Privacy Policy

On the processing of personal data in the MEDalon application and the medalon.hu / medalon-tag.com websites · v1.0 · Effective: 11 July 2026

This document describes how Innovatív Marketing Megoldások Kft. (the "Controller", "we") processes personal data in connection with operating the MEDalon application (a QR-based emergency medical ID system) and the associated medalon.hu and medalon-tag.com websites, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (the "GDPR").

Important: The MEDalon system also processes special categories of personal data (health data) — blood type, allergies, medications, medical conditions, emergency contacts. Article 9 of the GDPR provides stricter safeguards for such data, which are explained in detail below. Please read this policy carefully.

I. The Controller

Name:
Innovatív Marketing Megoldások Kft. (Ltd.)
Registered seat:
Gizella út 19/B, 1143 Budapest, Hungary
VAT / tax number:
25803965-2-42 (HU25803965)
Company reg. no.:
01-09-338878
Represented by:
Zsuzsanna Radics
Email:
hello@medalon.hu
Phone:
+36 70 500 0800
Websites:
https://medalon-tag.com · https://medalon.hu

We are not required to appoint a Data Protection Officer and have not done so. For any privacy matter, please contact us using the details above.

II. Processing activities

II.1. Registration and user account

Purpose: to create and manage your MEDalon account, provide the service, authenticate you and enable sign-in.

Data: email address, password (stored hashed only), account creation and last login times, language and app settings.

Legal basis: performance of a contract [Art. 6(1)(b) GDPR], as the account is necessary to use the service.

Retention: for the lifetime of the account or until you request deletion; after deletion, data is permanently removed within 30 days unless a longer retention period is required by law.

II.2. Emergency medical profile (special category data)

Purpose: the core of the MEDalon service — to store your emergency medical profile so that, in an emergency, first responders (paramedics, doctors, first-aid providers) can access it immediately by scanning the QR code on your MEDalon card.

Data: last name, first name, date of birth, blood type, allergies, regular medications, medical conditions (ICD-10 code or free text), communication language, "lives alone" indicator, other medical notes, name and phone number of emergency contact(s), optional profile photo. The system allows multiple profiles per account (e.g. for family members handled on their behalf).

Legal basis: your explicit consent [Art. 9(2)(a) GDPR], given when you create the profile by ticking the "I consent to the processing of my health data for the purposes of the MEDalon service" checkbox. Profiles of minors or persons lacking legal capacity are created and managed by their legal representative, who also gives the consent.

Retention: until you withdraw consent or delete the account/profile. Consent can be withdrawn at any time by deleting the profile in your account.

Encryption: special-category health data (blood type, allergies, medications, diagnoses, emergency contact details) is stored on the server with application-level encryption (XSalsa20-Poly1305, libsodium). The encryption key is kept separately from the database; encrypted data remains unreadable even in the event of a database leak. Detailed technical and organisational measures are described in Section VI.

II.3. Card order and activation

Purpose: to process your order of a MEDalon physical card (metal card, dog tag, keychain, family pack) or digital card (downloadable PDF), fulfil delivery or make the digital product available, and generate and link the activation code to your profile.

Data: customer name, email address, billing name and address; for physical products, shipping name and address and phone number (for courier notification); the ordered product and quantity, order time and reference; the unique activation code associated with the card (stored encrypted); card activation status and time of activation.

Legal basis: performance of a contract [Art. 6(1)(b) GDPR]; for accounting records, compliance with a legal obligation [Art. 6(1)(c) GDPR] under Section 169 of Hungarian Act C of 2000 on Accounting.

Retention: accounting documents (invoices) are retained for 8 years as required by law; other order data for the general civil-law limitation period after contract performance (5 years).

II.4. Payment

Purpose: to process electronic payment.

Data: the amount, time and reference of the payment, and payment status. We never receive or store your card details: payment is handled on the secure interface of our payment provider, Barion Payment Zrt.

Legal basis: performance of a contract [Art. 6(1)(b) GDPR].

Retention: for the time required to document the transaction, in line with statutory limitation rules.

II.5. Emergency QR code scan (public access)

Purpose: to allow first responders or emergency helpers rapid access to the emergency medical profile of a physically incapacitated data subject via scanning the QR code on the MEDalon card, in order to protect their life and physical integrity.

Data: the emergency medical profile data listed in II.2, displayed in read-only form.

