Privacy Policy
Privacy Policy – Snapmeter application
I. The data controller
The data-processing activities described in this Privacy Policy are carried out by the company identified below (hereinafter: the "Service Provider"), except where this Policy expressly provides otherwise.
The operator of the Snapmeter application:
- Name: Nodum Kft.
- Registered seat and postal address: 8256 Ábrahámhegy, Bökkhegyi út 8., Hungary
- Company registration number: 19 09 523696
- Tax number: HU25726055
- Representative: György Fehér
- Email: hello@snapmeter.app
- Website: www.nodum.hu
Privacy contact
The Service Provider does not appoint a mandatory Data Protection Officer under Article 37 of the GDPR, as its activities do not currently meet the criteria requiring such appointment. Users may submit their privacy-related questions and requests through the following contact:
- Name: György Fehér (representative of the Service Provider)
- Email: hello@snapmeter.app
II. Data protection principles applied by the Service Provider
The Service Provider, as data controller, undertakes that all data processing related to its activities complies with the requirements set out in this Policy, in applicable national legislation, and in the legal acts of the European Union.
The Service Provider operates the Snapmeter (hereinafter: the "Application"), which allows the User to record the readings of their utility meters, take and store photographs of those readings, and access the recorded data later.
Information on the Service Provider's data-processing activities is continuously available on the Service Provider's website.
The Service Provider is entitled to amend this Privacy Policy unilaterally. In the event of amendment, the Service Provider notifies the User by publishing the changes on its website. Material changes are also notified to the User by separate email sent to the User's registered email address.
The Service Provider is committed to protecting the personal data of its customers and partners and considers it of paramount importance to respect their right to informational self-determination. The Service Provider treats personal data confidentially and takes all security, technical and organisational measures that guarantee the security of the data.
The Service Provider's data-protection principles are in line with the applicable data-protection laws, in particular:
- Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation, GDPR);
- Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information (Infotv.);
- Act V of 2013 on the Hungarian Civil Code (Ptk.);
- Act CVIII of 2001 on Electronic Commerce Services (Eker. tv.);
- Act C of 2000 on Accounting (Sztv.), where the Service Provider supplies the service for a fee.
The Service Provider uses personal data only on the legal bases set out in the GDPR and strictly for specified purposes.
III. Legal basis, purpose, categories of data, and retention of processing activities
1. General legal bases
The Service Provider's processing activities may be based on the following legal grounds (GDPR Article 6(1)):
- point (a) – consent of the data subject;
- point (b) – performance of a contract, or steps prior to entering into a contract;
- point (c) – compliance with a legal obligation of the controller;
- point (f) – legitimate interests pursued by the Service Provider or a third party.
Where processing is based on consent, the data subject may withdraw that consent at any time during processing, without giving reasons. Withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal.
Persons under the age of 18 may not use the Service Provider's service. The Service Provider does not knowingly process the data of such persons.
2. Individual processing activities
2.1. Registration
Registration is required to use the Application. During registration the User provides identifying data once, so they do not have to enter them again at every use.
- Purpose of processing: identification and differentiation of the User; establishment and maintenance of the contractual relationship; enabling use of the Application.
- Legal basis: performance of a contract, GDPR Article 6(1)(b).
- Categories of personal data processed: display name, email address, password (stored in encrypted form), date of registration, date of last login.
- Retention period: duration of the active account plus 30 days after receipt of a deletion request (security recovery window). After those 30 days the registration data is irreversibly deleted.
- Consequences of not registering: the services of the Application cannot be used.
2.2. Recording and storage of meter readings
While using the Application the User records meter readings, which the Service Provider stores linked to the User's account and makes available to the User on the web interface at my.snapmeter.app.
- Purpose of processing: storage and display of the meter readings recorded by the User, and preparation of consumption statistics, as a core function of the Service.
- Legal basis: performance of a contract, GDPR Article 6(1)(b).
- Categories of personal data processed: meter identifier, meter reading value (e.g. kWh, m³), timestamp of recording, optional link to a photograph, link to the User.
