PRIVACY NOTICE
ON THE PROCESSING OF PERSONAL DATA IN CONNECTION WITH THE MY EBIKE ELECTRIC BICYCLE RENTAL SERVICE
(effective from: 1 July 2026)
PRIVACY NOTICE
ON THE PROCESSING OF PERSONAL DATA IN CONNECTION WITH THE MY EBIKE ELECTRIC BICYCLE RENTAL SERVICE
(effective from: 1 July 2026)
PRIVACY NOTICE
ON THE PROCESSING OF PERSONAL DATA IN CONNECTION WITH THE MY EBIKE ELECTRIC BICYCLE RENTAL SERVICE
(effective from: 1 July 2026)
|
DATA CONTROLLER |
||
|
NAME |
Szikla Krisztina, sole proprietor |
|
|
REGISTRATION NUMBER |
62512101 |
|
|
REGISTERED OFFICE / MAILING ADRESS |
8798 Zalabér, Zala út 25., Hungary |
|
|
REPRESENTATIVE |
Szikla Krisztina |
|
|
CONTACT |
e-mail: info@myebike.hu telefon: +36 20 408 9471 |
|
|
DATA PROTECTION OFFICER |
The controller has not appointed a data protection officer | |
(hereinafter collectively: "Controller")
|
DATA CONTROLLER |
||
|
NAME |
Szikla Krisztina, sole proprietor |
|
|
REGISTRATION NUMBER |
62512101 |
|
|
REGISTERED OFFICE / MAILING ADRESS |
8798 Zalabér, Zala út 25., Hungary |
|
|
REPRESENTATIVE |
Szikla Krisztina |
|
|
CONTACT |
e-mail: info@myebike.hu telefon: +36 20 408 9471 |
|
|
DATA PROTECTION OFFICER |
The controller has not appointed a data protection officer |
|
(hereinafter collectively: "Controller")
| DATA CONTROLLER | ||
|
NAME |
Szikla Krisztina, sole proprietor |
|
|
REGISTRATION NUMBER |
62512101 |
|
|
REGISTERED OFFICE / MAILING ADRESS |
8798 Zalabér, Zala út 25., Hungary |
|
|
REPRESENTATIVE |
Szikla Krisztina |
|
|
CONTACT |
e-mail: info@myebike.hu telefon: +36 20 408 9471 |
|
|
DATA PROTECTION OFFICER |
The controller has not appointed a data protection officer | |
(hereinafter collectively: "Controller")
|
DATA CONTROLLER |
||
|
NAME |
Szikla Krisztina, sole proprietor |
|
|
REGISTRATION NUMBER |
62512101 |
|
|
REGISTERED OFFICE / MAILING ADRESS |
8798 Zalabér, Zala út 25., Hungary |
|
|
REPRESENTATIVE |
Szikla Krisztina |
|
|
CONTACT |
e-mail: info@myebike.hu telefon: +36 20 408 9471 |
|
|
DATA PROTECTION OFFICER |
The controller has not appointed a data protection officer |
|
(hereinafter collectively: "Controller")
II. INTRODUCTION AND DEFINITIONS
The purpose of this Privacy Notice (hereinafter: “Notice”) is to enable the Controller, in fulfilment of its information obligations under Articles 13 and 14 of the GDPR, to provide data subjects with concise, transparent and intelligible information on its processing activities, in particular the purposes and legal bases of processing, retention periods, categories of personal data processed, recipients of the data, and the rights and remedies available to data subjects.
For the purposes of this Notice:
• “personal data” means any information relating to an identified or identifiable natural person;
• “data subject” means the natural person whose personal data are processed by the Controller;
• “processing” means any operation performed on personal data, including in particular collection, recording, storage, use, transmission or erasure;
• “controller” means the person or organisation that determines the purposes and means of processing;
• “processor” means the person or organisation that processes personal data on behalf of the Controller;
• “recipient” means the person or organisation to whom personal data are disclosed.
