← Egyesületi Tagdíj and support
Egyesületi Tagdíj Privacy Notice
Last updated:
This notice covers the Egyesületi Tagdíj application for Android and iOS and Bright Path Makers’ licensing and support processing. Visits to this website are covered by the separate Website Privacy Notice.
1. Controllers and responsibilities
The controller for Bright Path Makers’ own licensing and support processing is:
- Bright Path Makers Korlátolt Felelősségű Társaság (BPM)
- Registered seat: 1221 Budapest, Ady Endre út 89., Hungary
- Company registration number: 01-09-450726
- Privacy contact: info@brightpathmakers.com
- Product support: support@brightpathmakers.com
The association or other organisation using the application is the controller of its member and contact records. That organisation determines the purposes and legal bases, authorised operators, retention and email recipients, and provides its own notice to the people concerned. BPM does not automatically receive these records or provide central hosting for member data.
Records may concern minors and parent contacts. The application is an administrative tool for the organisation’s operators; the organisation is responsible for the lawful handling of minors’ data.
2. Data stored in the application
Data enters the application through the operator’s input or file import. Depending on use, records may include:
- Association name, teams, seasons, memberships and chargeable periods.
- Member name, local identifier, date of birth, minor/adult status, parent name, phone number, email and notes.
- Membership fees, payments, payment methods, arrears, cash handovers, names of people handing over or receiving money, dates, notes and voiding records.
- Operator/coach name, leader’s email address, SMTP profile and sending preferences.
- Email and activity logs: related records, recipients, subject, summary, sending status, error information and dates.
- Information needed to verify the local PIN, preferences, installation identifier, evaluation and licence state.
The main records are stored in an encrypted file. Keys and secrets are protected through Android Keystore-backed storage or iOS Keychain. The SMTP password is stored separately; the theme preference is stored in system preferences.
The local PIN and operator name do not create an online BPM user account. Optional biometric unlocking on iOS returns an authentication result to the application, not a biometric template. The application contains no analytics, advertising tracking or automatic upload of crash reports to BPM.
3. Email and SMTP
The operator configures email sending. A TLS-protected connection is made directly to the configured SMTP server. With Gmail, the provider is Google; the Gmail preset uses smtp.gmail.com and an app password. A custom SMTP provider can also be configured.
The provider receives the username/password needed for authentication and the sender, recipients, subject and message content. Messages may include member or parent names, teams, memberships, payments, arrears and payment notes. Management reports may include the names, email addresses and balances of members with arrears.
When automatic payment receipts are enabled, recording a payment also initiates email sending. Balance emails, monthly reports, test messages and retries are initiated by the operator. A manual draft or share action passes the content to the selected system application.
There is no BPM relay service in the sending path. Credentials and message content reach the configured provider directly. The SMTP password is excluded from the application’s full data backup. Sending can be disabled in settings and the stored SMTP password can be deleted; this does not delete messages already sent.
4. Evaluation and licensing
The 30-day evaluation without a licence and licence-validity checks operate locally. The application stores local state and time information for this purpose.
The installation identifier is a random string generated by the application. A licence request contains this identifier, an organisation identifier derived from the organisation’s name, the platform, application version, an optional licence-seat identifier, a one-time technical identifier and the creation time.
The operator exports, copies or shares the request. There is no automatic submission to BPM; BPM receives the request when the operator provides it for licence issuance. It does not contain member records, payments or SMTP passwords. The application verifies the issued licence’s signature locally using a public key.
5. BPM’s licensing and support processing
Licensing: under the agreement between the association and BPM, we handle the submitted request, organisation and installation identifiers, issued licence and related issuance logs. Issuance records may also include the organisation’s name and a supplied seat/operator label. The purpose is to issue and administer the organisation’s right to use the application.
Support: we process written or spoken issue descriptions, correspondence and contact details provided for a reply, to investigate and answer the request. We do not accept member data, association backups or sensitive data for support. We reproduce issues on BPM’s own systems from descriptions.
Legal basis: licensing administration and B2B contact/support information that can be linked to a person is processed under GDPR Article 6(1)(f). Our legitimate interest is administering licences and resolving issues under our agreement with the association. The organisation using the application determines the legal basis for its member records.
Access and storage: these licensing and support records are stored on BPM’s own computer. Access is restricted to authorised BPM representatives or employees. BPM does not disclose these records to external recipients or transfer them outside the EEA.
Retention: licence requests, licences, related logs and support case records are retained for 30 days after the relevant matter is closed, then manually and permanently deleted. This rule applies to the application’s licensing and support records; separate contractual and accounting documents are covered by the general B2B notice.
6. Backups, retention and local deletion
Android system backup is disabled for the application; file, preference, database and external-file areas are also excluded by its backup and device-transfer rules. On iOS, protected data files, internal safety copies and temporary export directories are marked as excluded from backup. The Keychain secrets used are not synchronised. The iOS theme preference has no separate backup exclusion and may be backed up by the operating system.
The operator can export password-encrypted full backups and unencrypted CSV reports. The selected file or sharing service may use cloud storage, such as iCloud Drive or Google Drive. Retention and deletion of those copies are managed by the organisation and its chosen provider.
The organisation determines how long to retain its local business records. Archiving and voiding preserve records; there is no automatic deletion of business data based on age. Licence expiry does not delete the records. Internal safety copies may also remain.
Local data can be deleted using the application’s deletion function or the operating system’s application-data controls. Uninstalling does not delete previous exports, messages held by mail providers or information already given to BPM. On iOS, deletion of Keychain items does not necessarily coincide with uninstalling the application.
7. External services and transfers
The SMTP provider and email recipients selected by the organisation, and storage or sharing services selected for exports, may receive data through the operator’s actions. Each provider’s own privacy terms apply. The organisation should consider where its provider processes data and whether it transfers data outside the EEA.
Apple and Google may process information relating to the operating system, store, backups and enabled diagnostic services under their own terms. This is separate from BPM’s licensing and support processing.
BPM does not use the application’s data for advertising tracking, profiling or automated decisions producing legal effects for the person concerned.
8. Rights and requests
You may request information about and access to personal data held by BPM, rectification, erasure or restriction of processing. You may object to processing based on legitimate interests. Data portability and withdrawal of consent apply where their legal conditions are met; the BPM processing described above is based on legitimate interests.
Send requests, including requests to delete licensing or support data, to info@brightpathmakers.com with enough information to identify the matter. Do not send member records or passwords. Requests concerning an association’s member records should be addressed directly to the organisation maintaining them.
You may complain to the competent supervisory authority. In Hungary: Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), 1055 Budapest, Falk Miksa utca 9–11., Hungary; NAIH website. You may also seek a judicial remedy.
When this notice changes, we will update the date shown on this page.