Introduction
Gerényi Álmos, sole proprietor (registered seat: 1144 Budapest, Füredi út 11/D, Hungary, tax number: HU92013090-1-42) (hereinafter: Service Provider, Data Controller) carries out its data processing activities in accordance with this notice.
We provide the following information in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, „GDPR”).
This privacy notice governs the data processing activities of the following website: https://xpectgame.com
This privacy notice is available at: https://xpectgame.com/adatkezeles
Amendments to this notice take effect upon publication at the above address.
Data Controller and Contact Information
- Name: Gerényi Álmos, sole proprietor
- Registered seat: 1144 Budapest, Füredi út 11/D, Hungary
- Postal address: 1144 Budapest, Füredi út 11/D, Hungary
- Tax number: HU92013090-1-42
- E-mail: contact@xpectgame.com
Definitions
„personal data”: any information relating to an identified or identifiable natural person („data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
„processing”: any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
„controller”: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data;
„processor”: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
„recipient”: a natural or legal person, public authority, agency or other body, to which the personal data are disclosed, whether a third party or not;
„consent of the data subject”: any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;
„personal data breach”: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;
„profiling”: any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person;
„third party”: a natural or legal person, public authority, agency or body other than the data subject, controller or processor.
Principles Relating to Processing of Personal Data
Personal data shall be:
- processed lawfully, fairly and in a transparent mannerin relation to the data subject („lawfulness, fairness and transparency”);
- collected for specified, explicit and legitimate purposesand not further processed in a manner that is incompatible with those purposes („purpose limitation”);
- adequate, relevant and limitedto what is necessary in relation to the purposes for which they are processed („data minimisation”);
- accurate and, where necessary, kept up to date(„accuracy”);
- kept in a form which permits identification of data subjects for no longer than is necessaryfor the purposes for which the personal data are processed („storage limitation”);
- processed in a manner that ensures appropriate security of the personal data through appropriate technical or organisational measures(„integrity and confidentiality”).
The Data Controller is responsible for, and must be able to demonstrate compliance with, the above principles („accountability”). The Data Controller declares that its data processing complies with the principles set out in this section.
1. Registration (Creating a User Account)
The fact of data collection, the scope of personal data processed and the purposes of processing:
| Personal data | Purpose of processing | Legal basis |
|---|---|---|
| E-mail address | Sign-in to the user account, communication, sending of system messages (e.g. e-mail verification, password reset). | Art. 6(1)(b) GDPR (performance of a contract) |
| Password (stored as a cryptographic hash) | Used to securely sign in to the user account. | Art. 6(1)(b) GDPR |
| Display name, username | Identification of the player within the game and on the leaderboards. | Art. 6(1)(b) GDPR |
| Timestamp of registration and last sign-in | Technical operation, security. | Art. 6(1)(f) GDPR (legitimate interest) |
| IP address during registration and sign-in | Prevention of abusive registrations and sign-ins, security. | Art. 6(1)(f) GDPR |
Scope of data subjects: all data subjects registered on the website.
Duration of processing: until the user account exists, or until the data subject’s erasure request. Upon deletion of the registration, the related personal data is erased immediately, with the exception of data that must be retained by law. The Data Controller notifies the data subject electronically of the erasure of any personal data provided, based on Article 19 GDPR.
Account termination and handling of inactivity: The user account is automatically deleted after 3 years of inactivity counted from the last logout. Any sign-in to the system automatically extends the validity of the account and cancels the inactivity period; a new three-year period starts at the next logout. Upon deletion, the personal data, results, leaderboard rankings and other profile-related information associated with the user are permanently removed. Aggregated statistical data that does not allow personal identification and is necessary for the operation of the system, statistical analyses and service development may, however, be retained.
Recipients of the data: the personal data may be handled by employees of the Data Controller authorised for that purpose. The data is transmitted to the data processors listed in section 12 (hosting, authentication, e-mail delivery service).
Please note that:
- processing is necessary for the performance of a contract aimed at creating and operating the account (Art. 6(1)(b) GDPR),
- you are required to provide your personal data so that we can register you,
- failure to provide the data will result in our inability to create the user account.
2. Sign-in with Google (OAuth)
As an alternative to registration and sign-in, the data subject may choose to sign in with a Google account. In this case, Google transmits the following data to the Data Controller in accordance with its own privacy policy:
- Data processed: name from the Google account, e-mail address, profile picture URL.
- Purpose: creating the user account and signing in.
