Privacy Notice
Last updated: 15 August 2026
Bountr Kft. operates the online travel planning and booking platform available at bountr.hu and bountr.com. This notice explains what personal data we process when you use the Platform, for what purpose and on what legal basis, for how long, who we share it with, and the rights available to you.
This is a translation for information purposes. The Hungarian version of this document is the authoritative text. In the event of any discrepancy, the Hungarian text prevails.
1. Who this notice covers
This notice applies to everyone who uses the Platform, whether or not you hold an account. For each processing activity in section 6 we indicate which of the following groups it concerns.
- Visitor: anyone who opens the Platform without registering or booking.
- Traveller: anyone who plans or books a trip through the Platform.
- Expert: a local expert who uploads an itinerary to the Platform.
- Waitlist subscriber: anyone who signed up for the waitlist or the newsletter.
- Partner contact: a natural person acting on behalf of a partner travel agency.
If anything here is unclear, or you would like it explained further, write to us at the address in section 2. We aim to write plainly; if a section is hard to follow, treat that as our failure.
2. The controller and how to reach us
The controller responsible for your personal data — the organisation that decides which data is processed and why — is:
- Name
- Bountr Korlátolt Felelősségű Társaság
- Short name
- Bountr Kft.
- Registered seat
- 1061 Budapest, Király utca 40. 4th floor 16., Hungary
- Company registration number
- 01-09-457194
- Registering authority
- Company Court of the Budapest-Capital Regional Court
- Tax number
- 33064062-2-42
- EU VAT number
- HU33064062
- Representative
- Dávid Szélyes, Managing Director
- contact@bountr.hu
- Phone
- +36 70 670 4889
- Website
- https://bountr.hu
Getting in touch about data protection
Please use the same email address for data protection enquiries, requests and complaints, with "Data protection" in the subject line.
The Platform is hosted by Vercel Inc. (340 S Lemon Ave #4133, Walnut, CA 91789, USA; privacy@vercel.com) and served from a region within the European Union.
We have not appointed a Data Protection Officer. Article 37 GDPR does not require us to: we are not a public authority, our core activities do not consist of regular and systematic monitoring of data subjects on a large scale, and we do not process special categories of data on a large scale.
3. The legal framework this notice rests on
- Regulation (EU) 2016/679 (GDPR)
- Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Hungary)
- Act CVIII of 2001 on Electronic Commerce Services (Hungary)
- Act XLVIII of 2008 on the Basic Requirements of Commercial Advertising Activity (Hungary)
- Act C of 2000 on Accounting (Hungary)
- Act CL of 2017 on the Rules of Taxation (Hungary)
- Act CLV of 1997 on Consumer Protection (Hungary)
- Act C of 2003 on Electronic Communications (Hungary)
4. The principles we follow
- We only ask for what we need. If the service works without a piece of data, we do not collect it.
- We only use it for what you gave it for. We do not sell your data, we do not pass it to third parties for their marketing, and we do not repurpose it without a legal basis.
- We do not keep it forever. Every processing activity below states a retention period.
- You decide on anything based on consent. Consent can be withdrawn at any time, without giving reasons, and withdrawal is as easy as giving it.
5. Bountr's role: where we are a controller and where we are not
Several parties are involved in a booking, so it matters who is responsible for what.
Bountr is an independent controller for operating the Platform, managing accounts, itinerary planning, the waitlist and newsletter, and for assembling and transmitting the booking request.
The partner travel agency is an independent controller from the moment we transmit the booking data to it. The Agency processes your data under its own responsibility and its own privacy notice in order to perform the travel contract, and Bountr is not responsible for that processing. You receive the Agency's identity and privacy notice during booking and in the booking confirmation.
Stripe is an independent controller for the payment transaction and fraud prevention. Bountr never sees, processes or stores any card or payment credential data. Payment takes place through Stripe, and the amount is credited directly to the Agency's payment account, where the Agency is the merchant of record. Bountr does not collect or hold traveller funds.
Our processors are the technology providers that process data on our behalf and on our instructions. They are listed in section 8, and we have a data processing agreement with each of them.
