← Back

Privacy Policy

Effective: July 14, 2026

Climbing Log (originally “Mászóedzés”) is an indoor climbing-logging app and its accompanying website at climbdiary.com. This policy explains what personal data the Provider processes when you use the Service, for what purpose and on what legal basis, for how long, with whom it is shared, and what rights you have. Processing is carried out in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (the General Data Protection Regulation, “GDPR”) and Hungarian Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information (the “Privacy Act”).

1. Data controller (the Provider)

  • Adattenger Korlátolt Felelősségű Társaság (Adattenger Kft.)
  • Registered seat: 1118 Budapest, Hegyalja út 72. 2. em. 2., Hungary
  • Company reg. no.: 01-09-396525 (Fővárosi Törvényszék Cégbírósága)
  • Tax number: 27752896-2-43
  • EU VAT number: HU27752896
  • Represented by: Mester Tamás
  • Email: tomi@data36.com

The Provider does not carry out processing that would require the mandatory appointment of a Data Protection Officer (DPO).

2. Data processed: purpose, legal basis and retention

Account data

Data:
Email address, name, and — if the sign-in provider supplies it — a profile picture. When signing in with Apple you may choose to hide your email address (Apple private relay address).
Purpose:
Creating and identifying your account, enabling sign-in, and providing the Service.
Legal basis:
GDPR Article 6(1)(b) — performance of the contract with the user (provision of the Service).
Retention:
For the lifetime of the account; permanently deleted when the account is deleted, or at the latest 4 years after your last sign-in.

Training data

Data:
The climbs you log: date, gym name, grades, number of attempts, style, character tags, notes and session reviews.
Purpose:
Displaying your own training and aggregating it into statistics.
Legal basis:
GDPR Article 6(1)(b) — performance of the contract (provision of the Service).
Retention:
For the lifetime of the account; permanently deleted together with the account.

Technical data

Data:
Operational logs automatically recorded by the server, IP address, and the time of the request.
Purpose:
Secure and reliable operation of the Service, troubleshooting, and abuse prevention.
Legal basis:
GDPR Article 6(1)(f) — the Provider’s legitimate interest (system security and operation).
Retention:
For a short period, typically no longer than 30 days.

3. Source of the data

Account data comes from you and from the provider you choose to sign in with (Google or Apple); with email-link sign-in you provide it yourself. Training data is entered by you. The Provider does not buy or collect personal data from third parties for marketing purposes.

4. Data processors

The Provider uses the following data processors to operate the Service. We do not sell your data to third parties.

  • DigitalOcean, LLC (hosting provider)105 Edgeview Drive, Suite 425, Broomfield, CO 80021, USA — operation of the Service’s server. Privacy policy
  • Sendinblue SAS (Brevo)106 Boulevard Haussmann, 75008 Paris, France — delivery of single-use sign-in emails. Privacy policy
  • Google Ireland LimitedGordon House, Barrow Street, Dublin 4, Ireland — “Sign in with Google” authentication. Privacy policy
  • Apple Distribution International Ltd.Hollyhill Industrial Estate, Hollyhill, Cork, Ireland — “Sign in with Apple” authentication. Privacy policy

Where a data processor processes data outside the European Economic Area, the transfer takes place with appropriate safeguards under the GDPR (e.g. the European Commission’s Standard Contractual Clauses or an adequacy decision).

5. Cookies

The website uses only the technically essential session cookie required to keep you signed in. The Service does not use advertising or analytics tracking cookies, and contains no third-party analytics system.

6. Data security

The Provider applies reasonable technical and organisational measures to protect data: traffic runs over an encrypted connection (HTTPS), access is restricted, and sign-in tokens are stored securely. In the event of a data breach, the Provider acts in accordance with Articles 33–34 of the GDPR.

7. Your rights

In connection with the processing you have the following rights:

  • access to the data held about you (GDPR Article 15);
  • rectification (GDPR Article 16);
  • erasure, the “right to be forgotten” (GDPR Article 17);
  • restriction of processing (GDPR Article 18);
  • data portability (GDPR Article 20);
  • objection to processing based on legitimate interest (GDPR Article 21).

You can submit a request at tomi@data36.com; we will respond without undue delay and at the latest within one month. You can also permanently delete your account and all your training data yourself at any time in the app via Profile → Delete profile.

8. Protection of minors

The Service is not intended for children. We process the data of a person under 16 only with the consent of the holder of parental responsibility (GDPR Article 8). We do not knowingly collect data from anyone under 13.

9. Remedies

If you believe that the processing of your data is unlawful, please contact us first at tomi@data36.com. You may also lodge a complaint with the supervisory authority:

  • Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH — the Hungarian Data Protection Authority)
  • Address: 1055 Budapest, Falk Miksa utca 9-11., Hungary
  • Postal address: 1363 Budapest, Pf.: 9.
  • Phone: +36 (1) 391-1400
  • Email: ugyfelszolgalat@naih.hu
  • Web: naih.hu

You may also take the matter to court; proceedings may be brought before the court of the place where you live or stay (GDPR Article 79, Privacy Act).

10. Changes to this policy

The Provider may amend this policy from time to time; the current version is published on this page with its effective date.

See also: Terms of Use · Support