PRIVACY POLICY

 

I. GENERAL INFORMATION AND CONTACT DETAILS

 

NutriAssistant.com Limited Liability Company (in Hungarian: NutriAssistant.com Korlátolt Felelősségű Társaság; registered seat: Kallós Dezső street 10. 2nd floor door no. 1., Dunaújváros, H-2400, Hungary, Company registration number: 07-09-030525; Statistical lot number: 27119383-6201-113-07.; Tax number: 27119383-2-07, Legal representative: Kristóf Ármin Szabó, managing director; web page: www.nutriassistant.com; E-mail: info@nutriassistant.com), as maintainer of www.nutriassistant.com and manager of the web site www.nutriassistant.com  and NutriAssistant mobile application (hereinafter referred to as: “Controller”) pays particular attention to the protection and correct management of your personal data. Your rightful interests regarding data protection belong to our main priorities, and we respect them during data collection as well as processing and managing. 

 

The Controller provides its services through the www.nutriassistant.com website and NutriAssistant mobile application. For the performance of its services, Controller processes personal data provided by its customers and other data subjects. By using the web site www.nutriassistant.com or NutriAssistant mobile application you agree to share some of your personal data with the Controller.

 

Personal data” means any information relating to an identified or identifiable natural person directly or indirectly, such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. Before you share this information with us, please read our data processing policy.

 

Certain personal data provided is also considered as health data. The relevant laws guarantee enhanced protection in respect of health data.

 

Changes to the Privacy Policy

Occasionally we may, in our discretion, make changes to this Privacy Policy. When we make material changes to this Privacy Policy, we’ll provide you with prominent notice as appropriate under the circumstances, e.g., by displaying a prominent notice within the Service or by sending you an email. In some cases, we will notify you in advance, and your continued use of the Service after the changes have been made will constitute your acceptance of the changes. Please therefore make sure you read any such notice carefully. If you do not wish to continue using the Service under the new version of this Privacy Policy, you may terminate this Privacy Policy by contacting us through info@nutriassistant.com.

 

In compliance with the relevant data protection legislation, especially the Act CXII of 2011 on information self-determination and freedom of information (hereinafter: “Information Act”), the Collector manages the data in the context of our activities as follows:

NutriAssistant.com Ltd.’s five directives protecting your data

We apply the following five directives at NutriAssistant.com Ltd.:

  1. Legal basis: We only use your data for purposes detailed in this document.
  2. Relevancy and accuracy: We only collect the data that are necessary for the data processing. We do everything we can to make sure the data stored by us is up to date and accurate.
  3. Data storage: In compliance with the law we shall store your data only as long as it is necessary for the processing.
  4. Access, rectification: The Data Subject shall have the right to access, correct, modify or erase his or her data.
  5. Data security and privacy: Our Company protects your data against alteration, accidental destruction and damage, unauthorized usage, disclosure, as well as against unauthorized access with technical and organizational measures.

 

II. LEGAL BASIS OF DATA PROCESSING

 

Legal basis: the data subject’s consent.

 

The legal basis of the personal data processing relating to the provision of the NutriAssistant service is the informed and voluntary consent of the data subject or on the conclusion of the contract based on this policy. By accepting this Privacy Policy gives his/her consent to Controller to process his/her data in order to reach the purpose of data processing. NutriAssistant.com Ltd has the right to do so until withdrawal of this consent.

 

While browsing www.nutriassistant.com, our Customers can use the website without revealing their identity or providing any personal data.  However, in certain cases, our customers must provide and submit their or third party’s personal data so that they can use the NutriAssistant services to a maximum extent.

 

As a general principle, we declare that when we request personal data from our customers, they can decide freely after having read the relevant information on our data processing whether they decide to provide the requested data or not.

 

Please note that if somebody does not provide his/her data, in certain cases he/she may not be able to use the service.

 

Controller also collects special categories of data that relates to health or addictions.

 

We never share the data of our customers with third parties unless there is a legal basis to do so, or only in anonym form.

 

In certain cases, the processing, storing and transfer of data is required by applicable laws.

