Privacy Policy
Purpose of this Privacy Policy
Blue Forest Foundation (hereinafter referred to as the Service Provider or the Data Controller), acting as the data controller, acknowledges that it is bound by the contents of this legal notice. The Data Controller undertakes to ensure that all personal data processing activities related to its operations comply with the provisions of this Privacy Policy, the applicable national legislation, and the legal acts of the European Union.
The Data Controller’s privacy principles relating to its data processing activities are continuously available at:
https://www.kekerdo.hu/bemutatkozas/gdpr/
The Data Controller reserves the right to amend this Privacy Policy at any time. Naturally, it will notify its audience of any changes in due course.
Blue Forest Foundation is committed to protecting the personal data of its partners and considers respect for the right to informational self-determination to be of paramount importance. Therefore, the Data Controller treats personal data confidentially and implements all security, technical, and organisational measures necessary to guarantee the security of personal data.
Below, Blue Forest Foundation describes its data processing practices.
Data Controller Details
Foundation name: Blue Forest Foundation
President of the Foundation: Mariann Hornyák
Registered office: Vércse utca 12, 4079 Debrecen, Hungary
Tax Number: 18907294-1-09
E-mail: hello@kekerdo.hu
Telephone: +36 70 551 2165 or +36 70 311 4565
Website: www.kekerdo.hu
Data Protection Officer
E-mail: info.kekerdo@gmail.com
Categories of Personal Data Processed
Personal data required during registration/purchase
-
Full name (surname and first name; in the case of a company, company name and tax number)
-
Full address (country, city, street, house number, floor, door number, postal code)
-
E-mail address
-
Telephone number
Technical Data
The Data Controller selects and operates the IT tools used in providing its services in such a way that the processed personal data are:
-
accessible to authorised persons only (availability);
-
authentic and verifiable (authenticity of data processing);
-
demonstrably unaltered (data integrity);
-
protected against unauthorised access (confidentiality).
The Data Controller protects personal data by implementing appropriate measures against unauthorised access, alteration, transmission, disclosure, deletion or destruction, as well as accidental destruction.
The Data Controller implements technical, organisational and administrative measures to ensure a level of data security appropriate to the risks associated with the processing activities.
During data processing, the Data Controller ensures:
-
Confidentiality: protecting information so that only authorised persons may access it;
-
Integrity: protecting the accuracy and completeness of the information and the processing methods;
-
Availability: ensuring that authorised users can access the required information whenever necessary and that the necessary tools are available.
Cookies
Purpose of Cookies
Cookies:
-
collect information about visitors and their devices;
-
remember visitors’ individual preferences, which may be used, for example, when using online services, so that they do not need to be re-entered;
-
facilitate the use of the website;
-
provide a better user experience.
To provide personalised services, the website places a small data file, known as a cookie, on the user’s computer and reads it during subsequent visits. If the browser returns a previously saved cookie, the service provider managing the cookie may associate the user’s current visit with previous visits, but only in relation to its own content.
Strictly Necessary Session Cookies
The purpose of these cookies is to enable visitors to browse the Data Controller’s website (www.kekerdo.hu), use its functions, and access its services smoothly and without interruption.
These cookies remain valid only for the duration of the browsing session. Once the browser is closed, they are automatically deleted from the user’s computer or any other device used for browsing.
Third-Party Cookies (Analytics)
The Data Controller also uses Google Analytics as a third-party analytics service.
By using Google Analytics, the Data Controller collects statistical information about how visitors use the website. This information is used to improve the website and enhance the user experience.
These cookies remain on the visitor’s computer or other browsing device until they expire or until they are manually deleted by the visitor.
Blue Forest Foundation’s Data Processing Activities
Any individual who provides personal data to the Foundation in any manner or who enters into a contractual relationship with the Foundation shall have their personal data processed by the Foundation in accordance with the data protection principles and provisions set out in this Privacy Policy.
By providing their personal data, the data subject accepts the terms and conditions set forth in this Privacy Policy.
Personal Data Processed
The Data Controller processes those personal data provided by the data subject that are necessary for handling the matter concerned, depending on the scope of the information made available by the data subject (e.g. name, telephone number, e-mail address and postal address).
