Privacy Policy
1. Data Controller
Name: P4IT Korlátolt Felelősségű Társaság (P4IT Kft.)
Registered office: 9022 Győr, Batthyány tér 10, 1st floor, apt. 4, Hungary
Company registration number: 08-09-029776
Tax number: 26262574-2-08
Email: [email protected]
Phone: +36 70 314 6509
Website: https://p4it.hu/
P4IT Kft. (hereinafter: Data Controller) processes personal data as the operator of the MENÜM (menum.hu) web application in the manner and for the purposes described in this policy. The Data Controller is committed to protecting users' personal data and acts in accordance with applicable data protection legislation.
2. Purpose and Legal Basis of Data Processing
| Processing activity | Legal basis | Purpose |
|---|---|---|
| Registration and login | Performance of contract — GDPR Art. 6(1)(b) | Creating and managing user accounts, sending login links |
| Eating log | User consent — GDPR Art. 6(1)(a) | Providing personal food diary functionality |
| Favourite restaurants | Performance of contract — GDPR Art. 6(1)(b) | Personalized restaurant highlighting |
| Restaurant suggestion | Legitimate interest — GDPR Art. 6(1)(f) | Improving the service based on user feedback |
| Error tracking (Sentry) | Legitimate interest — GDPR Art. 6(1)(f) | Ensuring service functionality, identifying errors |
Where the legal basis for processing is consent, consent may be withdrawn at any time without providing a reason. Withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal.
3. Scope of Processed Data
3.1 Registration and Account Data
| Data | Required | Purpose |
|---|---|---|
| Email address | Yes | Identification, sending login links |
| Username | No | Display name on the interface |
| Registration date | Automatic | Account administration |
3.2 Eating Log Data
The following data is processed when using the eating log feature:
- Date of the meal
- Name of the consumed food (from menu item or custom entry)
- Food category (soup, main course, salad, dessert, other)
- Source of the entry (logging method)
- Timestamp of the entry
Eating log data is visible only to the user. The Data Controller does not share this data with third parties, except for the data processors expressly identified in this policy.
3.3 Favourites and Suggestions
- Favourite restaurants: link between user identifier and restaurant identifier
- Restaurant suggestions: restaurant name, website URL (optional), description (optional), suggestion status
3.4 Login Codes
Signing in uses a six-digit code sent by email. The code itself is not stored — only an irreversible fingerprint of it (HMAC), linked to the user's account, valid for 10 minutes. It becomes invalid after use, after expiry, or after five failed attempts. The same mechanism confirms restaurant listing takeovers, there with a 15-minute validity.
4. Data Retention Periods
| Data | Retention period |
|---|---|
| Registration data (email, name) | Until account deletion |
| Eating log entries | Until account deletion or upon user request |
| Favourite restaurants | Until account deletion |
| Restaurant suggestions | 1 year after review |
| Login and takeover codes (as fingerprints) | 10 and 15 minutes respectively (validity), then periodic cleanup |
| Error tracking data (Sentry) | Per Sentry's retention policy (default 90 days) |
Upon account deletion, all personal data is removed from the database. Deletion does not apply to anonymized statistical data.
5. Data Processors and Third Parties
The Data Controller engages the following data processors to operate the Service:
5.1 Google LLC (Google Gemini AI)
- Purpose: Extracting and processing restaurant menu data from websites, translating menu items
- Data transferred: Restaurant website content, menu item text (not personal data)
- Registered office: 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
- Privacy policy: policies.google.com/privacy
5.2 Google LLC (Google Places API)
- Purpose: Restaurant search and coordinate lookup on the administration interface
- Data transferred: Search text (restaurant name — not personal data)
5.3 Sentry (Functional Software Inc.)
- Purpose: Error tracking and application performance monitoring in production
- Data transferred: Error messages, technical information, IP address (indirectly)
- Registered office: 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA
- Privacy policy: sentry.io/privacy
5.4 SMTP Email Provider
- Purpose: Sending login-code emails, restaurant takeover verification codes and system notifications
- Data transferred: User email address, six-digit login code; for a restaurant takeover, the contact email address published on the restaurant's own website
5.5 Hosting Provider
- Purpose: Operating the Service's servers
- Data transferred: All data stored in the database
- Provider: Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany) — hetzner.com
5.6 OpenStreetMap Foundation
- Purpose: Providing map tile backgrounds for the map feature
- Data transferred: User's IP address (as part of HTTP requests, indirectly)
- Privacy policy: osmfoundation.org
5.7 Stripe Payments Europe, Limited
- Purpose: Processing restaurant subscription payments, billing data and recurring charges
- Data transferred: The subscriber's email address and name, and the identifier of the restaurant the subscription belongs to. Card details never reach the Controller — they are entered directly on the payment page operated by Stripe, and the Service neither sees nor stores them.