 

III. PURPOSE OF DATA PROCESSING

 

How we use the information we collect

Consistent with the permissions you give us to collect the information, we may use the information we collect, including your personal information:

  1. to provide, personalize, and improve your experience with the Service, for example by providing customized, personalized, or localized content, recommendations, features, and advertising on or outside of the Service;
  2. to ensure technical functionality of the Service, develop new products and services, and analyze your use of the Service, including your interaction with the Service;

3.     to communicate with you for Service-related or research purposes including via emails, notifications, or other messages, which you agree to receive.

IV. CATEGORIES OF PERSONAL DATA PROCESSED

We may collect and store the following information:

1. Registration data

When you register for the Service, we may ask you for your email address.

Purpose of data processing: establishment of a NutriAssistant user account so that the user can use the NutriAssistant app and services.

Legal basis: Point a) of Article 6(1) of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter as “GDPR”).

Scope of personal data: Customer’s email address and optionally their occupation

Source of personal data: data provided by the Customer

Data retention period: the lifecycle of the NutriAssistant user account.

Data transfer: the Controller may under certain circumstances transfer personal data to any third parties. The Controller will only transfer the strictly necessary data to third parties while observing the applicable regulations

2. Client data

When using the Service, you may enter personal data about 3rd parties, such as clients of yours. You are responsible for having consent from these parties to do so. You should not store sensitive client data in our System. Sensitive data includes but not limited to e.g. social security number.

Purpose of data processing: establishment of a NutriAssistant user account so that the user can use the NutriAssistant app and services.

Legal basis: points a) and b) of Article 6(1) of the GDPR, i.e. the data processing is carried out on the basis of the Customer’s consent and it is necessary for a performance of a contract to which the data subject is a party; as well as points a) and c) of section 4(1) and point b) and c) of section 4(2) of the i.e. the data subject’s consent as well as points a) and c) of section 4(1) and point b) and c) of section 4(2) of the Act XLVII of 1997 on the processing of health data (hereinafter as “Act on health data”).

Scope of personal data: related to the physical or mental health of a natural person like free time activity, its term, steps taken, floors, active minutes, mood, asleep period, quality of sleep, blood pressure, pulse, blood sugar, quality of vision, quality of hearing, blood test results, home address, smoking habit, coffee- and alcohol consumption, diet, medical history, medical history in the family, medication used on a regular basis, sensitivity to medication or other allergy, email address, phone number and other contact information as well as other personal data.

Source of data: data provided by the Customer during the use of the NutriAssistant.com service.

Data retention period: the lifecycle of the NutriAssistant user account.

Data transfer: the Controller may under certain circumstances transfer personal data to any third parties. The Controller will only transfer the strictly necessary data to third parties while observing the applicable regulations

3. Usage data

When you use or interact with the Service, we may use a variety of technologies that collect information about how the Service is accessed and used. This information may include but is not limited to the following:

1.     information about how you interact with the service, such as the features of the Service you use;

2.     data you request from our servers, such as recipes, meal plans, and data you entered previously;

3.     technical data, which may include URL information, your IP address, the types of devices and browsers you are using to access or connect to the Service;

Purpose of data processing: to monitor the operations of the service, to personalize services and to prevent abuse, to identify user sessions, and to store data on a work session basis, to prevent data loss.

Legal basis: points a) and b) of Article 6(1) of the GDPR, i.e. the data processing is carried out on the basis of the Customer’s consent and it is necessary for a performance of a contract to which the data subject is a party.

Data retention period: Until the completion of the purpose.

 

Data transfer: the Controller may under certain circumstances transfer personal data to any third parties. The Controller will only transfer the strictly necessary data to third parties while observing the applicable regulations

4. Electronic communications between NutriAssistant.com Ltd. and Customers

The contact form on the webpage is for communication purposes. NutriAssistant.com Ltd. categorizes the emails of Customers and other data subjects based on the relevant email’s content.

In respect of the data contained in emails received, NutriAssistant.com assumes that the sending party gave its informed and voluntary consent to the processing of such data by NutriAssistant.com Ltd.

NutriAssistant.com Ltd. usually deletes the name and email address of the sending party together with any data provided voluntarily after five years from the date when such data was provided. However, in certain cases, the applicable law may specify a longer or shorter data retention period.

