This is an English translation of the Hungarian original, provided for information purposes. The Service is operated under Hungarian law, and the contractual relationship between the Provider and the User is governed by the Hungarian-language version of this document.
In the event of any discrepancy, ambiguity or dispute between the English and the Hungarian text, the Hungarian version shall prevail. The Hungarian version is available at any time, free of charge, at football-analytics.hu/aszf and football-analytics.hu/adatvedelem.
References to Hungarian legislation are given in their original form, because those acts and decrees are what actually apply; an English descriptive name is added for readability only.
Dataobjects Consulting Kft.
Registered seat: 2130 Szigetszentmiklós, Árnyas utca 14/a, Hungary
Company registration number: 13-09-141656
Tax number: 23006605-2-13
E-mail: mail@dataobjects.hu (data
protection and customer service enquiries)
This notice sets out, on the basis of Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter: the GDPR) and Act CXII of 2011 on the right to informational self-determination and freedom of information (hereinafter: the Infotv.), what personal data Dataobjects Consulting Kft. processes, for what purpose and on what legal basis, in the course of operating the website football-analytics.hu (hereinafter: the Website) and the Football Analytics service available on it (hereinafter: the Service).
| Data processed | user name, e-mail address and its verified status, password (stored exclusively in encrypted, non-reversible form), display name, the time and method of registration (with a password or with a Google account), the chosen interface language, the time of the last sign-in, the unsubscribe status for promotional e-mails and the unique unsubscribe identifier associated with it. The IP address at the time of registration is not stored among the account data: it appears in the abuse-prevention log (point 2.5) and in the log of legal declarations (point 2.8). |
|---|---|
| Purpose | creating and maintaining the user account, providing access to the Service, preventing misuse of the account |
| Legal basis | performance of a contract (Article 6(1)(b) GDPR); as regards the unsubscribe status and identifier, a legal obligation and the Provider's legitimate interest in giving effect to the unsubscribe request (Article 6(1)(c) and (f) GDPR) |
| Retention period | for as long as the user account exists; in the case of a deletion request, taking into account statutory retention obligations (for example accounting obligations) |
| Data processed | session identifier and CSRF protection token, and the associated IP address and browser identifier (user agent) |
|---|---|
| Purpose | maintaining the signed-in state, protection against unauthorised access and against fraud affecting user accounts (CSRF attack) |
| Legal basis | a technical condition necessary for the performance of the contract (Article 6(1)(b) GDPR) |
| Retention period | the session cookie lives in the browser for a maximum of 4 hours and may therefore survive the browser being closed; the signed-in state is nevertheless ended by the server-side session — after 4 hours of inactivity for an administrator account, and after 10 minutes of inactivity for other accounts. Both periods are rolling: every request restarts them. The CSRF cookie is valid for a maximum of 30 days. |
| Data processed | billing name / company name, tax number (in the case of company invoicing), billing address, e-mail address, telephone number (if provided), data relating to the Plan ordered and to the payment transaction (amount, date, status, transaction identifier), and, as evidence of VAT residence, the IP address at the time of the order, the billing country provided and the residence conclusion drawn from them |
|---|---|
| Purpose | performing the Subscription, issuing the invoice, carrying out and tracking the payment |
| Legal basis | performance of a contract (Article 6(1)(b) GDPR); as regards the billing data and the VAT residence evidence, also a statutory obligation (Act C of 2000 on accounting and Act CXXVII of 2007 on value added tax; Article 6(1)(c) GDPR) |
| Retention period | for accounting documents and the VAT residence evidence, 8 years as required by the Accounting Act; other data within the general limitation period (5 years) from the termination of the Subscription |
| Data processed | the name and e-mail address provided in the enquiry and the content of the enquiry |
|---|---|
| Purpose | answering the User's question or complaint |
| Legal basis | the Provider's legitimate interest in answering customer service enquiries; in the case of a contractual or pre-contractual relationship, Article 6(1)(b) GDPR |
| Retention period | a maximum of 3 years from the enquiry |
| Data processed | the time of sign-in and registration attempts, IP address, the outcome of the event (successful / unsuccessful) |
|---|---|
| Purpose | detecting and preventing unauthorised access attempts, bulk (automated) registration and other abuse |
| Legal basis | the Provider's legitimate interest in maintaining the security of its IT system (Article 6(1)(f) GDPR) |
| Retention period | a maximum of 12 months |
If the Provider activates the Cloudflare Turnstile bot protection service in the registration process, the IP address and certain browser characteristics may be transmitted to the system of Cloudflare, Inc. (United States) during the captcha check, solely for the purpose of filtering out bot activity. The Website applies captcha protection actively only if this function is switched on.