This Notice applies in particular to persons interested in the My eBike electric bicycle rental service, renters using the service (hereinafter: “Renter”), actual users designated by the Renter (hereinafter: “User”), and persons submitting complaints or enquiries. The material scope of this Notice covers processing activities connected with the electric bicycle rental service provided under the My eBike brand, the booking and prior consultation process, the Rental Agreement, handover and return, damage and complaint handling, and cooperation with Partners.
IV. APPLICABLE LEGISLATION
The Controller declares that it carries out its processing activities in compliance with the applicable data protection rules at all times, in particular:
• Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: “GDPR”);
• Act V of 2013 on the Civil Code (hereinafter: “Civil Code”);
• Act CL of 2017 on the Rules of Taxation (hereinafter: “Taxation Act”);
• Act CXXVII of 2007 on Value Added Tax (hereinafter: “VAT Act”);
• Act CLV of 1997 on Consumer Protection (hereinafter: “Consumer Protection Act”).
Within this Notice, the Controller provides information on the processing of your personal data broken down by processing activity. Data marked with an asterisk (*) are mandatory; all other data are optional. If mandatory data are not provided, the Controller may be unable to provide the service or may only be able to provide it with inadequate content.
|
PROCESSING ACTIVITY |
PURPOSE |
DATA PROCESSED |
LEGAL BASIS |
RETENTION |
RECIPIENTS |
|
Preliminary enquiry, booking and quotation |
Receiving rental requests, prior consultation, preparing quotations, recording and confirming bookings. |
Name* (identification); |
Art. 6(1)(b) GDPR – steps taken at the Renter’s request prior to entering into a Rental Agreement. |
If a contract is concluded: according to the retention period applicable to the Rental Agreement; if no contract is concluded: 1 year from closure of the quotation/booking. |
Processors under Section VII, in particular hosting provider and document-storage provider. |
|
Conclusion and performance of the Rental Agreement |
Conclusion and performance of the electric bicycle rental agreement; identification of the Parties; contact; fulfilment of rights and obligations arising from the Rental Agreement. |
Name*, birth name, place and date of birth*, mother’s name*, address*, telephone number*, e-mail address*; identifiers of Bicycle and Accessories*; rental period and locations*; fact that a photo ID was presented*; rental fee, deposit, delivery/return fee, payment method*; Renter’s signature*; in case of assistance/technical rescue, GPS coordinates. |
Art. 6(1)(b) GDPR – performance of the Rental Agreement. |
5 years from termination of the Rental Agreement; for data appearing on accounting documents, until expiry of the right to assess tax. For rescue/assistance, GPS data are retained for the period applicable to GPS processing. |
Processors under Section VII, in particular hosting and document-storage providers. |
|
Documentation of handover and return |
Recording the condition of the Bicycle and Accessories, evidencing performance of the rental and supporting settlement of the deposit. |
Date of Rental Agreement*, Renter’s name*, Users’ names and ages (identification of actual user and verification of age conditions), rental period*, Bicycle and Accessory identifiers*, date/time, place and condition data at handover/return, deposit settlement data, signatures of Renter and Lessor*. |
Art. 6(1)(b) GDPR – performance of the Rental Agreement. For User data: Art. 6(1)(f) GDPR – legitimate interest of the Controller: identifying persons authorised to use the Bicycle and enforcing the rules of use. |
5 years from termination of the Rental Agreement. |
Processors under Section VII, in particular hosting and document-storage providers. |
|
GPS tracking |
Protection of the Bicycle as an asset, management of late return, and assisting in locating a lost or stolen Bicycle. |
Bicycle identifier*, GPS-device identifier, current or last known geographical position, time of positioning, Bicycle speed data, alert-event data. |
Art. 6(1)(f) GDPR – legitimate interest of the Controller: protection of the high-value Bicycle, locating it in the event of theft, loss or failure to return, and protection of the Controller’s financial interests. |
72 hours after closure of the rental; 30 days in backups for system-recovery purposes; in the event of damage, delay or legal dispute, for as long as necessary to enforce claims, but no longer than 5 years. |