- Retention period: duration of the active account plus 30 days after receipt of a deletion request. Where a statutory obligation applies (e.g. Section 169 of the Accounting Act – 8-year retention of accounting vouchers), the affected data is retained for the period required by law, solely for that statutory purpose.
Please note, in particular for household Users, that meter-reading data may indirectly reveal lifestyle or property-usage patterns over longer periods, and therefore may qualify as personal data under the GDPR. The Service Provider does not transfer this data to third parties other than as set out in this Policy.
2.3. Taking and storing photographs – as a core function of the Service
When recording a meter reading, the User may take a photograph of the meter. The Service Provider stores the photograph on the server identified in this Policy and displays it to the User on the web interface.
- Purpose of processing: photographic corroboration of the meter reading, evidential value in disputes, and support of the User's own records.
- Legal basis: performance of a contract, GDPR Article 6(1)(b).
- Categories of personal data processed: photograph of the meter, timestamp of recording, link to the meter reading and to the User.
- Retention period: duration of the active account plus 30 days after receipt of a deletion request.
Technical and organisational measures: The Service Provider endeavours to ensure that photographs contain only the meter. The Service Provider operates a review process for uploaded photographs; if content unrelated to the meter is detected in a photograph (e.g. faces, identifiable household details), the photograph is deleted, or the irrelevant portion removed, without delay and no later than 30 days.
User responsibility: Please endeavour to take photographs that do not contain anything beyond the meter (in particular, faces of individuals or identifiable household objects). However, the Service Provider does not shift all responsibility to the User and also ensures the necessary level of data protection through its own technical measures.
2.4. Use of photographs to develop the character-recognition (OCR) model
To continuously improve the accuracy of the Service and the User experience, the Service Provider may use photographs taken of meters to train and develop the character-recognition (OCR) model.
- Purpose of processing: development of the Application's OCR model and improvement of its accuracy.
- Legal basis: legitimate interests of the Service Provider, GDPR Article 6(1)(f).
- Summary of the balancing test: The Service Provider has a legitimate interest in continuously improving the quality of the Service, since this is a prerequisite of its core business and directly serves the interests of Users as well (more accurate readings). The balancing considered that (i) photographs are taken exclusively of meters, (ii) during training the link between the photograph and the identifiable User is severed, and (iii) technical measures ensure the training data does not contain identifying information beyond the meter itself. The Service Provider concluded that the rights and freedoms of data subjects are not disproportionately affected given these measures.
- Categories of data processed: photographs of meters, in anonymised (non-User-linked) form.
- Retention period: for the lifetime of the model, up to a maximum of 5 years, after which the data is deleted from the training dataset.
Right to object: The User may object to processing based on this legitimate interest at any time and without giving reasons, by contacting hello@snapmeter.app. Upon objection, the Service Provider removes the User's photographs from the training dataset within 30 days and does not use them for this purpose thereafter. Individual images cannot be removed from models that have already been trained; the model neither stores nor reproduces the images used for training, and the training data is anonymised and contains no identifying information. Objection does not affect the core use of the Application.
2.5. Use of photographs for marketing purposes (opt-in)
The Service Provider uses photographs of meters for marketing purposes (the Service Provider's website, social media, presentations, customer materials) only with the User's explicit, prior and voluntary consent.
- Purpose of processing: presentation of the Service in promotional and marketing materials.
- Legal basis: explicit consent of the data subject, GDPR Article 6(1)(a).
- Giving consent: the User may give consent in the Application settings (or by separate email). Without consent, the Service Provider does not use photographs for marketing purposes. Refusal of consent has no adverse consequences.
- Categories of data processed: the meter photographs covered by the User's consent.
- Retention period: until consent is withdrawn, at most 2 years from the giving of consent. After 2 years the Service Provider requests fresh consent or ceases processing for this purpose.
Withdrawal of consent: The User may withdraw consent at any time and without giving reasons, by contacting hello@snapmeter.app or via the Application settings. Withdrawal does not affect the lawfulness of prior processing and does not affect the core use of the Application. Upon withdrawal the Service Provider removes photographs already published in marketing materials – where technically feasible – within 30 days.
