Privacy Policy for registrants of events organised by White Hat IT Security Kft.
Introduction
White Hat IT Security Kft. (headquarters: 1021 Budapest, Ötvös János u. 3. ; company registration number: 01-09-326869, tax number: 26373643-2-41, hereinafter referred to as “White Hat”) takes utmost care to ensure that the personal data of persons registering for the event organised by it is protected in accordance with the provisions of Regulation (EU) 2016/679 of the EUROPEAN PARLIAMENT AND OF THE COUNCIL of 21 October 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, and repealing Regulation (EC) No 95/46/EC (General Data Protection Regulation) (hereinafter referred to as “the Regulation” or “GDPR”) and the Hungarian Data Protection Act of 2011 on the right to information self-determination and freedom of information. CXII of 2011 and other applicable legislation.
The terms used in this Privacy Policy shall have the meaning given to them in the interpretative provisions of the GDPR.
The purpose of this Privacy Policy (the “Policy” or the “Privacy Policy”) is to provide White Hat’s event registrants with information about the data management practices that White Hat uses when processing their personal data. White Hat acknowledges that it is bound by this Notice and its contents, respecting the privacy rights and the right of self-determination of natural persons who use the Services in any way and of event registrants.
The event registrant uses the services of the Data Controller on his/her own behalf. Otherwise, the registrant is responsible for ensuring that the registrant’s consent to the processing of personal data provided or made available to third natural persons has been lawfully obtained. The registrant is responsible for the content provided or shared by the registrant and for the truthfulness, adequacy and accuracy of the personal data. White Hat shall not be liable for any omissions or consequences arising from incorrectly provided data, and White Hat expressly disclaims any liability in this regard.
The registrant has the right to withdraw his/her consent to the processing of part or all of his/her data, or to request the deletion of his/her data, by sending a written request to White Hat at the following e-mail address: privacy@whitehat.eu.
1. General provisions
1.1. Name and contact details of the Data Controller
Data Controller: White Hat IT Security Service Provider and Trading Limited Liability Company
Registered office: 1021 Budapest, Ötvös János u. 3.
Postal address: 1021 Budapest, Ötvös János u. 3.
Company registration number: 01-09-326869
Tax number: 26373643-2-41
Telephone number: +36 20 346 9646
Email address: privacy@whitehat.eu
Website address: https://www.whitehat.eu
1.2. Name and contact details of the Data Protection Officer
The Data Protection Officer of the controller is Alexandra Enyedi.
Contact details of the data controller: privacy@whitehat.eu
1.3. Purpose of the processing and scope of the data processed
Scope of personal data processed
The name, e-mail address and telephone number of the natural person and, if provided, the type of the organisation that employs the natural person, the job role and the name of Company.
Purpose of processing
The purpose of the processing is to maintain contact and to provide information related to the conference and post-event communication about a business proposal.
1.4. Legal basis for processing
Data processing is based on the voluntary and explicit informed consent of the event registrants based on Article 6(1)(a) of Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter: GDPR). By registering for an event, the event registrant confirms that he/she has fully read and understood this Privacy Policy, accepts the provisions contained herein as binding upon him/her and voluntarily and expressly consents to White Hat processing the personal data provided to it for the purposes set out in this Privacy Policy.
1.5. The period of storage of personal data
Personal data as described in this Notice will be kept for 12 months after the event. Registrants may opt out at any time and withdraw their consent to the processing of their data. As a result of a request for deletion, the Controller will delete the personal data of the data subject no later than [72 hours] after the relevant request.
1.6. Data processing
White Hat uses data processors to perform certain technical (IT) operations on personal data. The data processor(s) is/are:
- Microsoft Corporation (headquarters: Redmond, Washington, United States) – activities: mailing, registry platform operation, cloud and hosting services
2. Data access and security measures, data transfers
2.1. Access to data, data portability
Personal data may be accessed by those employees of White Hat who have a need to know in order to perform their duties. Personal data of event registrants will not be transferred to third parties.
2.2. Data security measures
The Data Controller shall take all reasonable measures to ensure the security of the data, in particular to provide an adequate level of protection against unauthorized access, alteration, disclosure, disclosure, deletion or destruction, accidental destruction or accidental damage. The Controller shall ensure the security of the data by appropriate technical and organisational measures.
The Data Controller shall select and operate the IT tools used for the processing of personal data in the provision of the service in such a way that the processed data:
- accessible to authorised persons (availability);
- authenticity and authentication are ensured (authenticity of processing);
- is verifiable (data integrity);
- is protected against unauthorised access (data confidentiality).
The data controller shall retain the following during the processing
- Confidentiality: protect the information so that only those who are entitled to access it have access to it;
- Integrity: to protect the accuracy and completeness of the information and the method of processing;
- Availability: making sure that when an authorised user needs it, he or she can actually access the information and the tools to do so are available.
3. Rights of the natural person/consent
A person registering for an event may request information in writing from White Hat via the contact details provided in point 1 to inform:
- what personal data,
- on what legal basis,
- for what purpose,
- from what source,
- for what purpose, for what purposes, for what purpose, for what purpose, for what purpose, for what purpose, for what purpose, for what purpose, for how long it is processing your personal data,
- data controller, to whom, when, under what law, to which personal data, to which personal data has been given access or to whom has personal data been transferred.
The Controller will provide the information to the registrant in a commonly used electronic format, unless the registrant requests it in writing on paper. White Hat will not provide oral information over the telephone.
White Hat will provide a copy of the personal information (in person at the office) to the registrant for the first time free of charge. For additional copies requested by the data controller, White Hat may charge a reasonable fee based on administrative costs. If the registrant requests a copy electronically, White Hat will provide the information to the registrant by email in a commonly used electronic format.