6. Processing activities, their purpose and legal basis
Each activity below states whose data we process, what we process, why, on what legal basis and for how long. Cookies are covered in section 12 and recipients in section 8.
a) Visiting the Platform and server-side logging
- Who it concerns
- All visitors
- Data processed
- Time of the request, the path requested, the HTTP method, the response status code, the running application version identifier, the IP address and the browser identifier (user agent)
- Purpose
- Keeping the Platform running, detecting and fixing errors, maintaining the security of the service
- Legal basis
- Legitimate interest — Art. 6(1)(f) GDPR — in the reliable operation of the Platform. We balanced this against your interests and found it proportionate, because the logging covers a narrow data set, is extremely short-lived, and is indispensable to providing the service.
- Who performs it
- Logging is performed automatically by the hosting provider. The application keeps no separate access log of its own, and no log forwarding to external systems is configured.
- Retention
- One hour. After that, the IP address associated with a request is retained neither by us nor by the hosting provider. If our service plan changes, this period may become longer under the provider's rules, in which case we will update this notice.
- Exception
- Technical logs created when the application is deployed are retained indefinitely. They contain no visitor data, only the technical output of the deployment.
b) Abuse prevention
- Who it concerns
- All visitors
- Data processed
- The visitor's IP address
- Purpose
- Preventing automated abuse and overload by limiting how many requests may arrive from the same address in a short period
- Legal basis
- Legitimate interest — Art. 6(1)(f) GDPR — in protecting the Platform and its users
- Retention
- Short-lived, until the limiting window expires, after which the record is deleted automatically.
c) Waitlist sign-up
- Who it concerns
- Waitlist subscriber
- Data processed
- Email address, time of sign-up, the language selected at sign-up
- Purpose
- Notifying you when the booking service goes live
- Legal basis
- Consent — Art. 6(1)(a) GDPR
- Retention
- Until consent is withdrawn, or until the purpose of the processing ceases
- Withdrawal
- Every message carries an unsubscribe link, and we action unsubscribes without delay. You can also write to contact@bountr.hu.
e) Creating and managing a user account
- Who it concerns
- Traveller, Expert
- Data processed
- Required: first and last name, email address, a non-reversible value derived from your password, role, and the date of registration. Your choice: bio, country, city, profile picture, and Instagram, TikTok and website links. For security: the technical data needed to protect the account, and the password recovery code and its expiry.
- Purpose
- Providing account-based features: saved itineraries, access to past bookings and their expert tips, uploading itineraries, and protecting the account against unauthorised access
- Legal basis
- Performance of a contract — Art. 6(1)(b) GDPR: by registering, you and Bountr enter into a contract for use of the Platform, governed by the terms and conditions. For the optional profile fields and the profile picture, consent — Art. 6(1)(a) — given by completing them and withdrawable at any time by clearing the field. For processing that protects the account, legitimate interest — Art. 6(1)(f).
- Signing in with Google
- If you sign in with your Google account, Google informs us of the sign-in and of your basic account details — your name and email address. We do not process a password in that case. Google acts under its own privacy policy.
- Retention
- Until the account is deleted. After deletion, data may be recoverable for up to six hours because of the system's backup mechanism, after which it is permanently gone. Data we are legally required to retain is kept for the statutory period even after account deletion.
- If not provided
- The Platform can be browsed without an account, and a booking can be completed as a guest. An account is required to upload an itinerary. The account works without restriction if the optional profile fields are left empty.
f) Saved and purchased itineraries
- Who it concerns
- Traveller
- Data processed
- Destination, city, dates, number of travellers, the accommodation and transport selected, the estimated budget and the extras selected. For a purchased itinerary, additionally the payment transaction reference, the amount paid and the time of purchase.
- Purpose
- Preserving planning in progress so it can be resumed later, and making the purchased itinerary and its expert content available
- Legal basis
- Performance of a contract — Art. 6(1)(b) GDPR
- Retention
- Saved itineraries until the account is deleted; data on purchased itineraries for five years from performance, in line with the general limitation period.
g) Sending feedback
- Who it concerns
- Visitor, Traveller, Expert
- Data processed
- The message you write and, if you provide them, your name, email address and any screenshot you attach
- Purpose
- Processing the feedback, fixing bugs, improving the Platform, and replying where needed
- Legal basis
- Consent — Art. 6(1)(a) GDPR — given by sending the feedback
- Processor
- Feedback is received through the Sentry error tracking system, which processes the data within the European Union.
