Privacy Policy
Last updated: July 25, 2026
This Privacy Policy explains how Livegames Kft. (“we”, “us”, “our”) collects, uses, and protects personal data when you use the Isopenat platform at isopenat.com (also available as mostszabad.hu for the Hungarian market, collectively “the Platform”).
Data Controller
Livegames Kft. Registered seat: 1183 Budapest, Vajk utca 18., Hungary Company registration number: 01-09-380396 Tax number: 29135125-1-43 EU VAT number: HU29135125 Email: info@nevezz.hu
We are not required to appoint a Data Protection Officer under the GDPR. For any data protection inquiries, please contact us at info@nevezz.hu.
What the Platform Does
Isopenat is a booking platform used by businesses and service providers (“Organizations”) to sell and manage their time. Organizations get a public booking page — hosted by us, and optionally embedded into their own website — where their customers (“Customers”) can:
- reserve a resource for a period of time (a court, a room, a table, a chair) or book a service with a fixed duration;
- register for a place in a class, course, or other group event;
- subscribe to a membership or season pass, paid on a recurring basis;
- join a waitlist when everything is taken.
Around that, the Platform provides the Organization with an admin area: a calendar, a booking and member list, pricing rules, cancellation policies, staff and coach accounts, automated confirmations and reminders, invoicing, and exports.
Who Is Responsible for Which Data
The Platform involves two distinct roles, and it matters which one applies to you.
We are the data controller for the Organization’s own account and for running the Platform itself: the accounts of the people who administer an Organization, billing records for our service fee, security and error logs, and the technical data described below.
The Organization is the data controller for the people who book with it — its Customers, event participants and members — and we act as its data processor. The Organization decides what to ask for on its booking and membership forms, how long to keep the records, and what to do with them. We process that data only to run the booking service on the Organization’s instructions, as described in this policy and in our data processing terms. If you booked with a business and want your data corrected or erased, contact that business first; you can also contact us and we will pass the request on.
We never use Customer or member data for our own marketing, and we never sell it.
What Personal Data We Collect and Why
Organization Account Data
When you register as an Organization, we collect:
- Name and email address of each administrator, coach, or staff member with access
- Password hash, or — if you sign in with Google, Facebook or Apple — the account identifier and basic profile the provider returns; if you use a passkey, its public key and credential identifier
- Business name, address, tax number, currency, timezone and other configuration
- Stripe account identifier (for payment processing)
- Booking configuration and scheduling data
Legal basis: Performance of a contract (GDPR Article 6(1)(b)) — this data is necessary to provide you with the Platform’s services under our Terms of Service.
Retention: Until account deletion, plus 5 years thereafter to comply with Hungarian commercial and tax record-keeping obligations.
Customer Booking Data
When a Customer makes a booking, we collect on the Organization’s behalf:
- Name and email address
- Phone number, where the Organization requires one or the Customer supplies one for reminders
- Booking details (date, time, resource, service, price)
- Transaction identifier and payment status (for paid bookings)
- Any answers the Customer gives to questions the Organization has added to its own booking form
Customers do not need to create an account to make a booking.
Legal basis: Performance of a contract (GDPR Article 6(1)(b)) — this data is necessary to process the booking and provide the service. Where an Organization asks for information beyond what the booking itself requires, that Organization is responsible for having a lawful basis for it.
Retention: 1 year from the date of the booking, except where a longer period applies to invoicing records (see below).
Event and Class Registration Data
When a Customer registers for a class, course or other group event, we additionally process the number of places booked, the session registered for, and — where the Organization has enabled it — the answers to any questions on its registration form. The Organization’s coaches and administrators can see the participant list for the sessions they are responsible for.
Legal basis: Performance of a contract (GDPR Article 6(1)(b)).
Retention: 1 year from the date of the session.
Membership Data
When a Customer takes out a membership with an Organization, we process on that Organization’s behalf:
- Name, email address and, where collected, phone number
- The plan and pricing tier chosen, subscription status, billing periods, and start, renewal and cancellation dates
- Payment records for each charge, including refunds and credit notes
- Team or group assignment and the assigned coach, where the Organization uses teams
- Answers to the Organization’s membership signup questions
- Internal notes and tags that the Organization’s administrators record against a member. These are visible only to the Organization’s administrators and are never shown to the member. They are still that member’s personal data, and the member’s rights under this policy apply to them.
An Organization may also add a member by hand — for someone who pays it in cash or by bank transfer — in which case we process the details the Organization enters.
Legal basis: Performance of a contract (GDPR Article 6(1)(b)).
Retention: For the duration of the membership plus 1 year, except where a longer period applies to invoicing records (see below).
Information Organizations Ask For Themselves
Organizations can add their own questions to their booking, event registration and membership forms. We do not choose these questions and we do not inspect the answers.
