Zásady ochrany osobných údajov
Name and contact details of the Controller
Name: Kacsó Sándor Béla
Residential address: 3300 Eger, Déva út 8.
Telephone: +36205459699
Email: [email protected]
Website: www.aetr561.hu
We use a processor to operate the IT system. The Processor provides sufficient guarantees to implement appropriate technical and organisational measures to ensure that processing meets legal requirements and protects the rights of data subjects.
Name and contact details of the Processor
Processor's name: MPTR Informatikai és Befektetési Korlátolt Felelősségű Társaság
Short name: MPTR Kft.
Registered office: 1088 Budapest, Szentkirályi utca 3. 5. em. 514.
Represented by: Molnár Péter, Managing Director
Company registration number: 01-09-334432
Tax number: 26206330-2-42
Legislation governing processing:
The principal legislation applicable to the processing described in this notice and the abbreviations used in this notice are:
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter: General Data Protection Regulation or GDPR)
Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom of Information (hereinafter: Infotv.)
Act V of 2013 on the Civil Code (Ptk.)
Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services.
Legal basis for processing:
The Controller always processes personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).
The legal bases for processing include, in particular:
a) Consent of the data subject (Article 6(1)(a) GDPR)
The following, in particular, are based on the data subject's voluntary consent:
the use of optional functional cookies,
local storage settings,
recording cookie choices.
b) Performance of a contract (Article 6(1)(b) GDPR)
Processing is necessary for the performance of the service contract between the user and the Controller, in particular:
user account management,
management of organisational permissions,
route planning,
CMR workflows,
fleet operation,
carrying out transport operations,
operating the application as intended.
c) Compliance with a legal obligation (Article 6(1)(c) GDPR)
To fulfil its legal obligations, the Controller processes, in particular:
tachograph and salary calculation records under EU Regulation 165/2014 and Directive 2006/22/EC,
driving time compliance,
data relating to rest periods,
transport, tax, payroll and record-keeping compliance under EU Regulation 561/2006,
driver activities,
records required by law.
Processing is necessary, in particular, to comply with Regulation (EC) No 561/2006 of the European Parliament and of the Council, Regulation (EU) No 165/2014 and other related transport and labour legislation.
d) Legitimate interests (Article 6(1)(f) GDPR)
The Controller processes data on the basis of its legitimate interests, in particular for:
maintaining IT system security,
handling misuse,
fraud prevention,
service diagnostics,
providing customer support,
improving the application's operation,
system operation.
The Controller declares that we do not draw conclusions about health status, biometric characteristics or fatigue from tachograph, activity or location data.
The underlying tachograph, activity and location data is processed for transport operations, salary calculations, security purposes and legal compliance.
Categories and purposes of data processed:
For the purposes of this notice, personal data means any information that can directly or indirectly identify a natural person.
The Tachograf AETR 561 APP is a digital service that supports road transport activities, processes tachograph data, analyses driving and rest periods, supports salary calculations and manages transport administration.
The Controller processes only the personal data necessary to provide the service.
4.1. Data processed
The Controller may process the following personal data in particular:
User and identification data
name;
email address;
telephone number;
user type;
user permissions;
login data;
session refresh data;
device identifiers.
Organisational and company data
organisational membership;
selected company;
company permissions;
subscription and billing metadata.
Transport and operational data
routes;
route points;
CMR records;
fleet data;
refuelling data;
vehicle reports;
vehicle comments.
Compliance and payroll data
The application processes, in particular:
driver tachograph files;
parsed ESM activity facts;
driving periods;
rest periods;
border-crossing events;
loading events;
driver salary calculation snapshots;
audit logs.
Location data
route-related GPS coordinates;
emergency alert location data;
border crossings;
addresses selected on a map
Communication data
emails;
notifications;
user feedback.
Evidence of consent and policy acceptance
The Controller records:
acceptance of the Privacy Notice;
acceptance of the Terms of Service;
cookie settings;
IP address;
User-Agent data;
audit data.
4.2. Purpose of processing
The Controller processes personal data solely for the following purposes:
managing user accounts;
managing subscriptions;
processing tachograph data;
analysing driving and rest periods;
administering transport tasks;
managing CMR documentation;
fleet management;
supporting salary calculations;
ensuring legal compliance;
providing customer support;
maintaining IT system security;
preventing fraud and unauthorised access;
identifying and correcting system errors;
developing the service.