Legal basis: protection of the vital interests of the data subject [Art. 9(2)(c) GDPR], where the data subject is physically or legally incapable of giving consent. The data subject expressly acknowledges the fact of public access when the profile is created; this is the operational foundation of the MEDalon system.

Retention: public access is possible while the card is valid (activated and not expired). The user may "lock" the card at any time in the account, which immediately terminates public access.

Logging: every QR scan is logged with a timestamp and truncated (anonymised) IP address for abuse detection and scan-statistics purposes (see II.8). The identity of the scanner is not recorded.

Abuse protection: the system applies IP-based rate limiting to prevent bulk retrieval of profile data.

II.6. Contact and customer support

Purpose: to receive and respond to your enquiries and complaints and to communicate with you.

Data: the details you provide (typically name, email address, message content).

Legal basis: your consent [Art. 6(1)(a) GDPR]; for complaints, compliance with a legal obligation [Art. 6(1)(c) GDPR] under Section 17/A of Hungarian Act CLV of 1997 on consumer protection, retained for 5 years.

Retention: until the enquiry is resolved; complaints are retained for 5 years.

II.7. Password reset

Purpose: to enable secure recovery of a forgotten password.

Data: the user's email address, a temporary reset token (stored hashed) and its expiration time (60 minutes).

Legal basis: performance of a contract [Art. 6(1)(b) GDPR].

Retention: until the token is used, or a maximum of 60 minutes, after which it is automatically deleted.

II.8. Audit log (security event log)

Purpose: to ensure the secure operation of the system, detect abuse, substantiate breach investigations, and support the exercise of data subject rights (e.g. "when was my card last scanned?").

Data: event type (e.g. QR scan, profile edit, admin action), timestamp, the profile/user identifier concerned, and truncated IP address.

Legal basis: the Controller's legitimate interest [Art. 6(1)(f) GDPR] in maintaining the integrity and security of the service.

Retention: 12 months from the event.

II.9. Newsletter and marketing (planned)

Purpose: to send news, offers and updates about our services by electronic means. This is currently planned; newsletters are only sent if you give explicit, separate consent.

Data: name, email address, time of consent.

Legal basis: your explicit consent [Art. 6(1)(a) GDPR].

Retention: until you withdraw consent (unsubscribe). Every newsletter includes a one-click unsubscribe link.

II.10. Analytics

Purpose: to measure traffic on the medalon.hu and medalon-tag.com websites and improve the user experience (Google Analytics 4).

Data: device and browser data, (truncated/anonymised) IP address, online identifiers, cookie-stored identifiers, and data about visitor behaviour.

Legal basis: your consent [Art. 6(1)(a) GDPR], given or refused via the cookie panel in line with Google Consent Mode v2. See the Cookie Policy.

Retention: for the lifetime of the relevant cookies or until you withdraw consent.

III. Cookies

We use cookies on our website and have integrated Google Consent Mode v2. Strictly necessary cookies are placed on the basis of our legitimate interest [Art. 6(1)(f)]; statistics and marketing cookies only with your consent [Art. 6(1)(a)]. Full details are in the separate Cookie Policy.

IV. Recipients and data processors

A processor is an organisation that processes personal data on our behalf. We use the following processors:

IV.1. Hosting provider

Name:
Tárhely.Eu Szolgáltató Kft.
Address:
Könyves Kálmán körút 12-14, 1097 Budapest, Hungary
Contact:
+36 1 789-2-789 · support@tarhely.eu · https://tarhely.eu

The processor stores personal data on European Union servers and is not entitled to access its content.

IV.2. Payment provider

Name:
Barion Payment Zrt.
Registered seat:
1117 Budapest, Irinyi József utca 4-20., Hungary
Company reg. no.:
01-10-048552 · Tax no.: 25353192-2-43
MNB licence:
H-EN-I-1064/2013 · https://www.barion.com

Barion Payment Zrt. carries out the processing of online payments. Card data is handled directly by Barion; we do not have access to it. Barion also acts as an independent controller in respect of the payment transaction and fraud prevention, as described in Barion's own privacy policy.

IV.3. Invoicing provider

Name:
KBOSS.hu Kft. (Számlázz.hu)
Registered seat:
1031 Budapest, Záhony utca 7., Hungary
Company reg. no.:
01-09-303201 · Tax no.: 13421739-2-41
Website:
https://www.szamlazz.hu

Through the Számlázz.hu system, KBOSS.hu Kft. issues, delivers and retains invoices as required by law.