Processors under Section VII, in particular hosting and VPS providers. Other recipients: competent authority, police. |
|
Payment, fees and deposit management |
Recording rental fees, deposits and other charges, settlement of the deposit and financial accounting. |
Renter’s name*; amount and legal title of charges*; payment method*; fact, date/time and amount of payment; transaction or bank identifier; confirmation of payment success; data on payment, deduction and refund of deposit; reason for deduction. |
Art. 6(1)(b) GDPR – performance of the Rental Agreement. |
5 years from termination of the Rental Agreement; for data on accounting documents, until expiry of the right to assess tax. |
Processors under Section VII, especially online invoicing and document-storage providers. Other recipient: Worldline Financial Services (Europe) S.A.; its Hungarian intermediary and processor BizWorks Kft. (BizPay), for card-terminal payments. |
|
Invoicing |
Issuing invoices and retaining accounting documents. |
Billing name*, billing address*, tax number; invoice items and amount, date of performance, payment method; billing e-mail address if the invoice is sent electronically. |
Art. 6(1)(c) GDPR – legal obligation (Section 179 of the VAT Act and Sections 77–78 of the Taxation Act). |
Until expiry of the right to assess tax, pursuant to Sections 78(3) and 202 of the Taxation Act. |
Processors under Section VII: hosting, document-storage and online invoicing providers. Other recipients: Hungarian National Tax and Customs Administration (NAV), accountant [Fehér Anita, 8900 Zalaegerszeg, Vörösmarty Mihály u. 22., feheranita0831@t-online.hu]. |
|
Handling damage, malfunction, accident and theft |
Documenting incidents, preliminary and final assessment of loss, settlement of deposit, enforcement of legal claims. |
Date of Rental Agreement*, Renter’s name*, name and signature of affected adult User, rental period*, date/time of damage report*, Bicycle and affected Accessory identifiers*, date/time, place and nature of incident, description of damage/missing item/fault, Renter/User statement, related evidence and reports, service/quotation data, damage assessment, cost and deposit settlement data. |
Art. 6(1)(f) GDPR – legitimate interest: documenting damage, settling deposit and damage claims, asserting, enforcing and defending legal claims. For any health data arising: Art. 9(2)(f) GDPR – establishment, exercise or defence of legal claims. |
5 years from closure of the incident or due date of the claim; in authority or court proceedings, until the end of the limitation period following final closure. |
Processors under Section VII: hosting and document-storage providers. Other recipients: insurer, repair service, expert, competent authorities. |
|
Enforcement of legal claims |
Establishment, exercise or defence of legal claims and participation in authority, court, notarial, enforcement and other legal proceedings. |
Identification, address and contact data; contractual, financial, complaint, damage and other case data relating to the matter; statements, evidence and procedural documents. |
Art. 6(1)(f) GDPR – legitimate interest: establishment, exercise or defence of the Controller’s legal claims and evidencing its position in proceedings. |
5 years from closure of the case/proceedings; if proceedings are pending, until the end of the limitation period following final closure. |
Other recipients: lawyer, legal adviser, competent authorities, conciliation body, notary, court, bailiff, expert and persons participating in the dispute/proceedings. |
|
Complaint handling |
Investigating, answering and recording consumer complaints. |
Name*; contact details*; content of complaint*; attachments; dates of submission and response*; minutes/record data*. |
Art. 6(1)(c) GDPR – legal obligation (Section 17/A of the Consumer Protection Act). |
Copy of the record and response: 3 years (Section 17/A(7) of the Consumer Protection Act). |
Processors under Section VII, especially hosting and document-storage providers. Other recipient: consumer-protection authority. |
|
Partner commission settlement and tracking rentals |
Identifying rentals generated through a Partner recommendation; calculating, settling and paying Partner commission. |
Name or identifier of referred/forwarded Renter, rental date and performance data, basic bicycle-rental fee, commission base, commission rate and amount, payment, invoice/document and transfer data. |
Art. 6(1)(f) GDPR – legitimate interests of the Controller and third party (Partner): performance of the cooperation agreement with the Partner and proof of the legal basis and amount of commission. |
