Privacy notice
Last updated: 20 September 2026
This notice explains how we handle data for visitors to the dietly.hu website and for users of the Dietly! software, under the EU General Data Protection Regulation (GDPR).
1. Data controller
- Name: Gábor Pap, sole trader (trading as: Dietly!)
- Registered seat: 2330 Dunaharaszti, Egry József utca 7, building D, Hungary
- Tax number: 92361063-1-33
- Registration number: 62788496
- Email: gdlabs@outlook.hu
2. The core principle: local storage and offline operation
Patient records, meal plans and recipes entered into Dietly! are stored exclusively on the user’s own computer, encrypted with AES-256 (SQLCipher). On launch, the app verifies that encryption is actually active and refuses to start against an unencrypted database.
We, the developer, never see, collect or store this data in any form: under the GDPR, the data controller for patient data is the dietitian using the software - the developer does not even act as a processor for it.
Sync between machines runs through the user’s own cloud folder (e.g. OneDrive, Google Drive, Dropbox), encrypted end to end - the developer’s servers are not involved at this point either, because there is no central sync server at all.
3. Visiting the website
The dietly.hu website uses no analytics or marketing cookies and stores no visitor data: there is no form on it, no tracking, no embedded social content, and even its typefaces are served from its own server rather than a third party (e.g. Google Fonts). The hosting provider (Netlify, Inc.) may record the IP address and time of a visit as part of standard web-server logging, solely to keep the site running securely (legal basis: legitimate interest, GDPR Art. 6(1)(f)).
4. Software licence check
The app periodically contacts the Microsoft Store to verify licence validity. It sends a fixed product identifier and receives a valid/invalid response; linking that check to a Microsoft account happens entirely inside Microsoft’s own systems, which the developer has no access to (legal basis: performance of a contract, GDPR Art. 6(1)(b)).
5. Bug reports and diagnostics (voluntary)
If you run into a technical problem, the app’s built-in bug-report feature can save an encrypted file of technical logs to your computer. Before that file is created, the app automatically strips out fields that reference personal patient data, and encrypts the content with the developer’s public key, which only the developer can decrypt.
The app never sends this file anywhere on its own - after saving it, it is entirely your choice whether, and how (e.g. by email), to pass it on to the developer. Legal basis: your voluntary consent, given by saving and sending the file (GDPR Art. 6(1)(a)).
6. Security measures
- The software applies local, file-level AES-256 encryption to patient data.
- The software has a built-in automatic screen lock on inactivity, to prevent unauthorised local access.
- All communication with the website (dietly.hu) is encrypted with SSL/TLS.
7. Your rights
Regarding the data we hold about you, you have the right to:
- Request information about the data we hold (right of access).
- Request correction if we hold inaccurate data about you.
- Request erasure ("the right to be forgotten") - except where retention is required by law (e.g. invoicing records).
- Request portability of the data you provided.
- Lodge a complaint with a supervisory authority or bring the matter to court.
8. Patients’ rights
Since patient data exists only with the dietitian using the software, any patient data-protection request (e.g. an export or deletion) must be handled by the dietitian directly - which is why Dietly! includes a built-in, one-click bulk GDPR export and deletion feature for that professional.
9. Recourse
If you believe our data handling is unlawful, Hungarian residents may complain to the National Authority for Data Protection and Freedom of Information (NAIH):
- Address: 1055 Budapest, Falk Miksa utca 9-11, Hungary.
- Postal address: 1363 Budapest, Pf.: 9, Hungary.
- Web: naih.hu