An Organization must not use these fields to collect special categories of personal data — health or medical information, biometric data, data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation — unless it has a lawful basis for doing so under GDPR Article 9 and has informed the person concerned. The Organization alone is responsible for what it asks for, and for the consequences of asking for it.
Waitlist Data
When a Customer joins a waitlist for a fully booked time slot, we collect their email address — and their phone number where SMS notification is in use — to send an automatic notification if the slot becomes available.
Legal basis: Performance of a contract (GDPR Article 6(1)(b)) — the waitlist is part of the booking service.
Retention: Until the waitlist entry is fulfilled or the relevant time slot has passed.
Payment Data
Online card payments are processed by Stripe, Inc. We do not store or have access to your full card details. We only receive a transaction identifier, payment status, and the payment amount from Stripe. For recurring membership payments, Stripe also holds the payment method on file under the Organization’s own Stripe account. Stripe acts as an independent data controller for the payment data it processes. For details on how Stripe handles your data, see Stripe’s Privacy Policy.
Notification Data
Confirmations, cancellations, waitlist alerts, invitations and reminders are sent by email through our email provider. Where an Organization has enabled SMS reminders, the recipient’s phone number and the message text are transmitted to our SMS provider for delivery. Both act as processors on our instructions, and we instruct them only to deliver the message.
Legal basis: Performance of a contract (GDPR Article 6(1)(b)) — notifications about a booking are part of the booking service.
Invoicing Data
Where an Organization connects an invoicing provider (Számlázz.hu or Billingo.hu) using its own account credentials, we transmit the details needed to issue an invoice for a booking or membership charge — the payer’s name and, where given, billing address and tax number, the amount, and the item description — to that provider on the Organization’s instruction. The Organization chooses the provider and is responsible for the content of the invoices issued in its name and for its own tax obligations.
We also process billing name, address, tax number and transaction records for Organizations in order to invoice our own service fee.
Legal basis: Legal obligation (GDPR Article 6(1)(c)) — to comply with Hungarian accounting and tax law (Act C of 2000, Sections 166–169).
Retention: 8 years from the date of invoice issuance, as required by law.
Technical and Log Data
When you use the Platform, our infrastructure automatically processes:
- IP address
- Browser type and version
- Pages visited and timestamps
- Security-related data (for fraud prevention and protection against attacks), including the result of the anti-bot challenge shown on some forms
- Diagnostic data when something goes wrong — the error, the page it happened on, and technical context needed to reproduce it
Legal basis: Legitimate interest (GDPR Article 6(1)(f)) — to maintain the security, availability, and performance of the Platform.
Retention: 1 year.
The Embedded Booking Widget
An Organization can embed its booking page into its own website. When it does, the booking page is loaded from our servers inside the Organization’s page, and this policy applies to that booking page exactly as it does on our own domain. The rest of the Organization’s website is not ours, and its own privacy policy governs it.
Cookies
The Platform uses only strictly necessary cookies. These are essential for the Platform to function and cannot be switched off. They include:
- Authentication cookies — to identify logged-in users and maintain sessions
- Cloudflare security cookies (
__cf_bm) and anti-bot challenge cookies — to protect the Platform from bots and malicious traffic - Stripe cookies (
__stripe_mid,__stripe_sid) — for fraud prevention during payment transactions
Because we only use strictly necessary cookies, no cookie consent banner is required under the ePrivacy Directive (Directive 2002/58/EC, Article 5(3)) and GDPR. These cookies do not track you for advertising or analytics purposes.
We do not use any analytics, marketing, or tracking cookies.
Who We Share Your Data With
We share personal data only with the following categories of recipients, and only to the extent necessary to operate the Platform:
Data Processors
These service providers process data on our behalf, under our instructions:
- Cloudflare, Inc. — hosting, content delivery, database storage, and security including bot protection. Privacy policy: cloudflare.com/privacypolicy
- Resend, Inc. — transactional email delivery (booking and membership confirmations, waitlist notifications, reminders, invitations, account-related emails). Privacy policy: resend.com/legal/privacy-policy
- SeeMe (seeme.hu) — SMS delivery, where an Organization has enabled SMS reminders
- Functional Software, Inc. (Sentry) — error and performance monitoring. Privacy policy: sentry.io/privacy
Independent Data Controllers
These service providers process data for their own purposes in addition to ours:
- Stripe, Inc. — payment processing. Stripe independently determines how it processes payment data. Privacy policy: stripe.com/privacy
- Google, Meta (Facebook) and Apple — only where you choose to sign in with one of these accounts, and only for the sign-in itself
- Számlázz.hu (KBOSS.hu Kft.) and Billingo Technologies Zrt. — only where an Organization has connected one of them with its own account, in which case the invoicing relationship is between that Organization and the provider
Organizations
When a Customer makes a booking, registers for an event, or takes out a membership, the relevant data is available to the Organization that runs it, and to the coaches and staff to whom that Organization has granted access. The Organization is the data controller for the data it holds about its Customers and members.