Commission-settlement and contractual data: 5 years from termination of the business relationship; invoice data: until expiry of the right to assess tax. |
Processors under Section VII, especially hosting and document-storage providers. Other recipient: Partner as independent controller. |
|
Handling data-subject rights |
Receiving, identifying, fulfilling and evidencing requests under the GDPR. |
Identification data, contact details, content of request, attachments, time/place/method of submission. |
Art. 6(1)(c) GDPR – legal obligation under Chapter III GDPR. |
Until expiry of the limitation period relating to the request; generally no longer than 5 years. |
Processors under Section VII, especially hosting and document-storage providers. |
Data sources: As a rule, the Controller collects personal data directly from the data subject (e.g. during enquiries, booking, contracting, handover/return, contact, complaint or damage handling). In certain cases data may originate from other sources: a Partner may, as an independent controller and at the data subject’s request, forward the interested person’s name and contact details; Partner contact-person and representative data may come from the Partner or public/authentic registers; payment and invoicing data may also come from the payment provider, bank, online invoicing provider or accountant; data connected with damage and legal claims may come from another affected party, repair service, expert, authority, court or public/authentic database.
Automated decision-making and profiling: The Controller does not carry out automated decision-making or profiling within the meaning of Article 22 GDPR that produces legal effects concerning the data subject or similarly significantly affects the data subject.
Detailed list of recipients: Processors are listed in Section VII. The Controller may also engage an IT contractor for operation, maintenance and security updates of the VPS and Traccar system. The Controller uses only processors providing sufficient guarantees for secure and lawful processing. Where necessary for contract performance, compliance with a legal obligation, the data subject’s consent or pursuit of the Controller’s legitimate interests, personal data may also be transferred to independent controllers, in particular Partners, payment providers, banks, insurers, accountants, NAV, repair services, distributors, experts, police, authorities, conciliation bodies, lawyers, legal advisers, courts, notaries and bailiffs.
Transfers to third countries: As a rule, the Controller does not transfer personal data to a third country or international organisation and primarily uses services operating within the European Economic Area. Transfers or access outside the EEA may nevertheless occur in the service chain of certain providers or sub-processors. In such cases transfers may take place only under the conditions and with the appropriate safeguards required by Chapter V GDPR. Information on the safeguards used may be requested from the Controller.
VI. DATA SECURITY
(1) The Controller takes all measures reasonably expected of it to ensure the security of personal data and an appropriate level of protection, in particular against unauthorised access, alteration, transmission, disclosure, erasure, destruction, accidental destruction or damage, and unavailability resulting from changes in technology.
(2) The Controller requires employees, staff and contractors with access to personal data to observe confidentiality obligations. Access to personal data is restricted through permission levels.
(3) To protect personal data stored on computers or networks, the Controller monitors incoming and outgoing electronic communications and protects IT systems with passwords, firewalls and antivirus protection.
(4) Paper-based personal data are kept in locked cabinets and are destroyed using a document shredder or a specialised document-destruction provider.
VII. PROCESSORS
(1) For professional processing of personal data, the Controller may engage processor companies under a separate contract or unilateral undertaking. Processors perform technical operations related to processing in accordance with the Controller’s instructions and decisions. They may not make independent decisions and may act only in accordance with the data-processing agreement and the Controller’s instructions.
(2) The processors having a contractual relationship with the Controller and the processing activities performed by them are listed below.