2.6. Internal training use
The Service Provider may also use photographs of meters for the internal training of its staff and for training members of the team developing the Application.
- Purpose of processing: internal training and professional development of the Service Provider's staff.
- Legal basis: legitimate interests of the Service Provider, GDPR Article 6(1)(f).
- Categories of data processed: meter photographs, in anonymised form (link to the User removed).
- Retention period: for the lifetime of the training materials, up to a maximum of 3 years.
Right to object: The User may object to this processing at any time by contacting hello@snapmeter.app.
2.7. Customer-support communications
The Service Provider responds to enquiries received at hello@snapmeter.app and, where necessary, contacts the User at their registered email address.
- Purpose of processing: answering support enquiries and resolving issues.
- Legal basis: performance of a contract (GDPR Article 6(1)(b)) and the legitimate interest of the Service Provider in complaint handling and dispute resolution (GDPR Article 6(1)(f)).
- Categories of data processed: email address, content of the enquiry, content of the replies.
- Retention period: 2 years after the enquiry (for potential later complaints or disputes).
2.8. Account termination and data deletion
Uninstalling the Application from a mobile device does not automatically delete the user profile (account). The User may initiate account deletion by sending a request to hello@snapmeter.app.
Upon receipt of the deletion request, the Service Provider:
- acknowledges receipt of the request within 7 days;
- removes the User's personal data from the system within 30 days;
- confirms the deletion in writing.
Certain data must be retained by the Service Provider for longer periods under statutory obligations (e.g. accounting vouchers for 8 years under Act C of 2000, where the User used a paid service). Such data is retained solely for the statutory purpose and cannot be used for other purposes.
3. Retention summary
| Data category | Retention period |
|---|---|
| Registration data (name, email, password) | Duration of active account + 30 days |
| Meter readings | Duration of active account + 30 days |
| Meter photographs (core service) | Duration of active account + 30 days |
| Photographs for OCR-model training | Up to 5 years, anonymised |
| Photographs for marketing (opt-in) | Until consent is withdrawn, max. 2 years |
| Photographs for internal training | Up to 3 years, anonymised |
| Customer-support correspondence | 2 years after the enquiry |
| Accounting vouchers (for paid service) | 8 years (Section 169 of the Accounting Act) |
Website: advertising measurement cookies (Google Ads)
When you visit snapmeter.app and choose “Accept” in the cookie banner, the website loads the Google tag provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). The tag sets cookies that let the Service Provider measure whether a visit from a Google ad led to a demo request (conversion measurement). If you choose “Reject”, or make no choice, the Google tag is not loaded and no such cookies are set.
- Legal basis: your consent (Article 6(1)(a) GDPR). You can withdraw it at any time with the “Cookie settings” link in the website footer; withdrawal does not affect processing carried out before it.
- Data processed: the Google tag sends Google the ad click identifier (GCLID), Google cookie identifiers, the address of the page viewed, the fact and time of a demo request, and browser and device information. Google also receives your IP address as part of the connection. Your name, email address and the content of the demo request are not sent to Google.
- Retention: Google Ads conversion cookies expire after 90 days. Your cookie choice is stored in your browser until you change it. If a demo request follows an ad click, the click identifier is kept with the request for up to 2 years so that the result can be counted in Google Ads.
- Transfers: Google may process data outside the EEA; such transfers are covered by the EU–US Data Privacy Framework and the Standard Contractual Clauses. Google’s privacy policy: policies.google.com/privacy.
IV. Data transfers and named data processors
The Service Provider, as data controller, is entitled and required to transfer to the competent authorities any personal data properly held by it where such transfer is required by law or by a binding authority decision. The controller cannot be held liable for such transfers or their consequences.
Any data transfer not indicated above is carried out by the Service Provider only with the prior and informed consent of the User.
The Service Provider uses the following data processors:
1. Hosting provider
- Name: Microsoft Ireland Operations Limited
- Registered seat: One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland
- Processing activity: provision of Microsoft Azure cloud infrastructure for storing the Application and its data
- Storage location: European Union (Ireland); data does not leave the European Economic Area (EEA)
- The Service Provider has a valid Data Processing Agreement (DPA) with Microsoft. Where Microsoft engages a sub-processor located outside the EEA, Microsoft ensures appropriate safeguards through the Standard Contractual Clauses (SCCs) adopted by the European Commission.