- Legal basis: Art. 6(1)(a) GDPR (consent of the data subject) and Art. 6(1)(b) GDPR (performance of a contract).
- Duration: until the user account exists, or until consent is withdrawn / the account is deleted.
Google’s privacy policy: https://policies.google.com/privacy
3. Sign-in with Facebook (OAuth)
As an alternative to registration and sign-in, the data subject may choose to sign in with a Facebook account. In this case, Facebook transmits the following data to the Data Controller in accordance with its own privacy policy:
- Data processed: name from the Facebook profile, e-mail address, profile picture URL.
- Purpose: creating the user account and signing in.
- Legal basis: Art. 6(1)(a) GDPR (consent of the data subject) and Art. 6(1)(b) GDPR (performance of a contract).
- Duration: until the user account exists, or until consent is withdrawn / the account is deleted.
Facebook’s privacy policy: Facebook Data Policy
4. User Profile and In-Game Appearance
| Personal data | Purpose |
|---|---|
| Display name, username | Identification of the player within the game, on leaderboards, in groups and on the profile. |
| Avatar (pre-set or generated by the user) | Personalisation of the profile. |
| Cover / background image, theme selection (light / dark mode) | Personalisation of the profile and appearance. |
| Language setting (Hungarian / English) | Displaying the interface in the appropriate language. |
Purpose of processing: providing the gaming experience and identifying the user within the game.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract); for data voluntarily shared by the user, Art. 6(1)(a) GDPR (consent).
Duration: until the user account exists, or until the data subject’s request for erasure or modification.
Recipients: due to the nature of the game, the display name, avatar and cover image are public: they are visible to every visitor (and to other players) on the leaderboards, in groups and on the public profile page.
5. Bets, Group Memberships and Points (How the Game Works)
| Personal data | Purpose |
|---|---|
| Submitted bets (home–away goals per match, per group) | Running the game, scoring after results are in. |
| Points (per group and global), positions achieved, badges | Creating leaderboards, tracking results. |
| Group membership, role within the group (member / admin), date of joining | Operating the group bet game. |
| Group invitations, applications, approvals | Managing the joining process. |
| End-of-season final results (position, points per season) | Long-term result archive, badges. |
Purpose of processing: technical operation of the bet game (placing bets, scoring, leaderboards, group competition).
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
Duration: until the user account exists. Upon deletion of the data subject’s account, the related bets and memberships are deleted; anonymised data processed for statistical purposes may be retained.
Recipients: members of the relevant group can see each other’s bets, points and positions after the kick-off of the match; on the global leaderboard, the display name, avatar and points are publicly visible.
6. Friends and Friend Requests
Scope of data processed: identifiers of the users sending and receiving the friend request, the status of the request (pending / accepted / rejected), the timestamp of the request.
Purpose: operating the in-game friend feature (adding friends, invitations, managing shared groups).
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
Duration: until the friendship exists, or until the data subject deletes it.
7. Notifications
Scope of data processed: recipient of the notification, type (e.g. friend request, group invitation, result), content, read / unread status, time of creation.
Purpose: informing the user about in-game events relevant to them.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
Duration: up to 1 year, or until the account is deleted.
8. In-Game Reports
Users are entitled to report usernames used by other users that are presumably offensive or obscene.
A report may concern only the content of the username. The Data Controller examines incoming reports within its own competence on a case-by-case basis and is entitled to decide whether the username in question qualifies as offensive, obscene or in breach of the rules of the service.
If the Data Controller finds the report well-founded, it is entitled to anonymise the username concerned. In place of the anonymised name, the system displays an automatically generated 12-character code string.
Following anonymisation, the data subject remains entitled to provide a new, unique username in accordance with the rules of the service.
The Data Controller is entitled to add the offensive or obscene expression concerned by the report to the dictionary of prohibited words in order to prevent the creation of similar usernames in the future.
Scope of data processed: identifier of the reporting and reported user / group, the reason for the report, and the time of the report.
Purpose: moderation, enforcement of community standards.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest of the Data Controller and other users in a safe community).
Duration: 1 year from the handling of the report, or until the matter is closed (whichever is later).
9. Login Statistics and Badges
For the purpose of awarding the „Warrior” and similar badges, the Data Controller records the following data:
Scope of data processed: date of daily sign-in (UTC), current sign-in streak, longest streak ever achieved, date of last sign-in.
Purpose: awarding player recognitions / badges based on activity.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract), and (f) (legitimate interest in providing the gaming experience).
Duration: until the user account exists.