Purpose of data processing: to identify users and to distinguish them from each other, communication, helpdesk, exercising the data controller’s and the data subject’s rights, to ensure accountability.

 

Legal basis: Point a) of Article 6(1) of the GDPR, the data subject’ consent.

Scope of personal data: date, time, name, telephone number, address, gender, other personal data provided.

Data retention period: Until the completion of the purpose.

 

Data transfer: The Controller may under certain circumstances transfer personal data to any third parties. The Controller will only transfer the strictly necessary data to third parties while observing the applicable regulations.

5. Cookies

 

NutriAssistant.com Ltd. uses cookies on its website. You can find out more about cookies and how to control them in the Cookie Policy section below.

 

Purpose of data processing: to monitor the operations of the service, to personalize services and to prevent abuse, to identify user sessions, and to store data on a work session basis, to prevent data loss.

Legal basis: Point a) of Article 6(1) of the GDPR, the data subject’ consent.

 

Data retention period: Until the completion of the purpose.

 

Data transfer: the Controller may under certain circumstances transfer personal data to any third parties. The Controller will only transfer the strictly necessary data to third parties while observing the applicable regulations.

 

 

V. TRANSMISSION OF THE DATA TO THIRD PARTIES AND OTHER COUNTRIES

What we do NOT do with the information we collect

We process your personal data and the information about you mainly within our inner circle. We will not sell your data to any third party.

 

Transfer to other countries

We transfer, process and store data on our servers located in multiple countries. Your personal information may therefore be subject to Hungarian law that are different from those in your country of residence. We will process your information as described in this Privacy Policy.

 

VI. DATA SECURITY AND PRIVACY MEASURES

We are committed to protecting our users’ information. We shall take all reasonable security measures to protect the personal data against unauthorized access, modification, transmission, disclosure, erasure, destruction, accidental destruction or damage as well as becoming inaccessible due to technological changes. These measures are administrative, computerized and physical. While we take data protection precautions, no security measures are completely secure, and we do not guarantee the security of user information. Your password protects your user account, so you should use an unique and strong password, limit access to your computer and browser, and log out after having used the Service.

NutriAssistant.com is hosted by a cloud service provider, Microsoft Azure, which is in full compliance with the GDPR. These hosting services are located within the European Union. For more information, please read Microsoft Azure’s privacy policy.

 

VII. COOKIE POLICY

By using our website NutriAssistant.com and related domains you accept the use of cookies in accordance with this Cookie Policy. In particular, you accept the use of Analytics Cookies for the purposes described below.

If you do not accept the use of these cookies please disable them following the instructions in this Cookie Policy, for instance by changing your browser settings so that cookies from this website cannot be placed on your computer or mobile device.

1. What is a cookie?

A cookie is a small amount of data, which often includes a unique identifier that is sent to your computer or mobile device browser from a website’s computer and is stored on your device’s hard drive. Each website can send its own cookie to your browser if your browser’s preferences allow it, but (to protect your privacy) your browser only permits a website to access the cookies it has already sent to you, not the cookies sent to you by other websites. Many websites do this whenever a user visits their website in order to track online traffic flows.

Users have the opportunity to set their devices to accept all cookies, to notify them when a cookie is issued, or not to receive cookies at any time. The last of these means that certain personalised features cannot then be provided to that user and accordingly they may not be able to take full advantage of all of the website’s features. Each browser is different, so check the “Help” menu of your browser to learn how to change your cookie preferences.

2. What cookies do we use?

A. Strictly necessary cookies

These cookies are essential in order to enable you to move around the website and use its features. These cookies don’t gather information about you that could be used for marketing or remembering where you have been on the internet. This category of cookies cannot be disabled.

B. Analytics cookies

During the course of any visit to our Website, the pages you see, along with any cookies, are downloaded to your computer or mobile device. We do this, because cookies enable website publishers to find out whether the device (and probably its user) has visited the Website before. This is done on a repeat visit by checking to see, and finding, the cookie left there on the last visit.

In order to be able provide relevant information to our visitors, we need aggregated statistical visitor data that is collected by means of cookies.

The cookies we use are “analytical” cookies. They allow us to recognize and count the number of visitors and to see how visitors move around the site when they are using it. This helps us to improve the way our Website works, for example, by ensuring that users are finding what they are looking for easily.

