Privacy Policy
On the data processing carried out on the website of the Europe Revival 2026 International Conference, held on 23–25 October 2026
Venue: BOK Hall (BOK Csarnok), Budapest
Effective from: 20 February 2026
This privacy policy has been prepared on the basis of Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter: General Data Protection Regulation, or GDPR), as well as Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom of Information (hereinafter: the Privacy Act / Infotv.).
I. Identification of the Data Controller
The publisher of this policy and the Data Controller is:
- Name: Centrum Misyjne Iris Global, Kościół Boży w Chrystusie w Krakowie
- Registered seat: ul. Tomickiego 22/15, 31-982 KrakĂłw, Poland
- Tax number: 6751770612
- Registration number: 522628094
- Representative: Dominika Mofele
- E-mail address: contact@iriskrakow.org
(Hereinafter: the Data Controller or the Organizer.)
II. Purpose and scope of the policy
The purpose of this privacy policy is to inform data subjects, in accordance with Article 13 of the GDPR, about the data processing carried out on the website of the international conference (hereinafter: the Conference) held by the Organizer between 23 and 25 October 2026 at the BOK Hall (Budapest).
The GDPR requires the Data Controller to take appropriate measures to provide the data subject with all information relating to the processing of personal data in a concise, transparent, intelligible and easily accessible form, using clear and plain language (Article 12(1) GDPR).
The scope of this policy extends to data processing related to registration on the Conference website, volunteer applications, payment of donations, the photographs and audio recordings made at the Conference, and the use of the website (cookies).
The Privacy Act (Infotv.) also prescribes the obligation of prior information towards the data subject. With this policy we fulfil this legal obligation.
III. Definitions
The terms used in this policy have the meaning defined in Article 4 of the GDPR. The most important terms are highlighted below:
Personal data: any information relating to an identified or identifiable natural person (the “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier (name, number, location data, online identifier) (Article 4(1) GDPR).
Processing: any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means: collection, recording, organisation, storage, alteration, retrieval, use, transmission, restriction, erasure or destruction (Article 4(2) GDPR).
Data Controller: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data (Article 4(7) GDPR).
Data Processor: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller (Article 4(8) GDPR).
Consent of the data subject: any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she signifies agreement to the processing of personal data relating to him or her (Article 4(11) GDPR).
Special categories of data: personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as genetic data, biometric data and data concerning health, and data concerning a natural person's sex life or sexual orientation (Article 9(1) GDPR).
Personal data breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed (Article 4(12) GDPR).
IV. Categories of personal data processed, purpose, legal basis and duration of processing
IV/1. Registration for the Conference (participants)
Categories of data processed: the participant's full name; e-mail address; country of origin.
Purpose of processing: handling registration for the Conference, keeping a record of participants, providing information related to the Conference, and carrying out organisational tasks.
Legal basis: the consent of the data subject (Article 6(1)(a) GDPR). By registering, the data subject voluntarily consents to the processing of their personal data.
Duration of processing: 1 year from the day of the Conference (23 October 2026), unless a longer retention period is prescribed by law.
Recipients of the data: the Organizer's employees / agents responsible for the event, and the data processors named in Chapter V.
Nature of the data supply: voluntary. The consequence of not providing the data is that registration for the Conference cannot be carried out.
IV/2. Volunteer registration
Categories of data processed: the volunteer's full name; e-mail address; country of origin; church affiliation.
Purpose of processing: keeping a record of volunteers, coordinating volunteer tasks related to the organisation of the Conference, and maintaining contact.
Legal basis: the explicit consent of the data subject (Article 6(1)(a) GDPR; with regard to church affiliation, explicit consent under Article 9(2)(a) GDPR).
Duration of processing: 1 year from the day of the Conference, unless a longer retention period is prescribed by law.
Important: church affiliation may qualify as special category data revealing religious belief. It is provided solely on the basis of the data subject's explicit, voluntary consent. Consent to the processing of this data must be given by ticking a separate checkbox on the registration form.
IV/3. Payment of support (donation)
Categories of data processed: the supporter's full name; e-mail address; the amount of the donation; the identifier of the payment transaction. (The Data Controller does not store banking data – card number, etc.; these are handled exclusively by the payment provider, Stripe.)
Purpose of processing: receiving and recording the support amount, and fulfilling the related accounting and tax obligations.
Legal basis: the establishment of the support relationship (Article 6(1)(b) GDPR), and the fulfilment of legal obligations under accounting and tax legislation (Article 6(1)(c) GDPR; Section 169 of Act C of 2000; Sections 169 and 202 of Act CXXVII of 2007).
Duration of processing: the retention period for accounting records is 8 years (Section 169(2) of Act C of 2000).
IV/4. Making photographs and audio recordings at the Conference
Categories of data processed: the image (photograph, video recording) of persons attending the Conference, as well as audio recordings.