- Retention
- Until the feedback has been processed, and for as long as fixing the reported issue requires
A screenshot may capture everything on your screen. Before sending, please check that it does not contain anything you would rather not share.
h) Sending an enquiry
- Who it concerns
- Visitor, Traveller
- Data processed
- Email address, number of travellers, planned dates and the note you write
- Purpose
- Answering the enquiry and making contact
- Legal basis
- Steps taken at your request prior to entering into a contract — Art. 6(1)(b) GDPR
- Retention
- Until the enquiry has been answered and any resulting transaction is concluded
The note field is free text. Please enter only what your enquiry requires, and do not provide data about health, religion, political opinions or other sensitive circumstances.
i) Trip planning and the AI assistant
- Who it concerns
- Traveller
- Data processed
- The data entered during planning: travel dates, number of travellers, departure city, accommodation tier, the days selected and removed, programme swaps, and the text of messages sent to the AI assistant
- Purpose
- Personalising the itinerary, providing suggestions and calculating the final price
- Legal basis
- Performance of a contract, or steps taken at your request prior to entering into a contract — Art. 6(1)(b) GDPR
- About the assistant
- The assistant has access to the selected itinerary's days, programmes and tags. It does not have access to the expert tips, to pricing data, or to the personal data you enter in later steps of the booking flow. If you voluntarily include personal data in a message to the assistant, we process it as part of that message.
- Automated decision-making
- The assistant suggests, it does not decide: every change is approved by you. Section 10 covers this in full.
- Processors
- We use large language model providers to operate the assistant: Google and OpenAI. Our agreements with them exclude the use of data processed for us to train models. For web searches supporting planning we use Serper.dev, which receives the text of the search query.
- International transfer
- These providers may also process data in the United States; the safeguards for that transfer are set out in section 9.
- Retention
- Saved planning data is retained for as long as the account exists, so you can resume planning later; where planning takes place without an account, until the session ends. If a booking is made, the data becomes part of the booking record and the retention period for bookings applies.
Please do not share data with the assistant that planning does not require, such as health data or document numbers.
j) Booking and transmission to the partner travel agency
- Who it concerns
- Traveller
- Data processed
- Full name, email address, phone number, language preference, the special requests you provide, travel dates, departure city, destination, the number and composition of travellers, accommodation tier, the final itinerary, the booking reference, the payment confirmation and the booking status
- Purpose
- Assembling and transmitting the booking to the partner travel agency so that it can conclude and perform the travel contract with you
- Legal basis
- Performance of a contract — Art. 6(1)(b) GDPR
- Recipient
- The partner travel agency performing the booking, which becomes an independent controller upon receipt. You receive the Agency's name, contact details and privacy notice during booking and in the booking confirmation.
- Retention
- Five years from performance, that is from the end of the trip, in line with the general limitation period under the Hungarian Civil Code, on the basis of legitimate interest in potential claims or disputes. Accounting records are retained for eight years.
- If not provided
- This data is indispensable to performing the booking; without it the booking cannot be carried out.
The special requests field is free text. If you enter data falling within a special category under Article 9 GDPR — a food allergy, reduced mobility or a health condition, for example — we process and transmit it to the Agency solely so that your request can be met. The legal basis is your explicit consent under Art. 9(2)(a) GDPR, given by completing the field and submitting the booking.
k) Fellow travellers and minors
- Who it concerns
- The Traveller and the fellow travellers they name
- Data processed
- Fellow travellers' names and the other data the booking requires; for a minor, their age or date of birth
- Purpose
- Performing the booking for all travellers
- Legal basis
- Performance of a contract, and the legitimate interest of Bountr and the Agency in performing the booking — Art. 6(1)(b) and (f) GDPR
- Retention
- Together with the booking data, for five years from performance of the booking
- Who provides it
- Data on fellow travellers, including minors, is provided by the adult Traveller making the booking. The Traveller warrants that they are entitled to do so: that the fellow travellers have consented or, in the case of a minor, that the Traveller holds parental responsibility or acts with the authorisation of the person who does. The Traveller must inform fellow travellers of this notice.
- Age limit
- Only persons aged 18 or over with full legal capacity may register and place a booking on the Platform. Minors can of course travel; the booking is placed by an adult. If we learn that a person under 18 has created an account, we will delete it.
l) Payment
- Who it concerns
- Traveller
- Data processed
- The fact, amount, currency and time of the payment, the transaction reference and the payment status
- What we do not process
- Card number, expiry date, security code, bank details. Bountr never sees or stores these.