Following the information, if the registrant does not agree with the data processing or the accuracy of the data processed, he/she may request the rectification, supplementation, erasure or restriction of the processing of personal data concerning him/her, as specified in point 6, or object to the processing of such personal data, or initiate the procedure specified in point 7.
3.1. Right to rectification and integration of personal data processed
Upon the written request of the registrant, the Data Controller shall, without undue delay, correct inaccurate personal data provided by the registrant in writing or in person, or complete incomplete data with the content indicated by the registrant. The Data Controller shall inform any recipient to whom it has disclosed the personal data of the correction or completion, unless this proves impossible or involves a disproportionate effort. The registrant shall inform these recipients of the data if they so request in writing.
3.2. Right to restriction of processing
The registrant may, by written request, ask the Data Controller to restrict the processing of his/her data if.
- the accuracy of the personal data is contested by the registrant, in which case the restriction shall apply for the period of time necessary to allow the Controller to verify the accuracy of the personal data,
- the processing is unlawful and the registrant opposes the deletion of the data and requests instead the restriction of their use,
- the Controller no longer needs the personal data for the purposes of processing, but the registrant requires them for the establishment, exercise or defence of legal claims.
With the exception of storage, personal data of the registrant may only be processed with the consent of the registrant or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State during this period. The controller shall inform in advance the registrant at whose request it has restricted processing of the lifting of the restriction of processing.
3.3 Right to erasure (right to be forgotten)
At the request of the registrant, the Data Controller shall delete personal data concerning the registrant without undue delay if one of the following grounds applies:
- the personal data are no longer necessary for the purposes for which they were collected or otherwise processed by the Data Controller;
- the registrant withdraws the consent on the basis of which the data were processed and there is no other legal basis for the processing;
- the personal data are unlawfully processed by the Data Controller.
The registrant may not exercise the right to erasure or blocking if the processing is necessary
- for the exercise of the right to freedom of expression and information;
- on grounds of public interest in the field of public health;
- for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes where the exercise of the right to erasure would make such processing impossible or seriously impair it; or
- for the establishment, exercise or defence of legal claims.
3.4. Right to data portability
The registrant has the right to request to receive the data he/she has provided in a machine-readable form. If technically feasible, he or she may request that the data be transferred to another controller. In all cases, the right is limited to the data provided by the registrant, no other data can be carried (e.g. statistics, etc.)
The registrant may only use the personal data relating to him/her that is held by the Data Controller:
- in a structured, widely used, machine-readable format,
- is entitled to transfer it to another controller,
- may request the direct transfer of the data to another controller, if technically feasible in White Hat’s system.
White Hat will only comply with a request for data portability on the basis of a written request sent by email or post. In order for a request to be granted, White Hat must be satisfied that the authorised registrant wishes to exercise this right. A registrant may request portability of data that he or she has provided to White Hat under this right. Exercising this right does not automatically result in the deletion of the data from White Hat’s systems, and therefore the registrant will remain on White Hat’s systems after exercising this right, unless he or she also requests the deletion of his or her data.
3.5. Deadline for fulfilling the request
The Data Controller shall inform the registrant of the measures taken without undue delay, but in any event within one month of receipt of any request pursuant to points 5.1 to 5.5. Where necessary, taking into account the complexity of the request and the number of requests, this time limit may be extended by a further two months, but in that case White Hat shall inform the registrant within one month of receipt of the request, stating the reasons for the delay, and that the registrant may lodge a complaint with the supervisory authority and exercise his/her right to judicial remedy.
If the registrant’s request is manifestly unfounded or excessive (in particular in view of its repetitive nature), the Data Controller may charge a reasonable fee for complying with the request or refuse to act on the request. The burden of proof shall be on the Data Controller.
If the registrant has submitted the request by electronic means, the information shall be provided by the Data Controller by electronic means, unless the registrant requests otherwise.
The Controller shall inform any recipient to whom or with whom the personal data have been disclosed of any rectification, erasure or restriction of processing that it has carried out, unless this proves impossible or involves a disproportionate effort. Upon request, White Hat will inform the registrant of these recipients.
4. Enforcement options
If the data subject considers that the Authority has infringed the applicable data protection requirements in the processing of his or her personal data, he or she may – lodge a complaint with White Hat IT Security Kft (White Hat IT Security Kft, address: 1021 Budapest, Ötvös János u. 3., postal address: 1021 Budapest, Ötvös János u. 3. E-mail: privacy@whitehat.eu, website: https://www.whitehat.eu), or – have the right to have his or her data protected by a court of law, which will rule on the matter out of turn. In the event of a breach of the rights of the Principal or other data subjects in connection with the processing of personal data, the Principal may, as a general rule, exercise their rights against the Principal before the district court of the place of residence of the data subject and, pursuant to the provisions of the applicable legislation, may also apply to the National Authority for Data Protection and Freedom of Information (postal address: 1534 Budapest, PO Box 834; address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c.). The court shall have the right to rule on the matter out of turn.
Personal data that our partners and customers ask us to process on their behalf (“Processor Data”). White Hat IT Security offers security services and solutions, and related support and professional services. With some exceptions as identified below, under applicable law, in certain contexts White Hat is considered the “processor” of the personal data we receive through the White Shark services or through our other IT security services, and our customer is (or acts on behalf of) the “controller” of the data (i.e. the company with the right to decide how the data is used).
Personal data that we handle for our own business (“Controller Data”), other than for our human resources and recruiting operations. Under applicable law, White Hat is a “controller” of this data.
This Privacy Policy includes details specific to Processor Data, details specific to Controller Data, and information relevant to our handling of both kinds of data.

