Privacy Policy
Marketplace&Crossborder Summit Privacy Policy, effective date: 1 August 2026
Tento dokument je k dispozici pouze v angličtině.
Ecommerce Trade Kft., as the organiser of the Marketplace&Crossborder Summit and as a data controller, pays particular attention to ensuring that, in its data processing activities, it acts in accordance with the applicable data protection legislation and established practices of the data protection authorities, whilst also taking into account the key international recommendations relating to data protection.
Ecommerce Trade hereby informs its customers and visitors about the personal data it processes, its practices regarding the processing of personal data, the organisational and technical measures it has put in place to protect personal data, and the methods and options available for data subjects to exercise their rights.
1. Preamble: Ecommerce Trade Kft. publishes information, articles and presentations relating to its activities on the website https://www.crossbordersummit.eu.
2. Definitions:
- Data subject: any identified or identifiable natural person on the basis of specific personal data;
- personal data: any data relating to an identified or identifiable natural person (hereinafter: data subject), as well as any conclusion drawn from such data concerning the data subject. Personal data retains this status throughout the data processing as long as a link to the data subject can be re-established. In particular, a person is considered to be identifiable if they can be identified – directly or indirectly – by name, an identifier, or one or more factors specific to their physical, physiological, mental, economic, cultural or social identity.
- data processing: any operation or set of operations performed on data, irrespective of the procedure used, such as, for example, collection, recording, organisation, storage, alteration, use, disclosure, publication, alignment or combination, blocking, erasure and destruction, as well as the prevention of further use of the data. Data processing also includes the taking of photographs, audio or video recordings, as well as the recording of physical characteristics suitable for identifying a person (e.g. fingerprints or palm prints, DNA samples, iris scans).
- data controller: a natural or legal person, or an organisation without legal personality, who or which determines the purposes of data processing, makes and implements decisions relating to data processing (including the means used), or has such decisions implemented by a data processor commissioned by them;
- consent: a voluntary and explicit expression of the data subject’s will, based on adequate information, by which they give their unambiguous consent to the processing of personal data relating to them – whether in full or in respect of specific operations.
- objection: a statement by the data subject objecting to the processing of their personal data and requesting the cessation of such processing or the erasure of the data processed;
- data processing: the performance of technical tasks related to data processing operations, irrespective of the method and means used to carry out the operations and the location of the application, provided that the technical task is performed on the data;
- data processor: a natural or legal person, or an organisation without legal personality, which processes data on the basis of a contract concluded with the data controller – including a contract concluded pursuant to a statutory provision;
- data blocking: the marking of data with an identifier for the purpose of restricting its further processing, either permanently or for a specified period;
- data destruction: the complete physical destruction of the data medium containing the data;
- third party: a natural or legal person, or an organisation without legal personality, who or which is not the data subject, the data controller or the data processor.
- Website: https://www.crossbordersummit.eu
By using the Website, the Data Subject acknowledges the contents of the Privacy Notice and consents to the data processing activities set out below.
3. Details and contact information for Ecommerce Trade Kft. (Data Controller or Service Provider)
Registered office: 1046 Budapest, Kiss Ernő utca 3/A;
Tax ID: 27121315-2-41; Tax ID (EU): HU27121315;
Company registration number: 01-09-350582;
email: info@crossbordersummit.eu
4. Data processed
4.1. Data provided when requesting a quote: it is possible to request a quote for the legal services listed on the Website, in the course of which the Data Subject is required to provide Ecommerce Trade with the personal data specified on the relevant quote request form.
4.2 Use of email addresses: the Service Provider pays particular attention to the lawfulness of the use of the email addresses it processes; consequently, it uses them only in the manner specified in section.
4.3 to send informational or promotional emails: processing of email addresses primarily serves to identify the Data Subject and to maintain contact whilst using the services provided by the Data Controller; therefore, emails are sent primarily for this purpose.
5. Newsletter
On the Website, the Service Provider offers the option to subscribe to a newsletter, through which any Data Subject can receive emails and thus keep track of the specialist articles and news available on the Website, without having to search the site.
Furthermore, in accordance with Section 6 of Act CVIII of 2001 on certain issues relating to electronic commerce services and information society services, and Act XLVIII of 2008 on the fundamental conditions and certain restrictions of commercial advertising activities (hereinafter: Grt.) Section 6 stipulates that newsletters may only be sent with the Data Subject’s prior, unambiguous and explicit consent.