- Purpose
- Confirming the booking, tracking that payment has been made, and settlement with the Agency
- Legal basis
- Performance of a contract — Art. 6(1)(b) GDPR
- Retention
- As part of the booking record, for five years from performance; accounting records are kept for eight years.
- How it works
- Payment is handled by Stripe. The amount is credited directly to the partner travel agency's payment account, where the Agency is the merchant of record. Bountr does not collect, process or hold traveller funds. Stripe acts as an independent controller for payment data under its own privacy policy.
m) Invoicing and accounting retention
- Who it concerns
- Expert, partner agency, and anyone for whom an accounting record is created
- Data processed
- Name, address, tax identification number or tax number, the amount invoiced or paid, the date of performance, bank account number
- Purpose
- Meeting statutory obligations: issuing invoices, bookkeeping and tax returns
- Legal basis
- Legal obligation — Art. 6(1)(c) GDPR — under Section 169(2) of Hungarian Act C of 2000 on Accounting and the Act on the Rules of Taxation
- Retention
- Eight years from issue of the accounting record. This is a mandatory retention period; we cannot deviate from it and cannot erase this data within that period.
n) Expert data and the expert contract
- Who it concerns
- Expert
- Data processed
- Name, home address, place and date of birth, tax identification number, bank account number, email address, phone number, display name, professional bio, portrait photo (if uploaded), and the uploaded itineraries and related materials
- Purpose
- Concluding and performing the expert contract, paying the licence fee, producing monthly statements, meeting tax and contribution obligations, and publishing the itinerary under the Expert's name
- Legal basis
- For the data needed to conclude and perform the contract, performance of a contract — Art. 6(1)(b) GDPR. For the tax identification number, home address and birth data, legal obligation — Art. 6(1)(c) — in connection with payer obligations. For the portrait photo and the public professional bio, the Expert's consent — Art. 6(1)(a) — which can be withdrawn at any time.
- What is public
- The Expert's name or display name, professional bio and, where uploaded, portrait photo appear publicly on the Platform alongside their itinerary. Home address, tax identification number, birth data and bank account number are never public; they are used solely for payment and tax compliance.
- Retention
- For the duration of the contractual relationship and five years after its termination. Accounting records are kept for eight years. As the licence is granted for the full term of copyright protection, we may retain the Expert's name and the fact of the licence relationship beyond that period, on the basis of legitimate interest, in order to evidence lawful use.
If consent for the portrait photo is withdrawn we remove the photo; this does not affect the licence rights in the itinerary.
o) Quality review of itineraries
- Who it concerns
- Expert
- Data processed
- The full content of the submitted itinerary, the Expert's identity, the time of submission, the review outcome and the notes accompanying it
- Purpose
- Checking whether a submitted itinerary meets the Platform's quality standards before it is published
- Legal basis
- Performance of a contract — Art. 6(1)(b) GDPR — and Bountr's legitimate interest in maintaining the quality of Platform content — Art. 6(1)(f)
- Retention
- Five years from termination of the contractual relationship
p) Partner travel agency contacts
- Who it concerns
- Partner contact
- Data processed
- Name, job title, business email address, business phone number
- Purpose
- Maintaining contact under the partnership, handling bookings and settlement
- Legal basis
- Legitimate interest — Art. 6(1)(f) GDPR — in effective communication with a contractual partner. The impact on the individual is minimal, as we process the data solely in a business capacity using business contact details.
- Retention
- Five years from the end of the cooperation
q) Complaint handling
- Who it concerns
- Anyone who submits a complaint
- Data processed
- Name, contact details, the content of the complaint, the related correspondence and our response
- Purpose
- Investigating and answering the complaint
- Legal basis
- Legal obligation — Art. 6(1)(c) GDPR — under Section 17/A of the Hungarian Consumer Protection Act, for consumer complaints
- Retention
- Five years for the complaint record and a copy of the response, under Section 17/A(7) of the Consumer Protection Act
r) Legal claims
- Who it concerns
- Anyone involved in a legal claim
- Data processed
- The existing data relating to the matter
- Purpose
- Establishment, exercise or defence of legal claims
- Legal basis
- Legitimate interest — Art. 6(1)(f) GDPR
- Retention
- Until the claim becomes time-barred or the dispute is finally concluded
As a rule we neither ask for nor process special categories of data under Article 9 GDPR. The only exception is the special requests you enter at booking, on the basis of your explicit consent. Please do not enter sensitive information into free-text fields.
