Time lock
Restart
Last modified: 2026-03-31.

Definitions and description of the service

The operator (further information: imprint and contact menu items) operates scifihir.hu (hereinafter: website), which allows registered users (hereinafter: users) to share comments on articles and positive or negative ratings on articles with each other and with visitors to the website (hereinafter: visitor), and also to correspond with each other through an internal messaging system. Use of the website is governed jointly by this privacy policy and the terms of use (hereinafter: policy).


In brief, summarized

We process and collect personal data only in accordance with the law. We request only the minimum necessary data! We do not send DM or marketing emails. We send system messages only.


Purpose of data processing

To enable the services used by the website's users in accordance with Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information and Regulation (EU) 2016/679 of the European Parliament and of the Council on the General Data Protection Regulation (GDPR).


Legal basis for data processing

The user has given consent for their personal data to be processed for a specific purpose. (use of the website's services)
The user is in a customer relationship with the operator and:


Data controller details

Detailed information: imprint and contact menu items.


Data processing overview

The user consents to the operator making the data they provide available:

to other users, and further consents to visitors also having access to content other than messages.

In addition to the data provided by the user, the operator stores the following data about users:

The operator stores data relating to user activity for 30 days from the time of the activity. The purpose of logging is to investigate the causes of errors that may arise during use of the website and to support development.


Deletion of user profile

It can be initiated simply (in the settings menu) with the click of a button. Data linked to the user is deleted immediately. We no longer process the data! The following user-linked data is deleted in this case:

Data that forms website content but is not directly linked to the user is not automatically deleted! This data loses its personal data character because the link to the data subject cannot be restored. (If the user wishes to delete these, they must request it before deleting their user profile, while it can still be identified which user they belong to.) These are the following:


Duration of data processing

The system automatically deletes messages that both parties have deleted (from their own mail).

The operator stores all known data (registered email address, username, encoded password) of users who registered but did not confirm their registration for 10 days from the time of registration. After 10 days the registration intent is voided and the data is deleted.

Logged data relating to user activity is stored for 15 days from the time of the activity. After that the data is deleted.

The operator deletes data if processing is unlawful, or if the affected user expressly requests it, or the purpose of data processing has ceased, or the specified storage period has expired, or it was ordered by a court or the data protection authority.

The operator does not disclose data stored about the user to third parties (except cooperation with authorities, any legal proceedings), and does not use it for advertising purposes.

No data processing other than that listed in this notice takes place.


Data security

The operator takes all necessary steps to ensure the security of personal data provided by the user both during network communication and during storage and retention of the data. Data is stored in a securely isolated, password-protected area provided by the hosting provider. Access to the data is strictly limited. The aim is to prevent unauthorized access to, alteration of, or use of personal data.

Data protection incident - A data protection incident is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to personal data transmitted, stored, or otherwise processed. The operator keeps records of data protection incidents, stating the facts relating to the incident, its effects, and the remedial measures taken. In the event of an incident – except where it is unlikely to pose a risk to the rights and freedoms of natural persons – the operator informs the data subject and the supervisory authority without undue delay, but no later than 72 hours after becoming aware of the data protection incident. The data subject need not be informed if any of the following conditions is met: the operator has implemented appropriate technical and organizational protection measures, and these measures were applied to the data affected by the data protection incident, in particular measures that protect and secure data against access by persons not authorized to access personal data; following the data protection incident the operator took further measures ensuring that the high risk to the rights and freedoms of the data subject mentioned in Article 33 (1) of the Regulation is no longer likely to materialize; providing information would require disproportionate effort. In such cases data subjects must be informed through publicly published information, or a similar measure must be taken to ensure similarly effective information for data subjects.


User rights and options for legal enforcement

The user is entitled at any time to request information about their personal data processed by the operator, and may modify them at any time. The user is also entitled to delete their data. Through the option created in the Settings menu, they may delete their entire user profile. The user may request information from the operator about the processing of their personal data, correction of their personal data, deletion or blocking of their personal data, restriction of processing, and may object to processing. User rights:

The user may exercise their rights at the contact details given in the data controller details section. The user may contact the operator with any question or remark relating to data processing. The operator is obliged to provide information in writing, in an intelligible form, in the same manner as the request, within the shortest time from submission of the request, but no later than 25 days. The user is entitled at any time to request correction or deletion of incorrectly recorded data. Some data can be corrected by the user themselves on the website. The user may request deletion of their personal data, which the operator will comply with no later than 15 days. Deletion does not apply to processing required by law (e.g. accounting regulations); the operator retains those for the necessary period. At the user's request the operator restricts processing if the accuracy of personal data is contested, or processing is unlawful, or in the case of the user's objection to processing, and if the operator no longer needs the personal data. The user is also entitled to receive the personal data concerning them, which they have provided, in a structured, commonly used, machine-readable format, and is entitled to transmit those data to another controller without hindrance from the operator (where the necessary conditions are met). The user may also enforce their rights before the Budapest-Capital Regional Court, 1055 Budapest, Markó u. 27., or before the regional court of the data subject's place of residence/registered office at the data subject's choice (legal background: Section 22 (1) of Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information). They may also request assistance from the President of the National Authority for Data Protection and Freedom of Information: Dr. Attila Péterfalvi (1024 Budapest, Szilágyi Erzsébet fasor 22/C., www.naih.hu, ugyfelszolgalat@naih.hu, Tel.: +36-1/391-1400). The operator may refuse to provide information to the user only in the cases and for the reasons defined in the Info Act and the Regulation. In such a case the operator informs the data subject in writing on which provision of the Info Act or the Regulation the refusal of clarification is based. If clarification is refused, the operator informs the data subject of the options for legal remedy. If the user provided third-party data during registration to use the service, the operator in such a case provides all possible assistance to the authorities conducting proceedings to establish the identity of the person committing the infringement.


Cookie policy and data processing 🍪

On the first visit to the website, a cookie banner appears with a genuine choice. We use modern, GDPR-compatible cookie management. The system allows each cookie category to be accepted or rejected individually.
You can change your settings at any time later as well. We respect your choices and store them for 12 months. We also use modern cookie categorization from which you can choose which are allowed or blocked.



Essential cookies (always active) These are indispensable for the website to function – session cookies, login state.
Analytics cookies (optional) Google Analytics – collection of anonymous statistical data to improve the website. When disabled, visitors are counted anonymously, but personal profiling, demographic analysis, and remarketing are fully disabled. This fully complies with the GDPR and European data protection requirements.
Marketing cookies (optional) Facebook Pixel, Google Ads – personalized ads and campaign measurement.

Save settings – Saves the selected settings:

Accept all – Automatically enables every optional cookie category:

Essential only – Automatically blocks every optional cookie:

Operational behavior and automatic actions based on choice:

We do not sell cookies to third parties. Only the selected service providers may receive access.

Further information:
Google privacy policy
Facebook privacy policy