Frequently used keywords
Frequently visited sites

Privacy Policy regarding the “MEapp” mobile application of the University of Miskolc

The University of Miskolc (hereinafter: University or Data Controller) applies the following legislation and internal legal norms regarding the data processing covered by this privacy policy (hereinafter: Policy):
a) Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Regulation (EC) No 95/46/EC (hereinafter GDPR);
b) Act CXII of 2011 on the Right to Informational Self-Determination and on the Freedom of Information (hereinafter: Information Act);
c) Act C of 2003 on Electronic Communications (hereinafter: the Electronic Communications Act);
d) Act V of 2013 on the Civil Code (hereinafter: the Civil Code);
e) Act C of 2000 on Accounting (hereinafter: Accounting Act);
f) Act CCIV of 2011 on National Higher Education (hereinafter: NHE Act);
g) Government Decree 87/2015 (IV.9.) on the implementation of certain provisions of Act CCIV of 2011 on National Higher Education
h) The Data Protection and Data Security Regulation of the University of Miskolc (hereinafter: Data Protection Regulation).

I Purpose of the Policy and Scope of Data Subjects

The purpose of this Privacy Policy is to provide comprehensive and transparent information regarding the data processing activities related to the University’s mobile application (hereinafter: MEapp). The objective of MEapp is to provide unified information to the University community and to enable access to institutional entitlements and services for students and employees.

Scope of Data Subjects: All natural persons who download and use MEapp, including:
• University students (with active or passive status),
• University employees (lecturers, researchers, doctoral students),
• Guest users (unregistered users who only access public functions).

In the case of guest users, no personal data is requested unless they choose to register in the application. Registered and logged-in users are identifiable based on the data stored in the shadow database (such as name, e-mail, institutional ID, legal relationship status). Optional data that may be provided in MEapp: nickname, profile picture, favorites

Data Processing Definitions:

a) personal data: any information relating to an identified or identifiable natural person (data subject);
b) processing: any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
c) controller: the natural person or legal entity, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data;
d) processor: a natural person or legal entity, public authority, agency or other body which processes personal data on behalf of the controller;
e) third party: a natural person or legal entity, public authority, agency or other body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data;
f) personal data breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.

Further definitions:

a) Administration Interface: The administration interface shall provide the opportunity to edit the master data and information necessary for the operation of MEapp. The administration interface must be protected by a secure login method.
b) Shadow Database: The University of Miskolc does not provide direct access to institutional systems for MEapp. Data required for the use of MEapp shall be stored in a shadow database; the operation, updating, and structural design of this database is the responsibility of the University.
c) ME-Card: The ME-Card is a virtual identification card linked to the user. A virtual ME-Card must be assigned to every user who has successfully logged into MEapp.
The virtual ME-Card generated by MEapp is not identical to the physical ME-Card used by University employees or its functional features.
Cases of the use of the ME-Card:
• utilization of discounts,
• entry to university buildings, venues, and events.
d) GPS-based navigation: GPS-based navigation assists users in navigating comfortably between the buildings and locations of the University of Miskolc, within the city, or in a broader environment. Furthermore, in connection with the discount system, it is suitable for providing map-level navigation support between participating partner locations.
e) In-app/Push Messages: In-app messages are system notifications within MEapp, while push messages are communications relevant only to the user, based on their specific interests and settings.

Principles of Data Processing:

a) Purpose limitation: The University shall collect personal data only for specified, explicit, and legitimate purposes and shall not process them in a manner that is incompatible with those purposes.
b) Data minimisation: The University’s data processing shall be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed. Accordingly, the University shall not collect or store more data than is strictly necessary for the achievement of the purposes of the data processing.
c) Lawfulness, fairness, and transparency: The University shall process data lawfully, fairly, and in a transparent manner in relation to the data subjects.
d) Accuracy and up-to-date principle: The University’s data processing shall be accurate and kept up to date. The University shall take every reasonable step to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay.
e) Storage limitation: The University shall store personal data in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed, with regard to the storage obligations defined in the relevant legislation.
f) Integrity and confidentiality: The University shall ensure appropriate security of the personal data by using appropriate technical or organisational measures, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage.
g) Accountability: The University shall be responsible for, and be able to demonstrate compliance with, the principles detailed above. To this end, the University shall ensure the continuous enforcement of the provisions of the regulations, the ongoing review of data processing activities, and, if necessary, the modification or supplementation of data processing procedures.
h) Data protection by design and by default: Taking into account the state of the art, the cost of implementation and the nature, circumstances and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons, the University shall, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organisational measures. The University is obliged to ensure that, by default, only personal data which are necessary for each specific purpose of the processing are processed.

