PRIVACY POLICY

For the website of the civil initiative for the establishment of Hungarian–Ukrainian Friendship Day

Effective from: 15 July 2026

1. Details of the Data Controller

Name of the Data Controller: Simon Richárd
Postal address: 1095 Budapest, Gabona utca 7., Hungary
Email address: info@richardsimon.eu
Telephone number: +36 30 591 7477 / +49 176 3544 1170
Website: https://magyarukran.hu

The Data Controller is the founder and coordinator of the civil initiative supporting the establishment of Hungarian–Ukrainian Friendship Day.

Questions, requests and complaints concerning the processing of personal data may be submitted via the email address or postal address specified above.

The Data Controller is not required to appoint a Data Protection Officer and therefore does not employ a separate Data Protection Officer.

2. Purpose and legal background of this Notice

This Notice explains what personal data the Data Controller processes in connection with the Hungarian–Ukrainian Friendship Day civil initiative, for what purposes, on what legal basis and for how long.

The processing of personal data is governed in particular by the following legislation:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council, the General Data Protection Regulation, hereinafter referred to as the GDPR;
  • Act CXII of 2011 of Hungary on Informational Self-Determination and Freedom of Information;
  • Act CVIII of 2001 of Hungary on Electronic Commerce Services and Certain Issues Related to Information Society Services;
  • Act XLVIII of 2008 of Hungary on the Basic Requirements and Certain Restrictions of Commercial Advertising Activities.

Under Article 13 of the GDPR, the Data Controller must provide clear information at the time personal data are collected, including information on the identity of the Data Controller, the purpose, legal basis and duration of the processing, the recipients of the data and the rights of the data subject.

3. Principles of data processing

The Data Controller processes personal data:

  • lawfully, fairly and transparently;
  • for predetermined and clearly defined purposes;
  • only to the extent necessary for those purposes;
  • accurately and, where possible, in an up-to-date form;
  • only for as long as necessary;
  • subject to appropriate technical and organisational safeguards.

The Data Controller does not sell or rent personal data and does not use them for purposes other than those specified in this Notice.

4. Supporting the initiative and processing online signatures

4.1. Purpose of the processing

The purposes of the processing are:

  • to collect and record statements supporting the establishment of Hungarian–Ukrainian Friendship Day;
  • to verify the authenticity and uniqueness of signatures;
  • to prevent abuse and duplicate signatures;
  • to provide technical confirmation of signatures;
  • to demonstrate public support for the initiative;
  • to prepare aggregated statistics that do not allow individuals to be identified;
  • to forward the petition, statements of support or the results of the initiative to the competent state authorities, public-law bodies and decision-makers.

An online statement of support does not constitute an officially verified signature under the rules governing referendum procedures.

4.2. Categories of personal data processed

Mandatory data

  • surname;
  • given name;
  • email address;
  • the fact and date of submission of the statement of support;
  • the fact and date of consent to the processing of personal data;
  • technical security data, such as IP address, form identifier and confirmation status.

Optional data

  • name of the organisation or institution;
  • job title, official position or role;
  • comment or personal message submitted by the signatory;
  • consent to the public display of the name and other data provided.

Failure to provide optional data does not prevent the person from supporting the initiative.

4.3. Legal basis for processing

The legal basis for processing is the data subject’s freely given, specific, informed and unambiguous consent under Article 6(1)(a) of the GDPR.

As supporting a petition concerning a matter of public life may, in certain circumstances, allow conclusions to be drawn regarding the data subject’s opinions or beliefs, the Data Controller applies enhanced protection to such data and, where necessary, also relies on the data subject’s explicit consent under Article 9(2)(a) of the GDPR.

In previous cases concerning signature-collection campaigns, the Hungarian National Authority for Data Protection and Freedom of Information, hereinafter referred to as the NAIH, emphasised that supporting a petition and receiving subsequent communications are separate processing purposes and therefore may not be based on a single general consent.

