DE!HOGYNEM Feszt
ProgrammeVenueFAQFrequently askedAccommodationTicketsContact
HUEN
← Back to the homepage

Privacy Notice

i

This is a machine translation of the original Hungarian document and is provided for information only. In the event of any discrepancy, the Hungarian version prevails.

"This data management information is Article 13 of the GDPR and is informative CXII of 2011 on the right to self-determination. based on § 20 of the Act made.”

Legal background The following is for the management of personal data governing legislation: – European Parliament and Council (EU) 2016/679 decree (GDPR, especially the Article 13), – is informative on the right to self-determination and freedom of information CXII of 2011 law (Infotv., especially the 20. §).

Purpose of data management the __I DON'T DEHOGYN__ organizing and holding a festival, informing visitors and performers, ensuring safety, and documenting and communicating the event online and offline.

SUBSCRIBERS TO THE DATA MANAGER'S NEWSLETTER

Subjects: persons who register online in order to send out the newsletter.

Personal data processed: name, e-mail address, phone number, county, previous data on sentry experience and team leadership, motorcyclist application-related information.

Source of data: the data subject.

Purpose of data management: sending information about the current Data Manager about movement and actions.

Legal basis for data management: consent of the data subject [GDPR Article 6 (1) point a)].

Duration of data management: until the consent of the data subject is revoked, or for inactive subscribers up to 2 years.

Data transfer: data transfer to a third country or international organization does not happen for  

DE!HOGYNEM FESTIVAL - DATA MANAGEMENT INFORMATION

SCOPE OF THE NOTICE

This information sheet for the DE!HOGYNEM Festival (hereinafter: Festival) related data management, especially for ticket purchases and for admission, as well as image, sound and contains rules related to the handling of video recordings.

In matters not regulated in this Notice, DE! Action Community The association's general information on data management applies, which can be found here to: [LINK].

DATA OF THE DATA CONTROLLER

Data controller name: DE! Action Community Association

Headquarters: 2660 Balassagyarmat, Rákóczi Fejedelem út 117. II. em. 1.

Tax number: 19429917-1-12

Registration number: 12-02-0002426

Email: deakciokozosseg@gmail.com

DE! Action Community Association is also the organizer of the Festival, a hereinafter: Organizer or Data Manager.

DATA MANAGEMENT RELATED TO TICKET PURCHASE AND ADMISSION

The online sale of tickets to the Festival is conducted by TIXA Hungary Kft. (headquarters: 5600 Békéscsaba, Dobozi út 58; hereinafter: TIXA) is carried out.

Personal data collected and managed by TIXA during the ticket purchase is considered an independent data controller. For TIXA's data management, TIXA own data management available at https://www.tixa.hu/adatvedelem information sheet applies.

TIXA fulfills the contract created with the ticket purchase, as well as the It is forwarded by the Organizer to ensure admission to the festival the personal data required for entry. TIXA in this a in the circle is the transmitter of the data, and the Organizer is the transmitted data recipient and independent data controller. TIXA and the Organizer are each other does not act as a data processor.

Affected parties: the person who buys a ticket for the Festival, or the ticket holder users.

Personal data handled: customer's name, e-mail address, ticket identifier, type, validity data, as well as during entry resulting technical data, so in particular ticket verification and the fact and date of its redemption.

Source and transmitter of the data: TIXA Hungary Kft.

The purpose of data management: checking the validity of the entrance ticket, a preventing unauthorized or repeated use of tickets, entry and ensuring re-entry, issuing a wristband, and settlement of possible problems related to entry.

The legal basis for data management: the contract created with the purchase of a ticket fulfillment based on Article 6 (1) point b) of the GDPR.

The consequence of not providing data: the necessary data in its absence, the validity of the entrance ticket cannot be checked, therefore for the Festival entry cannot be guaranteed.