For certain analysis reports within the Service, the Provider may use an artificial intelligence based language model (Anthropic Claude), solely for the purpose of turning statistical results that have already been calculated (for example 1X2 probabilities, expected number of goals, other metrics) into a short, plain-language text. In doing so, the User's personal data (in particular e-mail address, name, account data) are not transmitted to the AI provider; the model receives only statistical data relating to the match, the teams and the market, which cannot be linked to the User as an individual.
| Data processed | the type of declaration (acceptance of the T&C and the Privacy Notice; consent to the immediate commencement of the Service and to the loss of the right of withdrawal), the version number and time of the declaration, and the IP address and browser identifier (user agent) at the time the declaration was made |
|---|---|
| Purpose | legal proof that the User/Consumer expressly and in advance accepted the T&C, the Privacy Notice and — where required by consumer protection legislation — the immediate commencement of the Service and the loss of the right of withdrawal, during the order or the registration |
| Legal basis | compliance with a statutory obligation incumbent on the Provider and its legitimate interest in the subsequent provability of legal declarations (Article 6(1)(c) and (f) GDPR), in accordance with the relevant provisions of Government Decree 45/2014 (II. 26.) and of the Act on electronic commerce services (Ektv.) |
| Retention period | for as long as the account exists, or until claims relating to the contract in question become time-barred (5 years in the general case) |
| Data processed | an irreversible hash (SHA-256) of the User's e-mail address — without storing the raw e-mail address —, together with the number of free trial analyses used for that hash and the first/last time of such use; furthermore a salted, irreversible hash (SHA-256) of the IP address used at registration — without storing the raw IP address —, and the number of registrations without a Plan associated with that hash, with the first/last time |
|---|---|
| Purpose | to prevent the same person from repeatedly obtaining the one-off free trial allowance of a total of 20 analyses available without a Plan (see Section 5 of the T&C) by deleting their account and registering again with the same e-mail address, or by opening a series of accounts with new e-mail addresses from the same network |
| Legal basis | the legitimate interest of the Provider in preventing abuse of the Service and in protecting free-of-charge resources (Article 6(1)(f) GDPR) |
| Retention period | retained also after deletion of the account, since the very purpose of the record is to filter out repeated use after deletion. The Provider erases the hash of the e-mail address automatically 5 years after its last use. The hash of the IP address is processed by the Provider for as long as the purpose subsists; it is erased in the course of periodic review or at the request of the data subject |
The record contains no readable e-mail address: the original e-mail address cannot be reconstructed from the stored hash, which is only capable of determining whether a newly given e-mail address has previously appeared in the record. The record does not store the User's name, IP address, usage history or any other data.
| Data processed | the e-mail address of the Google account and its verified status, and the display name set in the Google account; the Provider neither accesses nor processes any other data of the Google account (for example the password or the content of other Google services) |
|---|---|
| Purpose | simplified registration and sign-in without entering a password |
| Legal basis | performance of a contract (Article 6(1)(b) GDPR) |
| Retention period | the same as the retention period for the user account data under point 2.1 |
Signing in with a Google account — where the Provider activates this function — is optional; the User may also use the Service by means of conventional registration with an e-mail address and password.
In the case of a multi-user Plan, the member(s) entitled to manage the Group may, to the extent necessary for managing the Group, access the basic data of the other members of the Group (display name, e-mail address, the status and time of joining or invitation, and the aggregate amount of Quota used by the member in question), and in the course of managing the Group may modify the member's display name and e-mail address, suspend the member's access, generate a new temporary password for the member's account, and delete the member's account. The member entitled to manage the Group may also view the "My favourites" entries of the members of the Group (see point 2.14). This sharing of data is necessary for the transparent management of the Group as a shared Subscription. The member entitled to manage the Group does not learn the members' passwords (generating a temporary password does not make the old password knowable) and cannot sign in to a third party's system on behalf of the member; the operations listed are logged.
