Privacy Policy
Planning & administration · Legal · 8 min
How Túranavigátor processes personal data obtained through use of the website — what we collect, why we collect it, how long we keep it and what rights you have.
Effective date: 7 September 2026.
This Privacy Policy explains how Berdó Nándor (hereinafter the “Data Controller”) processes personal data obtained through use of the Túranavigátor website available at the turanavigator.hu domain (hereinafter the “Website”).
The Website uses Nawarr Media as its owner and brand designation; its owner website is nawarr.hu. For personal-data processing, the Data Controller is Berdó Nándor.
When processing personal data, the Data Controller acts in accordance with, in particular, Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation, GDPR) and the applicable laws of Hungary.
1. Details of the Data Controller
2. Personal data processed, purposes and legal bases
2.1. Contact enquiries
If a User contacts the Data Controller by email, contact form or another available communication channel, the Data Controller may process the data necessary to respond to the enquiry.
- name,
- email address,
- telephone number, where optionally provided,
- any further personal data voluntarily provided in the enquiry,
- the content of the message and related communications.
Purpose of processing: receiving, identifying and responding to the enquiry and maintaining any necessary communication.
Legal basis: as a general rule, the legitimate interests of the Data Controller under Article 6(1)(f) GDPR. Where the enquiry relates to steps taken at the User’s request prior to entering into a contract, the legal basis is Article 6(1)(b) GDPR.
2.2. Article likes and views
The Website provides view-counter and like functions for articles. These functions do not require registration, and the Data Controller does not directly collect personal data capable of identifying the User in connection with them.
- the aggregated number of views of an article,
- the aggregated number of likes of an article,
- a marker stored locally in the visitor’s browser indicating that the article has already been liked from that device.
Purpose of processing: measuring article popularity, preventing multiple likes from the same device and improving the Website’s content.
Legal basis: the legitimate interests of the Data Controller under Article 6(1)(f) GDPR.
2.3. Newsletter
If the Website offers newsletter subscription, the Data Controller may process data voluntarily provided by the User: name, where required or voluntarily supplied, and email address.
Purpose of processing: sending newsletters, notifications and information related to the Website’s content.
Legal basis: the User’s consent under Article 6(1)(a) GDPR.
Consent may be withdrawn at any time by using the unsubscribe option provided in the newsletter or by sending a request to info@nawarr.hu. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
2.4. Technical, log and security data
During operation of the Website, the web server, hosting provider and security systems may record technical data, including in particular:
- IP address,
- date and time of the request and visit,
- the page or resource accessed,
- technical browser and device data,
- technical information relating to the operating system,
- referring page,
- log data relating to errors, misuse and security incidents.
Purpose of processing: ensuring operation of the Website, identifying faults, maintaining IT security, preventing unauthorised use and attacks and, where necessary, investigating them.
Legal basis: the legitimate interests of the Data Controller under Article 6(1)(f) GDPR.
2.5. Statistical and analytical processing
Analytical technologies may be used to analyse visits to and use of the Website. Where a particular technology involves the processing of personal data or storage on, or access to, the User’s device that requires consent, such processing may take place only after the required consent has been given.
A detailed description of analytical services and technologies used on the Website is available in the Cookie Policy.
2.6. Cookies and similar technologies
The Website may use cookies and other similar technologies. Technologies strictly necessary for the basic operation of the Website are handled separately from statistical, functional or marketing technologies that require consent.
Cookies and similar technologies requiring consent may be activated only after the User has given appropriate prior consent. The User may subsequently change or withdraw consent through the Website’s cookie settings.
The names, purposes, providers and storage periods of cookies are set out in the separate Cookie Policy.
3. Retention periods
3.1. Contact enquiries
Data relating to contact enquiries are processed for as long as necessary to respond to and close the enquiry. Where retention is justified for the establishment, exercise or defence of legal claims, the data may be retained for the period necessary for that purpose.
3.2. Likes and views
Aggregated view and like counts relating to articles are processed for as long as the article remains published. The like marker stored on the visitor’s device remains in the browser’s local storage until the visitor deletes it.
3.3. Newsletter
Personal data relating to the newsletter are processed until consent is withdrawn or the User unsubscribes, unless further retention of particular data is required by law or justified for the exercise of legal claims.
3.4. Technical and security data
Technical and security log data are processed by the Data Controller or its service provider for as long as necessary to fulfil operational, troubleshooting and security purposes. In the event of a security incident, relevant log data may be retained until the investigation of the incident and the handling of any related legal claims have been completed.
3.5. Cookies
The storage periods of individual cookies and similar technologies are set out in the separate Cookie Policy.
4. Processors, recipients and data transfers
The Data Controller may use external service providers to operate the Website. Depending on the nature of their services, these providers may act as processors, independent controllers or other recipients.
Categories of recipients may include in particular:
- hosting and infrastructure providers,
- email and communication service providers,
- website security and technical service providers,
- analytics and statistical service providers,
- consent-management and cookie-management services,
- marketing and advertising service providers, where their use is permitted.
If a service provider transfers personal data to a country outside the European Economic Area, the transfer may take place only where an appropriate legal basis and safeguards under Chapter V GDPR are in place.
The Data Controller may disclose personal data to an authority, court or other authorised body where required by law or by a binding order of an authority or court.
5. Processing based on legitimate interests
Where processing is based on legitimate interests, before commencing such processing the Data Controller weighs its legitimate interest, the necessity of the processing and the interests, fundamental rights and freedoms of the data subject.
The User has the right, on grounds relating to their particular situation, to object at any time to processing based on Article 6(1)(f) GDPR.
6. Users’ rights
Subject to the conditions of the GDPR, Users have in particular the following rights:
- the right to information and access,
- the right to rectification,
- the right to erasure,
- the right to restriction of processing,
- the right to data portability where the relevant conditions apply,
- the right to object where processing is based on legitimate interests,
- the right to withdraw consent at any time where processing is based on consent,
- the right to lodge a complaint with a supervisory authority,
- the right to a judicial remedy.
Requests relating to data processing may be submitted by email to info@nawarr.hu.
7. Complaint to the supervisory authority
If a User considers that the processing of their personal data infringes the GDPR or other applicable data-protection legislation, they may lodge a complaint with the National Authority for Data Protection and Freedom of Information.
8. Data security
The Data Controller applies technical and organisational measures appropriate to the nature of the processing in order to protect the security of personal data, in particular to reduce the risk of unauthorised access, disclosure, alteration, loss, destruction or other unlawful processing.
9. Automated decision-making
In operating the Website, the Data Controller does not use decision-making based solely on automated processing that would produce legal effects concerning the User or similarly significantly affect the User.
10. Amendments to this Privacy Policy
The Data Controller may amend this Privacy Policy where necessary, in particular following changes in legislation, changes to the operation of the Website, the introduction of a new service or changes to data-processing activities.
The version currently in force is published on the Website. Where a material change substantially affects Users, the Data Controller will provide appropriate information about the amendment.