Privacy Policy
Controller: Zero One Concept Kft. Service: MetricMatch sports analytics platform (metricmatch.net, app.metricmatch.net)
Version: 1.1 — DRAFT Effective from: 29 July 2026
1. Who processes your data
| Controller | Zero One Concept Kft. |
| Registered seat | 1054 Budapest, Honvéd utca 8. 1. em. 2. ajtó, Hungary |
| Company registration number | Cg. 01-09-190128 |
| Tax number | 24933090-1-41 |
| Represented by | Gábor Hegedüs, managing director |
| support@metricmatch.net | |
| Data protection matters | support@metricmatch.net |
We have not appointed a Data Protection Officer. Article 37 GDPR requires one where the core activity involves regular and systematic monitoring of data subjects on a large scale, or large-scale processing of special categories of data. Our core activity is the analysis of public sports market data; the set of user data is narrow and contains no special categories.
2. The principle behind the system
One thing is worth knowing first, because it shapes the whole architecture:
No financial data enters the system. In the bet journal, stakes are stored as percentages only, never as monetary amounts. The statistics work exactly the same, but we never learn your bankroll or the size of your bets. Card details are handled by the payment provider, not by us — we never see or store a full card number.
3. What we process, why, on what basis, for how long
3.1 Account data
| Data | e-mail address, password (as an irreversible cryptographic hash only), name, country, chosen package and sports, subscription expiry, registration date |
| Purpose | creating and operating your account, providing the Service, sign-in |
| Legal basis | performance of a contract — Art. 6(1)(b) GDPR |
| Retention | until the account is deleted; afterwards for up to 5 years solely for legal claims (general limitation period under Hungarian law), then erased |
| If not provided | an account cannot be created |
3.2 Billing and contract data
| Data | name, billing address, country; for businesses: company name, VAT number, registration number, representative; order details, amount paid |
| Purpose | issuing invoices, keeping accounting records, tax obligations |
| Legal basis | legal obligation — Art. 6(1)(c); Hungarian Accounting Act (Act C of 2000) Section 169, VAT Act |
| Retention | 8 years from the accounting document. This is mandatory: you may ask for erasure, but we cannot comply before the period expires |
3.3 Payment data
| Data | the customer identifier created at the payment provider, transaction status and amount. We do not receive or store full card numbers. |
| Purpose | collecting the subscription fee, renewal, refunds |
| Legal basis | performance of a contract — Art. 6(1)(b) |
| Retention | in line with the accounting retention period, 8 years |
There are two payment routes, and which one applies depends on where you placed your order:
| Where you ordered | Who processes the payment |
|---|---|
on our own website (metricmatch.net, app.metricmatch.net) | Stripe Payments Europe, Ltd. (Ireland) — https://stripe.com/privacy |
| on the Whop marketplace | Whop Inc. (United States) — https://whop.com/privacy |
Both also act as independent controllers under their own privacy policies. In the case of Whop, the provider may also act as merchant of record for tax purposes and settles EU consumer VAT through the One Stop Shop scheme.
The contract for the Service is in every case between you and Zero One Concept Kft. — the identity of the payment provider does not change that. Withdrawal, cancellation and refunds are therefore handled by us on both routes, through the same pages.
3.4 Bet journal
| Data | sport, match, outcome, bookmaker, odds, stake as a percentage (no monetary amount), status, result, recording timestamp, note |
| Purpose | letting you record and statistically evaluate the wagers you placed elsewhere |
| Legal basis | performance of a contract — Art. 6(1)(b) |
| Retention | until the account ends; exportable for 30 days after that, then erased or anonymised |
Aggregated, anonymised use. We use journal data in aggregated form, not attributable to any person, to measure and improve the accuracy of the Service. The aggregation does not permit re-identification, and we do not ask for separate consent, because anonymised data is no longer personal data.
3.5 Nickname and public card
| Data | the nickname you choose, the number of verified entries, aggregate accuracy measures |
| Purpose | displaying the public card at metricmatch.net/u/<nickname> |
| Legal basis | consent — Art. 6(1)(a) |
| Retention | until consent is withdrawn |
The card contains no name, e-mail address, individual wager, stake size or monetary amount. You can withdraw consent at any time and without consequence by turning sharing off; the page then becomes unavailable immediately. Withdrawal does not affect the lawfulness of processing before it, and we have no control over copies anyone may have saved of the public page in the meantime.
3.6 Telegram identifier
| Data | the numeric identifier of your Telegram account, only if you connect it |
| Purpose | sending notifications and providing access to the closed channel |
| Legal basis | performance of a contract — Art. 6(1)(b) |
| Retention | until you disconnect it, or the account is deleted |
Telegram Messenger is an independent controller; its own policy also applies to communication through it.
3.7 Operational event log
| Data | event type (registration, order started, payment, cancellation), timestamp, e-mail address, amount, technical details |
| Purpose | monitoring operation, debugging, abuse and fraud prevention, business reporting |
| Legal basis | legitimate interest — Art. 6(1)(f) |
| The interest | operating the Service reliably and detecting payment abuse; the log is narrow, is not used for profiling, and produces no legal effect for the data subject |
| Retention | 24 months |
3.8 Register of declarations (withdrawal, cancellation)
| Data | reference number, type of declaration, e-mail address, name, contract reference, reason, timestamp of receipt |
| Purpose | evidencing receipt of a withdrawal or cancellation, meeting the 14-day refund deadline |
| Legal basis | legal obligation — Art. 6(1)(c), and legal claims — Art. 6(1)(f) |
| Retention | 5 years — the limitation period. These rows are never erased automatically, because their whole purpose is to prove something later |
We deliberately do not store an IP address or browser fingerprint here: the timestamp and the e-mail address are enough to prove the declaration; anything more would be unnecessary collection.