Legal basis: performance of a contract, and the legitimate interest of the Provider and of the members of the Group in the transparent management of the shared Subscription (Article 6(1)(b) and (f) GDPR).
| Data processed | e-mail address |
|---|---|
| Purpose | sending operational and informational mailshots relating to the Service and not intended as advertising (for example notices about a change in functionality or planned maintenance), exclusively to active Users whose e-mail address has been verified |
| Legal basis | the Provider's legitimate interest in keeping Users up to date about the Service (Article 6(1)(f) GDPR) |
| Retention period | the log of the content of the mailshot sent and of the delivery status, for a maximum of 3 years from dispatch |
This function covers mailshots initiated manually by the Provider. In addition, the system also sends automatic promotional messages relating to the use of the Service — these are governed by point 2.18.
Upon deletion of the user account (whether at the User's own request or as a result of suspension or deletion under the T&C), the Provider removes the account and the group membership data from the live records and — solely for the purpose of enforcing legal claims and of the subsequent provability of legal declarations (see point 2.8) — saves them to an archive with restricted access. Besides the basic account data and the group membership, the archive also contains group invitations and the usage log entries referred to in point 2.15. The Provider automatically erases the archive 5 years after archiving. The log of legal declarations referred to in point 2.8 is retained by the Provider after the deletion of the account as well, but upon deletion the entry is detached from the user account of the data subject — the fact and time of the declaration remain, the attribution to an individual ceases. Accounting documents (invoices, transaction data) are retained after the deletion of the account as well, within the statutory retention period set out in point 2.3; however, upon deletion these are technically detached from the live user profile of the data subject, and are subsequently retained solely as accounting data, without being attributed to an individual.
If the Provider activates this function, then in the case of a Consumer (User) established or habitually resident in another Member State of the European Union, the country of the billing address and — as a second item of evidence of residence — the country estimated from the IP address are transmitted to the tax calculator service of Stripe, Inc., for the purpose of automatically determining the applicable rate of value added tax (VAT) on the invoice. The actual payment and invoicing take place in this case too as described in point 2.3, through Számlázz.hu — Stripe, Inc. only determines the applicable VAT rate, does not process any payment and does not handle card data. For as long as the Provider does not activate this function, no such transmission to Stripe, Inc. takes place; the VAT rate is then determined as set out in the relevant point of the T&C, on the basis of the billing country provided and the EU VAT number. The evidence used to establish VAT residence (the country provided, the IP address at the time of the order, the conclusion drawn) is retained by the Provider as set out in point 2.3, irrespective of whether this function is active.
| Data processed | the identifier of the match saved by the User, the names of the teams and of the competition, the date of the match, a snapshot of the analytical results valid at the moment of saving, together with the free-text tip/note entered by the User and the time of saving |
|---|---|
| Purpose | to retain and make retrievable the matches selected by the User and the notes attached to them, within the "My favourites" function of the Service |
| Legal basis | performance of a contract (Article 6(1)(b) GDPR) |
| Retention period | 7 days from the date of the match or — where no known match date is associated with the entry — 7 days from the date of saving; thereafter the system deletes the entry automatically, without any separate request. The User may also delete their own entries at any time. |
The User enters free text into the tip field. The Provider asks that the User not enter any personal data, whether their own or that of a third party, into this field, since it is intended solely for recording an analytical note relating to the match.