Purpose and Legal Basis of Data Processing
The purpose of processing the personal data provided by the data subject is to ensure the operation of the Foundation, its programmes, specialist activities, development services and sessions, as well as to assess applications, manage, administer and complete various requests and matters.
For the purpose of verifying employment, it is necessary to process certain personal and special categories of personal data (e.g. health data, criminal record, etc.). Such data are stored separately, in printed form, in a locked cabinet by the HR officer of the Blue Forest Public Benefit Foundation.
The legal basis for data processing carried out by the Blue Forest Public Benefit Foundation is the voluntary consent of the data subject and, where applicable, the legitimate interests of the Foundation (for example, in connection with employment relationships).
The data subject is responsible for ensuring that the personal data provided by them are accurate and truthful, both in relation to the Foundation and to third parties.
The Foundation does not verify the accuracy of the personal data provided and shall not be liable for the processing of inaccurate or false personal data supplied by the data subject, nor for any damage suffered by the data subject or any third party as a result of inaccurate or false information provided by the data subject.
Duration of Data Processing
The Foundation is entitled to process the personal data provided by the data subject for an indefinite period or, in the case of employees, for the period required by the applicable legislation governing the processing of personal data.
The Foundation shall delete personal data whenever the legal basis or purpose of the processing ceases to exist or when the data subject requests the deletion of their personal data in writing by withdrawing their consent.
The data subject may request information about the processing of their personal data at any time, review the personal data processed about them, and request the rectification, amendment, modification, deletion or restriction of such data.
The Foundation shall delete personal data if
a) the processing is unlawful;
b) the data subject requests the deletion or restriction of their personal data;
c) the data are incomplete or inaccurate, and this situation cannot lawfully be remedied, provided that deletion is not excluded by law;
d) the purpose of the processing has ceased to exist or the statutory retention period has expired;
e) deletion has been ordered by a court or by the Hungarian National Authority for Data Protection and Freedom of Information;
f) there are reasonable grounds to believe that the personal data provided by the data subject are inaccurate, unlawful or otherwise misleading.
Place of Data Storage
Personal data are stored at the registered office, premises and certain offices of the Data Controller, in secured areas, as well as on servers owned by the Data Controller.
The access rights to specific categories of personal data are set out in the tables attached to this Privacy Policy.
Personal Data Obtained Through Electronic and Postal Correspondence
Purpose of Processing
Incoming e-mails and postal correspondence relating to the Foundation are recorded in order to respond to requests submitted by data subjects. Postal correspondence may also be stored electronically.
Legal Basis
-
For electronic correspondence: the consent of the data subject (Article 6(1)(a) GDPR).
-
For postal correspondence: the Data Controller’s legitimate interest in retaining correspondence (Article 6(1)(f) GDPR).
Categories of Personal Data Processed
-
Name
-
Telephone number
-
E-mail address
-
Postal address
These data are processed for communication purposes.
Retention Period
Until the data subject withdraws their consent.
Source of the Data
Provided directly by the data subject.
Place of Storage
-
On servers owned by the Foundation at its registered office.
-
In paper form, where applicable, in access-controlled rooms secured by magnetic card entry.
-
Within internally developed systems and Microsoft SQL databases operated behind Microsoft SharePoint.
Personal Data of Participants in Community Service
Purpose of Processing
The purpose of processing personal data required for organising and certifying community service is to comply with applicable legal obligations.
Legal Basis
Compliance with a legal obligation (Article 6(1)(c) of the GDPR), in particular:
-
Act CXC of 2011 on National Public Education;
-
Section 133(1) of Decree No. 20/2012 (VIII. 31.) of the Ministry of Human Resources on the Operation of Educational Institutions and the Use of Names of Public Education Institutions.
Categories of Personal Data Processed
-
Name
-
Telephone number
-
E-mail address
-
Photograph
-
Other personal data required for the administration of community service
Retention Period
5 years.
Source of the Data
Provided directly by the data subject.
Place of Storage
On servers owned by the Blue Forest Foundation or in paper-based records kept at the Foundation’s registered office.
Personal Data of Individuals Entering the Foundation’s Registered Office, Premises or Sensory Garden
Purpose of Processing
To ensure the safe organisation of Foundation events and compliance with the Foundation’s internal regulations.
Legal Basis
Legitimate interest of the Data Controller (Article 6(1)(f) of the GDPR).
