Privacy Notice
Last updated: 11 September 2026
This Privacy Notice (hereinafter: the “Notice”) describes, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter: the “GDPR”) and other applicable Hungarian and European Union legislation, the circumstances governing the processing of personal data of visitors to the website established to provide information about the HunAIFA (Hungarian AI Factory Antenna) project and available at ________________________ (hereinafter: the “Website”), and of individuals submitting inquiries via the contact form (hereinafter: “Data Subjects” or “Users”).
The Website operator publishes this Notice to clearly inform Users about the processing of their personal data, as well as their rights as Data Subjects and their options for seeking redress. After reading and understanding this Notice, Users decide for themselves whether to provide their personal data. Unless otherwise stated, the provision of data is voluntary.
A condition for browsing and properly using the Website is that the User familiarize themselves with and acknowledge the terms regarding the processing of personal data set forth in this Notice.
The User is liable for any damages and resulting claims arising from the provision of false or inaccurate personal data while using the Website. If the User provides the personal data of a third party (such as contact information), the User is obligated to ensure that they have lawful authorization to disclose such data and that the third party in question receives appropriate information regarding the data processing.
1. Data Controllers
The Website is operated by the HUN-REN Research Institute for Computer Science and Automation (HUN-REN SZTAKI). In handling the professional inquiries described in Section 2.1 of this Notice, HUN-REN SZTAKI and the consortium partners listed below act as joint data controllers pursuant to Article 26 of the GDPR. With regard to the processing of personal data related to cookies and web analytics described in Section 2.2 of this Notice, HUN-REN SZTAKI acts exclusively as the sole data controller. The other consortium partners are not considered joint data controllers with respect to these operations.
The consortium partners (joint data controllers):
| Organization | Role | Address | Website | |
|---|---|---|---|---|
| HUN-REN SZTAKI | Coordinator | 1111 Budapest, Kende Street 13–17. | hunaifa-privacy@sztaki.hu | sztaki.hun-ren.hu |
| HUN-REN Hungarian Research Network (HUN-REN Center) | Partner | 1054 Budapest, Alkotmány utca 29. | — | hun-ren.hu |
| Eötvös Loránd University (ELTE) | Partner | 1053 Budapest, Egyetem tér 1–3. | — | elte.hu |
| HUN-REN Wigner Physics Research Center (Wigner FK) | Partner | 1121 Budapest, Konkoly-Thege Miklós út 29–33. | — | wigner.hu |
| Hungarian Chamber of Commerce and Industry (MKIK) | Partner | 1122 Budapest, Pethényi köz 10. | — | mkik.hu |
| Neumann Technology Platform (NTP) | Associate Partner | 1074 Budapest, Rákóczi út 70–72, 6th floor | — | — |
Primary Data Protection Contact
HUN-REN SZTAKI — hunaifa-privacy@sztaki.hu
1111 Budapest, Kende utca 13–17.
Data Subjects may exercise their rights by contacting the central point of contact or directly through any of the consortium partners.
Data Protection Officer
Contact information for the data protection officer of HUN-REN SZTAKI and the HUN-REN Center: andras.gyorgy@sbgk.hu
Contact information for the Data Protection Officer at ELTE: adatvedelem@elte.hu
Contact information for the Wigner FK Data Protection Officer: dpo@wigner.hun-ren.hu
Contact information for the MKIK Data Protection Officer: dpo@mkik.hu
Contact information for NTP’s Data Protection Officer: deak.jozsef@djsugyvediiroda.hu
Essential Contents of the Joint Data Controller Agreement
The joint data controllers listed in this section jointly determine the purpose and essential means of data processing related to the receipt, evaluation, assignment to a partner, and response to professional inquiries as described in Section 2.1.
Pursuant to the joint data controller agreement, HUN-REN SZTAKI receives the inquiries, operates the shared register, and manages access. The designated partners perform the professional assessment and handle the inquiries assigned to them. SZTAKI is responsible for preparing, updating, and publishing information regarding joint data processing, and coordinates the handling of Data Subject requests, deletions, data security issues, and personal data breaches. Each joint controller is responsible for its own staff, systems, the copies of personal data it processes, and the performance of the tasks assigned to it.
