Who is the data controller?
The Hungarian Kidney Foundation, (“the HKF“) and Blaguss Ltd. (1053 Budapest, Petőfi Sándor utca 11. 2. em. 6., e-mail: email@example.com, “Blaguss“) act as joint controllers of your personal data, because the HKF and Blaguss (jointly referred to as “we” or “us“) are jointly organizing and have shared responsibilities regarding the organization of the 27th BNS. Please note that where possible, we indicated the various data processing activities carried out by each data controller for which they bear separate responsibility.
What kind of personal data do we process?
Personal data may be provided to us by you, 27th BNS participants, faculty members, accompanying persons, and their employers’ or their contact persons.
Such personal data may broadly be grouped into the following categories:
- Identification data, such as name, date and place of birth, mother’s maiden name, maiden name, title and country of origin / nationality;
- Contact details, such as address, e-mail address, fax number and telephone number;
- Job related information, such as company name, employer/company, position, professional identification details, memberships in chambers and other associations, spoken languages;
- Congress program choices: the 27th BNS program choices of the participants, the services provided to you and the timing, description and recipients of the related economic transactions, including accommodation, social programs, optional tours and other related data;
- Banking and invoicing details, such as bank account number, payment and invoicing details;
- Communication details, such as email content, business letter content;
- Dietary choices information relating to meals offered during the 27th BNS (and this may also include sensitive data);
- Photographs, video recordings and audio recordings of your voice, image, actual or simulated likeness, and of other personal characteristics.
The provision of personal data is always voluntary. However, if you do not provide the information indicated above or on the registration sheet as mandatory, we may not be able to process your application to the Congress or comply with your request.
What are the sources of personal data that we process?
In most of the cases, we receive the above personal data from the persons / organisations registering for the 27th BNS.
The Purposes of the Data Processing:
The purposes for which we collect and use your personal data are set out below:
|Why We Collect and Use Personal Data
(responsible data controller)
|Personal Data Categories
|Manage your application to and participation at the 27th BNS (Blaguss and the HKF)
|Manage your Invitation Letter for visa purposes (Blaguss)
|Communications with you in respect of the 27th BNS (Blaguss and the HKF)
|Communications with you in respect of other services and events provided by or organized by the HKF and/or its partners (the HKF)
|Carrying on, managing and administering the proper organisation of the Congress, including data sharing among the HKF and Blaguss and with other third parties, such as hotels, catering companies and other third parties
(Blaguss and the HKF)
|Making and publishing photos for general promotional purposes of the 27th BNS (the HKF)
|Compliance with our accounting and taxation obligations (Blaguss and the HKF)
|Fulfill dietary requests (Blaguss)
|Comply with legal requests and answer to potential legal claims (Blaguss and the HKF)
Legal Bases for Data Processing
The legal grounds we are most likely to rely on for processing data in relation to you are outlined below:
- Consent  : The HKF may process data if and to the extent you have given specific consent to the processing of your data. The HKF asks for your consent so that it may use and publish your photo, for general promotional purposes of the 27th BNS or to inform you about the same or similar events held in the future. The provision of personal data is voluntary and this activity is carried out by the HKF only. If we have relied on consent as grounds for processing, you may withdraw your consent at any time – though, if you do so, that will not affect the lawfulness of our actions prior to your withdrawal of consent.
- Performance of Contract  : we rely on this legal basis if our data processing is necessary for performance of a contract with you or to take steps at your request to enter into a contract. This covers carrying out our contractual duties and exercising our contractual rights, including the registration and participation in 27th BNS programs and the organisation of accommodation and activities, including the provision of your data to other third parties, such as hotels, catering companies, tour guides and other third parties. If you do not provide the necessary information, your participation in the relevant programs might be delayed or be impossible.
- Legal obligation  : we process data if necessary to comply with our legal and regulatory obligations, such as, for example, to comply with tax reporting and accounting data retention obligations.
- Legitimate Interests : we rely on legitimate interest if processing is necessary for our or a third party’s legitimate purposes. We, or a third party, have legitimate interests in carrying on, managing and administering our respective operations effectively and properly, and, in connection with those interests, processing your data. We may process your data to communicate with you or to share personal data among the HKF and Blaguss to manage the 27th BNS effectively. Your data will not be processed on this basis if our or a third party’s interests are overridden by your own interests, rights and freedoms.
We will only process sensitive personal data about you if one or more of the grounds for processing sensitive personal data applies. The additional legal grounds we are most likely to rely on for processing sensitive personal data in relation to you are outlined below:
- Consent: You have given explicit consent to the processing of your dietary choices information, which may contain sensitive personal data on health (such as diabetes) or religious personal data (such as your preference regarding kosher meals). If we have relied on consent as grounds for processing, you may withdraw consent at any time – though, if you do so, that will not affect the lawfulness of our actions prior to your withdrawal of consent.
- Legal claims: Processing is necessary for the purpose of establishing, making or defending legal claims. Those could be legal claims made by ourselves or you or by others.
By providing personal data of your accompanying person or contact person to us, you warrant that:
- you have been authorized by that person(s) to provide such data;
- you will provide us with any updates or changes to that personal data, and you will fully indemnify and hold us harmless from and against any related claims and other consequences.