4.4. Duration of processing

The Data Controller processes personal data relating to statements of support:

  • until the consent is withdrawn; or
  • for one year after the initiative has ended; but
  • in any event for no longer than five years from the date of signature.

At the end of the five-year period, the Data Controller reviews whether continued processing is necessary and deletes or irreversibly anonymises personal data that are no longer required.

Where the data subject withdraws their support or consent, the Data Controller deletes the personal data without undue delay and, where possible, no later than within 30 days, unless further retention is necessary for the establishment, exercise or defence of legal claims.

4.5. Consequences of failure to provide data

The online statement of support cannot be recorded without the mandatory data.

Providing optional data is not a condition of supporting the initiative.

5. Public display of supporters’ data

Submitting a statement of support does not automatically mean that the signatory’s name or other personal data will be publicly displayed on the website.

A name, town or city, organisation, institution, position or comment may be published only where the data subject has provided separate and explicit consent.

Purpose of the processing

To publicly demonstrate the social, professional and institutional support for the initiative.

Legal basis

The data subject’s separate consent under Article 6(1)(a) of the GDPR.

Data that may be displayed publicly

Depending on the choice of the data subject:

  • name;
  • town, city or country;
  • name of organisation or institution;
  • job title or official position;
  • comment provided by the data subject for public disclosure.

Email addresses, telephone numbers, IP addresses and other contact or technical data are not made public.

Data published on the internet may become accessible to anyone, may be indexed by search engines and may be obtained by third parties. Consent to public display may be withdrawn at any time.

6. Submission of the petition to decision-makers

The Data Controller may submit or present the results of the initiative, in particular, to:

  • the National Assembly of Hungary;
  • Members of Parliament;
  • the competent ministries and other public authorities;
  • the Office of the President of Hungary;
  • the diplomatic missions of Hungary and Ukraine;
  • other public-law or institutional recipients connected with the purpose of the initiative.

As a primary rule, the total number of signatures, their geographical distribution and other anonymous statistics will be submitted.

The names of individual supporters may be disclosed only where this is necessary for the credible presentation of the petition and where the data subject was appropriately informed of this at the time of signing. Email addresses, IP addresses and newsletter-consent records will not be disclosed.

Where the Data Controller intends to submit the complete list of names, this must be stated separately and clearly on the signature form.

7. Communications relating directly to the signature

The Data Controller may use the signatory’s email address to send messages directly related to the signature, including:

  • confirmation of the email address or signature;
  • confirmation that the signature has been successfully recorded;
  • technical or data-protection information relating to the signature;
  • clarification of an incorrect, incomplete or potentially abusive signature;
  • a response to the data subject’s own request.

Such messages may not contain marketing communications concerning other campaigns, events or general news unless the data subject has provided separate consent.

8. Newsletter and regular information

8.1. Purpose of the processing

Subject to the data subject’s separate consent, the Data Controller may send information by email concerning:

  • the progress of the initiative;
  • the results achieved;
  • cultural, educational, diplomatic and civil-society programmes connected with Hungarian–Ukrainian Friendship Day;
  • events and opportunities to participate that are directly related to the initiative.

Subscribing to the newsletter is not a condition of signing the petition.

8.2. Legal basis

The data subject’s voluntary and separate consent under Article 6(1)(a) of the GDPR.

Separate checkboxes must be used for signing the petition and subscribing to the newsletter. The newsletter checkbox may not be pre-selected. According to the guidance of the European Data Protection Board, separate consent options must be provided for different processing purposes.

8.3. Categories of data processed

  • name;
  • email address;
  • date and time of subscription and consent;
  • technical data required to verify the subscription;
  • date of unsubscribing.

8.4. Duration of processing

Until the consent is withdrawn or the data subject unsubscribes from the newsletter.

The Data Controller may review and delete subscriptions that have remained inactive for an extended period at least once every three years.