10. Contact Form and E-mail Communication
On the contact page, a signed-in user can send a message to the Data Controller (bug report, question, request, other).
Scope of data processed: user’s display name, e-mail address (from registration), type of message, body of the message.
Purpose: communication, providing customer support. The message is transmitted via the Resend Inc. e-mail service to contact@xpectgame.com.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries).
Duration: up to 2 years, or until the matter is closed.
11. Bet Reminders and System Emails
The Data Controller sends automated system messages:
- e-mail address verification, password reset and password change (via Supabase Auth),
- bet reminder e-mails (for upcoming matches where the user has not yet placed a bet),
- occasional important system messages (e.g. service notice).
Purpose: supporting the intended use of the game.
Legal basis: system messages (verification, password reset): Art. 6(1)(b) GDPR; bet reminders: Art. 6(1)(a) GDPR (consent), which can be withdrawn at any time in the profile settings (turning e-mail notifications on / off).
Duration: until consent is withdrawn or until the account is deleted.
12. Data Processors Used
12.1 Hosting and Platform Provider (Vercel)
- Processor: Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. Privacy policy: https://vercel.com/legal/privacy-policy
- Data storage: Personal data is stored and processed exclusively within the European Economic Area (EEA).
- Activity: serving the website, providing static and dynamic content, logging (e.g. access logs, IP address, browser identifier) for security and performance purposes.
- Data processed: all personal data provided by the data subject, as well as technical data automatically recorded during the visit (IP address, user agent, request time).
- Duration: for the term of the contract with the processor; for access logs, according to Vercel’s own retention period (typically a few weeks).
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operating the website).
12.2 Database and Authentication (Supabase)
- Processor: Supabase, Inc., 970 Toa Payoh North #07-04, Singapore 318992. Privacy policy: https://supabase.com/privacy
- Data storage: Personal data is stored and processed exclusively within the European Economic Area (EEA).
- Activity: user database (PostgreSQL), authentication (e-mail/password, Google OAuth, Facebook OAuth), file storage (avatars, cover images), realtime notifications.
- Data processed: all user and game data (e.g. profile, bets, group membership, notifications).
- Duration: for the term of the contract with the processor, or until the data subject’s erasure request.
- Legal basis: Art. 6(1)(b) and (f) GDPR.
12.3 E-mail Delivery Service (Resend)
- Processor: Resend Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA. Privacy policy: https://resend.com/legal/privacy-policy
- Data storage: Personal data is stored and processed exclusively within the European Economic Area (EEA).
- Activity: sending transactional and reminder e-mails (contact, bet reminders, etc.).
- Data processed: recipient e-mail address, display name, content of the e-mail.
- Duration: for the term of the contract; according to Resend’s own logging period, e-mail metadata is stored for a limited time.
- Legal basis: Art. 6(1)(b) and (f) GDPR.
12.4 Sports Data Provider (football-data.org)
- Processor: football-data.org. Privacy policy: https://www.football-data.org/privacy
- Activity: providing match data and standings.
- Data processed: no personal data is transmitted to the provider; only match-related requests (anonymous API calls) are made.
- Legal basis: Art. 6(1)(f) GDPR.
12.5 Google Services
- Processor / joint controller: Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), and Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). Privacy policy: https://policies.google.com/privacy
- Activity: Google OAuth sign-in, Google Analytics statistics.
For more on Google services, see sections 13 and 14.
12.6 Facebook Services
- Processor / joint controller: Meta Platforms Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland), and Meta Platforms, Inc. (1 Meta Way, Menlo Park, CA 94025, USA). Privacy policy: Meta Data Policy
- Activity: Facebook OAuth sign-in.
13. Use of Google Analytics
This website uses Google Analytics, a web analytics service provided by Google Ireland Limited / Google LLC. Google Analytics uses so-called „cookies”, text files that are stored on your computer and help analyse the use of the website you visit.
The information generated by the cookies about the User\u2019s use of the website is usually transferred to and stored on a Google server. When IP anonymisation is activated, Google truncates the User\u2019s IP address within Member States of the European Union or in other states party to the Agreement on the European Economic Area beforehand.
Google uses this information to evaluate how the User uses the website, to compile reports on website activity for the website operator and to provide further services related to the website and internet usage.
Within Google Analytics, the IP address transmitted by the User\u2019s browser is not combined with other Google data. The User may prevent the storage of cookies by configuring their browser accordingly; however, please note that in this case not all functions of this website may be fully usable. The User may also prevent the collection and processing of the data generated by the cookies by downloading and installing the browser plug-in available at: https://tools.google.com/dlpage/gaoptout?hl=en
Legal basis: Art. 6(1)(a) GDPR (consent of the data subject, given in the cookie banner and revocable at any time).