Duration of data management: the Organizer shall provide the data necessary for admission to the It manages it for a maximum of 30 days after the end of the festival. If on this period, a specific complaint, abuse or legal dispute arises, that is affected data for the time necessary to settle the legal claim, up to a they can be kept until the end of the civil law limitation period.

The Organizer does not use the data received from TIXA to send newsletters, for advertising, profiling, ad optimization or other analytics for purpose.

PHOTO, AUDIO AND VIDEO RECORDINGS OF THE PERFORMERS

The Organizer or the photographer, videographer, or press representative commissioned by the Organizer media service provider provides image, sound and you can record videos.

Stakeholders: speakers, performers and contributors of the Festival.

Personal data processed: the name or stage name of the person concerned, likeness, his voice, movement, presentation, statement, as well as the place of the performance and information on the date.

Purpose of data management: Festival events and performances documenting, presenting the activities of the Festival and the Organizer and popularization, as well as the publication of the recordings by the Festival or the Organizer on his website, social media platforms, video sharer platforms, press releases and other online communications on its surfaces.

The legal basis for data management: the participant's preliminary, voluntary, express and verifiable consent pursuant to Article 6 (1) point a) of the GDPR, as well as a Civil Code 2:48. Based on paragraph (1) of §

The performer's participation in the Festival does not in itself replace the contribution. Regarding the preparation and publication of recordings consent in the performance contract or a separate consent must be recorded in a statement. The document should define a purpose, method, surfaces and duration of use of recordings.

Duration of data management: until the period specified in the consent, failing this, until the withdrawal of the consent, but no later than the Festival for the following five years. Withdrawal of consent does not affect prior to withdrawal the legality of data management.

After withdrawing the consent, the Organizer will take the recordings by him removed from controlled surfaces without undue delay. A The organizer cannot guarantee the deletion of the copies that the illegally downloaded by third parties after publication, shared or otherwise received.

CROWD RECORDS MADE OF FESTIVAL PARTICIPANTS

The Organizer or the person authorized by him for the events of the Festival for the purpose of documenting, presenting and promoting it in the area of the Festival you can take pictures, sound and video recordings.

By entering the Festival, participants acknowledge that a Mass shootings in public areas of the event and their overall effect a Presenting a festival, its atmosphere, programs or audience recordings can be made.

Stakeholders: participants, visitors and contributors of the Festival.

Personal data processed: image, voice, movement of the person concerned, behavior, as well as the place and time of recording. A audio recordings are not aimed at the individual or private nature of the participants to record your conversations.

Purpose of data management: documentation of the Festival, about the events of the Festival information, as well as the activities of the Festival and the Organizer presentation and promotion.

Legal basis for data management: for the Organizer to document the Festival, its legitimate interest in presenting and promoting Article 6 (1) of the GDPR on the basis of point f) of paragraph

2:48 of the Civil Code. Mass admission based on paragraph (2) of § its preparation and use does not require the separate consent of those concerned is necessary. Mass recording is only considered to be recording that in its overall effect the Festival, one of its programs or the audience perpetuates it, and on which individual persons are not recorded independently, highlighted appear as characters.

A featured portrait, interview or other unique piece of a participant to create and publish a recording, the relevant preview consent is required. A unique recording highlighted by a minor is exclusively a may be prepared and published with the appropriate consent of a legal representative.

The participant who does not wish to appear in a unique recording, this recording you can notify the photographer, videographer or the Organizer when making it to his colleague. The person concerned can also request the one that prominently depicts him afterwards to remove a recording if it properly identifies the recording.

Duration of data management: from the time the recordings were made up to five years. The Organizer regularly during this period review whether to continue to retain and publish recordings is it necessary.

PUBLICATION OF RECORDS

The Organizer will post the recordings on its own website, on the TOP page of the Festival web, and on social media and video sharing platforms, especially You can publish it on Facebook, Instagram and YouTube.

The service providers operating the platforms are the additional ones they carry out in terms of data management, they are considered independent data controllers. The platforms personal data may be transmitted in connection with its use also to countries outside the European Economic Area. Such data management its detailed conditions are in the data management information of the given platform included.