The data subject may unsubscribe using the link provided in each newsletter or by sending a request to info@richardsimon.eu.

9. Contact and correspondence

Where a data subject contacts the Data Controller by email, telephone or through the website’s contact form, the Data Controller may process the following data:

  • name;
  • email address;
  • telephone number;
  • content of the message;
  • date and time of the enquiry and response;
  • any other data voluntarily provided by the data subject.

Purpose of the processing

To respond to enquiries, maintain contact and handle complaints and data-protection requests.

Legal basis

  • the data subject’s consent;
  • taking steps at the request of the data subject;
  • where necessary, the Data Controller’s legitimate interest in documenting communications and legal claims.

Duration

For no longer than two years after the matter has been finally concluded, unless longer retention is necessary in connection with a legal claim.

Requests concerning the exercise of data-protection rights and the responses provided may be retained for five years after the request has been closed, in order to demonstrate the Data Controller’s compliance with the accountability principle.

10. Statistical data

The Data Controller may prepare anonymous statistics based on the statements of support, including:

  • the number of signatures;
  • the distribution of supporters by country, town or city;
  • the number of participating organisations and institutions;
  • changes in the number of signatures over time.

Anonymous data that can no longer be linked to an identified or identifiable natural person do not constitute personal data.

The Data Controller may use and publish anonymous statistics without any time limitation.

11. Technical log data and information security

When the website is visited, the web server and security systems may automatically record technical data, including:

  • IP address;
  • date and time of the visit;
  • address of the page viewed;
  • browser and operating-system type;
  • referring page;
  • error codes and security events;
  • session identifiers.

Purpose of the processing

  • to ensure the secure operation of the website;
  • to prevent cyberattacks and abuse;
  • to identify and correct errors;
  • to prevent duplicate or automated petition signatures;
  • to protect the Data Controller’s legal claims.

Legal basis

The Data Controller’s legitimate interest in ensuring the secure and reliable operation of the website under Article 6(1)(f) of the GDPR.

Duration

Security logs and server logs are, as a general rule, retained for no longer than 90 days. In the event of a security incident or legal dispute, the relevant data may be retained until the matter is concluded or until the applicable limitation period expires.

12. Cookies and similar technologies

The website may use cookies that are strictly necessary for its operation without the user’s consent.

Non-essential cookies, including analytics, marketing or external-media cookies, may be activated only after the data subject has given prior consent.

Detailed information on cookies is provided in the website’s separate Cookie Notice and cookie-settings interface.

Where the website embeds external video content, such as a YouTube video, it should be blocked until the user provides consent or displayed using an enhanced privacy mode.

Where any of the following services are used, the Cookie Notice must be supplemented accordingly:

  • Google Analytics;
  • Meta Pixel;
  • YouTube;
  • externally loaded Google Fonts;
  • Google reCAPTCHA;
  • Cloudflare Turnstile;
  • social-sharing plugins.

13. Data processors and recipients

The Data Controller may use data processors for the operation of the website. Data processors may process personal data only on the instructions of the Data Controller and only to the extent necessary to provide their services.

13.1. Hosting and server service provider

Name: Websupport s.r.o.
Registered office: Karadžičova 12, 821 08 Bratislava, Slovakia
Service: web hosting, database hosting and backup services
Data processed: personal data processed through the website and server logs

13.2. Domain and technical service provider

Name: Websupport s.r.o.
Registered office: Karadžičova 12, 821 08 Bratislava, Slovakia
Service: domain management, DNS services and technical infrastructure

13.3. Email and SMTP service provider

Name: Websupport s.r.o.
Registered office: Karadžičova 12, 821 08 Bratislava, Slovakia
Service: delivery of confirmation and information emails
Data processed: name, email address, message content and delivery data

13.4. Newsletter service provider

Name: Websupport s.r.o.
Registered office: Karadžičova 12, 821 08 Bratislava, Slovakia
Service: management of subscriptions and newsletters
Data processed: name, email address, subscription and unsubscription data

13.5. Website creator and administrator

Name: Simon Richárd
Address: 1095 Budapest, Gabona utca 7., Hungary
Service: WordPress maintenance, security and technical tasks
Access: only to the extent necessary to perform the relevant tasks

13.6. Theme and plugins used for the technical operation of the website

The website operates using the WordPress content-management system and uses the following theme and plugins.