14. Management of Cookies
Fact of processing, scope of data processed: unique identifiers, dates, timestamps.
Scope of data subjects: all data subjects visiting the website.
Purpose of processing: identifying users, maintaining sessions, tracking visitors, providing personalised functionality.
Main groups of cookies used:
| Cookie type | Legal basis for processing | Duration of processing |
|---|---|---|
| Session cookies and cookies strictly necessary for the operation of the website (e.g. authentication token, CSRF protection) | May be processed without consent (technically necessary) | Until the session ends; for tokens, according to the lifespan of Supabase Auth. |
| Functional cookies (e.g. language preference, dark mode) | May be processed without consent (the user’s express preference) | Up to 1 year. |
| Statistical cookies (e.g. Google Analytics) | Art. 6(1)(a) GDPR | 1 day – 2 years, in line with the cookie notice, or until consent is withdrawn. |
The data subject can delete cookies via the Tools / Settings menu of their browser (typically under the Privacy section). Detailed instructions are available at the following links:
- Google Chrome: support.google.com/chrome/answer/95647
- Microsoft Edge: support.microsoft.com
- Firefox: support.mozilla.org
- Safari: support.apple.com
If you restrict the storage of cookies on specific websites or disallow third-party cookies, this may, in certain circumstances, lead to the website no longer being fully usable.
15. Use of Hotjar
This website uses the Hotjarservice provided by Hotjar Ltd. (Level 2, St Julian's Business Centre, 3 Elia Zammit Street, St Julian's STJ 1000, Malta). Hotjar is a user behaviour analytics service that helps analyse the use of the website through, among other things, heatmaps, session recordings and feedback features.
Hotjar uses so-called „cookies” and other technologies to collect information about Users\u2019 website usage habits, including for example the device\u2019s IP address (in anonymised form), device type, browser information, geographic location (at country level), and actions performed on the website.
Hotjar uses this information to analyse Users\u2019 use of the website, to produce reports on the operation of the website, and to assist in developing the service and improving the user experience.
Hotjar processes IP addresses only for a short time and in anonymised form, and does not use them for direct identification of the User. Hotjar does not sell the collected data to third parties.
The User may prevent the storage of cookies by configuring their browser accordingly, and Hotjar tracking can also be disabled at the following page: Hotjar Opt-out page
Hotjar’s privacy policy: Hotjar Privacy Policy
Legal basis: Art. 6(1)(a) GDPR (consent of the data subject, given in the cookie banner and revocable at any time).
16. Social Media Platforms
The Data Controller is present on the following social media platforms in order to present its services and to keep in touch with prospective users and users:
- TikTok
- Discord
Scope of data processed: data publicly available on the data subject’s social media profile (name / username, public profile picture), and interactions posted by the data subject relating to the Data Controller’s page / channel (comments, messages, follows, reactions).
Scope of data subjects: natural persons who follow, interact with or send messages through the Data Controller’s social media page / channel.
Purpose of processing: presenting the Data Controller’s activities and services, marketing and communication on social media platforms, keeping in touch with prospects.
Legal basis of processing: voluntary consent of the data subject (Art. 6(1)(a) GDPR).
Duration of processing: for the duration of the data subject’s interaction, or until the content posted by the data subject is deleted. The Data Controller retains messages and communications for up to 2 years.
Facebook / Meta Joint Controllership
The processing of personal data for statistical purposes carried out on the Facebook page is joint processing of the Data Controller and Meta Platforms Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, D2 Dublin, Ireland). Details of the joint controllership arrangement are set out in the Controller Addendum to the Facebook Page Insights feature. The addendum is available at: facebook.com/legal/terms/page_controller_addendum
The Data Controller communicates by private message on the social page only if the user contacts it there.
Categories of data subjects:
- data subjects who have registered on the social platform and have „liked” the Data Controller\u2019s page,
- data subjects who contact the Data Controller via private message on the social platform.
Purpose of processing: sharing and promoting the Data Controller’s activities and services on the Facebook page.
Legal basis of processing: Art. 6(1)(a) GDPR – consent of the data subject.
Scope of data processed:
- the data subject\u2019s registered name,
- the data subject\u2019s public profile picture,
- other public data provided or shared by the data subject on the social platform.