The internal division of responsibilities does not limit the rights of Data Subjects or the responsibilities of the data controllers under the GDPR.
2. Description of Individual Data Processing Activities
2.1. Contact Form and Handling of Inquiries
Purpose of Data Processing
To receive professional inquiries and requests for collaboration related to the HunAIFA project; to assess infrastructure, computing capacity, and professional needs related to artificial intelligence; to respond to inquiries; to connect interested parties with relevant consortium partners; and to provide information about related services and funding sources.
Scope of Data Processed
Name, email address, name of institution/organization, sector of the organization (e.g., company, university, research institute, government agency, nonprofit organization), free-form message (purpose of the inquiry, question, proposal for collaboration, and any other personal data provided by the Data Subject).
Legal Basis for Data Processing
The legitimate interest of the data controllers pursuant to Article 6(1)(f) of the GDPR: the efficient processing of incoming professional inquiries, their forwarding to the appropriate consortium partner, and ensuring a response. The data controllers have verified the applicability of this legal basis through a prior balancing test.
Data Sharing and Transfer
HUN-REN SZTAKI records incoming inquiries in a shared register and shares them with consortium partners via the consortium’s closed, secure shared storage platform so that the inquiry can be processed and responded to by the partner with expertise in the relevant subject matter.
Assigning an inquiry to a specific partner and the partner’s initial direct contact do not, in and of themselves, terminate joint data processing. The rules governing joint data processing continue to apply to the handling of inquiries carried out for the purpose of the joint project.
If a partner independently determines the purpose and essential means of its own separate data processing, it acts as an independent data controller with respect to such operations and provides a separate privacy notice regarding them. The copy of the data retained in the shared database remains subject to the provisions of this Notice regarding joint data processing.
Duration of Data Processing
For a maximum of 1 (one) year from the date of the final response to the inquiry or the conclusion of the resulting cooperation/coordination process, or until the Data Subject successfully exercises their right to object.
Personal data processed under the joint controllership arrangement will be retained for no longer than one year after the final response to an inquiry handled for the joint purpose, or after the conclusion of the resulting discussions conducted for that purpose. The data will be erased earlier where required by the purpose of the processing or by another obligation to erase data under the GDPR.
2.2. Cookies and Web Analytics
The Website uses cookies to function, to remember visitors’ cookie settings, and to analyze website traffic.
HUN-REN SZTAKI is the independent data controller for the processing of personal data related to cookies and the use of Matomo web analytics. HUN-REN SZTAKI independently determines the purposes and essential means of this data processing and is responsible for the lawfulness of the data processing, providing appropriate information, managing the necessary consents, fulfilling Data Subject requests, and ensuring the security and deletion of the data.
HUN-REN SZTAKI does not share the personal data processed in this manner with other consortium partners, nor does it link it to the shared register of contact inquiries. Consortium partners may only receive anonymous, aggregated visitor statistics that cannot reasonably be linked to any natural person.
The use of cookies for statistical purposes and the related web analytics data processing are carried out solely on the basis of the User’s prior consent. Refusal to give consent does not prevent browsing the Website or using the contact form. The User may withdraw their consent at any time, free of charge, via the “Cookie Settings” interface located in the Website’s footer. Withdrawal does not affect the lawfulness of data processing carried out on the basis of consent prior to its withdrawal.