Categories of Personal Data Processed
-
Image recordings
-
In certain cases involving security risks:
-
Name
-
Telephone number
-
Retention Period
-
CCTV recordings: 72 hours
-
Other personal data: until the end of the event, or within one week after the event, where applicable.
Source of the Data
Provided by the data subject.
Place of Storage
On the video recording server operated by the Blue Forest Foundation.
Personal Data of Employees of the Blue Forest Foundation
Purpose of Processing
Processing personal data arising from the employment relationship.
Legal Basis
-
Performance of an employment or service contract (Article 6(1)(b) GDPR);
-
Act XXXIII of 1992 on the Legal Status of Public Employees;
-
Decree No. 20/2012 (VIII.31.) of the Ministry of Human Resources;
-
Consent of the data subject;
-
Compliance with legal obligations (Article 6(1)(c) GDPR).
Categories of Personal Data Processed
Personal data necessary for employment and for the performance of contractual obligations.
Retention Period
No statutory limitation period.
Source of the Data
Provided by the data subjects.
Place of Storage
On computers located at the headquarters of the Blue Forest Public Benefit Foundation and in locked filing cabinets in paper format.
Personal Data of Volunteers
Purpose of Processing
-
Establishment and maintenance of the volunteer relationship;
-
Communication with volunteers.
Legal Basis
-
Compliance with a legal obligation (Article 6(1)(c) GDPR), in particular Act LXXXVIII of 2005 on Public Interest Volunteer Activities;
-
Performance of a contract (Article 6(1)(b) GDPR).
Categories of Personal Data Processed
-
Name
-
Residential address
-
E-mail address
-
Date and place of birth
-
Telephone number
Retention Period
5 years.
Source of the Data
Provided directly by the data subject.
Recipients of the Data / Data Transfers
Hungarian Central Statistical Office (Központi Statisztikai Hivatal).
Place of Storage
On computers located at the headquarters of the Blue Forest Foundation.
Cookies Stored in the User’s Browser
The websites of the Blue Forest Public Benefit Foundation place small data files, known as cookies, on the user’s computer and retrieve them during subsequent visits. If the browser returns a previously stored cookie, the service provider managing the cookie may associate the user’s current visit with previous visits, but only with regard to its own content.
The detailed Cookie Policy of the Blue Forest Foundation is available at:
or, where applicable, in the Cookie Policy of the relevant website operated by the respective data controller.
Purpose of Processing
-
Identifying the visitor’s current browsing session;
-
Performing web analytics;
-
Enhancing website security.
The IT firewall system may also place security cookies in the user’s browser to protect against session hijacking attacks. Certain third-party service providers may also place cookies on the website for analytical purposes.
Legal Basis
The Data Controller has a legitimate interest in storing cookies on users’ browsers (Article 6(1)(f) GDPR).
Categories of Personal Data Processed
Please refer to the detailed Cookie Policy available at:
Retention Period
Please refer to the detailed Cookie Policy published on:
(or on the website of the relevant data controller).
Source of the Data
The visitor’s computer and web browser.
When visiting the website, Google Analytics and Facebook may place cookies for web analytics purposes. Further details are available in the relevant Cookie Policy.
Server Log Data
Purpose of Processing
The servers hosting the website record requests sent by visitors’ browsers and computers in order to minimise the risk of security incidents and to ensure the secure operation of the IT infrastructure.
Legal Basis
The Data Controller’s legitimate interest in ensuring the security of its IT systems (Article 6(1)(f) GDPR).
Categories of Personal Data Processed
-
IP address
-
Type and header of incoming request
-
Browser type
-
Date and time of the request
-
Pages visited
Retention Period
30 days.
Source of the Data
The visitor’s computer and web browser.
Purpose, Method and Legal Basis of Data Processing
General Principles of Data Processing
The Data Controller processes personal data on the basis of the data subject’s voluntary consent or statutory authorisation.
Where data processing is based on voluntary consent, data subjects may withdraw their consent at any stage of the processing.
In certain cases, the processing, storage or transfer of specific categories of personal data is required by law. Where applicable, our clients will be informed separately of such legal obligations.
The Data Controller’s data processing practices comply with the applicable data protection legislation, including, but not limited to, the following:
-
Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information;
-
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation – GDPR);
-
Act V of 2013 on the Civil Code;
-
Act C of 2000 on Accounting;
-
Act LIII of 2017 on the Prevention and Combating of Money Laundering and Terrorist Financing;
-
Act CCXXXVII of 2013 on Credit Institutions and Financial Enterprises.