Our website uses the following cookies.

Cookie

Domain

Type ⇅

Description

Duration

_fbp

.nutriassistant.com

Advertisement

This cookie is set by Facebook to display advertisements when either on Facebook or on a digital platform powered by Facebook advertising, after visiting the website.

3 months

fr

.facebook.com

Advertisement

Facebook sets this cookie to show relevant advertisements to users by tracking user behaviour across the web, on sites that have Facebook pixel or Facebook social plugin.

3 months

test_cookie

.doubleclick.net

Advertisement

The test_cookie is set by doubleclick.net and is used to determine if the user's browser supports cookies.

15 minutes

MUID

.clarity.ms

Advertisement

Bing sets this cookie to recognize unique web browsers visiting Microsoft sites. This cookie is used for advertising, site analytics, and other operations.

1 year 24 days

ANONCHK

.c.clarity.ms

Advertisement

The ANONCHK cookie, set by Bing, is used to store a user's session ID and also verify the clicks from ads on the Bing search engine. The cookie helps in reporting and personalization as well.

10 minutes

_gcl_au

.nutriassistant.com

Analytics

Provided by Google Tag Manager to experiment advertisement efficiency of websites using their services.

3 months

ARRAffinity

.nutriassistant.com

Necessary

ARRAffinity cookie is set by Azure app service, and allows the service to choose the right instance established by a user to deliver subsequent requests made by that user.

session

ARRAffinitySameSite

.nutriassistant.com

Necessary

This cookie is set by Windows Azure cloud, and is used for load balancing to make sure the visitor page requests are routed to the same server in any browsing session.

session

CLID

www.clarity.ms

Other

No description

1 year

_clck

.nutriassistant.com

Other

No description

1 year

_clsk

.nutriassistant.com

Other

No description

1 day

SM

.c.clarity.ms

Other

No description available.

session

SRM_B

.c.bing.com

Performance

Used by Microsoft Advertising as a unique ID for visitors.

1 year 24 days

 

 

Google Analytics

Our Website use Google Analytics, a web analytics service provided by Google, Inc. ("Google"). Information collected by the Google Analytics cookies will be transmitted to and stored by Google on servers in the United States of America in accordance with its privacy practices. To see an overview of privacy at Google and how this applies to Google Analytics, please click here.  You may opt out of tracking by Google Analytics by clicking here.

 

Cookie source

Cookie name

Expiration time

Purpose

Google Analytics

_ga 

_gid 

_gat

26 months

24 hours

1 minute

Used to distinguish users

Used to distinguish users

Used to throttle request rate. 

 

 

3. How to manage and delete cookies

We will not use cookies to collect personally identifiable information about you. However, if you wish to restrict or block the cookies which are set by one of our Websites, you can do this through your browser settings. The Help function within your browser should tell you how.
Alternatively, you may wish to visit www.aboutcookies.org which contains comprehensive information on how to do this on a wide variety of browsers. You will also find details on how to delete cookies from your computer as well as more general information about cookies. For information on how to do this on the browser of your mobile phone you will need to refer to your handset manual.

To opt out of being tracked by Google Analytics across all websites visit http://tools.google.com/dlpage/gaoptout.

Disabling a cookie or category of cookie does not delete the cookie from your browser, you will need to do this yourself from within your browser.

If you have disabled one or more Analytics Cookies, we may still use information collected from cookies prior to your disabled preference being set, however, we will stop using the disabled cookie to collect any further information.

To ask questions or comment about our Cookie Policy, please contact us at info@nutriassistant.com.

VIII. YOUR RIGHTS

It is important for us that you are aware of your rights provided under data protection laws. For this purpose, we set out below your rights relating to the personal data provided to us. (Please note that the list might not be complete.)

 

        Right to withdraw consent: If you gave your consent to the use or processing of your data, you may withdraw your consent by sending an e-mail to info@nutriassistant.com at any time provided that the relevant data is not necessary for the provision of the service.

        Right to access data: By contacting us by email to info@nutriassistant.com you may request information anytime on whether we are processing your data or not. If yes, you are also entitled to get access to the personal data stored by us and to request a copy of them. In addition, you may request information about how we process your personal data.