- Registered office: 1 Grand Canal Street Lower, Grand Canal Dock, Dublin 2, Ireland
- Privacy policy:stripe.com/privacy
6. Data Transfers to Third Countries
Certain data processors of the Service (Google LLC, Functional Software Inc.) are companies headquartered in the United States. For Stripe, the contracting entity is Stripe Payments Europe, Limited (Ireland), which may also transfer data within its group to Stripe, Inc. (USA). Data transfers from the European Union to the United States are carried out with the following safeguards:
- EU-US Data Privacy Framework: Google LLC and Functional Software Inc. are certified participants of the EU–US Data Privacy Framework, which ensures an adequate level of protection based on the European Commission's adequacy decision.
- Standard Contractual Clauses (SCC): Contracts with data processors include the Standard Contractual Clauses approved by the European Commission.
The Data Controller regularly reviews the safeguards for data transfers to third countries and applies additional measures where necessary.
7. Cookies and Local Storage (localStorage)
The Service does not use traditional cookies. To maintain user sessions, the following data is stored in the browser's local storage (localStorage):
| Key | Content | Purpose |
|---|---|---|
user_token | JWT authentication token | Maintaining user login session |
user_info | User ID, email address, name (JSON) | Quick access to user data on the interface |
admin_token | Admin JWT token (admin users only) | Admin authentication |
This data is automatically deleted upon logout. Users can also delete locally stored data at any time through their browser settings.
Third-party services (Sentry, OpenStreetMap) may use their own cookies and tracking technologies. These are subject to the respective service providers' privacy policies.
8. Browser Geolocation
The map feature may optionally request the user's browser geolocation permission to calculate distances to restaurants. This feature operates according to the following principles:
- Use of geolocation is entirely voluntary and requires browser permission.
- Coordinates are not sent to the server and are not stored in the database.
- Location data exists only temporarily on the client side, in the browser's memory.
- Geolocation data is automatically cleared when the page is closed.
9. Data Security
The Data Controller applies appropriate technical and organizational measures to protect personal data, including:
- JWT token-based authentication with limited validity
- Login codes stored only as fingerprints, with automatic expiry (10–15 minutes) and a capped number of attempts
- Password-protected administration interface
- HTTPS encrypted communication
- Data access restricted to the necessary minimum
- Regular security reviews
10. Rights of Data Subjects
Under the GDPR and Hungarian data protection law, users have the following rights:
10.1 Right of access (GDPR Art. 15)
Users may request information about what personal data the Data Controller processes about them and obtain a copy thereof.
10.2 Right to rectification (GDPR Art. 16)
Users may request the correction of inaccurate personal data or the completion of incomplete data.
10.3 Right to erasure (GDPR Art. 17)
Users may request the deletion of their personal data. Account deletion results in the removal of all associated data (eating log, favourites, suggestions).
10.4 Right to restriction of processing (GDPR Art. 18)
Users may request the restriction of processing under certain conditions.
10.5 Right to data portability (GDPR Art. 20)
Users have the right to receive their personal data in a structured, commonly used, machine-readable format.
10.6 Right to object (GDPR Art. 21)
Users may object to processing based on legitimate interest. In case of objection, the Data Controller will no longer process the data unless there are compelling legitimate grounds for the processing.
10.7 Withdrawal of consent
Where processing is based on consent, the user may withdraw it at any time by contacting [email protected]. Withdrawal does not affect the lawfulness of prior processing.
10.8 Right to lodge a complaint
Users have the right to lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH):
Name: Hungarian National Authority for Data Protection and Freedom of Information
Address: 1055 Budapest, Falk Miksa utca 9-11, Hungary
Website: naih.hu
Email: [email protected]
Users may also seek judicial remedy before the competent court at their place of residence or domicile.
How to exercise your rights
To exercise your rights, please contact us at [email protected]. Requests will be fulfilled within 30 days of receipt. This period may be extended by an additional 60 days if necessary, in which case the user will be informed.
11. Changes to This Policy
The Data Controller reserves the right to unilaterally amend this privacy policy. Users will be informed of changes through the Service's interface and, in case of material changes, via email.
Continued use of the Service constitutes acknowledgement of the amended policy.
This policy takes effect on March 31, 2026.