We do not sell personal data to any third party. We do not share data with advertisers.
International Data Transfers
Some of our service providers (Stripe, Resend, Cloudflare, Sentry) are based in the United States. When personal data is transferred outside the European Economic Area, we ensure appropriate safeguards are in place:
- Transfers to the United States are covered by the EU-U.S. Data Privacy Framework, where the recipient is certified, or by Standard Contractual Clauses (SCCs) adopted by the European Commission.
- We verify that each provider maintains adequate data protection measures in accordance with GDPR Article 46.
Our SMS and invoicing providers are established in Hungary, so no transfer outside the EEA takes place for those services.
Your Rights Under the GDPR
As a data subject, you have the following rights regarding your personal data:
- Right of access (Article 15) — You can request confirmation of whether we process your data and obtain a copy of it.
- Right to rectification (Article 16) — You can request correction of inaccurate data or completion of incomplete data.
- Right to erasure (Article 17) — You can request deletion of your data when it is no longer necessary for the purposes for which it was collected, or when you withdraw consent (where applicable). This right may be limited where we have a legal obligation to retain data.
- Right to restriction of processing (Article 18) — You can request that we limit the processing of your data in certain circumstances.
- Right to data portability (Article 20) — You can request to receive your data in a structured, commonly used, machine-readable format, where the processing is based on consent or contract and is carried out by automated means.
- Right to object (Article 21) — You can object to processing based on legitimate interests. We will stop processing unless we demonstrate compelling legitimate grounds that override your interests.
To exercise any of these rights, contact us at info@nevezz.hu. We will respond within one month of receiving your request. This period may be extended by a further two months if the request is complex, in which case we will inform you of the extension within the first month.
Where the data concerns a booking or a membership, the Organization you booked with is the controller. Please contact that Organization directly where you can — it will usually be able to act immediately. If you contact us instead, we will forward your request to the Organization and assist it in responding.
Account Deletion
Organizations can delete their own account and organization from the Platform’s settings, or request deletion by emailing info@nevezz.hu, in which case we will process it within 15 days. Deleting an organization removes its booking pages and its Customer and member records from the Platform, subject to the retention periods above — invoicing records in particular must be kept for 8 years by law.
Customers who have made bookings or hold a membership without an account can request erasure of their data by contacting the Organization concerned, or us at info@nevezz.hu.
Data Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These include encrypted data transmission (HTTPS/TLS), access controls that limit each Organization’s staff to that Organization’s own data, role-based restrictions so that a coach sees only the members and sessions assigned to them, and regular security reviews. The Platform is hosted on Cloudflare’s infrastructure, which provides DDoS protection, web application firewall, and other security features.
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority (NAIH) without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify affected individuals directly, in accordance with GDPR Article 34. Where we act as a processor for an Organization, we will notify that Organization without undue delay so it can meet its own obligations.
Data Processing Agreements
We maintain Data Processing Agreements (DPAs) with all service providers that process personal data on our behalf, in accordance with GDPR Article 28. For Organizations that act as data controllers and require a Data Processing Agreement with us, one is available upon request at info@nevezz.hu.
Automated Decision-Making
We do not use automated decision-making or profiling as defined by GDPR Article 22.
Children’s Data
The Platform is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16, we will take steps to delete it promptly.
Some Organizations run junior classes and youth teams. Where an Organization books or enrols a minor, it is that Organization’s responsibility to obtain the consent of the holder of parental responsibility where the law requires it, and to make sure the account and contact details it enters belong to an adult.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make changes, we will update the “Last updated” date at the top of this page. If the changes are significant, we will notify registered Organizations by email. Continued use of the Platform after changes constitutes acceptance of the updated policy.
Complaints and Legal Remedies
If you believe your data protection rights have been violated, we encourage you to contact us first at info@nevezz.hu so we can resolve the issue.
You also have the right to lodge a complaint with the supervisory authority:
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH) Address: 1055 Budapest, Falk Miksa utca 9-11., Hungary Postal address: 1363 Budapest, Pf. 9. Phone: +36 (30) 683-5969 or +36 (30) 549-6838 Website: naih.hu
You may also file a complaint with the supervisory authority of the EU Member State where you reside or work.
Additionally, you have the right to an effective judicial remedy before a competent court. In Hungary, such cases fall under the jurisdiction of the regional courts (törvényszékek). You may choose to bring proceedings before the court of your habitual residence.