II. Contact details of the data controller and the data protection officer

Details of the data controller:
Data controller’s name: University of Miskolc
Responsible data controller: Information Technology Centre, Centre for Communication
Registered office and mailing address: 3515 Miskolc, Egyetemváros, Egyetem út 1.
MoE institutional ID No: FI87515

Telephone: +36 (46) 565-11115
Represented by Prof. Dr. Horváth Zita, Rector

Details of the Data Protection Officer:
Officer’s name: Dr Salamon-Somlyai Dóra
Contact details: adatvedelem@uni-miskolc.hu

III. Legal basis for data processing

III.1 Pursuant to Article 6(1)e) of the GDPR, the processing of basic data necessary for the operation of MEapp is a task carried out in the exercise of official authority vested in the University (Data Controller), providing information to the employees and students of the University and ensuring the functionality of MEapp.

III.2 Pursuant to Article 6(1)a) of the GDPR, the management and use of the optional functions of MEapp shall take place exclusively based on the data subject’s consent, in accordance with the provisions of the GDPR.

IV. Purpose, Scope and Duration of the Processed Data

Purpose of data processing

Scope of data processed

Legal basis for data processing

Duration of data processing

Login, identification (M365 SSO)

• Name,
• M365 e-mail address,
• institutional ID,
• legal relationship status (in case of active students and lecturers),
• timetable data (exclusively in case of lecturers and students),
• Faculty (exclusively in case of students and lecturers),
• Major (exclusively in case of students and lecturers),
• Validity of student ID (exclusively in case of students).

Pursuant to Article 6(1)a) of the GDPR, the legal basis is the voluntary consent of the data subject, which is manifested by logging into the application.

For 1 day from the erasure of the account by the MEapp user. After 1 day, the data shall be anonymized and shall become unidentifiable in the shadow database.

Displaying the user profile

Required data from the shadow database

Article 6(1)(a) of the GDPR

For 1 day from the erasure of the account by the MEapp user. After 1 day, the data shall be anonymized and shall become unidentifiable in the shadow database.

Convenience functions (optional)

Nickname, profile picture, favourites (news, events, discounts)

Article 6(1)(a) of the GDPR

For 1 day from the erasure of the account by the MEapp user. After 1 day, the data shall be anonymized and shall become unidentifiable in the shadow database.

Displaying news and events

Favourite categories, tags

Article 6(1)(a) of the GDPR

For 1 day from the erasure of the account by the MEapp user. After 1 day, the data shall be anonymized and shall become unidentifiable in the shadow database.

Operating the commercial discount system

Favourites, viewed offers (optional), ME-Card ID

Article 6(1)(a) of the GDPR

For 1 day from the erasure of the account by the MEapp user. After 1 day, the data shall be anonymized and shall become unidentifiable in the shadow database.

Generating the ME-Card

1D identifier (barcode), 2D identifier (QR code extension), user ID

Article 6(1)(a) of the GDPR

For 1 day from the erasure of the account by the MEapp user. After 1 day, the data shall be anonymized and shall become unidentifiable in the shadow database.

Authentication and entitlement verification

ME-Card ID, login timestamp, event-related entitlement

Article 6(1)(a) of the GDPR

For 1 day from the erasure of the account by the MEapp user. After 1 day, the data shall be anonymized and shall become unidentifiable in the shadow database.

GPS-based navigation

Device GPS location data (real-time, not stored)

Article 6(1)(a) of the GDPR

Automatically deleted following processing.

Notifications (in-app and push)

Notification settings, interests, device push ID

Article 6(1)(a) of the GDPR

Automatically deleted following processing.

Operation of the administration interface

Admin users’ names, e-mail addresses, access logs

Article 6(1)(a) of the GDPR

Technical logs and security events

IP address, device identifiers, error and system logs

Article 6(1)(a) of the GDPR

Duration of data processing: The duration of data processing performed by MEApp is aligned with the existence of the user account. The processing of personal data continues until the user deletes their account using the function provided within the application for this purpose.
The uninstallation of the application from the user’s mobile device does not, in itself, result in the erasure of personal data and is not considered a termination of the account. Personal data can only be erased by the erasure of the user account within the application.
Following the initiation of the account erasure, the user’s personal data shall be anonymized within the MEApp database within a maximum of 1 day, as a result of which the data will become unidentifiable in an irreversible manner and can no longer be linked to the data subject.