The purpose, duration, and legal basis for the processing of personal data associated with each cookie are set forth in the table below.
| Cookie Name | Type | Purpose | Lifespan | Legal Basis |
|---|---|---|---|---|
cc_cookie | Essential / Required | To record the visitor’s cookie settings (accept/reject). | 1 year | Legitimate interest (GDPR Article 6(1)(f)) |
_pk* (e.g., _pk_id, _pk_ses) | Statistical / Analytical | Traffic measurement, traffic statistics, and website development using Matomo software. | up to 13 months | Consent (GDPR Article 6(1)(a)) |
3. Recipients and Data Processors
Personal data contained in the inquiries referred to in Section 2.1 may be accessed by designated employees of the joint data controllers who are bound by confidentiality obligations, to the extent necessary for the performance of their duties. Personal data related to cookies and web analytics as described in Section 2.2 may be accessed by designated employees of HUN-REN SZTAKI who are bound by confidentiality obligations, as well as by duly authorized personnel of the data processors engaged by HUN-REN SZTAKI for this purpose, to the extent necessary for the performance of their duties.
For the storage of personal data related to inquiries under Section 2.1 and for the operation of the Website, the consortium may engage technical data processors (hosting providers) under a data processing agreement in accordance with Article 28 of the GDPR. With regard to personal data related to cookies and web analytics as described in Section 2.2, SZTAKI engages a data processor on its own behalf.
4. Data Subjects’ Rights and Remedies Regarding Data Processing
4.1. How Data Subjects May Exercise Their Rights and How Their Requests Are Handled
With regard to the joint data processing described in Section 2.1, the Data Subject may exercise their rights against any of the joint controllers pursuant to Article 26(3) of the GDPR. HUN-REN SZTAKI coordinates the handling of these requests as the central point of contact.
With regard to data processing related to cookies and web analytics as described in Section 2.2, Data Subject rights may be exercised against HUN-REN SZTAKI as the independent data controller. In both cases, HUN-REN SZTAKI accepts requests via the following contact information:
Via email:
hunaifa-privacy@sztaki.hu
By mail:
HUN-REN Research Institute for Computer Science and Automation (HUN-REN SZTAKI)
1111 Budapest, Kende utca 13–17.
The data controller responsible for the relevant data processing will review the Data Subject’s request without undue delay, but no later than 1 (one) month from the date of receipt of the request, and will inform the Data Subject of the measures taken in response to the request. If necessary, taking into account the complexity of the request and the number of requests received, this deadline may be extended by an additional 2 (two) months pursuant to Article 12(3) of the GDPR. The data controller responsible for the relevant data processing shall inform the Data Subject of any extension of the deadline within 1 (one) month of receiving the request, specifying the reasons for the delay.
In the case of a request submitted electronically, the data controller responsible for the relevant data processing shall primarily provide the response electronically, unless the Data Subject expressly requests it in another form. If the data controller responsible for the relevant data processing does not take action in response to the Data Subject’s request, it shall inform the Data Subject without delay, but no later than 1 (one) month from receipt of the request, of the reasons for failing to take action and of the Data Subject’s available remedies.
In the case of a request from a Data Subject regarding joint data processing, the one-month deadline is calculated from the date the request is first received by any of the joint data controllers; the internal transfer of the request among the data controllers does not restart the deadline.
4.2. Right to Information and Access (Article 15 of the GDPR)
The Data Subject has the right to receive confirmation from the data controllers responsible for the processing in question as to whether their personal data is being processed, and if such processing is taking place, the Data Subject has the right to access the personal data and the following information:
- the purposes of the data processing;
- the categories of personal data concerned;
- the recipients or categories of recipients (in particular, consortium partners) to whom the personal data have been or will be disclosed;
- the planned duration of the storage of the personal data;
- the Data Subject’s right to request the rectification, erasure, or restriction of processing of personal data, and to object to the processing of such personal data;
- the right to lodge a complaint with a supervisory authority;
- if the data were not collected from the Data Subject, any available information regarding their source;
- the fact and logic of the use of automated decision-making, including profiling (if applicable).
At the request of the Data Subject, the data controller responsible for the data processing in question shall provide the Data Subject with a copy of the personal Data Subject to such processing free of charge the first time. A reasonable fee based on administrative costs may be charged for additional copies.
To ensure compliance with data security requirements, the data controller responsible for the relevant data processing is required to verify the identity of the person submitting the request; therefore, the provision of information or the issuance of a copy may be contingent upon confirmation of the Data Subject’s identity.