Purpose of processing: documenting the events of the Conference, producing subsequent reports and promotional materials, and supporting the Organizer's communication activities.
Legal basis: the consent of the data subject (Article 6(1)(a) GDPR). During registration, the data subject consents to the making and use of photographs and audio recordings by ticking a separate checkbox. Pursuant to Section 2:48(2) of Act V of 2013 on the Civil Code, no separate consent of the person concerned is required for recordings made at a public event, provided that the recording relates to coverage of the public event.
Duration of processing: until consent is withdrawn, but no longer than 5 years from the day of the Conference.
The data subject may withdraw their consent at any time. The withdrawal of consent does not affect the lawfulness of processing prior to the withdrawal. In the event of withdrawal, the Data Controller will – where technically possible – remove the recording from public platforms.
IV/5. Use of cookies on the website
Cookies are short data files placed on the user's device by the visited website. Their purpose is to make the internet service easier and more convenient.
- Strictly necessary cookies: required for the proper operation of the website and may be used without consent (Article 6(1)(f) GDPR; Section 13/A(3) of the Ekertv.).
- Functional cookies: serve to improve the user experience (e.g. remembering language settings). Legal basis: the consent of the data subject.
- Statistical and analytical cookies: serve to measure traffic and analyse user habits. Legal basis: the consent of the data subject.
The user can disable or delete cookies at any time in their browser settings.
V. Data Processors
The Data Controller uses the following data processors to operate the website and provide its services. The prior consent of the data subject is not required for the use of a data processor, but they must be informed of it.
- Hosting and IT provider: Tárhely.Eu Szolgáltató Kft. (1097 Budapest, Könyves Kálmán körút 12–14., Hungary).
- Payment provider: Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland).
- Accounting provider: [Name, seat and contact details of the accounting firm].
VI. Data transfers
The Data Controller does not transfer personal data to a third country (outside the European Economic Area), unless the data subject has explicitly consented to it, it is required by law, or an adequacy decision of the European Commission (Article 45 GDPR) or appropriate safeguards (Article 46 GDPR) are in place.
Personal data may be accessed only by the Data Controller and the data processors named in Chapter V, in a limited manner through the assignment of authorisation levels.
VII. Data security measures
In order to ensure the security of personal data, the Data Controller takes the technical and organisational measures necessary to give effect to the GDPR and the Privacy Act (Article 32 GDPR). It protects the data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
The website operates with SSL/TLS encryption, which ensures the secure transmission of data. The Data Controller equips its IT systems with a firewall and virus protection.
In the event of a personal data breach, the Data Controller acts in accordance with Articles 33–34 of the GDPR: it reports the breach without undue delay, but no later than within 72 hours, to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), and, where necessary, notifies the data subjects.
VIII. Rights of the data subject
- Right to prior information (Articles 13–14 GDPR).
- Right of access (Article 15 GDPR).
- Right to rectification (Article 16 GDPR).
- Right to erasure (“the right to be forgotten”, Article 17 GDPR).
- Right to restriction of processing (Article 18 GDPR).
- Right to data portability (Article 20 GDPR).
- Right to object (Article 21 GDPR).
- Right to withdraw consent (Article 7(3) GDPR) – withdrawal does not affect the lawfulness of processing prior to the withdrawal.
- Automated decision-making and profiling (Article 22 GDPR): the Data Controller does not carry out such activities.
IX. Remedies
In the event of an infringement of their rights, the data subject may use the following remedies:
1. Lodging a complaint with the supervisory authority (Article 77 GDPR). The Hungarian supervisory authority:
- Name: Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
- Seat: 1055 Budapest, Falk Miksa utca 9–11., Hungary
- Postal address: 1363 Budapest, Pf.: 9.
- Phone: +36 (1) 391-1400
- E-mail: ugyfelszolgalat@naih.hu
- Website: naih.hu
International participants may also turn to the supervisory authority of the EU/EEA Member State of their habitual residence.
2. Judicial remedy (Article 79 GDPR). The data subject is entitled to a judicial remedy where they consider that their rights have been infringed as a result of the processing of their personal data. Proceedings may also be brought before the court of the data subject's place of residence or stay (Section 22 of the Privacy Act).
3. Compensation (Article 82 GDPR). Any person who has suffered material or non-material damage as a result of an infringement of the GDPR is entitled to compensation from the Data Controller or the data processor.
X. Final provisions
This Privacy Policy is effective from 20 February 2026. The Data Controller reserves the right to unilaterally amend the Policy; data subjects will be informed of any amendment on its website.
Legislation taken into account when preparing this Policy: the GDPR; the Privacy Act (Infotv.); the Civil Code (in particular regarding the right to one's image and voice recording, Section 2:48); the Ekertv.; Act C of 2000 on Accounting; Act CXXVII of 2007 on Value Added Tax.
In matters not regulated by this Policy, the provisions of the GDPR and the Privacy Act (Infotv.) shall govern.