13.6.1. Twenty Twenty-Five theme

The WordPress Twenty Twenty-Five theme provides the website’s visual appearance and basic structural operation.

The theme itself is not used to independently collect or transfer personal data. Data processing may occur only in connection with other website functions, such as the signature-collection form, technical logging or the use of external content.

13.6.2. Elementor

The Data Controller uses the Elementor plugin to create the website’s pages, content blocks and mobile-responsive design.

The plugin primarily performs editing and display functions. Elementor’s own form-processing feature is not used on this website, and therefore no separate collection of visitor data takes place through the plugin.

Any technical or usage data connected with Elementor may be transmitted to Elementor’s provider only where the Data Controller separately enables the sharing of usage data or activates an external Elementor service.

13.6.3. Petitioner

The Petitioner plugin provides the technical system for the online collection of statements of support and signatures. The plugin enables the operation of the signature form, storage of signatures, sending of confirmations, handling of duplicate or potentially abusive submissions and export of data. It may also support a public list of supporters, anonymous signing, newsletter consent and email confirmation.

Depending on the actual configuration of the form, the following data may be processed through the plugin:

  • name;
  • email address;
  • organisation or institution;
  • job title or official position;
  • comment;
  • consent statements;
  • date and time of signature;
  • IP address and technical data.

Petitioner operates within WordPress, and the data are primarily stored in the website’s own database. Data may be transmitted to additional external providers where separate external services are configured for email delivery, spam protection or other functions.

13.6.4. Polylang

The Polylang plugin enables the management of the Hungarian, Ukrainian and English versions of the website and the preservation of the visitor’s language preference.

According to information provided by the developer of Polylang, the plugin does not generally collect visitors’ personal data. It may place a technical cookie that remembers the visitor’s language preference so that the website is displayed in the selected language during a subsequent visit.

The sole purpose of this cookie is to retain the language setting; it is not used for advertising or profiling.

13.6.5. AddToAny Share Buttons

The AddToAny plugin enables visitors to share pages of the initiative through social-media platforms, messaging applications or email.

The sharing options may link to Facebook, LinkedIn, WhatsApp, X, Pinterest and other external services.

According to AddToAny, the service does not sell personal data and, according to its own statement, does not store personal data during the basic operation of the sharing function. However, typical server-log data may be processed temporarily as part of the technical operation of the service, including IP address, browser data, the address of the shared page and the time of sharing.

When a visitor clicks on a social-sharing button, they are redirected to the website or application of the relevant external provider. From that point onward, the processing of personal data is governed by the privacy policy of that provider.

Social-media providers may identify the visitor where the visitor is logged in to the relevant service. The Data Controller has no control over the processing carried out by external providers.

13.6.6. Site Kit by Google and Google Analytics

The website uses the Site Kit by Google plugin to integrate Google Search Console, Google Analytics and Google PageSpeed Insights, and to analyse website traffic, technical performance and visibility in search engines.

Using Google Analytics, the Data Controller may receive aggregated statistical information, including:

  • the number of website visitors;
  • the pages viewed;
  • the date, time and duration of visits;
  • the approximate geographical location of visitors;
  • the type of device, browser and operating system used;
  • the source from which the visitor reached the website;
  • certain actions performed on the website.

Google Analytics may use first-party cookies, in particular the _ga cookie, to distinguish individual visitors and sessions. The service may transmit technical data to Google, including information derived from IP addresses, device and browser data, session identifiers and data concerning the use of the website.

