for the data processing, security or content of such websites, and the placement of a link does not in itself constitute endorsement of them.

Information shared on a public or semi-public interface — such as the OI75 Community or third-party social platforms — may be visible to other users. Data subjects should carefully consider what personal data they publish on such interfaces.


12. Enforcement — lodging a complaint with the authority

12.1. Complaint to the Controller

If the data subject considers that the processing of their personal data infringes their rights, they may in the first instance contact the Controller at the email address hello@oi75.com or by post (Nyugati tér 7, 1055 Budapest, Hungary). The Controller investigates the complaint and provides a reasoned, written answer.

12.2. Complaint to the supervisory authority

The data subject may also lodge a complaint with the supervisory authority:

Name

Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH)

Address

Falk Miksa utca 9-11, 1055 Budapest, Hungary

Postal address

1363 Budapest, Pf.: 9, Hungary

Phone

+36 1 391 1400

Fax

+36 1 391 1410

Email

ugyfelszolgalat@naih.hu

Website

https://naih.hu

12.3. Recourse to the courts

In the event of an infringement of their rights, the data subject may turn to the regional court competent for their place of residence or for the registered seat of the Controller. At the data subject's choice, proceedings may also be brought before the regional court of their place of residence.


13. Amendment of this Policy

The Controller reserves the right to amend this Policy unilaterally. The Controller informs data subjects of any amendment:

by publishing the updated version on the Website;
by email notification sent to registered users and Members (in the case of a material change).

The amended Policy takes effect from the day of publication.


14. Entry into force

This Privacy Policy enters into force on 12 August 2026 and remains valid until withdrawn or until the next amendment enters into force. It replaces version 2.1 (effective from 29 July 2026).

Changes in version 2.2: a new Section 9.11 on the artificial intelligence (AI) provider (Anthropic PBC); a new Section 9.12 on the operator of the app backend (Cloudflare, Inc.); an extension of Section 2.8 covering in-app purchases; an extension of Section 9.1 covering Shopify's role as an independent controller; the addition of provisions previously present only in the online store's template policy (7.10 prohibition of discrimination and targeted advertising, 9.13 business transactions, 11.5 third-party websites); and a related extension of Section 10 (international data transfers).


Budapest, 12 August 2026

AVEROLS-MANDO Kft.

Controller

---

This Privacy Policy was originally drawn up in Hungarian. In the event of any discrepancy between the Hungarian and the English version, the Hungarian version prevails.