Privacy Policy
This policy covers the personal data Parasztsuli handles: what you can ask us to do with it, who else it passes through, and how long we keep it. It is meant to be read rather than filed, so each part says not only what happens but why. The website is supported by the Visnyeszéplak Village Preservation and Community Education Association.
Exercising your rights
To ask what data is held about you, to have it corrected, or to have it erased, email the organizer of the event you took part in. They decided the event happened and who was invited, and they are the right first contact. Parasztsuli acts on their instruction for the event's data, and on its own account for the platform itself.
For anything Parasztsuli decided rather than the organizer — how long things are kept, your account, this platform's own terms — or if an organizer does not answer you, write to info@parasztsuli.hu. That one address takes rights requests, privacy questions and support alike, so you never have to work out which of the three you have.
There is deliberately no button here that does this for you. A request to see or delete someone's data has to be checked against the person making it, and a form that skips that check is a way to read a stranger's answers.
When you make a request, we answer without undue delay and within one month at the latest. That period can be extended by up to two further months for a request that is genuinely complex, and if that happens we tell you, and why, within the first month.
You can also ask for a copy of the data you gave Parasztsuli yourself, in a common machine-readable form, or ask us to pass it to another service where that is technically possible.
If you believe your data has been mishandled, you can complain to the supervisory authority. In Hungary that is the National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság), whose contact details are published at naih.hu. You can go to them whether or not you have raised it with us first.
Which of the two of us decided what is set out in who is responsible for your data.
Who else processes your data, and where
Parasztsuli runs on servers hosted by Exoscale. The application, the database, file storage and the upload scanners are our own software running on those servers.
Email is the exception on our side: the messages we send you — confirming your address, invitations, notices about an event — are handed to EmailLabs to deliver. They receive the address the message goes to, its subject and its contents, and whether it arrived. They have no access to anything else we hold about you.
The other exception happens without us touching it at all, because your browser is told to make the request rather than us: the maps shown on event pages load their tiles from CARTO. That request carries your IP address, your browser's user agent, the page you are looking at, and the map coordinates you are looking at. It happens as the page loads, including for visitors who are not signed in.
One more request leaves your browser the same way, but only for the person setting where an event happens. As they type an address into the location picker, or click a point on the map, their browser asks the OpenStreetMap Foundation to turn one into the other — an address into map coordinates, or a point into an address. That request carries their IP address and the address they typed or the point they clicked. Unlike the map tiles above, it does not fire for someone simply viewing an event — only while a location is being chosen, as an event is created or edited.
Cookies
Parasztsuli sets only cookies the site needs to do what you asked of it. There are no advertising cookies, no analytics or tracking cookies, and nothing here is shared with anyone or used to build a profile of you. Every cookie below is set by Parasztsuli itself, not by a third party.
| Cookie | What it does | How long it lasts |
|---|---|---|
sessionid |
Keeps you signed in while you use the site. | Until you sign out, or a spell of inactivity passes. |
csrftoken |
Protects the forms you submit from being forged by another site. | While you are using the site. |
django_language |
Remembers a language you choose, so you are not returned to the default. | Until your browser session ends. |
invite_grant |
Remembers that your browser holds a valid invitation, so you need not open the link again on every page. | Tracks the invitation's own expiry. |
invite_arrival |
A brief marker that carries an invitation from its link to the page it opens. | A couple of minutes. |
guest_identity |
Recognises you as the same guest from page to page, so you can respond without an account. | Up to about a month for a public event; otherwise the invitation's remaining life. |
answered_as_member |
Records only that this browser already answered an event, so the form is not shown again in a loop. | The event's own access period. |
pending_verification |
Reminds you, on a later visit, to check your email and confirm a response you have not yet verified. | As long as the confirmation link itself lasts. |
Most hold only a random identifier or a signed token — never your email or password, and none of them can be read by another site.
You can block or delete cookies in your browser's settings at any time. The ones above are what make signing in, holding an invitation and answering work, so removing them stops those parts of the site working until they are set again.
The map tiles and address lookup described above are the one exception that is not ours: your browser talks to those providers directly, and any cookie they set is theirs, governed by their own policy rather than this one.
How long things are kept
A record created about someone who never signed up is kept until 360 days after the last event they were part of has ended, and is then erased. An account created for someone by an organizer that is never claimed expires 60 days after it was created. Access logs are kept for 30 days.
An access log line is the ordinary trace a web server keeps to run and protect the service — your IP address, the page requested, and when. We use it to keep the service working and secure, not to build a picture of you.
Basis: Civil Code (Polgári Törvénykönyv, “Ptk.”) § 6:22(1), “Elévülés” (Limitation of claims): “Ha e törvény eltérően nem rendelkezik, a követelések öt év alatt évülnek el.” — “Unless otherwise provided by this Act, claims shall lapse in five years.”
Erasure here means your personal details are overwritten and cannot be recovered. The fact that somebody attended an event is not erased, because it is also part of the event's own history and of other people's.
Version 1.0 · Terms of Service · Who is responsible for your data