Purpose of the processing: measuring website traffic, conducting aggregated analysis of user behaviour, improving the operation and content of the website and monitoring its technical performance.

Legal basis: the data subject’s prior and voluntary consent under Article 6(1)(a) of the GDPR.

Cookies and data-collection tags relating to Google Analytics are activated only where the visitor consents to statistical processing through the cookie-settings interface. The website uses Google Consent Mode, which adapts the operation of Google tags to the visitor’s cookie choices. However, according to the Site Kit documentation, the website operator remains responsible for providing appropriate information and obtaining valid consent.

Visitors may withdraw or modify their consent at any time through the website’s cookie settings. Refusing consent does not prevent use of the website’s essential functions, but the relevant visit may not appear, or may appear only in a limited form, in the web-analytics statistics.

In providing its services, Google may act as a data processor and, in relation to certain processing operations, as an independent data controller.

Service provider: Google Ireland Limited
Registered office: Gordon House, Barrow Street, Dublin 4, Ireland
Service: Google Analytics, Google Search Console, PageSpeed Insights and Site Kit integration
Google Privacy Policy: available through Google’s privacy policies.

Google may also process data outside the European Economic Area, particularly in systems located in the United States of America. Such transfers may take place on the basis of applicable adequacy decisions, the EU–US Data Privacy Framework, standard contractual clauses approved by the European Commission or other appropriate safeguards.

13.6.7. Yoast SEO

The Yoast SEO plugin is used for the technical optimisation of the website for search engines, including:

  • managing page titles and meta descriptions;
  • creating an XML sitemap;
  • creating technical data that can be interpreted by search engines;
  • managing social-media sharing previews;
  • supporting the search-engine optimisation of content.

According to information provided by Yoast, the plugin does not store visitors’ personal data during its basic operation but instead processes the website’s content and technical data. Usage data may be transmitted to Yoast only where the Data Controller separately consents to this or enables the transmission of usage statistics.

14. Transfers of personal data to third countries

The Data Controller seeks to use service providers that store personal data within the European Economic Area.

Certain technical service providers may process personal data outside the European Economic Area, particularly in the United States of America.

Such transfers may take place only on an appropriate legal basis and subject to appropriate safeguards, including:

  • an adequacy decision adopted by the European Commission;
  • transfer to a service provider participating in the EU–US Data Privacy Framework;
  • the use of standard contractual clauses adopted by the European Commission;
  • other safeguards compliant with the GDPR.

The specific conditions governing international data transfers are set out in the privacy notices of the relevant data processors.

15. Personal data of minors

The initiative’s online support platform is primarily intended for persons who have reached the age of 16.

A person under the age of 16 may provide personal data only with the permission of their legal representative.

Where the Data Controller becomes aware that it is processing personal data relating to a minor without the required permission, the data will be deleted without undue delay.

16. Automated decision-making and profiling

The Data Controller does not use solely automated decision-making or profiling that produces legal effects concerning the data subject or similarly significantly affects them.

The system may use automated technical checks to identify spam, bots, false signatures or duplicate signatures. Such checks are not used to assess the data subject’s opinions or personal characteristics.

17. Data security

The Data Controller applies appropriate technical and organisational measures to protect personal data, in particular against:

  • unauthorised access;
  • unauthorised alteration;
  • unlawful disclosure;
  • loss of data;
  • destruction;
  • malicious cyberattacks.

The measures applied include:

  • encrypted HTTPS connections;
  • regular security updates;
  • strong and unique passwords;
  • multi-factor authentication where available;
  • restricted administrative access;
  • regular and protected backups;
  • spam and attack protection;
  • access and security logging;
  • regular reviews of databases and access rights.

Only the Data Controller and persons expressly authorised by the Data Controller may access personal data.