Rights of Data Subjects and Available Legal Remedies
The data subject may request information regarding the processing of their personal data and may request the rectification of inaccurate personal data or, except where processing is mandatory by law, request the deletion or withdrawal of consent, exercise the right to data portability and the right to object, using the methods indicated when the data were collected or by contacting the Data Controller using the contact details provided above.
2.1 Right to Information
The Data Controller shall take appropriate measures to provide data subjects with all information referred to in Articles 13 and 14 of the GDPR and all communications under Articles 15–22 and Article 34 of the GDPR in a concise, transparent, intelligible and easily accessible form, using clear and plain language.
2.2 Right of Access
The data subject has the right to obtain confirmation from the Data Controller as to whether or not personal data concerning them are being processed.
Where such processing is taking place, the data subject has the right to access the personal data and the following information:
-
the purposes of the processing;
-
the categories of personal data concerned;
-
the recipients or categories of recipients to whom the personal data have been or will be disclosed, including recipients in third countries or international organisations;
-
the envisaged period for which the personal data will be stored;
-
the right to request rectification, erasure or restriction of processing and the right to object;
-
the right to lodge a complaint with a supervisory authority;
-
information on the source of the personal data where they were not collected from the data subject;
-
the existence of automated decision-making, including profiling, and meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.
The Data Controller shall provide the requested information within one month of receiving the request.
2.3 Right to Rectification
The data subject has the right to request the correction of inaccurate personal data relating to them processed by the Blue Forest Foundation and to request the completion of incomplete personal data.
2.4 Right to Erasure (“Right to be Forgotten”)
The data subject has the right to request that the Blue Forest Foundation erase personal data relating to them without undue delay where one of the following grounds applies:
-
the personal data are no longer necessary for the purposes for which they were collected or otherwise processed;
-
the data subject withdraws the consent on which the processing is based and there is no other legal basis for the processing;
-
the data subject objects to the processing and there are no overriding legitimate grounds for the processing;
-
the personal data have been processed unlawfully;
-
the personal data must be erased in order to comply with a legal obligation under Union or Member State law applicable to the Data Controller;
-
the personal data were collected in relation to the offer of information society services.
The right to erasure shall not apply where processing is necessary:
-
for exercising the right of freedom of expression and information;
-
for compliance with a legal obligation requiring processing under Union or Member State law;
-
for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller;
-
for reasons of public interest in the area of public health;
-
for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes;
-
or for the establishment, exercise or defence of legal claims.
2.5 Right to Restriction of Processing
The data subject has the right to request that the Data Controller restrict processing where one of the following applies:
-
the accuracy of the personal data is contested by the data subject, for a period enabling the Data Controller to verify the accuracy of the personal data;
-
the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead;
-
the Data Controller no longer needs the personal data for the purposes of processing, but they are required by the data subject for the establishment, exercise or defence of legal claims;
-
the data subject has objected to processing pending the verification of whether the legitimate grounds of the Data Controller override those of the data subject.
Where processing has been restricted, such personal data shall, with the exception of storage, only be processed with the data subject’s consent or for the establishment, exercise or defence of legal claims, for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or of a Member State.
A következő részben még a következő jogok következnek:
-
Right to Data Portability
-
Right to Object
-
Automated Decision-Making and Profiling
-
Right to Withdraw Consent
-
Right to Seek Judicial Remedy
-
Complaints to the Hungarian Supervisory Authority (NAIH)
2.6 Right to Data Portability
The data subject has the right to receive the personal data concerning them, which they have provided to the Data Controller, in a structured, commonly used and machine-readable format, and has the right to transmit those data to another data controller without hindrance.
2.7 Right to Object
The data subject has the right to object, on grounds relating to their particular situation, at any time to the processing of their personal data where the processing is carried out in the public interest or in the exercise of official authority vested in the Data Controller, or where the processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party, including profiling based on those provisions.
Where the data subject objects, the Data Controller shall no longer process the personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or unless the processing is necessary for the establishment, exercise or defence of legal claims.
2.8 Automated Decision-Making, Including Profiling
The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.