LIST OF PROCESSORS
|
NAME |
REGISTERED OFFICE |
PROCESSING ACTIVITY |
CONTACT |
|
Microsoft Ireland Operations Limited |
One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland |
Document-storage provider: Microsoft OneDrive service; storage of electronic documents |
Microsoft privacy statement / contact page |
|
Tárhely.Eu Szolgáltató Kft. |
1097 Budapest, Könyves Kálmán körút 12-14., Hungary |
Hosting provider: web hosting, e-mail accounts, webmail and related electronic data-storage services |
support@tarhely.eu |
|
Aruba S.p.A. |
Via San Clemente 53, 24036 Ponte San Pietro, Italy |
VPS provider: virtual server and infrastructure; storage of data of the Traccar GPS tracking system |
privacy@staff.aruba.it; dpo@staff.aruba.it |
|
KBOSS.hu Kft. (szamlazz.hu) |
1031 Budapest, Záhony u. 7., Hungary |
Online invoicing provider: invoicing service for issuing legally compliant invoices by electronic means |
info@szamlazz.hu |
The natural person concerned by processing has the following rights under the GDPR, exercisable using the Controller’s contact details in Section I. The Controller responds substantively to requests concerning processing within one month of receipt – or within two months in exceptionally complex cases – provided the applicant has supplied suitable contact details.
(1) Right of access: the data subject may obtain information on what data the Controller processes, on what legal basis, for what purpose and for how long; to whom and when access was provided or data were transferred and on what legal basis; the source of the data; and whether automated decision-making, including profiling, is used. To ensure data security and protect rights, the Controller must verify that the requester is the data subject. A first copy of the personal data undergoing processing is provided free of charge; for further copies a reasonable fee based on administrative costs may be charged.
(2) Right to rectification: the data subject may request without undue delay the rectification of inaccurate personal data and completion of incomplete data, including by supplementary statement, provided the request does not seek to alter another person’s statement or objectively recorded data (e.g. biological or physical characteristics, image, etc.).
(3) Right to erasure (‘right to be forgotten’): where the conditions apply, the data subject may request erasure without undue delay, in particular where the data are no longer necessary for the purpose collected, consent is withdrawn and no other legal basis exists, processing was unlawful, the data subject successfully objects, or erasure is required by law. The Controller may exceptionally refuse erasure, in particular where processing is necessary for the establishment, exercise or defence of legal claims.
(4) Right to restriction of processing: restriction may be requested where the accuracy of data is contested (for the verification period); processing is unlawful but erasure is opposed; the Controller no longer needs the data but the data subject requires them for legal claims; or the data subject has objected (pending verification whether the Controller’s legitimate grounds override those of the data subject). The Controller informs the data subject before restriction is lifted.
(5) Right to data portability: where processing is based on consent or contract and is carried out by automated means, the data subject may receive personal data concerning them in electronic form and request transmission to another controller. Exercise of this right may not adversely affect the rights and freedoms of others.
(6) Right to object: the data subject may, on grounds relating to their particular situation, object at any time to processing based on Art. 6(1)(f) GDPR, including related profiling. The Controller must then cease processing unless it demonstrates compelling legitimate grounds overriding the data subject’s interests, rights and freedoms, or grounds connected with the establishment, exercise or defence of legal claims.
If the data subject considers processing unlawful, they may first contact the Controller using the contact details above, or seek a remedy from the competent bodies as follows:
• lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság – NAIH), address: 1055 Budapest, Falk Miksa utca 9-11.; website: www.naih.hu; e-mail: ugyfelszolgalat@naih.hu; phone: +36 (1) 391-1400; or
• bring proceedings before the competent court according to their residence or place of stay; the court proceeds as a matter of priority. The competent regional court can be identified through the Hungarian Courts’ court-finder service.
My eBike
MY EBIKE – ÁLTALÁNOS SZERZŐDÉSI FELTÉTELEK / BÉRLETI FELTÉTELEK
elektromos kerékpárok bérbeadásához
Hatályos: 2026.07.01. napjától