Withdrawal of consent: the data subject may withdraw consent to the processing at any time and may delete their post or comment. If the data subject withdraws consent, the Data Controller will delete the conversation conducted with them. The withdrawal of consent does not affect the lawfulness of the processing based on consent prior to its withdrawal.
The Instagram service is also operated by Meta Platforms Ireland Limited. The method, purposes and legal basis of processing are the same as described for Facebook. Meta\u2019s privacy policy: privacycenter.instagram.com/policy
TikTok
The TikTok service is operated by TikTok Technology Limited (10 Earlsfort Terrace, Dublin, D02 T380, Ireland). The Data Controller processes interactions publicly published by the user (follows, likes, comments) on the legal basis of consent (Art. 6(1)(a) GDPR). TikTok\u2019s privacy policy: tiktok.com/legal/page/eea/privacy-policy/en
Discord
The Discord service is operated by Discord Netherlands B.V. (Schiphol Boulevard 195, 1118 BG Schiphol, Netherlands). The Data Controller enables community communication on a Discord server / channel; the data subject becomes a member of the server through voluntary joining. Scope of data processed: the user\u2019s Discord name, identifier, profile picture, and the messages and reactions sent on the server.
Legal basis: Art. 6(1)(a) GDPR (consent).
Duration: until the user leaves the server or until the message is deleted; for moderation purposes the Data Controller may retain messages for up to 2 years.
Discord’s privacy policy: discord.com/privacy
On any of the above platforms – according to the settings of their own social account – the data subject may at any time delete their comments, likes or withdraw their following.
Transmission of personal data, recipients and categories of recipients: for the concept of recipient, see Article 4(9) GDPR. The Data Controller transmits the data subject’s personal data to state bodies or authorities – in particular courts, the prosecution service, investigating and misdemeanour authorities, and the Hungarian National Authority for Data Protection and Freedom of Information – only in exceptional cases and on the basis of a statutory obligation.
Automated decision-making (and profiling): no automated decision-making, including profiling, takes place in the course of the processing.
17. Customer Relations and Other Data Processing
If any question arises in the course of using the Data Controller’s services, or if the data subject has a problem, they may contact the Data Controller in the ways specified on the website (e-mail, contact form, social pages).
The Data Controller deletes incoming e-mails and messages – along with the enquirer\u2019s name, e-mail address and any other personal data voluntarily provided – after no more than 60 days from the date the data was provided, or after the matter is closed.
We provide information about data processing activities not listed in this notice at the time the data is collected.
Upon exceptional requests from authorities or, based on statutory authorisation, from other bodies, the Service Provider is required to provide information, disclose or transfer data, or make documents available. In such cases, provided the requesting party has specified the precise purpose and the scope of data, the Service Provider discloses only as much personal data as is strictly necessary to achieve the purpose of the request.
18. Rights of Data Subjects
1. Right of access: You have the right to obtain from the Data Controller confirmation as to whether or not your personal data is being processed, and, where it is, access to the personal data and the information listed in the Regulation.
2. Right to rectification: You have the right to obtain from the Data Controller, without undue delay, the rectification of inaccurate personal data concerning you. Taking into account the purposes of the processing, you have the right to have incomplete personal data completed.
3. Right to erasure: You have the right to obtain from the Data Controller the erasure of personal data concerning you without undue delay, and the Data Controller has the obligation to erase your personal data without undue delay where the conditions of Article 17 GDPR are met. The user account can also be deleted from the profile settings, which automatically results in the deletion of the related data.
4. Right to be forgotten: Where the Data Controller has made the personal data public and is obliged to erase it, it shall take reasonable steps – including technical measures – to inform other controllers of the erasure request.
5. Right to restriction of processing: You have the right to obtain from the Data Controller restriction of processing where one of the conditions of Article 18 GDPR applies.
6. Right to data portability: You have the right to receive the personal data concerning you, which you have provided to a controller, in a structured, commonly used and machine-readable format, and have the right to transmit that data to another controller.
7. Right to object: In the case of processing based on legitimate interest, you have the right to object, on grounds relating to your particular situation, at any time to the processing of your personal data, including profiling.
8. Objection in the case of direct marketing: Where personal data is processed for direct marketing purposes, you have the right to object at any time, including profiling. Where you object, the personal data shall no longer be processed for such purposes.
9. Automated individual decision-making, including profiling: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. The website does not apply any automated decision-making that produces legal effects on the data subject; the calculation of points and the leaderboard ranking are technical in nature, being the mathematical evaluation of the bets placed by the data subject.