2.9 Right to Withdraw Consent
The data subject has the right to withdraw their consent at any time.
2.10 Right to Seek Judicial Remedy
If the data subject believes that their rights have been infringed, they may initiate legal proceedings against the Data Controller. The competent court shall give priority to such proceedings.
Data Protection Authority Procedure
Complaints may be lodged with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH).
Name: Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Registered Office:
1125 Budapest, Szilágyi Erzsébet fasor 22/C, Hungary
Postal Address:
1530 Budapest, P.O. Box 5, Hungary
Telephone: +36 1 391 1400
Fax: +36 1 391 1410
E-mail: ugyfelszolgalat@naih.hu
Website: http://www.naih.hu
8. Data Processing Relating to TEDxDebrecen Events
8.1 Data Processing Related to Ticket Sales, Organisation, Operation and Evaluation of TEDxDebrecen Events
Purpose of Processing
The purpose of processing personal data is to organise, operate and evaluate the TEDxDebrecen event (hereinafter referred to as the “TEDxDebrecen Event”), as required by TED, the holder of the TED licence.
The Data Controller participates in the organisation of the TEDxDebrecen Event in an administrative and financial capacity and processes personal data necessary for fulfilling these responsibilities.
For the preparation, organisation and operation of the TEDxDebrecen Event, the Data Controller processes:
-
personal data provided during ticket purchase;
-
contact details;
-
where applicable, information relating to participation in the event;
-
data required for the mandatory post-event evaluation.
The post-event evaluation is mandatory under the requirements of the TED licence holder. Consequently, processing the personal data of ticket purchasers is necessary for conducting this evaluation.
In addition, personal data are processed for the following purposes:
-
selling admission tickets to the TEDxDebrecen Event;
-
fulfilling the contract concluded through ticket purchase;
-
communicating with ticket purchasers regarding the event;
-
informing ticket purchasers about any changes affecting the event or its possible cancellation;
-
providing benefits to ticket purchasers;
-
reserving seats;
-
issuing invoices;
-
granting discounts.
For these purposes, it is necessary to process the personal data provided during ticket purchase that are required for:
-
purchasing tickets;
-
invoicing;
-
delivering tickets to the data subject;
-
notifying participants of any changes relating to the TEDxDebrecen Event.
Electronic ticket sales are carried out through the electronic ticketing system operated by TIXA Hungary Ltd., available at www.tixa.hu.
TIXA Hungary Ltd.
Registered office: 5600 Békéscsaba, Dobozi út 58, Hungary
Tax number: 24813064-2-04
Company registration number: 04-09-012827
TIXA Hungary Ltd. provides the electronic ticketing system required for ticket sales. Both the Blue Forest Foundation and TIXA Hungary Ltd. act as independent data controllers with respect to the personal data processed during ticket sales.
TIXA Hungary Ltd. maintains its own Privacy Policy governing the technical operation of the ticketing system, which is available at:
The Data Controller processes the personal data entered by the data subject in the ticketing system during the purchase process.
Legal Basis
Ticket purchase
Performance of a contract (Article 6(1)(b) GDPR) and compliance with legal obligations relating to accounting (Article 6(1)(c) GDPR), in particular Section 169(1)-(4) of Act C of 2000 on Accounting.
Event organisation and communication
Performance of a contract (Article 6(1)(b) GDPR).
Mandatory event evaluation
Legitimate interests of the Data Controller (Article 6(1)(f) GDPR).
The legitimate interest arises from the contractual obligation imposed by the TED licence holder. Failure to complete the mandatory evaluation may result in the loss of the right to organise TEDxDebrecen events.
Categories of Personal Data Processed
Ticket purchase
-
Name
-
E-mail address
-
Password
-
Residential address
-
Telephone number
-
Delivery address
Event organisation
-
Name
-
E-mail address
-
Telephone number
Mandatory event evaluation
-
Name
-
E-mail address
Retention Period
Personal data processed in connection with ticket purchases
Personal data relating to ticket purchases shall be retained for 8 years plus the current financial year from the date of invoice issuance, in accordance with the retention requirements set out in the Hungarian Accounting Act.
Personal data processed for organising and operating the event
Personal data processed for the organisation, operation and communication relating to the TEDxDebrecen Event shall be retained for 30 days following the successful completion of the event.