Following anonymization, only statistical data unsuitable for identification shall remain, which do not qualify as personal data. Upon completion of the anonymization, the data processing regarding the data subject shall permanently cease. The storage period is in accordance with the principle of storage limitation set forth in Article 5(1)e) of the GDPR.

In the case of guest users, no data processing takes place until they log into the MEapp.

V. The use of cookies in the application

Fact of data collection, categories of processed data, and purpose of processing

Scope of Data Subjects

Natural persons using the MEapp, as well as those who initiate a registration process within the MEapp.

Purpose of data processing

– secure authentication and identification of users,
– maintaining the login session,
– ensuring single sign-on (SSO) within the application,
preventing security risks related to the session.

Duration of data processing, deadline for the erasure of data

The cookies are automatically erased upon closing the session or upon the expiration of their defined lifespan.

Identity of potential data controllers authorized to access the data, recipients of personal data

Data Controller and data processors involved in the operation of the application.

Data stored in cookies are not transferred to third-party marketing or analytics providers.

Information on the rights of data subjects regarding data processing

• right to be informed about the data processing,
• right of access to their personal data,
• right to rectification if the data are inaccurate,
• right to erasure if the processing is no longer necessary or is unlawful,
• right to restriction of processing,
• right to object to the processing (except in the case of legal obligations),
• right to lodge a complaint with the National Authority for Data Protection and Freedom of Information (NAIH).

Since these are strictly necessary (session) cookies, disabling them may cause the application to malfunction.

Legal basis for data processing

Article 6(1)(f) of the GDPR – the legitimate interest of the controller in ensuring secure, authenticated operation.

The type of cookies used by the MEapp are strictly necessary session cookies:

These cookies are essential for users to be able to use the application as intended and for its basic functions to operate correctly. Among other things, the cookies enable the management of the user session and remembering actions performed within the application during the given period of use. Without the application of these cookies, the secure and seamless operation of the application cannot be ensured.

The validity of strictly necessary cookies is limited exclusively to the current session of use; upon termination of the session, logout, or closing of the application, these cookies are automatically erased from the user’s device.

Cookie names

Expiration

Description

AUTH_SESSION_ID

Session

Identifier of the authentication process (e.g., login).

KC_AUTH_SESSION_HASH

Session (1 minute, but renewed during the session)

Hash calculated from the value of the AUTH_SESSION_ID cookie. Protects the integrity of the AUTH_SESSION_ID cookie.

KEYCLOAK_IDENTITY

Session

Evidence of successful authentication. Stores user and other identifiers in JWT format. Ensures SSO functionality.

KEYCLOAK_SESSION

Session (1 day but, can be configured)

Session ID No. Responsible for session duration.

VI. Data Processors, data Transfer, Automated Decision-Making

In order to operate MEapp and fully perform data processing tasks, the University utilizes external data processors.

Delta Systems Korlátolt Felelősségű Társaság

Registered office: 1134 Budapest, Róbert Károly körút 70-74.
Company registration number: 01-09-882938
Tax number: 13978774-2-44

PC Trade Systems Informatikai Kereskedelmi és Szolgáltató Korlátolt Felelősségű Társaság

Registered office: 6728 Szeged, Back Bernát utca 2.
Company registration number: 06-09-030000
Tax number: 12937303-2-06

During the operation of MEApp, no data transfer to countries outside the European Union takes place. Personal data processed by the application are primarily stored and processed on the infrastructure of the Information Technology Centre of the University of Miskolc, as the production system and its associated databases are hosted on servers operated by the University.
Certain data technically necessary for the operation of the service—subject to an agreement between the University and the service provider—may also be stored or processed in the cloud services provided by Microsoft. Microsoft performs data processing within the European Union in data centres located in Ireland and acts as a data processor in compliance with GDPR requirements. Microsoft acts as a data processor, and the processing of data is subject to Microsoft’s contractual Data Protection Addendum (DPA) and EU-approved data protection standards.

Accordingly, no data transfer to a third country occurs, and the entire data processing process remains under the jurisdiction of EU data protection legislation.

MEApp does not employ automated decision-making or profiling pursuant to Article 22 of the GDPR.

