Source language: Hungarian; this document is a translation of the Hungarian source version.
Version: 1.0
Effective date: 9 September 2026
1. Controller
- Controller: Dr Rudolf Laufer, sole proprietor
- Registered office: Nefelejcs utca 22, 2nd floor, door 24, 1078 Budapest, Hungary
- Sole proprietor registration number: 20919435
- Tax number: 60461975-1-42
- Privacy contact: education@pharm.academy
- Website: https://pharm.academy
Dr Rudolf Laufer is the owner, operator and software developer of Pharm Academy. A company is currently being established for the project’s long-term operation and is expected to begin operating in January 2027. Paid services will become available only after the company begins operating; the controller details and this Notice will be updated following incorporation.
Hereinafter referred to as the “Controller”.
2. Purpose and principles of this Notice
This Notice explains which personal data the Controller processes when operating the pharm.academy website and related educational service, for what purposes, on which legal bases and for how long, who may access the data, and which rights data subjects have.
The Controller processes personal data lawfully, fairly and transparently, for specified purposes, only to the extent and for the period necessary, and protects the data through appropriate technical and organisational measures.
Acknowledging that this Privacy Notice has been read does not mean that consent is the legal basis for every processing activity. The applicable legal basis is identified separately for each purpose.
3. Summary of processing activities
3.1. Registration and user accounts
Data processed: username, email address, secure password hash, name if provided by the user, registration and activation timestamps, account status, user role, registration language, and the version and timestamp relating to the Terms of Use and Privacy Notice acknowledged by the user.
Purpose: creating the account, identification, login, account security, communication and provision of the service.
Legal basis: steps necessary before entering into a contract and performance of the contract (Article 6(1)(b) GDPR); for security logging, the Controller’s legitimate interests (Article 6(1)(f) GDPR).
Retention: for as long as the account exists and for up to 30 days after termination, except for data required for a legal claim, legal obligation or security incident. Data will roll out of backups within no more than 90 days.
3.2. Language and institutional profile
Data processed: preferred language, country, university, faculty, the official name entered by the user for a country, university or faculty that is not listed, and the profile-data version.
Purpose: personalising the service, providing content, permissions and functions associated with an institution or faculty, and assessing demand for institutions not yet listed.
Legal basis: performance of the service (Article 6(1)(b) GDPR); for aggregated institutional demand analysis, the Controller’s legitimate interests in developing the service and preparing institutional partnerships (Article 6(1)(f) GDPR).
Safeguard: only aggregated numbers may be used for institutional outreach. A student’s name, email address, Neptun code or other individual identifier may not be disclosed for this purpose.
Retention: for as long as the account exists or until the user changes the data. Irreversibly anonymised aggregated statistics may be retained without a time limit.
3.3. Learning activity, quizzes and results
Data processed: user ID, question set opened, question and exercise type, answers, correct and incorrect results, percentage summaries, attempt status, technical data needed to resume an attempt, start and completion timestamps, and practice history.
Purpose: operating quizzes, resuming interrupted question sets, displaying results, tracking progress, personalised practice and detecting service errors.
Legal basis: performance of the service (Article 6(1)(b) GDPR); legitimate interests for security, troubleshooting and prevention of abuse (Article 6(1)(f) GDPR).
Retention: for as long as the account exists. When the account is terminated, results may be deleted or irreversibly anonymised unless a partner-institution agreement, legal claim or another appropriate legal basis requires longer retention.
3.4. Question suggestions, content contributions and error reports
Data processed: user ID, submitted question, answer option, comment, explanation, category, contributor declaration, submission time and processing status.
Purpose: content development, professional review, error correction, preventing abuse and communicating with the contributor.
Legal basis: performance of a service initiated by the user (Article 6(1)(b) GDPR), and legitimate interests in content development and managing legal claims (Article 6(1)(f) GDPR).
Retention: the submission and its review history are retained while the account exists or, in the case of a legal claim, until the end of the applicable limitation period. Educational content lawfully acquired and stripped of personal data may be retained after account termination.
