Privacy Notice
Source language: Hungarian; this document is a translation of the Hungarian source version.
Version: 0.1-draft
Effective date: [TO BE COMPLETED BEFORE LAUNCH]
1. Controller
- Controller: [FULL REGISTERED NAME OF THE COMPANY]
- Registered office: [EXACT ADDRESS OF THE NEW REGISTERED OFFICE]
- Company registration number or other registration number: [TO BE COMPLETED]
- Tax number: [TO BE COMPLETED]
- Privacy contact: education@pharm.academy
- Website: https://pharm.academy
Hereinafter referred to as the “Controller”.
2. Purpose and principles of this Notice
This Notice explains which personal data the Controller processes when operating the pharm.academy website and related educational service, for what purposes, on which legal bases and for how long, who may access the data, and which rights data subjects have.
The Controller processes personal data lawfully, fairly and transparently, for specified purposes, only to the extent and for the period necessary, and protects the data through appropriate technical and organisational measures.
Acknowledging that this Privacy Notice has been read does not mean that consent is the legal basis for every processing activity. The applicable legal basis is identified separately for each purpose.
3. Summary of processing activities
3.1. Registration and user accounts
Data processed: username, email address, secure password hash, name if provided by the user, registration and activation timestamps, account status, user role, registration language, and the version and timestamp relating to the Terms of Use and Privacy Notice acknowledged by the user.
Purpose: creating the account, identification, login, account security, communication and provision of the service.
Legal basis: steps necessary before entering into a contract and performance of the contract (Article 6(1)(b) GDPR); for security logging, the Controller’s legitimate interests (Article 6(1)(f) GDPR).
Retention: for as long as the account exists and for up to 30 days after termination, except for data required for a legal claim, legal obligation or security incident. Data will roll out of backups within no more than 90 days.
3.2. Language and institutional profile
Data processed: preferred language, country, university, faculty, the official name entered by the user for a country, university or faculty that is not listed, and the profile-data version.
Purpose: personalising the service, providing content, permissions and functions associated with an institution or faculty, and assessing demand for institutions not yet listed.
Legal basis: performance of the service (Article 6(1)(b) GDPR); for aggregated institutional demand analysis, the Controller’s legitimate interests in developing the service and preparing institutional partnerships (Article 6(1)(f) GDPR).
Safeguard: only aggregated numbers may be used for institutional outreach. A student’s name, email address, Neptun code or other individual identifier may not be disclosed for this purpose.
Retention: for as long as the account exists or until the user changes the data. Irreversibly anonymised aggregated statistics may be retained without a time limit.
3.3. Learning activity, quizzes and results
Data processed: user ID, question set opened, question and exercise type, answers, correct and incorrect results, percentage summaries, attempt status, technical data needed to resume an attempt, start and completion timestamps, and practice history.
Purpose: operating quizzes, resuming interrupted question sets, displaying results, tracking progress, personalised practice and detecting service errors.
Legal basis: performance of the service (Article 6(1)(b) GDPR); legitimate interests for security, troubleshooting and prevention of abuse (Article 6(1)(f) GDPR).
Retention: for as long as the account exists. When the account is terminated, results may be deleted or irreversibly anonymised unless a partner-institution agreement, legal claim or another appropriate legal basis requires longer retention.
3.4. Question suggestions, content contributions and error reports
Data processed: user ID, submitted question, answer option, comment, explanation, category, contributor declaration, submission time and processing status.
Purpose: content development, professional review, error correction, preventing abuse and communicating with the contributor.
Legal basis: performance of a service initiated by the user (Article 6(1)(b) GDPR), and legitimate interests in content development and managing legal claims (Article 6(1)(f) GDPR).
Retention: the submission and its review history are retained while the account exists or, in the case of a legal claim, until the end of the applicable limitation period. Educational content lawfully acquired and stripped of personal data may be retained after account termination.
Users must not submit health data relating to an identifiable patient or other unnecessary special-category personal data.
3.5. Attendance data
Data processed: event or attendance-series identifier, session, token, Neptun code or other authorised student identifier, submission time, user ID, and validity and processing status.
Purpose: recording participation in an educational event or session, preventing duplicate or unauthorised check-ins, and generating a participant list.
Legal basis: performance of the relevant service (Article 6(1)(b) GDPR), a lawful instruction or legitimate interest of the event organiser (Article 6(1)(f) GDPR), and, where necessary, a separate institutional agreement.
Retention: for the period agreed with the event organiser or partner institution; in the absence of a separate rule, for no more than one year after the event is closed. In the event of a legal claim or disputed attendance, the data concerned may be retained until the matter is resolved.
Before attendance data is used by a partner institution, it must be determined separately whether the institution and the Service Provider act as independent controllers, joint controllers, or in a controller–processor relationship.
3.6. Service messages and communication
Data processed: name or username, email address, type of message, sending time, technical delivery data and the content of messages sent by the user.
Purpose: account activation, password reset, security and service notices, and responding to support requests.
Legal basis: performance of the contract (Article 6(1)(b) GDPR); legitimate interests for security messages (Article 6(1)(f) GDPR).
Retention: technical delivery logs for no more than 90 days; support correspondence for no more than two years after the matter is closed, or until a related legal claim is resolved.