Personal data processed for the mandatory event evaluation
Personal data processed for the mandatory evaluation required by the TED licence holder shall be retained for 30 days following the successful completion of the evaluation.
Source of the Personal Data
The personal data are provided directly by the data subject.
Recipients of the Data / Data Transfers
Personal data are transferred only to TED Conferences, LLC for the purpose of conducting the mandatory post-event evaluation required by the TED licence holder.
TED Conferences, LLC processes the transferred personal data in accordance with its own Privacy Policy, available at:
https://www.ted.com/about/our-organization/our-policies-terms/privacy-policy
Place of Data Storage
- The electronic webshop operated by the Service Provider;
- Computers located at the headquarters of the Data Controller.
8.2 Processing of Personal Data for the Promotion of TEDxDebrecen Events
Purpose of Processing
The purpose of processing personal data is to organise and promote the TEDxDebrecen Event, provide information about speakers and presentations, and communicate the credibility and professional quality of the event.
The purpose of processing also includes informing the data subject about the Data Controller’s TEDxDebrecen-related activities and future TEDxDebrecen events by sending newsletters, informational materials, useful information, current news, marketing communications and recommendations relating to TEDxDebrecen services via e-mail (info@tedxdebrecen.com).
Legal Basis
The data subject’s prior, freely given and explicit consent (Article 6(1)(a) of the GDPR).
Categories of Personal Data Processed
- Name
- E-mail address
Retention Period
Until the purpose of the processing ceases to exist or until the data subject withdraws their consent.
Source of the Personal Data
Provided directly by the data subject.
Recipients / Data Transfers
No personal data are transferred to third parties.
Place of Data Storage
On computers located at the headquarters of the Blue Forest Foundation and on servers owned by the Foundation.
Other Provisions
The Data Controller shall provide information about any data processing activities not specifically listed in this Privacy Policy at the time the relevant personal data are collected.
Please note that courts, public prosecutors, investigating authorities, authorities responsible for misdemeanour proceedings, administrative authorities, the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), the Hungarian National Bank, and any other authorities authorised by law may request information, the disclosure or transfer of personal data, or the provision of documents from the Data Controller.
The Blue Forest Foundation shall disclose personal data to the competent authorities only where such authority specifies the exact purpose and scope of the requested data, and only to the extent strictly necessary to achieve that purpose.
8.3 Processing of Personal Data Related to Erasmus+ Training Courses
Purpose of Processing
The Blue Forest Foundation organises Erasmus+ training courses for teachers, educators, therapists, and other professionals.
Personal data are processed for the purposes of:
-
responding to enquiries and pre-registration requests;
-
evaluating applications and communicating with prospective participants;
-
preparing quotations and confirming course participation;
-
organising and administering Erasmus+ training courses;
-
preparing and managing Learning Agreements and other Erasmus+ documentation;
-
communicating with participants before, during and after the course;
-
issuing certificates of attendance and other course-related documents;
-
maintaining attendance records;
-
fulfilling contractual and legal obligations;
-
managing invoicing and payments where applicable;
-
ensuring the proper administration and implementation of Erasmus+ mobility activities.
Legal Basis
Personal data are processed on the following legal bases:
-
the data subject’s consent (Article 6(1)(a) GDPR), where the individual submits a pre-registration enquiry;
-
taking steps at the request of the data subject prior to entering into a contract and the performance of a contract (Article 6(1)(b) GDPR), where participation in a course is confirmed;
-
compliance with legal obligations applicable to the Data Controller (Article 6(1)(c) GDPR), including accounting and financial obligations;
-
the legitimate interests of the Data Controller (Article 6(1)(f) GDPR), where necessary for the organisation, administration and quality assurance of Erasmus+ training activities.
Categories of Personal Data Processed
Depending on the stage of the registration process, the Data Controller may process the following personal data:
-
full name;
-
organisation or school name;
-
country;
-
postal address;
-
e-mail address;
-
telephone number;
-
participant’s position or professional role;
-
preferred course;
-
preferred course dates;
-
English language proficiency;
-
Learning Agreement information;
-
Erasmus+ project information, where applicable;
-
invoicing details;
-
attendance records;
-
certificate information;
-
correspondence relating to the course;
-
any additional information voluntarily provided by the participant.