 

VII. Rights of data subjects

In the course of data processing, the University unconditionally guarantees the data subjects the following rights:

a) Right to transparent information [Articles 12-14 of GDPR]: the data subject shall have the right to receive information about the processing of their personal data and all related information before the processing begins. This Privacy Policy is available within the MEapp, ensuring that the data subject can access and review it at any time.
b) Right of access to personal data [Article 15 of GDPR]: the data subject may request information in writing, including by electronic means, about the processing of their personal data and may inspect it. At the request of the data subject, the data controller shall provide information at any time on the data processed by it concerning the data subject, the source of the data, the purpose of the data processing, the legal basis, the duration, the circumstances of any data protection incident, its effects and the measures taken to remedy it, and, in the case of the transfer of the data subject’s personal data, the legal basis and recipient of the data transfer. The data controller facilitates the exercise and enforcement of this right by the data subject by publishing a document entitled “Request for information on the processing of personal data” on the data controller’s website under the Public Interest Data/Data Processing/Documents related to data processing tab (http://www.uni-miskolc.hu/adatkezelessel-kapcsolatos-dokumentumok), in order to enable the data subject to submit a request with appropriate content when exercising this right. Furthermore, the data controller shall accept any request if the data subject’s intent to exercise this right can be determined from its content and the data subject can be identified beyond reasonable doubt. The data subject may also submit such requests electronically to the data protection officer specified in Section II of this Guide.
c) Right to rectification of personal data [Article 16 of GDPR]: the data subject may request the rectification of his personal data without undue delay if it contains inaccurate data and, taking into account the purposes of data processing, the completion of his personal data.
d) Right to erasure of personal data [Article 17 of GDPR]: the data subject is entitled to request from the controller the erasure of personal data concerning him or her without undue delay, except mandatory data processing, if one of the conditions set out in Article 17(1) of GDPR is met. In the event of the erasure of personal data, the data controller—taking into account available technology and the cost of implementation—shall take reasonable steps, including technical measures, to inform any further data controllers or data processors processing the data that the data subject has requested the erasure by them of any links to, or copy or replication of, those personal data. The data controller shall be entitled to restrict the right to erasure and to refuse or decline the erasure of data if any of the conditions set forth in Article 17(3) of the GDPR are met.
e) Right to restriction of processing [Article 18 of GDPR]: the data subject may request the restriction of the processing of their personal data if:
ea) the accuracy of the personal data is contested by the Data Subject, for a period enabling the controller to verify the accuracy of the personal data;
eb) the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead;
ec) the Controller no longer needs the personal data for the purposes of the processing, but they are required by the Data Subject for the establishment, exercise or defence of legal claims;
ed) the data subject has objected to the processing; in this case, the restriction applies for a period until it is determined whether the legitimate grounds of the controller override those of the data subject.
Where processing has been restricted, such personal data shall, with the exception of storage, only be processed with the data subject’s consent or for the establishment, exercise, defence of legal claims or for the protection of the rights of another natural person or legal entity or for reasons of important public interest of the European Union or of a Member State.
f) Right to data portability [Article 20 of GDPR]: the data subject shall have the right to receive the personal data concerning him which he has provided to the University in a structured, commonly used, machine-readable format and the right to forward such data to another data controller without being hindered by the University.
g) Right to object [Article 21 of GDPR]: The data subject has the right to object at any time, on grounds relating to his or her particular situation, to the processing of personal data concerning him or her. In such a case, the controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.
h) Right to lodge a complaint with a supervisory authority, right to a judicial remedy, and right to lodge a complaint [Article 77-79 of GDPR]: If any data subject has any comments in connection with the University’s data processing or feels that the processing of their data is unlawful, please contact our data protection officer in the first instance. In the event of an infringement, the Data Subject may also take legal action (the action may be brought, at the option of the Data Subject, before his competent court of justice of the place of residence or temporary domicile), or contact the National Authority for Data Protection and Freedom of Information (1055 Budapest, Falk Miksa utca 9-11., mailing address: 1363 Budapest, Pf. 9.; tel.: +36 (1) 391-1400, website URL address: http://naih.hu; e-mail address: ugyfelszolgalat@naih.hu).

Requests to exercise the rights of the data subject must be submitted to the data controller’s postal address or to the email address adatvedelem@uni-miskolc.hu. The data controller will provide information in writing as soon as possible, but within a maximum of 25 days (or 15 days in the case of an objection).

VIII. Miscellaneous provisions

The provisions of this Privacy Policy shall be applied in accordance with the effective Data Protection Policy. This Privacy Policy shall be published electronically on the controller’s website.
The controller reserves the right to modify the provisions of this Privacy Policy. Data subjects shall be notified of any modification before the commencement of the data processing corresponding to such modification.