The Controller does not process or store payment card data. Electronic payments are carried out exclusively through the payment service provider's secure system.
Duration of processing:
The Controller processes personal data only for as long as necessary to achieve the purpose of processing or for the retention period specified by applicable legislation.
The retention periods associated with each processing purpose are as follows:
Data category
Retention period
Active user account data
For as long as the user account is active
Identification data of deleted user accounts
Anonymised 60 days after the deletion request has been fulfilled
Deleted organisational access
Deleting an organisation starts a 60-day appeal/restoration window; member login is disabled immediately
Personal data associated with deleted organisations whose restoration window has expired
If not restored within 60 days, the associated user identification data is anonymised
Company invitations, access links and refuelling data
Retained in recoverable form for up to 730 days after deletion, after which they are permanently deleted
Company invitation expiry
Can be configured up to one year in the future
Soft-deleted operational records
Permanently deleted only after the retention window has expired and only if the record has already been marked as deleted
Soft-deleted route and transport data
Permanently deleted 2555 days (7 years) after deletion
Soft-deleted CMR documents
Permanently deleted 1095 days (3 years) after deletion
Uploaded tachograph files (DDD, ESM)
395 days (13 months)
Parsed ESM activity facts and derived compliance timelines used to reconstruct salary/compliance calculations
2555 days (7 years)
Driver salary calculation snapshots
2555 days (7 years)
Audit logs
13 months
Feedback and support data
There is currently no automatic, fixed deletion deadline; data is retained until an authorised administrator manually deletes it
Evidence of policy acceptance
Earlier records superseded by a newer acceptance are deleted after 24 months; the most recent acceptance may be retained for as long as necessary for auditability
Evidence of cookie consent
24 months
Data export files
For 1 month after generation or until earlier cleanup
After the retention period expires, the Controller irreversibly deletes or anonymises personal data, unless further retention is required by law or is necessary to enforce a legal claim of the data subject or the Controller.
Where processing is based on the data subject's consent, the data subject may withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
Persons with access to data:
The Controller ensures that only persons who need personal data to perform their duties and who are subject to appropriate confidentiality obligations have access to it.
The Controller uses processors to operate the IT system, provide the electronic service and operate the application.
6.1. The Controller's processor
MPTR Informatikai és Befektetési Korlátolt Felelősségű Társaság (MPTR Kft.)
The processor's tasks include, in particular:
operating the application,
providing server infrastructure,
database management,
creating backups,
system maintenance,
IT support.
The processor may process personal data only on the Controller's instructions.
6.2. Further processors and recipients
In operating the application, the Controller may share data with the following processors and third-party recipients:
Stripe Payments Europe Limited / Stripe LLC
(processor and/or independent controller depending on the processing operation, Ireland and United States)
Payment and subscription data, including customer and contact identifiers, Stripe customer, subscription, payment and invoice identifiers and statuses, payment method and transaction metadata, billing and fraud prevention; payment card data is handled by Stripe and is not stored by Tacho561;
transfers to the United States
safeguards: EU-US Data Privacy Framework and the 2021 EU Standard Contractual Clauses
DigitalOcean LLC
(processor, United States; Tacho561's infrastructure is configured for the ams3 region in Amsterdam, Netherlands)
Kubernetes application hosting, managed PostgreSQL and Valkey services, backups and S3-compatible DigitalOcean Spaces object storage for account, transport, compliance, uploaded file and operational data;
safeguard: EU-US Data Privacy Framework, with the 2021 EU Standard Contractual Clauses under DigitalOcean's data processing agreement as a fallback
Plus Five Five Inc. (Resend)
(processor, United States)
Resend SMTP relay for delivering transactional emails, including account verification, security, notification and data export messages; processes sender and recipient email addresses, message headers, content and attachments, and delivery metadata;
safeguards: EU-US Data Privacy Framework and the 2021 EU Standard Contractual Clauses
Cloudflare Inc.