Our legitimate interests to process personal data
|Legitimate interest test
|Manage the participant’s or accompanying persons’ application to and participation at the 27th BNS, including the communications with them
|We have a legitimate interest to perform our obligations and exercise our rights relating to participant’s, faculty members’, or accompanying persons’ application to and participation at the 27th BNS, including any communications with participants, faculty members, accompanying persons and their contact persons and sharing participant’s, faculty members’ or accompanying persons’ personal details with service providers of the 27th BNS.
|Carrying on, managing and administering the proper organisation of the 27th BNS, including data sharing among the HKF and Blaguss
|The HKF and Blaguss are jointly organizing and have shared responsibilities regarding the organization of the 27th BNS. For this purpose, we have a legitimate interest to share personal data of the 27th BNS participants, faculty members and accompanying persons to manage and administer the proper organisation of the 27th BNS and the 27th BNS programs.
|Comply with legal requests and answer to potential legal claims
|We have a legitimate interest process personal data for any legal claims made by ourselves or you or by others.
We have established that we have a prevailing legitimate interest to process your personal data. If you need more detailed information on our legitimate interests and the legitimate interest test’s results, please contact us via e-mail at firstname.lastname@example.org
Who may have access to personal data?
Within the HKF and Blaguss only the officers and persons responsible for the 27th BNS organization may have access to your data on a “need to know” basis.
We may share personal data with third parties, the providers of services who are involved into the provision of contractual services (hotels, restaurants, accreditation entities, providers of printing services, tour guides, web developers, etc.). For a full and up-to-date list of these recipients, please write to email@example.com
International data transfers
Personal data are usually not, but as an exception, may be provided to parties (such as our service providers) that are located outside the European Economic Area (“EEA”). In such cases, we will ensure that the personal data is subject to measures that provide an equivalent level of protection as provided by data privacy laws in the EU (such as the EU General Data Protection Regulation; GDPR). Please contact us via the e-mail at firstname.lastname@example.org if you would like to receive from us the copy of these measures that secure the adequacy of personal data transfers abroad.
How long do we retain personal data?
Personal data is stored by us or by our IT hosting providers on our behalf, but only as long as necessary for the performance of our obligations and strictly for the time necessary to achieve the purposes for which the information was obtained. The personal data will be removed from our records or properly anonymized when it is no longer needed. We will retain your data during the supplier’s business relationship with us until the statute of limitations under civil laws (i.e. 5 years). Under Section 169 of the Act on Accounting and other tax related legislation, at least eight years statutory data retention obligation applies to personal data in accounting documents, including contracts, communication and business correspondence. However, access to such personal data will then be highly restricted.
What are the rights of private individuals?
Considering that we (the HKF and Blaguss) are joint controllers of personal data, we are jointly responsible for the compliance with your data subject rights indicated in this section.
A consent given to us to keep or otherwise use personal data can always be withdrawn. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. In addition, you will be entitled to the following:
- Right of access: You have the right to obtain from us confirmation as to whether or not personal data concerning you is being processed, and, where that is the case, to request access to the personal data. The access information includes – inter alia – the purposes of the processing, the categories of personal data concerned, and the recipients or categories of recipients to whom the personal data have been or will be disclosed. You have the right to obtain a copy of the personal data undergoing processing. For additional copies requested by you, we may charge a reasonable fee based on administrative costs.
- Right to rectification: We are required to rectify inaccurate personal data, or to complete personal data that is incomplete, on request.
- Right to erasure (right to be forgotten): You have the right to ask us to erase your personal data.
- Right to restriction of processing: You have the right to request the restriction of processing your personal data. In this case, the respective data will be marked and may only be processed by us for certain purposes.
- Right to data portability: You have the right to receive the personal data concerning you which you have provided to us in a structured, commonly used and machine-readable format and you have the right to transmit those personal data to another entity without hindrance from us.
- Right to object: You have the right to object, on grounds relating to your particular situation, at any time to the processing of your personal data by us and we can be required to no longer process your personal data. If you have a right to object and you exercise this right, and your objection is substantiated, your personal data will no longer be processed for such purposes by us. Exercising this right will not incur any costs. Such a right to object may not exist, in particular, if the processing of your personal data is necessary to take steps prior to entering into a contract or to perform a contract already concluded.
- Right to complaint: In case of complaints you also have the right to lodge a complaint with the competent supervisory authority, in particular in the Member State of your habitual residence or alleged infringement of the GDPR. If you reside in Hungary, that is the Hungarian Data Protection and Freedom of Information Authority (address: 1126 Budapest, Szilágyi Erzsébet fasor 22/C., Telephone: +36-1-391-1400, Telefax: +36-1-391-1410, e-mail: ügyfelszolgalat@naih.hu). Before contacting the authority or taking legal action, we would highly appreciate it if you first contacted us so that we may address and resolve any issues promptly. Also, please keep in mind that both Blaguss and the HKF are responsible for their own actions and data processing activities, and we do not bear joint and several liability for each other’s actions and their consequences.
We would be much obliged to provide further information or respond to requests to exercise the rights described above. Such requests addressed to us may be sent either to Blaguss by sending a mail to email@example.com or to HKF by sending an e-mail to firstname.lastname@example.org with “PRIVACY INQUIRY” in its subject. If your concern or request relates to a particular activity and you know the data controller responsible for that specific activity, we should be grateful if you would address that data controller directly.