3.9 Server and security logs
| Data | IP address, request time, page requested, error codes |
| Purpose | operation, debugging, defending against attacks |
| Legal basis | legitimate interest — Art. 6(1)(f): security of the system and of user data |
| Retention | 30 days; in the event of a security incident, until it is closed |
3.10 Support correspondence
| Data | what you write, and your e-mail address |
| Purpose | answering your enquiry, handling complaints |
| Legal basis | performance of a contract, or for complaints legal obligation (Hungarian Consumer Protection Act) |
| Retention | 5 years for complaints as required by law, otherwise 2 years |
4. What we do NOT do
Worth stating, because each of these is common in comparable services:
- No analytics or marketing cookies — no Google Analytics, no Facebook
pixel, no heatmaps, no session recording.
- We do not sell or rent personal data.
- We send no advertising about wagering activity, and carry no bookmaker
advertising.
- No automated individual decision-making within the meaning of Art. 22
GDPR. Analytical outputs are information on which you decide; they produce no legal effect concerning you.
- No special categories of data (health, biometric, beliefs, etc.) are
processed, and none are requested.
5. Who has access (processors and recipients)
| Who | What they do | Where | Basis |
|---|---|---|---|
| Hetzner Online GmbH | hosting, server operation | Germany / Finland (EU) | data processing agreement |
| Stripe Payments Europe, Ltd. | payment processing for orders placed on our own website | Ireland; also the US within the group | Chapter V safeguards (standard contractual clauses / EU-US Data Privacy Framework) |
| Whop Inc. | payment processing and access management for orders placed on the Whop marketplace; also merchant of record for tax purposes | USA | Chapter V safeguards |
| Telegram Messenger | notifications — only if you connect it | international | independent controller |
| Google LLC (Google Fonts) | serving typefaces | USA | see Section 5.1 |
| Accountant / auditor | accounting records | Hungary | legal obligation |
| Authorities, courts | disclosure required by law | — | legal obligation |
Internally, only the managing director has access, to the extent necessary.
5.1 Google Fonts — plain disclosure
The website and the terminal currently load typefaces from Google's servers (fonts.googleapis.com, fonts.gstatic.com). This means that when the page opens, your IP address is transmitted to Google, a US company. This is not a cookie but a technical connection, and it cannot be made subject to prior consent without breaking the appearance of the page.
We intend to replace this: the typefaces will be served from our own server, after which no data is transmitted to any third party when a page opens. Until that is done, we state the fact here — silence would be the problem, not the typeface.
6. Transfers to third countries
Data is processed primarily within the European Union. There are two exceptions, both listed in the table above: intra-group flows at the payment provider, and the serving of typefaces. In both cases Chapter V GDPR safeguards apply (standard contractual clauses, and certification under the EU-US Data Privacy Framework respectively).
7. Your rights
You may exercise the following rights at any time, free of charge — write to support@metricmatch.net. We respond within one month; in complex cases this may be extended by two months, of which we will inform you.
| Right | What it means | Limit |
|---|---|---|
| Access (Art. 15) | information about what we process, and a copy | — |
| Rectification (Art. 16) | correcting inaccurate data | — |
| Erasure (Art. 17) | the "right to be forgotten" | not applicable to accounting data for 8 years, nor to the register of declarations for 5 years |
| Restriction (Art. 18) | "freezing" data during a dispute | — |
| Portability (Art. 20) | machine-readable export, including to another provider | for data based on contract and consent |
| Objection (Art. 21) | against processing based on legitimate interest | we weigh it, and stop unless we have compelling grounds |
| Withdrawal of consent (Art. 7) | turning the public card off | does not affect processing before withdrawal |
Permanent deletion of your account may be requested at any time — we will do it promptly and without argument, within the mandatory retention periods above.
7.1 Where to complain
Hungarian National Authority for Data Protection and Freedom of Information (NAIH) 1055 Budapest, Falk Miksa utca 9-11., Hungary · Postal: 1363 Budapest, Pf. 9. Phone: +36 1 391-1400 · E-mail: ugyfelszolgalat@naih.hu · https://naih.hu
If you live in another EEA state, you may also turn to the supervisory authority of your own residence. You may also go to court, including the court of your own domicile.
8. Security
- Passwords are never stored in readable form, only as a modern,
irreversible hash.
- All connections are encrypted (HTTPS).
- The authentication cookie is signed,
HttpOnly, andSecurein production. - Secrets (API keys, payment keys) exist only in the server's environment
variables; they are in neither the source code nor the backups.
- Regular backups, restricted access, logging.
In the event of a personal data breach we notify NAIH within 72 hours of becoming aware, and if the breach is likely to result in a high risk to your rights, we inform you directly as well.
9. Children
The Service is not available to anyone under 18. We do not knowingly collect data from minors. If such data reaches us we erase it without delay — please tell us at support@metricmatch.net.
10. Changes to this policy
We may amend this policy following a change in law or in the Service. We notify you of any material amendment at the e-mail address on your account at least 30 days in advance. The current text is available at metricmatch.net/privacy, with its version number and effective date.
Document ends. Version 1.0 draft — pending legal review.