IV.4. Accounting provider

Name:
HANS-GLOBÁL Kft.
Registered seat:
1188 Budapest, Napló utca 13. A, Hungary
Company reg. no.:
01-09-729261 · Tax no.: 13320951-1-43

Based on the issued invoices, the accountant carries out our accounting and tax-reporting obligations.

IV.5. Shipping provider (physical cards)

Name:
Magyar Posta Zrt. (Hungarian Post — MPL)
Registered seat:
Dunavirág utca 2-6, 1138 Budapest, Hungary
Website:
https://www.posta.hu

Magyar Posta Zrt. delivers physical card products via post. For this purpose we transfer the recipient's name, shipping address, phone number and shipment identifier. Magyar Posta Zrt. acts as an independent controller in respect of processing related to postal delivery, as described in its own privacy notice. Note: physical shipping is only available for Hungary. International customers receive digital products only.

IV.6. Analytics providers

ProviderPurposeLocation
Google Ireland Ltd. / Google LLC (Google Analytics 4)Website traffic measurement, UX improvementDublin, Ireland / USA

For data collected via consent-based cookies, Google acts partly as an independent controller and partly as a processor.

IV.7. Transfers to third parties

Beyond the above, we do not transfer personal data to third parties unless required by law (e.g. a lawful authority or court request).

V. International (third-country) transfers

Emergency medical profile data and user account data are stored exclusively within the European Union (on Tárhely.Eu Kft.'s Hungarian servers) and are not transferred to third countries.

Analytics providers (Google) may in some cases transfer data outside the European Economic Area, including to the United States. Such transfers take place with appropriate safeguards, primarily under the European Commission's adequacy decision for the EU–US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses (SCCs). Without your explicit consent, no analytics data is transferred.

VI. Data security

We apply appropriate technical and organisational measures to protect personal data — in particular special category health data:

In the event of a data breach we act in accordance with Articles 33–34 GDPR, and — if the breach is likely to result in a high risk to the rights and freedoms of data subjects — inform affected users without undue delay.

VII. Your rights

Within the retention period you have the rights below under the GDPR. To exercise them, contact us using the details above; we will respond within 30 days.

VII.1. Right to withdraw consent

You may withdraw consent-based processing at any time without giving reasons. This does not affect the lawfulness of processing before withdrawal. Withdrawal of consent to the processing of your emergency medical profile results in the deletion of the profile (and its health data).

VII.2. Right of access

You may obtain confirmation of whether we process your data and, if so, access it and receive information about the purposes, categories, recipients, retention, your rights and remedies.

VII.3. Right to rectification

You may request correction of inaccurate data and completion of incomplete data. Profile data can also be edited at any time directly in the MEDalon application.

VII.4. Right to erasure ("right to be forgotten")

You may request erasure where data is no longer needed, you withdraw consent with no other legal basis, you object to processing, or processing is unlawful. Erasure does not override statutory retention obligations (e.g. 8-year invoice retention). Account deletion can also be initiated in the application; all associated data is then permanently deleted within 30 days.

VII.5. Right to restriction

You may request restriction of processing where you contest accuracy, processing is unlawful but you oppose erasure, you need the data for legal claims, or you have objected to processing.

VII.6. Right to object

On grounds relating to your particular situation, you may object at any time to processing based on legitimate interests (e.g. the audit log).

VII.7. Right to data portability

For consent- or contract-based automated processing, you may receive the data you provided in a structured, commonly used, machine-readable format (e.g. JSON, CSV) and, where technically feasible, have it transmitted to another controller.

VII.8. Right to lodge a complaint

If you believe we have breached data protection rules, you may lodge a complaint with the supervisory authority:

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address: Falk Miksa utca 9-11, 1055 Budapest, Hungary
Mail: 1363 Budapest, Pf. 9.
Email: ugyfelszolgalat@naih.hu · Phone: +36 (1) 391-1400
Web: https://naih.hu

You may also bring the matter before the competent court of your place of residence or stay, or the supervisory authority of your EU/EEA country.

VIII. Other provisions

VIII.1. Amendments

We reserve the right to amend this Policy. The current version is always available on medalon.hu and medalon-tag.com. Where a change materially affects processing, we will inform users appropriately (via a notice upon login and/or by email).

VIII.2. Minors

Independent use of the MEDalon service (creating an account and giving one's own data-processing consent) is available to natural persons who have reached the age of 16. The emergency medical profile of a minor is created and managed by their legal representative.

← Back to home