Magyar · English · Deutsch · Español · Italiano · Ελληνικά
AT (AnywhereTransit) Rider App — Privacy Policy
Effective: 18 August 2026 · Version: 1.0
Courtesy translation. This English text is provided for convenience only; in all legal matters the Hungarian original is authoritative.
This policy provides the information required by Articles 13–14 of the
GDPR (Regulation (EU) 2016/679) about the data processing connected to
the use of the AT Rider App. The App Store "Privacy Nutrition Label" and
the Google Play "Data safety" form supplement, but do not replace, this
policy.
1. Data controller
| Field | Value |
|---|---|
| Company name | FESZTIZ Korlátolt Felelősségű Társaság (FESZTIZ Kft.) |
| Registered office | 6635 Szegvár, Iskola utca 41., Hungary |
| Contact (privacy matters) | info@anywheretransit.com |
| Data protection officer | Not designated — the obligation under Article 37 GDPR does not apply to the Service Provider |
2. What data we process, for what purpose and on what legal basis
| Data category | Purpose | Legal basis (Art. 6 GDPR) | Retention |
|---|---|---|---|
| Account data (e-mail address, name/nickname, password hash) | Registration, login | (1)(b) performance of a contract | Until the account is deleted |
| Device/push token | Notifications (departure reminders, announcements) | (1)(a) consent (by enabling notifications) | Until consent is withdrawn or the account is deleted |
| Favourite stops/routes/trips | User experience | (1)(f) legitimate interest | Until the account is deleted |
| Booking data (service, time, passenger name) | Fulfilment of the transfer booking | (1)(b) performance of a contract | Until the account is deleted; accounting records for 8 years under Act C of 2000 on accounting |
| Ticket purchase and payment transaction data (without card data) | Ticket sales, invoicing | (1)(b) performance of a contract, (1)(c) legal obligation | Accounting records for 8 years |
| Problem report/support message | Customer support | (1)(f) legitimate interest | 1 year from closure |
Important technical clarification: the Rider App **does not send its
own GPS position to the server.** Location is used exclusively on the
device, locally (list of nearby stops, map centring, in-app navigation);
the displayed live vehicle positions are only received — they are
provided by the driver application, which is a separate processing
context.
3. Who we share the data with
- Barion Payment Zrt. (payment provider) — the data necessary to
process the payment, under Barion's own privacy policy. The AT
platform never sees card data.
- Hosting/server provider — the platform infrastructure operates
within the EU; the data is stored within the EU.
- The Operator performing the carriage — in the case of a booking or
ticket purchase, the minimum data needed for fulfilment (e.g. the
passenger's name, the booked service).
- Apple (APNs) and Google (FCM) — they deliver push notifications as
data processors; the transfer takes place on the basis of their
certification under the EU–US Data Privacy Framework and the standard
contractual clauses (SCC) of the European Commission.
- In case of an official request, to the extent required by law.
4. Your rights
Under the GDPR you have the right to:
- access the data processed about you,
- request rectification of inaccurate data,
- request erasure ("right to be forgotten"),
- request restriction of processing,
- object to processing based on legitimate interest,
- request data portability (in a structured, machine-readable
format),
- withdraw consent at any time (this does not affect the lawfulness
of processing carried out before the withdrawal),
- lodge a complaint with the **Hungarian National Authority for Data
Protection and Freedom of Information** (NAIH — 1055 Budapest, Falk
Miksa utca 9–11.; postal address: 1363 Budapest, Pf. 9.;
ugyfelszolgalat@naih.hu; +36 1 391 1400) or turn to a court.
To exercise these rights: info@anywheretransit.com. Account deletion can
also be initiated from the application (Account → Delete account) — this
starts the deletion process; records subject to statutory retention
(invoices) are kept, separated from the account, until the end of the
retention period.
5. Automated decision-making
The service does not use solely automated decision-making within the
meaning of Article 22 GDPR that would produce legal effects concerning
the data subject.
6. Data security
Passwords are never stored in readable form — we use the built-in,
iterated, salted hashing of ASP.NET Core Identity. All network traffic
is TLS-encrypted. Login uses a short-lived access token and a separate
refresh token; the refresh token is rotated on every use, so a stolen,
already-used token cannot be reused. After repeated failed login
attempts the account is temporarily locked. In the event of a personal
data breach the Service Provider acts in accordance with Articles 33–34
GDPR: it reports the breach to the NAIH without undue delay, where
feasible within 72 hours, and — if the breach is likely to result in a
high risk — also informs the data subjects.
7. Children's data
The service is not directed at persons under 16; we process the data of
a data subject under 16 only with the consent of their legal guardian.
If we become aware that we process a minor's data without such consent,
we delete it.
8. Changes to this policy
We may update this policy from time to time; we notify you of material
changes within the application.
*Related documents: Terms and Conditions · Cookie Policy · Accessibility Statement*