The entries may be viewed by a member of the Provider's staff with administrator privileges in the course of operating and troubleshooting the Service, and — solely in respect of the members of their own Group — by the member entitled to manage the Group; this includes the free-text tip or note. However, neither of them can delete an entry — only the User may delete an entry, otherwise the automatic expiry described above applies.
| Data processed | the user identifier and username, the identifier and name of the Group, the menu identifier and path of the function used, the parameters of the request (for example the pair of teams and the date range examined), the time of the event, and whether the request was authorised against the Quota and, if not, the reason for this |
|---|---|
| Purpose | accurate and subsequently verifiable accounting for the Quota associated with the Plan, enforcement of the per-user Quota cap, provision of the free re-opening of matches already retrieved on the same day, and detection of use of the Service contrary to its purpose or in an abusive manner |
| Legal basis | performance of a contract (Article 6(1)(b) GDPR) and the Provider's legitimate interest in preventing abuse (Article 6(1)(f) GDPR) |
| Retention period | for as long as the account exists; on deletion of the account the log entries relating to the User are removed from the live records and transferred to the restricted-access archive referred to in point 2.12, from where the Provider erases them automatically after 5 years |
In addition, the Provider maintains an administrator activity log, which records the username of the member of staff performing the administrative operation, the type of operation, the user or group concerned, a short description of the operation and its time. The purpose of this is the subsequent traceability and accountability of changes to permissions, quotas and subscriptions; the legal basis is the Provider's legitimate interest in the auditability of its operations (Article 6(1)(f) GDPR).
| Data processed | the identifier of the user concerned, associated with the session of the administrator performing the switch, together with the times at which the switch began and ended and the log entry for the operation |
|---|---|
| Purpose | investigation of customer service reports and remedying of faults in the Service, where the fault can be reproduced only in the permission, plan or data state of the particular User |
| Legal basis | the Provider's legitimate interest in troubleshooting and in operating its customer service (Article 6(1)(f) GDPR) |
| Retention period | the switched state itself lasts until the session is closed or the administrator switches back; the log entry is retained in the administrator activity log referred to in point 2.15 |
While the switch is in effect, the administrator sees the interface as the User concerned would see it. The administrator does not learn and cannot change the User's password, and the switch does not result in signing in on behalf of the User to any third-party system (in particular, not to their Google account). The beginning and the end of the switch are logged in every case, and the interface indicates the switched state in a warning bar.
| Data processed | the unique referral code assigned to the User; on registration, the identifier of the User through whose referral code the registration took place; in the event of a credit, the amount of Extra quota credited, the name of the plan on which the credit was based and the time of the credit |
|---|---|
| Purpose | determining and crediting the one-off Extra quota due under the referral programme, and enabling the credit to be verified subsequently |
| Legal basis | performance of a contract and the Provider's legitimate interest in operating the referral programme (Article 6(1)(b) and (f) GDPR) |
| Retention period | for as long as the account exists; the record of the referral relationship and of the credit ceases together with the deletion of the account |
The referral code is not derived from the User's e-mail address or name; it is a randomly generated identifier and is therefore not in itself capable of identifying the User. On their Profile page the referrer sees only the amount credited, the name of the plan and the time of the credit. The e-mail notification sent about the credit, however, names the person referred by the display name given in their account (or, failing that, by their username); this transfer of data is necessary for the accounting of the referral credit and for its verifiability.
| Data processed | e-mail address, display name, the plan and quota status of the Group, the time of the last sign-in, the unsubscribe status and the unique unsubscribe identifier, and, per message type, the time of the last dispatch |
|---|---|
| Purpose | Notification (transactional) message: alerting the User to the forthcoming expiry of the Subscription, 7, 3 and 1 days before expiry — this concerns the ending of a service ALREADY PURCHASED, is therefore not advertising, and cannot be switched off. Promotional (marketing) message: a weekly reminder to Users who have no Plan, or who have not signed in for a week, about the unused trial allowance and the possibilities offered by the Service. |
| Legal basis | for the notification message, performance of a contract (Article 6(1)(b) GDPR); for the promotional message, the Provider's legitimate interest in maintaining the existing customer relationship and in recommending its own similar service (Article 6(1)(f) GDPR), with an unsubscribe option |
| Retention period | the log of the fact of dispatch (user, message type, time) for as long as the account exists; the unsubscribe status for as long as the account exists |
The promotional messages are switched on by default and can be stopped at any time with a single click: every such message contains an unsubscribe link at the bottom, and unsubscribing can also be carried out and reversed at any time on the Profile page. Unsubscribing applies SOLELY to promotional messages. Individual (transactional) messages forming part of the operation of the Service — such as the 7/3/1-day notice of the expiry of the Subscription, password reset, e-mail address verification, the invoice notification and confirmation of account deletion — continue to be sent after unsubscribing. The Provider sends promotional messages only to active accounts and to verified e-mail addresses. Messages belonging to the registration process (verification of the e-mail address, group invitation) go, by their very nature, to addresses that are not yet verified or that do not yet have an account.