(processor, United States; R2 object storage restricted to European Union jurisdiction)
S3-compatible Cloudflare R2 object storage and content delivery for certain non-sensitive uploaded images (profile pictures, CMR cargo and delivery photos, refuelling receipts, and photos attached to vehicle reports and driving events);
R2 objects are stored and processed within EU jurisdiction and delivered through unguessable public URLs;
R2 is not used for tachograph files, signatures or data exports;
access or transfers relating to Cloudflare account, administrative, security and support data may involve the United States.
safeguards: EU-US Data Privacy Framework and the 2021 EU Standard Contractual Clauses
OpenStreetMap Foundation
(third-party recipient, United Kingdom)
map tile display;
safeguard: UK adequacy decision
CARTO
(third-party recipient, Spain)
map tile display;
safeguard: processing in the EEA
OpenStreetMap Nominatim
(third-party recipient, Germany)
address geocoding;
safeguard: processing in the EEA
Transport companies and organisations with which you are associated
Optional error monitoring services
such as Sentry, if enabled in the deployment
6.3. Transfers to authorities
The Controller transfers personal data to courts, prosecutors, investigating authorities, administrative bodies or other authorities only in cases prescribed by law where disclosure is legally required.
6.4. International transfers
Primary application, database and object storage processing takes place largely within the European Economic Area, in DigitalOcean's Amsterdam region and Cloudflare R2's EU jurisdiction. Stripe Payments Europe, Limited is established in Ireland. Where Stripe, DigitalOcean, Plus Five Five, Inc. (Resend) or Cloudflare transfers personal data to or accesses it from the United States, the transfer relies on the relevant provider's EU-US Data Privacy Framework certification and/or the 2021 EU Standard Contractual Clauses. Transfers to the OpenStreetMap Foundation (United Kingdom) rely on the UK adequacy decision.
You may request a copy of the relevant safeguards using the privacy contact details above.
We maintain an internal register of sub-processors; we notify affected customers of material changes at least 30 days in advance.
Security of personal data:
When processing personal data, the Controller ensures compliance with the data security requirements of Article 32 GDPR and takes all reasonable technical and organisational measures to ensure that personal data is adequately protected.
The Controller selects and operates the IT systems used for processing so that the personal data processed:
is accessible to authorised persons (availability),
has its accuracy and integrity ensured (integrity), and
is adequately protected against unauthorised access, modification, disclosure, deletion, destruction or other unauthorised processing (data confidentiality).
In particular, the Controller applies the following measures:
operating an access rights management system;
using authenticated user access;
operating an audit logging system;
creating regular backups;
using encrypted data communications;
using firewalls and other IT protection solutions;
installing regular security updates;
appropriately selecting and monitoring processors.
The Controller and processors ensure the security of processing through technical and organisational measures reflecting the state of the art, taking into account the nature, purposes and circumstances of processing and the risks to the rights and freedoms of data subjects.
In the event of a personal data breach, the Controller acts in accordance with the obligations set out in Articles 33–34 GDPR.
Rights and means of enforcement
The GDPR sets out the data subject's data protection rights and remedies in detail.
In particular, the data subject has the right to:
receive advance information about the processing of their personal data;
request access to personal data processed by the Controller;
request rectification or completion of their personal data;
request erasure of their personal data (right to be forgotten);
request restriction of processing;
exercise the right to data portability;
object to processing of their personal data where it is based on the Controller's legitimate interests;
withdraw consent at any time where processing is based on consent.
Data subject requests may be submitted to the Controller in writing or electronically using the contact details specified in section 1.
The Controller responds to a data subject's request without undue delay and no later than one month after receipt.
Where justified by the complexity or number of requests, the Controller may extend the deadline by up to two further months and informs the data subject of this within one month of receiving the request.
As a general rule, exercising data subject rights is free of charge.
If a data subject's request is manifestly unfounded or excessive, particularly because of its repetitive character, the Controller may charge a reasonable fee or refuse to act on the request in accordance with Article 12(5) GDPR.
If the Controller does not take action on a request, it informs the data subject within one month of receiving the request of the reasons for not taking action and of the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.
Right of access and information: (ARTICLES 13–15 GDPR)
The data subject has the right to obtain information from us as to whether the Controller is processing their personal data. If so, they are entitled to access and information about the data processed about them.
The data subject may also request information from the Controller in writing about:
the purpose of processing,
the categories of data concerned,
the recipients to whom the Controller has disclosed personal data,
the source of the data,
the period for which the data is stored,
whether a processor is used and, if so, the processor's name, address and activities relating to processing,
the circumstances and effects of any personal data breach and the measures taken to address it.
