Privacy policy

Privacy policy

Effective date: 2026-09-09 Last updated: 9 September 2026

1. Controller and contact

The operator of the Supermarket POS official website (supermarkets.cpos.hu) and the controller for the processing described here — as well as public contact channels — are those stated on the current About us page. The operator / controller identity and company register details are authoritative there; this page deliberately does not repeat the company name, registered office, registration number, tax number, phone numbers, or email addresses. Please use the About us channels for privacy requests and rights exercises as well. If About us changes, that page prevails.

A Data Protection Officer (DPO) or EU representative is not separately named at present; we do not list unverified roles on this page.

2. Scope of this policy

This notice covers:

  1. Official website — visiting public pages under supermarkets.cpos.hu.
  2. Software (Supermarket POS) — the application installed or used in a hospitality venue, where processing relates to our role (see sections 3–4). Business / sales data in the software stay, by default, where you choose to deploy (local machine or a cloud server), as also described on the homepage.
  3. Plugins / third parties — services from the plugin marketplace under separate terms follow their own privacy notices and agreements; they do not replace this policy, and this policy does not replace them.

Out of scope: NTAK, e-receipt, invoicing or other authority / mandatory systems’ own processing (see the FAQ and official guidance).

3. Types of data and sources

3.1 Website visitors

The site currently has no contact form and no newsletter signup. We therefore do not ask you on the website for a name, email address or similar data you would fill in yourself.

Hosting / server environments may record technical logs (for example IP address, timestamp, requested URL, browser type) as a normal part of keeping the service secure. Exact scope and retention follow hosting practice; the precise number of days is set by operations.

Web analytics tools (visitor-tracking scripts) are not configured at present. If we introduce such a tool later, we will update this page before or as it goes live.

3.2 Software users / business data

Business data held in Supermarket POS (for example sales, inventory, local login accounts on the installed instance) remain according to your deployment choice:

  • on a local machine, or
  • on a cloud / remote server you choose.

Who can access that data in your environment is determined by your installation and access rights. This policy does not claim that all software data automatically flows into our cloud; nor does it claim that no technical data can ever be processed during support or a chosen cloud operation. Exact controller / processor roles depend on the concrete deployment and any cloud service agreement.

3.3 Direct contact

If you contact us via the channels on About us (phone, email), we process the data you provide in order to reply and handle the matter.

4. Purposes and legal bases

| Purpose | Typical data | Legal basis (GDPR) | | --- | --- | --- | | Displaying the site and keeping it securely running | Technical logs / necessary cookies | Legitimate interests (Art. 6 (1) f) — stable, secure service) and/or steps prior to a contract if you enquire | | Answering your enquiry | Contact and matter data you send | Legitimate interests or steps toward a contract (Art. 6 (1) f / b) | | Analytics / marketing measurement on the site | — | Not carried out at present (no analytics tool configured) | | Storing software business data in the chosen environment | Business / sales data on the deployed instance | Depends on your role as operator / customer; on our side typically performance of a contract or processing on your instructions — set out in the relevant agreements |

5. Retention

  • Website technical logs: retained under hosting / operations practice for as long as needed for security and troubleshooting; the exact number of days is determined by operations.
  • Enquiries: until the matter is closed, and for any statutory limitation / accounting period that applies.
  • Software business data: set in your deployment environment by you (or by the contractual framework of a chosen cloud provider); the website alone does not set a shop’s business-data retention policy.

When the purpose ends, we delete or anonymise the data unless law requires longer retention.

6. Recipients and transfers

  • Hosting / infrastructure providers — to the extent needed to run the site (as processors).
  • Authorities — only where legally required.
  • Plugin providers — only if you use such a service; their notices then also apply.

International transfers outside the EEA: based on the currently known operating picture, we do not advertise active marketing-oriented transfers to third countries. If hosting or a future analytics tool involves such a transfer, we will apply appropriate safeguards (e.g. adequacy decision / standard contractual clauses) and update this notice.

7. Cookies and similar technologies

We may use cookies or similar technologies (local storage, session identifiers, etc.) as needed to run the site — for example to keep a language preference or a session.

  • Necessary / functional: may support page display and basic features.
  • Analytics / marketing cookies: not configured at present.

We do not claim that we “never track” or that “no technical data is created”: technical logs and necessary cookies can be part of operating the site. You can restrict cookies in your browser; some features may then work less well.

The short footer / banner text comes from the brand cookie_note field; this section is the detailed explanation.

8. Your rights and complaints

Subject to GDPR and Hungarian law, you may request:

  • information and access,
  • rectification,
  • erasure (“right to be forgotten”),
  • restriction of processing,
  • data portability (where applicable),
  • objection where processing is based on legitimate interests.

Send requests via the channels on About us. Statutory response deadlines apply.

You may also lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH): https://www.naih.hu · 1055 Budapest, Falk Miksa utca 9-11. · ugyfelszolgalat@naih.hu

9. Changes

We update this notice when needed (for example a new analytics tool, a new form, or a changed deployment model). The updated version applies from the publication date; material changes will be indicated on the site.