18. Personal-data breaches

In the event of a personal-data breach, the Data Controller assesses the likely consequences, takes the necessary measures to mitigate harm and documents the incident.

Where the breach is likely to result in a risk to the rights and freedoms of natural persons, the Data Controller reports it to the competent supervisory authority in accordance with the GDPR.

Where the breach is likely to result in a high risk, the Data Controller also appropriately informs the affected data subjects.

19. Rights of the data subject

The data subject may exercise the following rights through the Data Controller’s contact details.

19.1. Right to information and access

The data subject may request confirmation as to whether the Data Controller processes their personal data and may request access to the data and information concerning the purpose, legal basis, duration and recipients of the processing.

19.2. Right to rectification

The data subject may request the correction of inaccurate personal data or the completion of incomplete data.

19.3. Right to erasure

The data subject may request the deletion of their personal data, in particular where:

  • the purpose of the processing has ceased to exist;
  • consent has been withdrawn and there is no other legal basis;
  • the processing is unlawful;
  • deletion is required by law.

19.4. Right to restriction of processing

The data subject may request restriction of the processing where they contest the accuracy of the data, the processing is unlawful or the data are required for the establishment, exercise or defence of a legal claim.

19.5. Right to data portability

Where processing is automated and based on consent, the data subject may request the personal data provided by them in a structured, commonly used and machine-readable format.

19.6. Right to object

Where processing is based on legitimate interests, the data subject may object to the processing of their personal data.

19.7. Right to withdraw consent

The data subject may withdraw their consent at any time without giving reasons.

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

19.8. Withdrawal of support

The data subject may separately request:

  • deletion of their supporting signature;
  • removal of their name from the public list of supporters;
  • deletion of their comment;
  • termination of their newsletter subscription.

According to the NAIH’s summary, the GDPR grants data subjects, among other rights, the rights of access, rectification, erasure, restriction, data portability and objection.

20. Handling requests from data subjects

Requests may be submitted using the following contact details:

Email: info@richardsimon.eu
Telephone: +36 30 591 7477 / +49 176 3544 1170
Postal address: Simon Richárd, 1095 Budapest, Gabona utca 7., Hungary

Before fulfilling a request, the Data Controller may, where necessary, request additional information to verify the identity of the applicant.

The Data Controller responds without undue delay and, in any event, no later than one month after receiving the request. Taking into account the complexity and number of requests, this period may be extended by a further two months. The Data Controller informs the data subject of any extension within one month.

Requests are generally handled free of charge. Where a request is manifestly unfounded or excessive, in particular because of its repetitive nature, the Data Controller may charge a reasonable fee or refuse to act on the request.

21. Legal remedies

Where the data subject considers that the processing of their personal data infringes the GDPR or other data-protection legislation, they may first contact the Data Controller.

The data subject may also lodge a complaint with the supervisory authority:

Hungarian National Authority for Data Protection and Freedom of Information
Address: 1055 Budapest, Falk Miksa utca 9–11., Hungary
Postal address: 1363 Budapest, P.O. Box 9., Hungary
Email: ugyfelszolgalat@naih.hu
Telephone: +36 1 391 1400
Website: naih.hu

Where their rights have been infringed, the data subject may also bring court proceedings. At the data subject’s choice, proceedings may also be brought before the court having jurisdiction over their place of residence or stay.

At the data subject’s request, the NAIH may initiate a data-protection administrative procedure where the data subject alleges an infringement connected with the processing of their personal data.

22. Amendments to this Notice

The Data Controller may amend this Notice, in particular in the event of:

  • changes in legislation;
  • the appointment of a new data processor;
  • the introduction of a new technical service;
  • changes to the purposes or processes of data processing.

The amended Notice takes effect upon publication on the website.

Where an amendment materially changes the purpose of processing based on consent, the Data Controller will request renewed consent. Continued use of the website does not in itself constitute consent to a new purpose of processing.

Issued in Budapest on 15 July 2026.