When exercising the right of access, the data subject may also request a copy of their personal data being processed. For requests submitted electronically, unless the data subject requests otherwise, the Controller provides the requested information electronically by email or as a PDF file. If the data subject's right of access adversely affects the rights and freedoms of others, the Controller may refuse to fulfil the request to the extent necessary and proportionate.
Right to rectification and completion: (ARTICLE 16 GDPR)
The data subject may request in writing that the Controller amend their personal data, rectify incorrect data or data requiring clarification, and complete incomplete data. (For example, they may change their email or postal address at any time or ask the Controller to rectify any inaccurate personal data it processes.)
The Controller is not required to erase data where processing is necessary to comply with a legal obligation or to establish, exercise or defend legal claims.
Right to erasure and to be forgotten: (ARTICLE 17 GDPR)
The Controller processes personal data under the applicable legislation for the processing periods specified in this Privacy Notice.
The data subject has the right to request that the Controller erase personal data concerning them without undue delay where any of the following grounds applies:
the data is no longer necessary for the purpose for which the Controller collected or processed it,
the data subject has withdrawn the consent on which processing was based and there is no other legal basis for processing,
the data subject objects to processing and, where applicable, there are no overriding legitimate grounds for processing,
the personal data has been processed unlawfully,
the data must be erased to comply with a legal obligation laid down in a binding European Union legal act or legislation applicable to the Controller,
the personal data was collected in connection with the provision of information society services.
Please note that the Controller is not required to erase personal data in every case, particularly where processing is necessary to comply with a legal obligation.
Right to restriction of processing: (ARTICLE 18 GDPR)
The data subject may request in writing that the Controller restrict processing of their personal data if any of the following applies:
the data subject contests the accuracy of the personal data, in which case restriction applies until the data considered incomplete or inaccurate has been verified,
processing is unlawful and the data subject requests restriction instead of erasure,
the personal data is no longer needed for processing purposes, but the data subject requires it to establish, exercise or defend legal claims,
the data subject has objected to processing, but the Controller's legitimate interests override those of the data subject; restriction applies for the period needed to determine this.
The Controller informs the data subject before lifting a restriction on processing.
Right to data portability: (ARTICLE 20 GDPR)
The data subject has the right to receive the personal data they have provided to the Controller in a structured, commonly used, machine-readable format and to transmit that data to another controller without any hindrance from the Controller.
Right to object: (ARTICLE 21 GDPR)
The data subject may object to processing of their personal data under Article 6(1)(e) and (f) of the General Data Protection Regulation that is necessary for the legitimate interests of the Controller or a third party, including profiling based on those provisions. In such cases, the Controller no longer processes the personal data unless it demonstrates compelling legitimate grounds for processing which override the data subject's interests, rights and freedoms, or which relate to the establishment, exercise or defence of legal claims.
Remedies relating to processing
Complaint to a supervisory authority:
To enforce their rights, the data subject may initiate an investigation or regulatory proceedings on the grounds that their rights have been infringed in connection with the processing of their personal data or that there is an imminent risk of such an infringement, in particular:
if they consider that the Controller restricts the exercise of the data subject rights specified in section 8.1 or rejects their request to exercise those rights (initiation of an investigation), and
if they consider that, when processing their personal data, the Controller or a processor engaged by it or acting on its instructions infringes requirements for processing personal data laid down in legislation or a binding European Union legal act (request for regulatory proceedings).
Competent supervisory authority:
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH – Hungarian National Authority for Data Protection and Freedom of Information)
1055 Budapest, Falk Miksa utca 9-11.
Postal address: 1363 Budapest, Pf.: 9.
Telephone: +36-1-391-1400
Fax: +36-1-391-1410
Email: [email protected]
Website: http://naih.hu/
Initiating court proceedings
Independently of their right to lodge a complaint, the data subject may also bring court proceedings in the event of an infringement described in the preceding section. The competent court for the Controller is the Egri Törvényszék (Eger Regional Court), but the data subject may also bring proceedings before the regional court for their place of residence.
Contact details for regional courts are available at http://birosag.hu/torvenyszekek
The data subject may also bring proceedings before the court having jurisdiction in the Member State of their habitual residence if their habitual residence is in another Member State of the European Union.
If we become aware of misuse of data, we take the necessary measures in accordance with legal requirements.
Final provisions
This Privacy Notice takes effect on …………………….. 2026.
The Controller may unilaterally amend this notice where justified by changes in legislation, changes in regulatory practice, development of the service or changes in the circumstances of processing.