Users must not submit health data relating to an identifiable patient or other unnecessary special-category personal data.
3.5. Attendance data
Data processed: event or attendance-series identifier, session, token, Neptun code or other authorised student identifier, submission time, user ID, and validity and processing status.
Purpose: recording participation in an educational event or session, preventing duplicate or unauthorised check-ins, and generating a participant list.
Legal basis: performance of the relevant service (Article 6(1)(b) GDPR), a lawful instruction or legitimate interest of the event organiser (Article 6(1)(f) GDPR), and, where necessary, a separate institutional agreement.
Retention: for the period agreed with the event organiser or partner institution; in the absence of a separate rule, for no more than one year after the event is closed. In the event of a legal claim or disputed attendance, the data concerned may be retained until the matter is resolved.
Before attendance data is used by a partner institution, it must be determined separately whether the institution and the Service Provider act as independent controllers, joint controllers, or in a controller–processor relationship.
3.6. Service messages and communication
Data processed: name or username, email address, enquiry category and subject, language, message submitted by the user, submission time, status, version and acknowledgement time of the Privacy Notice, and technical delivery data relating to system messages.
Purpose: handling contact and support requests, responding to enquiries, account activation, password reset, and sending security and service notices.
Legal basis: taking steps at the data subject’s request before entering into a contract and performance of a contract (Article 6(1)(b) GDPR); legitimate interests in operating and securing the service and handling enquiries in a documented manner (Article 6(1)(f) GDPR).
Retention: a message stored through the contact form is retained as a general rule for 90 days from submission; technical delivery logs for no more than 90 days; support correspondence arising from continued handling of the matter for no more than two years after it is closed. Data required for a legal claim or obligation may be retained until the matter is resolved.
3.7. Newsletter and marketing
Registration does not currently constitute a newsletter subscription. If a newsletter is introduced later, users may subscribe through a separate, voluntary and unticked-by-default checkbox.
Legal basis: consent (Article 6(1)(a) GDPR). Consent may be withdrawn at any time without disadvantage. Unsubscribing does not affect use of the service.
3.8. Server logs and information security
Data processed: IP address, date and time, requested URL, response code, basic browser and device data, session identifier, security incident and error information.
Purpose: operating the website, troubleshooting, detecting attacks and abuse, and ensuring account and network security.
Legal basis: the Controller’s legitimate interests in secure and reliable operation (Article 6(1)(f) GDPR).
Retention: as a general rule, no more than 90 days; in the event of a security incident, for the period necessary to investigate the incident and manage legal claims.
4. Mandatory and voluntary data
Without data marked as mandatory on the registration interface, the account or relevant function cannot be provided. Failure to complete an optional field does not in itself result in a disadvantage unless the information is necessary for a separately requested function.
Users must not enter unnecessary personal data—particularly patient data, medical records, passwords or another person’s confidential information—into free-text fields.
5. Automated personalisation
The system may select questions or content, calculate results and provide learning suggestions based on the institutional profile, language, previous answers and practice status. This is educational automated personalisation that does not by itself produce legal effects, constitute an official assessment, or similarly significantly affect the data subject.
6. Recipients and processors
Personal data may be accessed only by the Controller, an authorised employee or contributor, and processors providing necessary services, and only to the extent required for their tasks.
6.1. Hosting and server operation
- Provider: DotRoll Kft.
- Address: 1148 Budapest, Fogarasi út 3–5, Hungary
- Task: hosting, database, backup and related technical services.
- Data concerned: data stored on the website and server logs.
6.2. Electronic mail
- Provider: Google Ireland Limited and relevant Google group companies.
- Address: Gordon House, Barrow Street, Dublin 4, Ireland.
- Task: providing pharm.academy business email and correspondence through Google Workspace.
- Data concerned: email address, name, message content and delivery data.
6.3. Transactional system emails
- Provider: Amazon Web Services EMEA SARL.
- Address: 38 Avenue John F. Kennedy, L-1855 Luxembourg, Luxembourg.