| Data processed | the recipient's e-mail address, the subject and full text of the message, the dispatch status (successful or unsuccessful), any error message, and the times of creation and dispatch |
|---|---|
| Purpose | enabling delivery to be verified subsequently, detecting unsuccessful dispatch and resending the message, and investigating customer service reports |
| Legal basis | the Provider's legitimate interest in the verifiability of delivery and in troubleshooting (Article 6(1)(f) GDPR) |
| Retention period | the Provider processes the log entry for as long as the purpose subsists, as a guide for a maximum of 3 years from dispatch; deletion is not automatic but is carried out in the course of periodic review or at the request of the data subject |
The log contains the full text of the message, because a delivery dispute can only be resolved afterwards if it can be established exactly what was sent. The log contains no password: the identifier in a password reset message is single-use and time-limited.
| Data processed | the time of the deletion request, the single-use identifier belonging to the confirmation link and its expiry time, the IP address at the time of the request, and the time at which the request was closed (confirmation or expiry) |
|---|---|
| Purpose | ensuring that only the person entitled can delete the account, and enabling abusive deletion requests (not originating from the person entitled) to be filtered out |
| Legal basis | the Provider's legitimate interest in preventing misuse of the account (Article 6(1)(f) GDPR) |
| Retention period | on deletion of the account the record of the request ceases together with the account; an unconfirmed, expired request cannot be used after expiry, and its deletion is carried out in the course of periodic review |
The confirmation identifier is not in itself capable of signing in to the account: it can be used solely to confirm deletion, once, and is invalid after the expiry time.
In the course of providing the Service, the Provider uses the following processors and independent controllers:
| Provider | Role | Seat / place of processing |
|---|---|---|
| Tárhely.eu Szolgáltató Kft. | hosting service | Hungary |
| Számlázz.hu (KBOSS.hu Kft.) | electronic invoicing and intermediation of online card payment (providing the payment interface) | Hungary |
| OTP Mobil Kft. (SimplePay) | carrying out the card payment through the Számlázz.hu payment interface | Hungary |
| Barion Payment Zrt. | carrying out the card payment through the Számlázz.hu payment interface | Hungary |
| API-Sports / API-Football | source of public sports statistics and market (odds) data; does not process the User's personal data | European Union |
| Anthropic PBC | generating the AI-based textual summary, on the basis of the limited set of data described in point 2.7 | United States |
| Cloudflare, Inc. | optional bot protection (captcha), if activated | United States |
| Google Ireland Limited | optional sign-in with a Google account, on the basis of the limited set of data described in point 2.9, if activated | European Union (Ireland) / United States |
| Stripe, Inc. | optional determination of the VAT rate (tax calculation) in the case of a foreign Consumer, on the basis of the limited set of data described in point 2.13, if activated; does not process payments | United States |
| ipapi.co | optional estimation of country from the IP address as the second item of evidence of VAT residence, if activated; the Provider transfers the IP address only | United States |
| European Commission (VIES) | optional verification of the validity of the EU VAT number provided in the case of a corporate User, if activated | European Union |
| Magyar Nemzeti Bank, or a public exchange rate service | retrieving the official exchange rate for the indicative conversion of prices; no personal data of the User is transferred | European Union |
| Public website of Szerencsejáték Zrt. | source of the match list for the weekly Toto round; no personal data of the User is transferred | Hungary |
| Google Ireland Limited (Google Analytics 4, Google Ads) | measuring website traffic and advertising performance, solely with the User's cookie consent (section 4); without consent the measurement code is not even loaded and no data is transferred | European Union (through Google's infrastructure the United States may also be involved) |
| Meta Platforms Ireland Limited (Meta Pixel) | optional, only if the Provider switches it on: measuring registrations arriving from Facebook/Instagram advertisements, solely with the User's cookie consent | European Union (through Meta's infrastructure the United States may also be involved) |
Where a provider established in the United States is used, the Provider ensures appropriate safeguards under Chapter V of the GDPR (in particular the standard contractual clauses issued by the European Commission). Transfers of data connected with functions that are currently inactive (for example Cloudflare Turnstile, Google sign-in, Stripe Tax VAT calculation) only take place from the actual activation of the function onwards; upon activation the Provider updates this notice.