RIGHTS OF THE DATA PARTIES

The data subject is entitled to:

- request information and access to the management of your personal data;

- request correction, deletion or processing of your personal data limitation;

– in the case of data processing based on consent, your consent at any time to withdraw;

– in the case of data processing based on legitimate interest, related to your own situation to object to data processing for a reason;

- to live if the conditions specified in the law exist with your right to data portability;

- submit a complaint to the National Data Protection and Freedom of Information To contact the authorities or the court.

Stakeholder requests can be submitted to the e-mail address deakciokozosseg@gmail.com in.

National Data Protection and Freedom of Information Authority

Headquarters: 1055 Budapest, Falk Miksa utca 9–11.

Mailing address: 1374 Budapest, Pf. 603.

E-mail address: ugyfelszolgalat@naih.hu

Website: https://www.naih.hu

DATA SECURITY AND AUTOMATED DECISION MAKING

The Organizer takes appropriate technical and organizational measures to ensure the on the protection of managed personal data, especially unauthorized access, alteration, transmission, disclosure, deletion, damage or against destruction.

It is automated during data processing according to this Notice no decision-making or profiling takes place.

WEB SERVER LOGGING

Affected: visitors to the Website.

Managed personal data: IP address, date and time of the visit, a the address of the page visited, the type of browser and operating system and version.

Data source: the data subject's device when using the Website.

Purpose of data management: to ensure the safe operation of the Website, a control of the operation of the system, as well as the prevention of abuses and investigation. The purpose of data management is also to protect the integrity of the system and protection of confidentiality.

Consequence of not providing data: Website is secure operation and prevention of abuses cannot be guaranteed.

Legal basis for data management: legitimate interest of the Data Controller [GDPR Article 6 (1) paragraph point f)], which ensures the safe operation of the Website maintenance, the integrity and availability of the IT system to secure your job, as well as unauthorized access and related to the prevention and investigation of abuses.

Duration of data management: maximum 30 days.

Data transfer: personal data will not be transferred, except for IT data processors providing service and hosting services

Withdraw consent

If the data is processed based on the data subject's consent, the data subject is entitled to withdraw his consent at any time. A withdrawal of consent does not affect the consent-based, a the legality of data management before withdrawal. Withdraw consent all personal data will be deleted.

WHO CAN WE SHARE YOUR PERSONAL DATA WITH?

DATA PROCESSORS

IT (e.g. storage space, IT services, web development) and other technical service providers (e.g. newsletter service) we have to use your services as well.

The data processors will handle your personal data on our behalf, strictly according to our instructions and providing appropriate guarantees beside.

The volunteers also have access to the data according to their level of authorization are granted access with whom the Data Controller enters into a data processing contract. The contact details of the volunteer watchmen (especially their names, e-mail address and telephone number) - on the basis of their consent contained in the contract - a are forwarded to group leader sentry volunteers. 

NAME OF EACH DATA PROCESSOR

Some personal data provided to us - for the purpose of data management regard - we can forward it to the data processors we engage. The data processors have entered into a contract with the data controllers for the received personal data it is handled in accordance with the provisions of the data processing contract, and others they cannot be used for data management purposes. Data processors of all times the current list is available from the Data Manager. 

Our permanently cooperating data processors are the following:

DATA PROCESSING ACTIVITY, PURPOSE

NAME

SEAT

MANAGED DATA

Google services (Gmail, Forms, Sheets) 

maintaining contact, handling incoming inquiries, processing forms, organization and registration of data

Google Ireland Limited

Ireland

name, e-mail address, message content, data entered in the form, technical data (e.g. IP address, time)

Infrastructure services related to website operation

hosting and server operation

Webkomfort Kft.

1181 Budapest, Havanna u. 8.

the personal data managed by the Data Controller through the Website is complete scope, especially contact data, as well as for the operation of the Website related technical data (e.g. IP address, log data)

Providing and operating the website interface 

platform service required to display the website

Wix.com Ltd.