Where participants voluntarily provide information relating to dietary requirements, accessibility needs, disabilities, allergies or other special requirements, such information shall be processed solely for the purpose of ensuring the safe and appropriate organisation of the training course.
Source of the Personal Data
Personal data are collected directly from the data subject through:
-
the online pre-registration form;
-
registration forms;
-
Learning Agreements;
-
e-mail correspondence;
-
other documents voluntarily submitted during the application process.
Recipients of the Data
Personal data may be shared only where necessary with:
-
the participant’s sending institution;
-
Erasmus+ programme authorities or National Agencies, where required;
-
service providers engaged by the Data Controller for organising the course (such as accommodation providers or certificate printing services, where applicable);
-
accounting and financial service providers;
-
public authorities where disclosure is required by applicable law.
The Data Controller does not sell or otherwise disclose personal data to third parties for marketing purposes.
International Data Transfers
Where participation in Erasmus+ programmes requires the transfer of personal data outside the participant’s country of residence, such transfers shall be carried out only where necessary for the implementation of the Erasmus+ programme and in accordance with the applicable provisions of the GDPR.
Retention Period
Personal data submitted through the pre-registration form shall be retained for up to 24 months, unless the data subject withdraws their consent earlier.
Where a participant enrols in an Erasmus+ training course, personal data shall be retained for as long as necessary to fulfil contractual obligations and to comply with applicable European Union and Hungarian legal requirements relating to Erasmus+ project administration, accounting and financial documentation.
Where legal obligations require longer retention periods, personal data shall be retained for the period prescribed by law.
Photographs and Video Recordings
Photographs and video recordings may be taken during Erasmus+ training courses for documentation, dissemination and communication purposes.
Such materials may be published on the Foundation’s websites, social media platforms, newsletters, Erasmus+ dissemination materials and other communication channels.
Where required under applicable law, the processing of photographs or video recordings for promotional purposes shall be based on the participant’s consent.
Participants may object to the use of their image at any time by contacting the Data Controller.
Certificates
Upon successful completion of the training course, the Blue Forest Foundation may issue a Certificate of Attendance or other course completion certificate.
For this purpose, the participant’s name, organisation, course title, course dates and other information necessary for issuing the certificate may be processed.
Data Security
The Blue Forest Foundation implements appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, loss or destruction.
Access to personal data is restricted exclusively to authorised personnel whose duties require such access.
8.4 Erasmus+ Course Newsletters and Marketing Communications
Purpose of Processing
The Blue Forest Foundation may send newsletters and other electronic communications to individuals who have participated in or expressed interest in Erasmus+ training courses.
The purpose of processing personal data is to:
- provide information about upcoming Erasmus+ training courses;
- inform participants about new courses, workshops and educational opportunities;
- share Erasmus+ project news and professional updates;
- invite participants to future training activities organised by the Blue Forest Foundation;
- distribute educational materials and resources related to the Foundation’s activities.
Participants will receive marketing communications only if they have given their prior consent.
Legal Basis
The legal basis for processing personal data for marketing purposes is the data subject’s freely given, specific, informed and unambiguous consent in accordance with Article 6(1)(a) of the GDPR.
Consent may be withdrawn at any time without affecting the lawfulness of processing carried out prior to the withdrawal.
Categories of Personal Data Processed
The Data Controller may process the following personal data:
- full name;
- e-mail address;
- organisation or institution;
- country;
- courses previously attended;
- preferences relating to future Erasmus+ training opportunities.
Source of the Personal Data
Personal data are collected directly from the data subject through:
- Erasmus+ pre-registration forms;
- course registration forms;
- Learning Agreements;
- newsletter subscription forms;
- other consent forms completed by the participant.
Recipients of the Data
Personal data are processed by the Blue Forest Foundation and may also be processed by trusted service providers acting on behalf of the Data Controller for the purpose of delivering e-mail communications.
Such service providers process personal data solely on the documented instructions of the Data Controller and in accordance with applicable data protection legislation.
Retention Period
Personal data processed for marketing communications shall be retained until the data subject withdraws their consent or unsubscribes from the mailing list.
The data subject may unsubscribe at any time by using the unsubscribe link included in every marketing e-mail or by contacting the Data Controller directly.
Data Security
The Blue Forest Foundation applies appropriate technical and organisational measures to ensure the security and confidentiality of personal data processed for marketing communications.