| Cookie name | Purpose | Lifetime | Legal basis |
|---|---|---|---|
| fa_session | maintaining the signed-in state | a maximum of 4 hours in the browser; the signed-in state is ended by the server (administrator: 4 hours, other accounts: 10 minutes of inactivity; the period restarts on every request) | strictly necessary, performance of a contract |
| fa_csrf | protection against CSRF attack | a maximum of 30 days | strictly necessary, legitimate interest |
| fa_lang | storing the interface language selected by the User | a maximum of 1 year | strictly necessary for the functionality requested by the User |
| session | temporary storage of the single-use technical values (state and nonce identifiers) belonging to the Google sign-in flow | until the end of the browser session | strictly necessary, for the functionality requested by the User |
| fa_cookie_dontes | storage of the User's cookie consent (in the browser's local storage, not as a cookie) | until withdrawn by the User | strictly necessary, compliance with a legal obligation (demonstrability of consent) |
| _ga, _ga_* | statistical — Google Analytics 4: measuring visits and site usage (how many visitors arrive, what they look at, where they drop off) | a maximum of 2 years | the User's consent |
| _gcl_* | advertising — Google Ads: measuring whether a visitor who clicked an advertisement went on to register or subscribe (conversion measurement) | a maximum of 90 days | the User's consent |
| _fbp | advertising — Meta (Facebook/Instagram) Pixel, only if switched on by the Provider: measuring registrations arriving from Meta advertisements | a maximum of 90 days | the User's consent |
The cookies in the first four rows of the table are strictly necessary for the operation of the Website, therefore the law does not require prior consent for them; without these the Website cannot be used.
The statistical and advertising cookies are placed by the Provider solely on the basis of the User's prior, explicit consent. On the cookie bar shown when the Website is first opened, the User may choose between "Accept" and "Necessary only". Until the User consents, the measurement code of Google Analytics, Google Ads and the Meta Pixel is not even loaded, so these cookies are not created and no data is transferred to the above providers.
Consent may be withdrawn or modified at any time, without giving reasons, by clicking the "Cookie settings" link in the footer of the Website; the cookie bar then reappears and the User may make a new decision. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal. Cookies already placed may be deleted by the User in their browser settings.
With the statistical and advertising cookies the Provider measures the use of the Website and the effectiveness of its advertisements. By this means the Provider does not identify the User by name, and does not sell or transfer data to advertisers for their own marketing purposes.
In connection with the processing of their personal data, the User has the following rights under the GDPR: access to the data processed, rectification of the data, erasure, restriction of processing, data portability, and the right to object to processing based on legitimate interest. Where processing is based on consent, the consent may be withdrawn at any time without giving reasons; this does not affect the lawfulness of processing carried out before the withdrawal.
A request to exercise the above rights may be submitted by the User to the e-mail address mail@dataobjects.hu. The Provider answers the request without undue delay and in any event within one month.
If the User considers that the processing of personal data relating to them infringes the provisions of the GDPR or of the Infotv., they may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság; address: 1055 Budapest, Falk Miksa utca 9-11.; postal address: 1363 Budapest, Pf. 9.; e-mail: ugyfelszolgalat@naih.hu; website: naih.hu), or may seek a remedy before the court (törvényszék) competent for their domicile or place of residence.
In the interest of the security of personal data, the Provider applies appropriate technical and organisational measures, including an encrypted (HTTPS) connection, non-reversible storage of passwords, and CSRF and other security mechanisms protecting sessions.
The Provider reserves the right to amend this notice unilaterally, in particular in the event of a change in legislation or an extension of the scope of the Service. The notice in force at any given time is continuously available on the Website (football-analytics.hu/adatvedelem).
The operation is running. Please wait for the result.
The page is loading. Please wait and do not navigate away.