Israel

website data, submitted forms, contact data, IP address, browser data, device data, logging, fraud prevention, system security, access protection

Electronic signature service - SignNow

electronic signature of documents, management of the signature process, authentication and tracking of documents

airSlate, Inc.

USA

name, e-mail address, content of the signed document, date of signature, IP address, technical data, audit log data

Online payment service - Stripe

receiving donations, conducting transactions, legal obligations performance (e.g. accounting) 

Stripe Technology Europe Ltd.

Ireland

name, e-mail address, transaction details (amount, date), with payment related technical data

TRANSMISSION OF DATA TO INDEPENDENT DATA MANAGER ADDRESSES

We share your personal data, we may also share:

with our lawyers and other consultants when we ask for professional advice them;
  • with the lawyers of the Society for Freedoms (TASZ), or if necessary according to the Civil, professional and with social organizations for the professional notification, objection, or in order to file a report. 
  • DATA SERVICE TO AUTHORITIES AND LAW ENFORCEMENT

    Fulfilling authority inquiries 

    Your personal data is our legal obligation in order to fulfill it, we may also share it with other third parties - a a court, the regulatory authority or an administrative body acting in accordance with its requirements.

    The Data Controller is the courts, the prosecutor's office, the investigative authorities (police), the electoral bodies (NVB, OEVB) and statutory authority is obliged to contact other authorities for the requested personal data - in addition to specifying the exact purpose and scope of data - to make it available. These data services do not qualify under Article 4, Clause 9 of the GDPR classic data transfer, their legal basis is Article 6 (1) paragraph c) of the GDPR point (fulfilment of legal obligation).

    Reporting and enforcement

    If the Data Controller protects the integrity of the election detects a suspicion of a crime or rule violation, the person recorded is entitled evidence (e.g. photo, video recording, testimony) voluntarily hand over to the competent authorities, only the infringement in the circle that is absolutely necessary for its proof. Data transfer the legitimate interest of the Data Controller and the community is the elections to ensure its purity and to protect basic democratic values [GDPR Article 6 (1) f) ponjat].

    DATA TRANSFER TO A THIRD COUNTRY

    As a general rule, the Data Controller does not transmit personal data to the European Outside the Economic Area. 

    However, in the case of some service providers used by the Data Controller online payment (Stripe), electronic payment may be transmitted signature (SignNow), website operation and analytics (Wix) and Google in connection with correspondence, form and data storage services 

    In all cases, the Data Controller ensures that the transfer to a third country data transmission should take place under appropriate guarantees, especially the European one Commission's compliance decisions, as well as in Chapter V of the GDPR using specific other data transfer mechanisms.

    Stripe - online payment

    The Data Controller for processing online payments is Stripe Technology You use the services of Europe Ltd. During the provision of the service a personal data may be transferred to the United States. It is data is transferred based on the EU-US Data Protection Framework. A As a general rule, Stripe acts as a data processor, in some cases (e.g. fraud prevention) acts as a data controller.
    Privacy Policy: https://stripe.com/privacy

    SignNow - electronic signature

    The Data Controller for the electronic signature of documents is airSlate Inc. (SignNow) service. By using the service in connection with the transfer of personal data to the United States can be avoided. The data transfer is the EU-US Data Protection Framework, and based on general terms and conditions. The service provider as a general rule, it is a data processor, but in the case of some functions it is independent can also act as a data controller.
    Privacy Policy: https://www.airslate.com/legal/privacy

    Wix - website operation and analytics

    The Data Controller uses the services of Wix.com Ltd. to operate the website is used. The personal data to Israel (to which the European Commission conformity decision applies), as well as in some cases the United They can also be forwarded to the States. According to the Wix rule acts as a data processor, however certain functions (e.g. analytics) they may also contain independent data management elements.
    Privacy Policy: https://www.wix.com/about/privacy

    Google - Mail, Forms and Data Storage
    The Data Controller uses the services of Google Ireland Limited (Gmail, Google Forms, Google Sheets). By using the service in connection with the transfer of personal data to the United States can be avoided. Data transmission is based on the EU-US Data Protection Framework is happening. As a general rule, Google acts as a data processor.
    Privacy Policy: https://policies.google.com/privacy

    EXTERNAL SERVICE PROVIDERS

    In the course of our data management, external service providers video sharing platforms and we also use social media platform services.

