Privacy Policy

Effective: 9 June 2026

1. The controller

The controller: Pro-Sharp Hungary Zrt. (the “Controller”) — registered seat: 1145 Budapest, Bácskai utca 29/A, Hungary; company reg. no.: 01-10-143757; tax no.: 33095424-2-42; EU VAT no.: HU33095424; electronic contact: bizcup@pro-sharp.hu.

Under Article 37 GDPR the Controller is not required to appoint a Data Protection Officer (DPO) and has not appointed one; for data-protection matters the Controller is available at the contact above.

This policy sets out the processing of personal data in connection with the use of the bizcup.app platform (the “Platform”).

2. Controller and processor roles

BizCup is a multi-party product, so roles depend on the specific processing situation:

• In respect of its own employees’ data, the participating Company is generally an independent controller. Where the Controller processes such data on the Company’s behalf in order to operate the corporate league, it acts as a processor; this is governed by the Data Processing Terms (DPA) under Article 28 GDPR, which the Company accepts by using the Platform and which are available at www.bizcup.app/legal/dpa.

• In respect of users who register publicly and voluntarily, and of its own marketing and the global ranking, Pro-Sharp Hungary Zrt. acts as an independent controller.

This policy focuses on the latter role; where Pro-Sharp Hungary Zrt. acts as a processor, the relevant Company’s own privacy policy also applies.

3. Data, purposes and legal bases

DataPurposeLegal basis (GDPR Art. 6)
Name / display name, company e-mailAccount creation, identification, loginPerformance of contract [6(1)(b)]
Company (e-mail domain), team/departmentLeague assignment, team competitionPerformance of contract [6(1)(b)]
Predictions, points, rankings, statisticsRunning the Game, leaderboardsPerformance of contract [6(1)(b)]
Profile picture (if provided by SSO)Profile displayContract / legitimate interest [6(1)(b)/(f)]
Log data (IP, device/browser, timestamp)Security, abuse prevention, operationsLegitimate interest [6(1)(f)]
Web-analytics data (Google Analytics, via cookies)Measuring usage, improving the PlatformConsent [6(1)(a)] — off by default
Display in cross-company national ranking (limited data: first name/nickname + company)Cross-company competitionConsent or legitimate interest per admin setting [6(1)(a)/(f)] — opt-in
Publishing results and highlights (first name/display name + company; photo only with consent)Promoting the Contest, media (web, LinkedIn, press)Legitimate interest; explicit consent for photo or detailed highlighting [6(1)(f)/(a)]
League/company verification data (domain proof; optionally VAT number)Authenticating the league, preventing abuseLegitimate interest / legal obligation [6(1)(f)/(c)]
Marketing messages (newsletter, product offers)Direct marketingExplicit consent [6(1)(a)] — separate, off by default
Slack integration data (if the company connects it)Sending notificationsContract / company’s instruction

We do not request or process calendar, mail or contacts access for participation. We do not process special (sensitive) categories of data.

Public-ranking principle. The cross-company public company ranking displays only company-level, aggregated data (company name + points/position), without personal data. Public appearance in the cross-company individual ranking is opt-in and minimised (first name or nickname + company). User-written content within a company league (nicknames, predictions, messages) is not made public and stays within the closed league.

League/company verification. To confirm domain control when a company league is created, we may process data (e.g. the company e-mail / SSO tenant, or a DNS or file-based verification token), and — if the company chooses — a VAT number for legal-name checks (which may be personal data for a sole trader). We use this solely to authenticate the league and prevent illegitimate company claims.

4. SSO and password handling

For Google Workspace / Microsoft 365 login, authentication is performed by Google or Microsoft; we receive only basic profile data (name, e-mail, possibly picture) and never see or store your password. For classic e-mail + password registration, passwords are stored only with industry-standard one-way encryption (hash + salt).

5. Recipients and processors

Besides the Controller’s staff, the following sub-processors may process data on the Controller’s behalf, solely for the purposes above:

• hosting / cloud infrastructure and e-mail / magic-link delivery — Microsoft Azure (Microsoft Ireland Operations Ltd.), in an EU data centre;

• web analytics — Google Analytics (Google Ireland Ltd.); active only with consent to analytics cookies, and may involve transfer to the USA to Google LLC under the EU–US Data Privacy Framework;

• sports-data provider (fixtures, results) — the actual provider will be listed (public match data only, typically without personal data);

• Slack (only if the company connects it) — Slack Technologies.

An up-to-date sub-processor list is available on request or on the Platform. We do not sell data to third parties.

6. Transfers outside the EU/EEA

Data is processed primarily within the EU (Microsoft Azure). Some sub-processors (e.g. Google Analytics) may also process data outside the EU/EEA, in the USA; we do so only with appropriate safeguards under the GDPR (EU–US Data Privacy Framework or the EU Standard Contractual Clauses — SCC). Details are available on request.

7. Retention

Different retention periods apply depending on purpose:

• Game-related data (account, predictions, points, raw ranking data): for the duration of the Contest and subsequent settlement; thereafter deleted or anonymised within at most 8 weeks of the tournament’s end, unless a law requires longer retention.

• Anonymised / aggregated statistics (e.g. aggregated company results, non-identifiable data): may be kept and used without time limit, as this is no longer personal data.

• Marketing data (contact details of players who explicitly consented to marketing): processed until consent is withdrawn — independently of the 8-week game-data deletion.

• Already-published content (a post, card or highlight published with the player’s consent): publication remains lawful; later deletion of an account does not automatically retract already-published material (future use can be stopped by withdrawing consent).

• Log data: for a limited period needed for the security purpose.

For data processed on the Company’s behalf, the Data Processing Terms and the company’s instructions govern deletion.

8. Your rights

You have the right to access, rectification, erasure, restriction and data portability, and to object to processing based on legitimate interest and to direct marketing; consent may be withdrawn at any time, free of charge (without affecting prior processing). We provide self-service account and data deletion on the Platform, and requests can also be made at bizcup@pro-sharp.hu. We respond without undue delay, within one month at the latest.

Where the Company processes as controller, you may also address your request to it; we will route you to the appropriate party.

9. Complaints

You may lodge a complaint with the supervisory authority: Hungarian National Authority for Data Protection and Freedom of Information (NAIH) — 9-11 Falk Miksa utca, 1055 Budapest; ugyfelszolgalat@naih.hu; www.naih.hu. You may also seek a judicial remedy.

10. Security

Data is transmitted over an encrypted channel (TLS) and stored encrypted; we apply access control, logging and risk-proportionate organisational and technical measures against unauthorised access and loss.

11. Cookies

Cookie use is governed by the Cookie Policy (bizcup.app). Only strictly necessary cookies are active by default; analytics and marketing only with separate consent.

12. Changes

The Controller may update this policy; the current version is always available on the Platform, with the date shown. Material changes are communicated on the Platform.

Privacy Policy · BizCup