- Services: Amazon Simple Email Service (SES) and Amazon Simple Notification Service (SNS).
- Planned task: relaying transactional emails generated by the website and processing failed-delivery and complaint events. The configured sending region is Europe (Frankfurt),
eu-central-1. - Data concerned: sender and recipient email addresses, any name included in the message, subject and message content, technical delivery data, and bounce and complaint data.
The Amazon SES integration has been configured and tested with verified recipients, but the service is currently subject to sandbox restrictions and cannot be used for production sending to general users. Production use may begin only after AWS grants production access and the complete email flow has been retested. Amazon SES will not be used for marketing newsletters; it is intended solely for event-triggered system messages necessary for the service.
If the website later uses a separate newsletter, payment, analytics or social-login provider, this Notice will be updated before activation with the provider’s name, task, the data concerned and safeguards for any transfer to a third country.
6.4. Partner institutions
A partner institution may access institutional functions only on the basis of an agreement, defined permissions and clarified data protection roles. For general partnership or marketing outreach, only aggregated student numbers may be disclosed.
7. Transfers outside the European Economic Area
Some international providers may technically process data in a country outside the European Economic Area. In such a case, the Controller will use the provider only where a safeguard under Chapter V GDPR applies, such as an adequacy decision, standard contractual clauses or another lawful transfer mechanism.
8. Cookies and similar technologies
The website may use strictly necessary cookies to maintain sessions, login, security and language settings. Some functions cannot operate without these cookies, and their use therefore does not require separate consent.
Analytics, convenience or marketing cookies that are not strictly necessary may be activated only after appropriate prior information and—where required—voluntary consent. Rejecting non-essential cookies must not prevent basic use of the service.
The names, providers, purposes and expiry periods of cookies actually used will be listed in a separate cookie notice or cookie settings interface based on a technical cookie audit completed before launch.
9. Data security
The Controller applies access restrictions, encrypted HTTPS connections, separated database users, permission management, backups, logging, updates and other proportionate technical and organisational measures.
No internet service can guarantee the complete absence of risk. A suspected privacy or account-security incident may be reported to education@pharm.academy.
10. Rights of data subjects
Subject to the conditions laid down by law, a data subject may request:
- information and access to personal data processed about them;
- rectification of inaccurate data or completion of incomplete data;
- erasure of personal data;
- restriction of processing;
- data portability under the conditions of the GDPR;
- to object to processing based on legitimate interests;
- to withdraw consent at any time where processing is based on consent;
- to lodge a complaint with a supervisory authority or seek a judicial remedy.
The right to erasure is not absolute. The Controller may refuse or restrict erasure where retention is necessary to comply with a legal obligation, establish, exercise or defend legal claims, investigate a security incident, or on the basis of another exception under the GDPR. The data subject will receive reasons in such a case.
Requests may be sent to education@pharm.academy. The Controller will respond without undue delay and, as a general rule, within one month. Where necessary and subject to the conditions of the GDPR, this period may be extended by a further two months, and the data subject will be informed of the extension.
To prevent unauthorised data requests, the Controller may reasonably request confirmation of the data subject’s identity.
11. Supervisory authority and remedies
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
- Address: 1055 Budapest, Falk Miksa utca 9–11, Hungary
- Postal address: 1363 Budapest, PO Box 9, Hungary
- Email: ugyfelszolgalat@naih.hu
- Telephone: +36 1 391 1400
- Website: https://www.naih.hu
The data subject may also bring proceedings before a court.
12. Users who are minors
The service is intended primarily for users participating in higher education or interested in health sciences education. A person with limited or no legal capacity may use the service only in accordance with applicable law and, where necessary, with the involvement of their legal representative.
13. Amendments to this Notice
The Controller may amend this Notice because of a new feature, processor, processing purpose, change in law or security requirement. The version and effective date are displayed at the top of the document. Registered users will be informed of a material change on the website or by email and, where the nature of the change requires it, will be asked to provide a new declaration.