3.7. Newsletter and marketing
Registration does not currently constitute a newsletter subscription. If a newsletter is introduced later, users may subscribe through a separate, voluntary and unticked-by-default checkbox.
Legal basis: consent (Article 6(1)(a) GDPR). Consent may be withdrawn at any time without disadvantage. Unsubscribing does not affect use of the service.
3.8. Server logs and information security
Data processed: IP address, date and time, requested URL, response code, basic browser and device data, session identifier, security incident and error information.
Purpose: operating the website, troubleshooting, detecting attacks and abuse, and ensuring account and network security.
Legal basis: the Controller’s legitimate interests in secure and reliable operation (Article 6(1)(f) GDPR).
Retention: as a general rule, no more than 90 days; in the event of a security incident, for the period necessary to investigate the incident and manage legal claims.
4. Mandatory and voluntary data
Without data marked as mandatory on the registration interface, the account or relevant function cannot be provided. Failure to complete an optional field does not in itself result in a disadvantage unless the information is necessary for a separately requested function.
Users must not enter unnecessary personal data—particularly patient data, medical records, passwords or another person’s confidential information—into free-text fields.
5. Automated personalisation
The system may select questions or content, calculate results and provide learning suggestions based on the institutional profile, language, previous answers and practice status. This is educational automated personalisation that does not by itself produce legal effects, constitute an official assessment, or similarly significantly affect the data subject.
6. Recipients and processors
Personal data may be accessed only by the Controller, an authorised employee or contributor, and processors providing necessary services, and only to the extent required for their tasks.
6.1. Hosting and server operation
- Provider: DotRoll Kft.
- Address: 1148 Budapest, Fogarasi út 3–5, Hungary
- Task: hosting, database, backup and related technical services.
- Data concerned: data stored on the website and server logs.
6.2. Electronic mail
- Provider: Google Ireland Limited and relevant Google group companies.
- Task: providing pharm.academy business email and correspondence through Google Workspace.
- Data concerned: email address, name, message content and delivery data.
If the website later uses a separate SMTP, transactional email, newsletter, payment, analytics or social-login provider, this Notice will be updated before activation with the provider’s name, task, the data concerned and safeguards for any transfer to a third country.
6.3. Partner institutions
A partner institution may access institutional functions only on the basis of an agreement, defined permissions and clarified data protection roles. For general partnership or marketing outreach, only aggregated student numbers may be disclosed.
7. Transfers outside the European Economic Area
Some international providers may technically process data in a country outside the European Economic Area. In such a case, the Controller will use the provider only where a safeguard under Chapter V GDPR applies, such as an adequacy decision, standard contractual clauses or another lawful transfer mechanism.
8. Cookies and similar technologies
The website may use strictly necessary cookies to maintain sessions, login, security and language settings. Some functions cannot operate without these cookies, and their use therefore does not require separate consent.
Analytics, convenience or marketing cookies that are not strictly necessary may be activated only after appropriate prior information and—where required—voluntary consent. Rejecting non-essential cookies must not prevent basic use of the service.
The names, providers, purposes and expiry periods of cookies actually used will be listed in a separate cookie notice or cookie settings interface based on a technical cookie audit completed before launch.
9. Data security
The Controller applies access restrictions, encrypted HTTPS connections, separated database users, permission management, backups, logging, updates and other proportionate technical and organisational measures.
No internet service can guarantee the complete absence of risk. A suspected privacy or account-security incident may be reported to education@pharm.academy.
10. Rights of data subjects
Subject to the conditions laid down by law, a data subject may request:
- information and access to personal data processed about them;
- rectification of inaccurate data or completion of incomplete data;
- erasure of personal data;
- restriction of processing;
- data portability under the conditions of the GDPR;
- to object to processing based on legitimate interests;
- to withdraw consent at any time where processing is based on consent;
- to lodge a complaint with a supervisory authority or seek a judicial remedy.
The right to erasure is not absolute. The Controller may refuse or restrict erasure where retention is necessary to comply with a legal obligation, establish, exercise or defend legal claims, investigate a security incident, or on the basis of another exception under the GDPR. The data subject will receive reasons in such a case.
Requests may be sent to education@pharm.academy. The Controller will respond without undue delay and, as a general rule, within one month. Where necessary and subject to the conditions of the GDPR, this period may be extended by a further two months, and the data subject will be informed of the extension.
To prevent unauthorised data requests, the Controller may reasonably request confirmation of the data subject’s identity.
11. Supervisory authority and remedies
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
- Address: 1055 Budapest, Falk Miksa utca 9–11, Hungary
- Postal address: 1363 Budapest, PO Box 9, Hungary
- Email: ugyfelszolgalat@naih.hu
- Telephone: +36 1 391 1400
- Website: https://www.naih.hu
The data subject may also bring proceedings before a court.
12. Users who are minors
The service is intended primarily for users participating in higher education or interested in health sciences education. A person with limited or no legal capacity may use the service only in accordance with applicable law and, where necessary, with the involvement of their legal representative.
13. Amendments to this Notice
The Controller may amend this Notice because of a new feature, processor, processing purpose, change in law or security requirement. The version and effective date are displayed at the top of the document. Registered users will be informed of a material change on the website or by email and, where the nature of the change requires it, will be asked to provide a new declaration.