How to exercise your rights:
You can initiate access to your personal data, erasure, modification or restriction of processing, and data portability in the following ways:
- by e-mail at contact@xpectgame.com,
- by post at 1144 Budapest, Füredi út 11/D, Hungary,
- in the user profile settings (where account deletion and modification of certain data can be performed directly).
19. Response Deadline
The Data Controller takes action and informs you of the measures taken in response to the above requests without undue delay, but in any case within twenty-five (25) calendar days of receipt of the request.
If necessary, this period may be extended by 2 months. The Data Controller informs you of any extension of the deadline, stating the reasons for the delay, within twenty-five (25) calendar days of receipt of the request.
If the Data Controller does not take action on your request, it informs you, without delay and at the latest within twenty-five (25) calendar days of receipt of the request, of the reasons for not taking action and of your right to lodge a complaint with a supervisory authority and to exercise your right to a judicial remedy.
20. Security of Data Processing
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the Data Controller and the processor implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including, among others:
- the pseudonymisation and encryption of personal data (communication via HTTPS/TLS, storage of passwords in cryptographic hash form);
- the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
- the ability to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident (regular backups);
- a process for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures for ensuring the security of the processing.
Specific data security measures:
- Data is processed in a PostgreSQL database on the Supabase platform, with row-level security (RLS) rules, so that users can only access their own data and the data visible to them based on the nature of the game.
- User passwords are not stored in their original form; only industry-standard cryptographic hashing provided by Supabase Auth is used.
- The website is accessible only over an encrypted (HTTPS) channel.
- Administrative privileges (admin role) are assigned only to user accounts explicitly designated for this purpose.
- The processors (Supabase, Vercel) operate the server infrastructure in accordance with their own high-level security standards, including physical access protection, logging, backups and incident management.
- The system is automatically backed up and archived on a regular basis.
21. Notification of a Personal Data Breach to the Data Subject
Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the Data Controller communicates the breach to the data subject without undue delay.
The communication to the data subject must describe in clear and plain language the nature of the personal data breach, contain the name and contact details of the contact point providing further information, describe the likely consequences of the breach, and describe the measures taken or proposed by the Data Controller to address the breach, including, where appropriate, measures to mitigate any possible adverse effects.
The data subject does not need to be informed if any of the following conditions are met:
- the Data Controller has implemented appropriate technical and organisational protection measures, and those measures were applied to the data affected by the personal data breach (e.g. encryption);
- the Data Controller has taken subsequent measures which ensure that the high risk to the rights and freedoms of the data subject is no longer likely to materialise;
- the notification would involve disproportionate effort. In such cases, the data subjects must be informed via publicly available information.
22. Reporting a Personal Data Breach to the Authority
The Data Controller notifies the personal data breach to the competent supervisory authority pursuant to Article 55 GDPR without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification is not made within 72 hours, it shall be accompanied by reasons for the delay.
23. Review in the Case of Mandatory Data Processing
Where the duration of mandatory data processing or the periodic review of its necessity is not specified by law, a local government decree or a binding legal act of the European Union, the Data Controller reviews, at least every three years from the commencement of the processing, whether the processing of personal data by it or by a processor acting on its behalf or instructions is necessary for the achievement of the processing purpose.
The Data Controller documents the circumstances and outcome of this review, retains the documentation for ten years following the review, and makes it available, upon request, to the Hungarian National Authority for Data Protection and Freedom of Information (hereinafter: the Authority).
24. Right to Lodge a Complaint
A complaint may be lodged against any infringement by the Data Controller with the Hungarian National Authority for Data Protection and Freedom of Information:
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
1055 Budapest, Falk Miksa utca 9-11., Hungary
Postal address: 1363 Budapest, Pf. 9.
Phone: +36-1-391-1400
Fax: +36-1-391-1410
E-mail: ugyfelszolgalat@naih.hu
Website: www.naih.hu
The data subject may also turn to a court in respect of the infringement. The data subject may, at their choice, bring the proceedings before the regional court competent for their place of residence or stay.
25. Closing Provisions
In preparing this notice we have had regard to the following legislation:
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (GDPR);
- Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom of Information (Infotv.);
- Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services (in particular § 13/A);
- Act XLVII of 2008 on the Prohibition of Unfair Commercial Practices Against Consumers;
- Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activity (in particular § 6);
- Act C of 2003 on Electronic Communications (in particular § 155);
- Recommendation of the Hungarian National Authority for Data Protection and Freedom of Information on the data protection requirements of prior information.
Date of last update: 2026. 05. 29.