You may ask for the rectification, deletion, restriction of your data and you may object to the processing of your personal data. You may submit a complaint to the supervisory authority (www.naih.hu).

If we received the data from a third party you are entitled to request information about this.

Right to rectification: You may request NutriAssistant.com Ltd. to rectify any inaccurate data or add missing data without undue delay. You can request the rectification his or her data any time by email to info@nutriassistant.com.

Right to erasure: You may request by sending an email to info@nutriassistant.com that we delete certain personal data stored with us without undue delay if:

-          We no longer need the relevant personal data;

-          You withdraw your consent relating to the processing of the relevant personal data;

-          You object to the processing of your personal data;

-          the relevant personal data must be deleted in order to comply with a legal obligation;

-          You are concerned about the legal basis of our data processing.

Right to restriction of processing: If you contest the accuracy, justification or lawfulness of our data processing, you may request the restriction of certain processing activities.

You may also request the restriction of processing if we no longer need the personal data for the purposes of the processing, but we are required by you for the establishment, exercise or defense of legal claims. In addition, you may request the restriction of processing if you doubt the legitimate ground of data processing.

During the restriction, no data processing activities may be carried out, with the exception of storage. Regarding the termination of the restriction, you will be informed by NutriAssistant.com Ltd. in advance.

        Complaint, recourse:

NutriAssistant.com Ltd. shall process your data complying with this policy and in accordance with the law and guidelines.

If you consider that your rights as a Data Subject have been infringed by the Controller do not hesitate to contact us, so we can find a solution for you.

The Data Subject shall have the right to lodge a complaint with the authorities if he or she is not satisfied with our data processing services or considers that the data processing has infringed his or her rights or there is an imminent danger for infringe his or her rights.

Hungarian Data Protection Authority (in Hungarian: Nemzeti Adatvédelmi és Információszabadság Hatóság)

Registered seat: Szilágyi Erzsébet fasor 22/C., Budapest, H-1125, Hungary

Address: Pf. 5., Budapest, H-15340, Hungary

Telephone number: +36-1-391-1400

Fax number: +36-1-391-1410

Email: ugyfelszolgalat@naih.hu

Website: http://www.naih.hu

 

The concerned Data Subjects have the following two options:

 

1. The Authority shall have the right to examine the legality of the data processing in case the rights of the Data Subjects determined in Section 14 of the Information Act are impended, or his or her application relating to them has been rejected.

2. The Authority shall have the right to launch a data protection procedure if it considers that the processing of the Data Subject’s personal data by the Controller infringes on the effective data protection legislation or on the standards determined by the legally binding acts of the European Union.

We inform our Data Subjects that they can bring action before the civil court or turn to the data protection authority. The concerned Data Subject shall be able to find detailed information on this and the duties of the Controller in the legal provisions of the European Union and of the Council on the protection of individuals with regard to the processing of personal data and on the free movement of such data, in the Regulation 2016/679 (27. April 2016) that has superseded the Directive 95/46/EC, in the Act CXII of 2011  on information self-determination  and freedom of information, furthermore in the Section 13/A of Act CVIII of 2001  on certain issues of electronic commerce activities and information society services.

        Judicial proceedings

It is the data controller to prove that data processing is carried out in compliance with applicable laws. The lawfulness of the data transfer must be proved by the transferee. Any disputes are within the competence of the regional court (törvényszék in Hungarian). The Data Subject may also bring proceedings before the courts where the Data Subject has his or her place of habitual residence. Parties with no legal capacity shall also have the right to become parties to the proceeding. The Authority shall have the right to intervene in proceedings in order to help the concerned party to succeed.

If the court upholds the data subject’s claim, then the court may order the data controller to provide information, rectify data, restrict access to the data, delete the data, to erase the conclusions resulting from automatic decision-making process, to comply with the objection of the data subject or to provide the data requested by the transferee.

If the court rejects the transferees claim, then the data controller must delete the relevant personal data within 3 days. The data controller is also required to delete the relevant data where the transferee does not file a claim with the court in due course. The court may order that its judgement must be published if it considers it to be necessary with respect to the interest of data protection and the rights of the data subjects.

 

In case you have further questions regarding personal data protection please contact us under info@nutriassistant.com.