4.3. Right to Rectification (Article 16 of the GDPR)
The Data Subject has the right to request that the data controller responsible for the relevant data processing rectify inaccurate personal data concerning him or her without undue delay, or—taking into account the purposes of the data processing—to request that incomplete personal data be completed (for example, in the case of a changed contact email address or institutional name).
4.4. The Right to Erasure (“Right to Be Forgotten”) (Article 17 of the GDPR)
The Data Subject has the right to request that the data controller responsible for the relevant data processing erase personal data concerning him or her without undue delay if any of the following grounds apply:
- the personal data is no longer necessary for the purpose for which it was collected or otherwise processed (e.g., the inquiry has been definitively answered and closed);
- the Data Subject withdraws the consent on which the processing of cookie data is based, and there is no other legal basis for the processing;
- the Data Subject objects to data processing based on legitimate interests pursuant to Article 21(1) of the GDPR, and there is no overriding legitimate ground for the data processing;
- the personal data has been processed unlawfully;
- the personal data must be erased to comply with a legal obligation under Union or Hungarian law applicable to the controller responsible for the processing in question.
If the data contained in an inquiry has been shared with consortium partners, HUN-REN SZTAKI shall immediately notify the relevant partners of the request for erasure in order to ensure that the erasure is carried out.
4.5. Right to Restriction of Processing (Article 18 of the GDPR)
The Data Subject has the right to request the restriction (blocking) of data processing if any of the following conditions are met:
- the Data Subject disputes the accuracy of the personal data (the restriction applies for the period necessary to verify the accuracy of the data);
- the processing is unlawful, but the Data Subject opposes the erasure of the data and requests the restriction of its use instead;
- the data controller responsible for the processing no longer needs the personal data for processing purposes, but the Data Subject requires it to assert, exercise, or defend legal claims; or
- the Data Subject has objected to the processing (the restriction applies for the period until it is determined whether the legitimate grounds of the data controllers take precedence over the legitimate grounds of the Data Subject).
In the event of a restriction, personal data may be processed – with the exception of storage – only with the Data Subject’s consent, or for the purpose of establish, exercise or defend legal claims, or for reasons of important public interest.
4.6. The Right to Data Portability (GDPR Article 20)
If the processing is based on the Data Subject’s consent (Article 6(1)(a) of the GDPR) or on a contract and is carried out by automated means, the Data Subject has the right to receive the personal data concerning him or her, which he or she has provided, in a structured, commonly used, and machine-readable format, and to request the direct transmission of such data to another controller, where technically feasible.
4.7. The Right to Object and the Right to Withdraw Consent (GDPR Article 21 and Article 7(3))
Objection to data processing based on legitimate interests: The Data Subject has the right to object at any time, on grounds relating to his or her particular situation, to the processing of his or her personal data based on the legitimate interests of the data controller responsible for the processing in question (Article 6(1)(f) of the GDPR) (including the processing and internal sharing of data submitted via the contact form). In this case, the data controller responsible for the processing in question may no longer process the personal data, unless it demonstrates that the processing is justified by compelling legitimate grounds that override the interests, rights, and freedoms of the Data Subject, or that are related to the establishment, exercise, or defense of legal claims.
Withdrawal of Consent: In cases of data processing based on consent (web analytics cookies), the Data Subject has the right to withdraw their consent at any time, free of charge, via the cookie settings located in the website footer. The withdrawal of consent does not affect the lawfulness of data processing carried out prior to the withdrawal.
4.8. Exclusion of Automated Decision-Making and Profiling (GDPR Article 22)
The data controller responsible for the relevant data processing does not use decision-making or profiling based solely on automated processing in the operation of the Website or in the handling of inquiries.
4.9. Enforcement of Rights and Legal Remedies
If the Data Subject believes that their rights have been infringed upon in connection with the processing of their personal data, we recommend that they first submit their complaint to the central data protection contact point at the email address hunaifa-privacy@sztaki.hu or at the postal address of HUN-REN SZTAKI (1111 Budapest, Kende utca 13–17), so that the data controller responsible for the relevant data processing can immediately investigate and remedy the issue.