    Facebook and Instagram services are provided by Meta Platforms Ireland Ltd. provides. During the operation of social media sites, the Data Controller and Meta Platforms Ireland Ltd. is joint with respect to certain data management may be considered a data controller.

    Meta also manages users' data for its own purposes, for which it is The data controller has no influence.

    YouTube is provided by Google Ireland Limited. The videos when viewing Google's user data in its own data management according to its regulations.

    The Data Controller has no influence on the further actions carried out by the platform for data management.

    AUTOMATED DECISION MAKING, PROFILE CREATION

    The Data Controller in the course of his activities to achieve his goals does not perform automated decision-making - including profiling. 

    DATA SECURITY MEASURES

    The Data Controller is technical and organizational in proportion to the risks applies measures, taking into account the state of the art, a implementation costs, as well as the nature and scope of data management, circumstances and goals. Data security includes personal physical, logical and administrative protection of data.

    The Data Controller for the management of personal data during the provision of the service chooses and operates applied IT tools in such a way that the processed data: 

    accessible to those authorized to do so (availability); 
  • its authenticity and authentication are ensured (authenticity of data management); 
  • its immutability can be verified (data integrity); - unauthorized access be protected against (data confidentiality).
  • The Data Controller treats personal data confidentially and appropriately measures are taken to protect them in particular against unauthorized access, change, transmission, disclosure, deletion or destruction and against accidental destruction or damage

    SECURITY MEASURES EMPLOYED

    The Data Controller's data security system in particular includes the following measures includes:

    access control and authorization management, 
  • procedures for handling data protection incidents, 
  • systems monitoring, 
  • safe storage and transmission of data, 
  • regular testing and review, 
  • informing and training relevant employees. 
  • The applied measures are regularly reviewed by the Data Controller, and, if necessary, to the development of technology, as well as the emerging updates with regard to risks.

    THE RIGHTS CONCERNED

    The rights that a in connection with the processing of your personal data, you are entitled to the GDPR and based on applicable Hungarian data protection legislation.

    The rights of stakeholders are not unlimited: their exercise is subject to conditions may or may be limited in cases defined by law.

    In all cases, data subject requests are subject to the relevant data protection we judge in accordance with the laws, and we fulfill them if its legal conditions exist, or if there is a law to that effect obliges us.

    This Data Management Notice does not provide and cannot be interpreted as that rights that go beyond the rights granted by law would create.

    The exercise of stakeholder rights may not limit the rights of others and freedoms.

    The right to transparent information

    You have the right to clear, transparent and easily understandable information about how we handle your personal data and about what rights you have in relation to data management.
    We comply with this obligation through this Data Management Notice.

    Right of access

    You have the right to receive feedback on whether we handle your personal data your data, and if so, you are entitled to access it for the following information:

    scope of processed personal data, 
  • the purpose of data management, 
  • the legal basis for data management, 
  • the duration of data management, 
  • recipients of data transmissions. 
  • The right of access cannot violate the rights and freedoms of others, therefore in certain cases - especially with regard to the data of another person - can be limited

    Right to rectification

    You are entitled to request the correction of your inaccurate personal data, and supplementing incomplete data.