7. How long we keep the data
A retention period is given for every processing activity in section 6. The table below summarises the main periods.
| Data | Retention period |
|---|---|
| Server logs | One hour |
| User account and saved itineraries | Until the account is deleted |
| Purchased itineraries and booking data | Five years from performance |
| Accounting records | Eight years from issue of the record |
| Consumer complaints and our response | Five years |
| Processing based on consent: waitlist, newsletter, feedback, analytics cookies | Until consent is withdrawn |
| Your cookie choice | Six months, after which we ask again |
After an account is deleted, the data may be recoverable for up to six hours because of the system's backup mechanism, after which it is permanently gone.
8. Recipients and processors
Within Bountr, access is limited to those staff and contributors who need it to perform their duties. Beyond that, the following external parties are involved.
Independent controllers
From the moment they receive the data, the parties below act under their own responsibility and their own privacy notice.
| Recipient | Data | Why |
|---|---|---|
| Partner travel agency, identified at booking | Booking data, traveller data, the itinerary | Concluding and performing the travel contract |
| Stripe Payments Europe, Ltd. (Ireland) and affiliates | Payment data and card data, which Bountr does not see | Processing the payment and fraud prevention |
- Stripe's privacy notice:stripe.com/privacy
- Google's privacy notice:policies.google.com/privacy
Processors
The following providers process data on our behalf and on our instructions. We have a data processing agreement with each of them.
| Provider | Function | Location of processing |
|---|---|---|
| Vercel Inc. (USA) | Hosting and running the Platform | European Union |
| Neon (part of the Databricks group, USA) | Database service | European Union; because the provider has remote access, the contract also relies on standard contractual clauses |
| Cloudflare, Inc. (USA) | File and image storage, content delivery | European Union; images uploaded by users do not leave the European Union |
| Google Ireland Limited | Sign-in with Google, web analytics where you consent, address lookup, large language model | Ireland and United States |
| OpenAI (USA) | Large language model for the AI assistant | United States |
| Serper.dev (USA) | Web search for the trip planner | United States |
| Mapbox, Inc. (USA) | Map service | United States |
| Amadeus | Flight and accommodation price queries | European Union and United States |
| Viator | Programme and experience data and bookings | European Union and United States |
| Resend | Transactional email | European Union |
| Sentry | Error tracking, operational monitoring and receiving feedback | European Union |
| Accounting firm | Bookkeeping | Hungary |
We do not currently use a newsletter delivery system or invoicing software. When we introduce either, we will update this notice in advance and name the provider. The same applies to any new processor.
Beyond this we disclose data only where the law requires it, or where an authority or court requests it lawfully, and to our legal counsel in the event of a dispute. What we never do: we do not sell your data, we do not pass it to third parties for their own marketing, and we do not share it with data brokers.
9. Transfers outside the European Economic Area
The data belonging to your account, your itineraries and the images you upload are stored within the European Economic Area.
Some of the providers listed in section 8 also process data in the United States or another country outside the European Economic Area. Such a transfer takes place only where one of the safeguards under Chapter V GDPR applies:
- An adequacy decision — Art. 45 GDPR: for US providers, the EU-U.S. Data Privacy Framework, where the provider appears on the official, publicly verifiable list.
- Standard contractual clauses adopted by the European Commission — Art. 46(2)(c) GDPR — supplemented by technical and organisational measures and a prior assessment of the risk of the transfer.
- The list of certified participants in the framework:dataprivacyframework.gov
To find out which safeguard applies to a specific provider, or to obtain a copy of the safeguard used, write to contact@bountr.hu.
10. Automated decision-making and profiling
We do not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you, and we do not carry out profiling within the meaning of Article 22 GDPR.
The AI assistant makes suggestions, but every decision is made and approved by you.
Prices are calculated automatically, but they are not personalised: the same parameters — destination, dates, number of days, accommodation tier, party size — produce the same price for every user. We do not apply pricing differentiated by individual behaviour or profile.
11. Data security
We apply the technical and organisational measures required by Article 32 GDPR to protect personal data.
- Data is transmitted over an encrypted connection and stored encrypted.
- We do not store passwords: we keep only a value from which the password cannot be reconstructed.
- We do not store card or banking data; it is handled solely by the payment provider.
- The database and user-uploaded images are stored within the European Union.