The Data Subject may initiate an investigation or administrative proceedings with the competent supervisory authority. The name and contact information of the data protection supervisory authority are as follows:
National Authority for Data Protection and Freedom of Information (NAIH)
Headquarters: 1055 Budapest, Falk Miksa Street 9–11
Mailing address: 1363 Budapest, P.O. Box 9
Phone: +36 (1) 391-1400
Email: ugyfelszolgalat@naih.hu
Website: www.naih.hu
The Data Subject may bring civil proceedings if their rights have been infringed. Such proceedings fall within the jurisdiction of the regional courts (törvényszékek). The Data Subject may also choose to bring proceedings before the regional court having territorial jurisdiction over their place of residence or temporary residence. A list of the competent courts and their contact details is available on the courts’ portal: birosag.hu/torvenyszekek.
5. Data Security Measures
HUN-REN SZTAKI, the operator of the Website, and the consortium partners pay special attention to the security of personal data. In accordance with the requirements set forth in Article 32 of the GDPR, taking into account the state of the art, the costs of implementation, as well as the nature, scope, context, and purposes of the processing, and the risks of varying likelihood and severity to the rights and freedoms of Data Subjects, the joint controllers implement the following technical and organizational measures:
5.1. Network and Communication Security (Encryption)
Secure Data Transmission Channels (HTTPS/TLS)
All data traffic between the Website and the visitor, including the completion and submission of the contact form, takes place via the encrypted HTTPS protocol and state-of-the-art TLS encryption, preventing unauthorized interception, alteration, or manipulation of the transmitted data.
Server and Network Security
The servers hosting the Website operate on HUN-REN SZTAKI’s strictly protected server infrastructure—equipped with dedicated, state-of-the-art network firewalls, intrusion detection and prevention systems (IDS/IPS), and DDoS protection—or within the environment of an audited European cloud service provider.
5.2. Access Protection and Access Control
Role-Based Access Control (RBAC) and the “Need-to-Know” Principle
Access to data received via the contact form and to records maintained in the shared cloud storage is restricted exclusively to designated employees of HUN-REN SZTAKI and the consortium partners whose direct responsibility is to professionally evaluate and respond to the specific inquiry.
Multifactor Authentication (MFA/2FA)
Access to the project’s shared storage and cloud-based administrative interfaces is possible only with a unique user ID, strong password requirements, and multi-factor authentication.
Event Logging and Traceability
Access to, modifications of, and data retrievals from the registry and systems are subject to security logging to enable the retrospective detection and investigation of unauthorized access attempts.
5.3. Data Storage Security, Backup, and Data Integrity
Protection of Data at Rest
Databases and Excel spreadsheets stored on the server are housed on encrypted storage devices.
Regular Backups
Regular, encrypted backups are made of the systems and databases, ensuring that, in the event of a physical or technical incident, access to personal data and the availability of the data can be restored in a timely manner (business continuity).
Virus and Malware Protection
Data files are monitored by centrally managed virus and malware protection software that is continuously updated on the systems.
5.4. Organizational Measures
Strict Confidentiality Obligation
In accordance with Section 10 of the consortium agreement and the partners’ internal job responsibilities, all persons who have access to inquiries and personal data have undertaken a strict, indefinite confidentiality obligation.
Staff Awareness and Training
Professionals involved in the project receive regular updates on data protection and information security regulations, as well as on secure data handling procedures.
6. Review and Amendment of This Notice
The circumstances of data processing may change from time to time, and the data controller responsible for a given data processing activity may decide at any time to supplement its ongoing data processing with a new data processing purpose; therefore, data controllers reserve the right to amend this Notice at any time.
Data controllers will provide notice of such changes on the Website and, depending on the nature of the changes and where warranted, will also notify Data Subjects via the contact information provided to them.