               It's for deletion right ("right to be forgotten")

    You have the right to request the deletion of your personal data if:

    the purpose of data management has ceased, 
  • data processing is illegal, or 
  • there is no legitimate reason for further processing of the data. 
  • The right to erasure is not unlimited and does not apply in particular if if data management is necessary:

    to fulfill a legal obligation, or 
  • to submit, enforce or defend legal claims. 
  • The right to restrict data processing

    You are entitled to request the restriction of data processing if:

    you dispute the accuracy of your personal data, 
  • the data processing is illegal, but you do not request the deletion of the data, 
  • the data controller no longer needs the data, but you do to assert a legal claim, 
  • you objected to data processing. 
  • In case of limitation, we store the data, but do not process it in any other way, except by statutory authority or consent.

    The right to data portability

    You have the right to the personal data we manage about you receive it in a structured, widely used, machine-readable format, and forward them to another data controller if:

    data processing is based on consent or contract and 
  • is done in an automated way. 
  • The right to protest
  • You have the right to protest for reasons related to your own personal situation against the processing of your data if the data processing is based on a legitimate interest.

    In this case, data management will be terminated, unless proven we know that data management is so compelling legitimate reasons are justified, which take precedence over your interests, rights and against your freedoms or related to legal requirements.

    Right to a remedy

    You are entitled to submit a complaint to the supervisory authority or to go to court if, in your opinion, the handling of your personal data violates the law.

    WHERE CAN YOU GO IF YOU HAVE A QUESTION OR WANT TO GET A LEGAL REMEDY?

    If you need more information about the management of your personal data you wish to request or exercise any of your data subject rights, or if you consider that our data management does not comply with the law regulations, please contact us below contact:

    Email: deakciokozosseg@gmail.com

    Submission and handling of stakeholder requests

    Requests from stakeholders are primarily accepted in writing by e-mail. It is identified inquiries from the e-mail address you previously provided considered a request.

    Please provide all necessary information in your application to identify and fulfill your request. The answer is the same we provide it on the communication channel on which you submitted the request, unless you ask otherwise.

    Additional information, if necessary, during the evaluation of applications we may ask to confirm your identity. If it is identification is not possible, we may refuse to fulfill your request.

    Data retention in relation to requests

    Received requests, complaints and related to them we keep communication for 6 months.

    If a legal claim arises in the case, the data will be transferred to the within the applicable limitation period - usually 5 years under Act V of 2013 (Civil Code) - we can keep it.

    The right to appeal to a data protection authority

    You have the right to complain to the National Data Protection and Freedom of Information Authority (NAIH) before:

    Headquarters: 1055 Budapest, Falk Miksa utca 9–11. 
  • Mailing address: 1374 Budapest, Pf. 603. 
  • Phone: +36 1 391 1400 
  • E-mail: ugyfelszolgalat@naih.hu 
  • Website: www.naih.hu
  • Right to go to court

    You have the right to go to court if, in your opinion, it is personal handling your data violates the law.

    The trial is based on the choice of the person concerned or the place of residence of the person concerned can also be initiated before the court of your place of residence.

    MODIFICATION OF DATA MANAGEMENT NOTICE

    The Data Controller reserves the right to present a Data Management Information unilaterally modify it, if the scope of the managed data is the data management circumstances and the relevant legal environment changes.

    The Data Management Information Sheet complies with the legal requirements and the emerging in accordance with jurisprudence, it is constantly reviewed and updated we keep

    DE! Action Community will inform those concerned about the amendments communication interfaces - especially on the website and/or social media on media platforms - we will inform you in a clearly visible manner.

    If the modification is based on the data subject's consent affected, if necessary to apply the modified data management conditions we once again ask for the Data Subject's consent.

    The version of the Data Management Notice that is valid at all times is DE! It is available on the official websites of Action Community.

    [1] especially the right to informational self-determination and CXII of 2011 on freedom of information. law (a hereinafter: Infotv.) in compliance with its provisions



    DE!HOGYNEM Feszt
    ProgrammeVenueFrequently askedAccommodationTicketsContact
    FacebookInstagramTikTok

    © 2026 DE!HOGYNEM Feszt

    Privacy noticeFestival rules
    DE! Akcióközösség