- Access to the production system is limited to those who need it, and we keep a record of it.
- Accounts are protected against automated abuse by technical measures.
- We select providers that offer adequate guarantees, and we conclude data processing agreements with them.
In the event of a personal data breach
We act under Articles 33-34 GDPR: we notify the Hungarian National Authority for Data Protection and Freedom of Information within 72 hours of becoming aware, unless the breach is unlikely to result in a risk. Where the breach is likely to result in a high risk to your rights and freedoms, we will also inform you without undue delay.
Please note that transmission over the internet cannot be considered entirely secure in itself, so keep your password confidential and do not reuse it on another service.
13. Deleting your account and obtaining your data
Your profile offers two options that need no request: you can download everything we hold about you in a machine-readable format, and you can permanently delete your account. You do not need to contact us or wait out the one-month deadline.
When you delete your account we remove your profile, your saved plans, your enquiries, your newsletter subscription and your profile picture.
Two things we cannot remove entirely, and it is important you know this in advance:
- Records evidencing a purchase must be retained for accounting purposes, but we strip out everything identifying you personally, and they are no longer linked to your account. Because the transaction reference still exists at the payment provider, this data is pseudonymised rather than anonymised, so your rights continue to apply to it.
- Images belonging to published itineraries are retained, because the itinerary would be incomplete without them and others may already have purchased it. From the moment your account is deleted, these images cease to be linked to you.
If anything on the interface does not work, write to contact@bountr.hu and we will do it for you.
14. Your rights
You have the following rights under the GDPR. To exercise any of them, it is enough to write to contact@bountr.hu.
| Right | What it means |
|---|---|
| Access — Art. 15 | You may ask whether we process personal data about you and, if so, obtain a copy of it. |
| Rectification — Art. 16 | You may ask us to correct inaccurate data and complete incomplete data. |
| Erasure — Art. 17 | You may ask us to delete your data where the purpose has ceased, you have withdrawn consent, or the processing is unlawful. We cannot erase data we are legally required to retain, or that is needed to establish or defend legal claims. |
| Restriction — Art. 18 | You may ask us to store but not otherwise use data, for example while a dispute about its accuracy is resolved. |
| Data portability — Art. 20 | For data processed automatically on the basis of consent or contract, you may request it in a structured, commonly used, machine-readable format, or ask us to transmit it directly to another controller. |
| Objection — Art. 21 | You may object to processing based on legitimate interest. You may object to processing for direct marketing at any time without giving reasons, and we will then stop processing your data for that purpose. |
| Withdrawal of consent — Art. 7(3) | Where processing is based on consent, you may withdraw it at any time. This does not affect the lawfulness of processing before withdrawal. |
How we handle your request
We respond within one month of receipt. Where the request is complex, this may be extended by two months, and we will inform you of the extension within one month of receipt. Information and action are free of charge.
Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, we may charge a reasonable fee or refuse to act; we always give reasons.
Where we have reasonable doubts about the identity of the person making the request, we may ask for further information. This protects your data from being disclosed to someone else.
You can exercise your rights of access and portability immediately, without making a request: your profile lets you download a full copy of your data at any time.
15. Remedies
If you believe our processing has harmed you, please contact us first at contact@bountr.hu. Most matters are resolved fastest this way.
You may also lodge a complaint with the supervisory authority:
- Authority
- Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
- Address
- 1055 Budapest, Falk Miksa utca 9–11., Hungary
- Postal address
- 1363 Budapest, Pf. 9., Hungary
- ugyfelszolgalat@naih.hu
- Phone
- +36 1 391 1400
- Website
- naih.hu
If your habitual residence is not in Hungary, you may also complain to the supervisory authority of the Member State of your residence or place of work. You may also bring proceedings before a court: such cases fall within the competence of the regional court, and proceedings may be brought before the court of your place of residence or stay, at your choice.
16. Changes to this notice
We may amend this notice from time to time, for instance when we introduce a new service, engage a new processor, or the law changes.
We publish the amended notice on the Platform with the effective date. For material changes — a new processing purpose, a new third-country recipient, or a significant extension of a retention period — we also notify registered users by email at least 15 days before the change takes effect.
Where a change affects processing based on your consent, we will ask for fresh consent; prior consent does not extend to a new purpose.
This notice was drawn up in Hungarian. The English version is provided for information; in the event of a discrepancy, the Hungarian text prevails.