Privacy Policy – M2Opinion App and m2opinion.com Website
1. Data Controller Information
Name: APPON LINE Kft.
Registered Office: 2120 Dunakeszi, Római utca 1/1, Hungary
Company Registration Number: 13-09-229851
Tax Number: 23137631-2-13
E-mail: info@appon.hu
Website: https://www.appon.hu
Hereinafter referred to as the Data Controller.
2. Purpose of Data Processing
The purpose of the M2Opinion application and the m2opinion.com website is to analyze users’ laboratory reports and outpatient records using artificial intelligence, and to generate textual evaluations, summaries, or recommendations based on this analysis.
3. Legal Basis for Data Processing
The legal basis for data processing is the user’s voluntary consent under Article 6(1)(a) of Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR).
In addition, data processing may also be based on the legitimate interests of the Data Controller (e.g., to ensure service security, perform error corrections, or carry out statistical analyses).
4. Scope of Data Processed
During registration and use of the application, the following personal data may be provided:
- name
- e-mail address
- billing address (only in case of paid services)
- date of birth
The content created within the application (texts, feedback, evaluations, etc.) is processed by the Data Controller’s systems, but no personally identifiable data are transferred to the artificial intelligence service provider.
5. Data Transfer and Depersonalization
Files and content uploaded to the M2Opinion application are depersonalized by the Data Controller’s system, meaning that all personally identifiable information (such as name, e-mail, date of birth, address, etc.) is removed or replaced before being transmitted for processing to the artificial intelligence system.
Data Processor:
OpenAI, L.L.C.
Address: 3180 18th Street, San Francisco, CA 94110, USA
Website: https://openai.com/privacy
Data transfers are carried out under the EU–U.S. Data Privacy Framework, approved by the European Union.
6. Duration of Data Storage
Personal data provided during registration are retained by the Data Controller for as long as the user account remains active.
Uploaded medical reports are stored only for the duration of the analysis process and are encrypted during that time.
After evaluation, all source files are immediately deleted.
Users may request account deletion at any time via e-mail (support@m2opinion.com) or through the contact form on the m2opinion.com website.
After an account is deleted, all personal data are permanently removed from the system within 30 days.
7. Data Security
The Data Controller applies all reasonable technical and organizational measures to ensure data security, including:
- encrypted data transmission (HTTPS)
- secure servers and password protection
- restricted access permissions
- regular data backups
8. Rights of the Data Subject
Users have the right to:
- request information about data processing,
- request rectification or erasure of their data,
- request restriction of processing,
- object to data processing, and
- request data portability.
The Data Controller will fulfill such requests as soon as possible, but no later than within 30 days.
9. Right to Lodge a Complaint
If the user believes that their data are being processed unlawfully, they may file a complaint with the following authority:
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address: 1055 Budapest, Falk Miksa utca 9–11.
Postal address: 1363 Budapest, Pf. 9.
Website: https://naih.hu
10. Final Provisions
The Data Controller reserves the right to modify this Privacy Policy at any time.
The revised version will be published on the website.
Effective as of: October 1, 2025