Magyar · English · Deutsch · Español · Italiano · Ελληνικά

AT (AnywhereTransit) Rider App — Privacy Policy

Effective: 18 August 2026 · Version: 1.0

Courtesy translation. This English text is provided for convenience only; in all legal matters the Hungarian original is authoritative.

This policy provides the information required by Articles 13–14 of the

GDPR (Regulation (EU) 2016/679) about the data processing connected to

the use of the AT Rider App. The App Store "Privacy Nutrition Label" and

the Google Play "Data safety" form supplement, but do not replace, this

policy.

1. Data controller

Field Value
Company name FESZTIZ Korlátolt Felelősségű Társaság (FESZTIZ Kft.)
Registered office 6635 Szegvár, Iskola utca 41., Hungary
Contact (privacy matters) info@anywheretransit.com
Data protection officer Not designated — the obligation under Article 37 GDPR does not apply to the Service Provider

2. What data we process, for what purpose and on what legal basis

Data category Purpose Legal basis (Art. 6 GDPR) Retention
Account data (e-mail address, name/nickname, password hash) Registration, login (1)(b) performance of a contract Until the account is deleted
Device/push token Notifications (departure reminders, announcements) (1)(a) consent (by enabling notifications) Until consent is withdrawn or the account is deleted
Favourite stops/routes/trips User experience (1)(f) legitimate interest Until the account is deleted
Booking data (service, time, passenger name) Fulfilment of the transfer booking (1)(b) performance of a contract Until the account is deleted; accounting records for 8 years under Act C of 2000 on accounting
Ticket purchase and payment transaction data (without card data) Ticket sales, invoicing (1)(b) performance of a contract, (1)(c) legal obligation Accounting records for 8 years
Problem report/support message Customer support (1)(f) legitimate interest 1 year from closure

Important technical clarification: the Rider App **does not send its

own GPS position to the server.** Location is used exclusively on the

device, locally (list of nearby stops, map centring, in-app navigation);

the displayed live vehicle positions are only received — they are

provided by the driver application, which is a separate processing

context.

3. Who we share the data with

process the payment, under Barion's own privacy policy. The AT

platform never sees card data.

within the EU; the data is stored within the EU.

ticket purchase, the minimum data needed for fulfilment (e.g. the

passenger's name, the booked service).

data processors; the transfer takes place on the basis of their

certification under the EU–US Data Privacy Framework and the standard

contractual clauses (SCC) of the European Commission.

4. Your rights

Under the GDPR you have the right to:

format),

of processing carried out before the withdrawal),

Protection and Freedom of Information** (NAIH — 1055 Budapest, Falk

Miksa utca 9–11.; postal address: 1363 Budapest, Pf. 9.;

ugyfelszolgalat@naih.hu; +36 1 391 1400) or turn to a court.

To exercise these rights: info@anywheretransit.com. Account deletion can

also be initiated from the application (Account → Delete account) — this

starts the deletion process; records subject to statutory retention

(invoices) are kept, separated from the account, until the end of the

retention period.

5. Automated decision-making

The service does not use solely automated decision-making within the

meaning of Article 22 GDPR that would produce legal effects concerning

the data subject.

6. Data security

Passwords are never stored in readable form — we use the built-in,

iterated, salted hashing of ASP.NET Core Identity. All network traffic

is TLS-encrypted. Login uses a short-lived access token and a separate

refresh token; the refresh token is rotated on every use, so a stolen,

already-used token cannot be reused. After repeated failed login

attempts the account is temporarily locked. In the event of a personal

data breach the Service Provider acts in accordance with Articles 33–34

GDPR: it reports the breach to the NAIH without undue delay, where

feasible within 72 hours, and — if the breach is likely to result in a

high risk — also informs the data subjects.

7. Children's data

The service is not directed at persons under 16; we process the data of

a data subject under 16 only with the consent of their legal guardian.

If we become aware that we process a minor's data without such consent,

we delete it.

8. Changes to this policy

We may update this policy from time to time; we notify you of material

changes within the application.


*Related documents: Terms and Conditions · Cookie Policy · Accessibility Statement*