2. Other data processors
The Service Provider may engage other data processors from time to time (e.g. newsletter providers, analytics tools). The current list of engaged data processors is made available by the Service Provider on the User's request at any time.
V. Manner of storing personal data and security of processing
1. The Service Provider's computing systems and other storage locations are maintained at its data processors. Cloud services are provided by the Service Provider at https://my.snapmeter.app. Data is not transferred outside the EEA.
2. The Service Provider selects and operates the IT tools used to process personal data in a way that ensures the processed data:
- a) is accessible to those authorised (availability);
- b) is authentic and verifiable (authenticity of processing);
- c) can be shown to be unchanged (integrity);
- d) is protected against unauthorised access (confidentiality).
3. The Service Provider protects data with appropriate measures – in particular against unauthorised access, alteration, transfer, disclosure, deletion or destruction, and accidental loss or damage.
4. The Service Provider stores passwords in a non-reversible (hash) form. Access to the system is logged.
5. The IT systems of the Service Provider and its partners are protected against fraud, espionage, sabotage, vandalism, computer viruses, intrusion and other attacks. The operator ensures security through server-level and application-level protection procedures.
6. Electronic messages transmitted over the internet are vulnerable to network threats. The Service Provider takes every precaution that can reasonably be expected against such threats; however, the Service Provider is not liable for damage caused by unavoidable attacks despite the exercise of the greatest possible care.
Personal-data breach
In the event of a personal-data breach, the Service Provider notifies the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) in accordance with Article 33 of the GDPR without undue delay and no later than 72 hours after becoming aware, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the breach is likely to result in a high risk to the rights and freedoms of data subjects, the Service Provider also notifies the affected data subjects directly. The Service Provider maintains an internal breach register.
VI. Remedies and enforcement
1. Rights of the data subject
Data subjects may exercise the following rights via the contact details set out in Section I of this Policy:
- Right of access (GDPR Article 15) – information on what data the Service Provider processes about them;
- Right to rectification (Article 16) – correction of inaccurate data;
- Right to erasure / "right to be forgotten" (Article 17) – in certain cases, the right to request deletion of data;
- Right to restriction of processing (Article 18);
- Right to data portability (Article 20) – receiving data in a structured, commonly used, machine-readable format;
- Right to object to processing based on legitimate interest (Article 21);
- Right to withdraw consent (Article 7(3)).
The Service Provider responds to a data subject's request without undue delay and in any event within one month (30 days) of receipt. For complex or numerous requests this period may be extended by a further 2 months; in that case the Service Provider informs the data subject of the reasons for the extension within the first month of receipt. Providing information is free of charge.
2. Right to a judicial remedy
A data subject whose rights are infringed may bring an action against the data controller before a court. The court handles the matter out of turn. The data subject may choose to file the action with the court at their place of residence or their place of stay. A list of Hungarian courts is available at https://birosag.hu/torvenyszekek.
3. Proceedings before the supervisory authority
A complaint may be lodged with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH):
- Name: National Authority for Data Protection and Freedom of Information
- Address: 1055 Budapest, Falk Miksa utca 9-11., Hungary
- Mailing address: 1363 Budapest, Pf. 9., Hungary
- Phone: +36-1-391-1400
- Email: ugyfelszolgalat@naih.hu
- Website: www.naih.hu
VII. Minors
The services of the Application may only be used by natural persons who have reached the age of 18. The Service Provider does not knowingly process personal data of persons under the age of 18. If the Service Provider becomes aware that it is processing data of a person under 18, it deletes that data without delay.
VIII. Final provisions
This Privacy Policy (version 2.1) takes effect on 3 October 2026. The Service Provider retains previous versions in its internal records.
If the Policy is amended, the Service Provider publishes the amended text on its website and notifies Users of material changes by separate email.
Nodum Kft.
3 October 2026.