The Data Subject may unsubscribe from the newsletter at any time, free of charge, without restriction or justification. They may do so by clicking on the ‘Unsubscribe’ link in the newsletter or by sending a request for removal to Ecommerce Trade (by email or post). In this case, the Service Provider will not contact the Data Subject with any further newsletters or offers.
6. Technical data, cookies
The data from the Data Subject’s computer used to log in, which is generated whilst using the service and which the Service Provider’s system records as an automatic result of technical processes. These include, in particular, the date and time of the visit, the IP address of the Data Subject’s computer, and the type of browser used.
The system automatically logs the data recorded in this way upon login and logout, without any specific declaration or action on the part of the Data Subject. This data cannot be linked to other personal user data, except in cases required by law. Only the Data Controller has access to this data.
The Data Controller and the external service providers listed below place and read small data packets, known as cookies, on the Data Subject’s computer in order to provide a personalised service. If the browser returns a previously stored cookie, the service provider managing the cookie may link the data stored during the Data Subject’s current visits with previous data, but only in relation to its own content.
The Service Provider uses the following cookie:
- Security cookie.
- Session cookies: These are automatically deleted after the Data Subject’s visit.
- Persistent cookies: These cookies are stored for a longer period in the browser’s cookie file. The duration of this storage depends on the settings the Data Subject has applied in their web browser.
Some of these cookies serve to enable the Service Provider’s Website to operate more efficiently and securely; they are essential for certain functions of the Website ( ) or certain applications to work properly. Other cookies, meanwhile, have been placed to enhance the user experience (e.g. to provide optimised navigation).
The ‘Help’ function, found in the menu bar of most browsers, provides information on how the Data Subject can
- how to disable cookies,
- how to accept new cookies,
- how to instruct their browser to set a new cookie, or
- how to disable other cookies.
External servers assist with the independent measurement and auditing of the Website’s visitor statistics and other web analytics data (Google Analytics). The data controllers can provide the Data Subject with detailed information regarding the processing of this measurement data. Their contact details are: www.google.com/analytics/
The Website uses Google AdWords remarketing tracking codes. The purpose of this is to enable us to target visitors to the site with remarketing adverts on websites within the Google Display Network at a later date. The remarketing code uses cookies to tag visitors. Users of the Website may disable these cookies by visiting the Google Ads Settings manager and following the instructions provided there. Thereafter, the Data Subject in question will no longer see personalised offers from the Service Provider.
If the Data Subject does not wish Google Analytics to measure the above data in the manner and for the purpose described, they should install the add-on that blocks this in their browser.
7. Purpose of data processing
The Data Controller stores and processes the data provided by the Data Subject for specific purposes only, namely to fulfil requests for quotations, to maintain contact, – where applicable – to enable invoicing, and to provide subsequent evidence of the terms of the contract entered into.
The purpose of data recorded automatically is to compile statistics and to facilitate the technical development of the Website.
The Data Controller shall not use, nor may it use, the personal data provided for any purposes other than those specified above. The disclosure of personal data to third parties or public authorities – unless otherwise required by law – is only possible with the prior, express consent of the Data Subject.
In any instance where the Data Controller intends to use the data provided for a purpose other than that for which it was originally collected, it shall inform the Data Subject of this and obtain their prior, express consent, or provide them with the opportunity to prohibit such use.
The Service Provider engages data processors in connection with the operation of the Website and the ticket sales interface, the fulfilment of ticket purchases, the settlement of payments, the sending of transactional and marketing emails, and the automated transfer of data between these systems. Data processors process personal data exclusively on the documented instructions of the Data Controller, on the basis of a data processing agreement concluded with the Data Controller, and are not entitled to use the data for their own purposes.
Data processors engaged by the Data Controller:
1. Gridaly sp. z o.o. – ticket sales interface, registration, confirmation and transactional emails
Registered office: ul. Nowogrodzka 64/43, 02-014 Warsaw, Poland
Company registration number (KRS): 0000893606; NIP: 7011027905; REGON: 388640049
Data protection officer: Bartosz Szuryga (iod@gridaly.com)
Data processing activity: operation of the ticket purchasing and registration interface; processing of the data provided during registration; sending of order confirmation and other transactional emails relating to the Event.
Data processed: name, email address, company name, job title, billing data and any further data provided during registration.
Data storage: Amazon Web Services and Google cloud infrastructure; the data processor’s privacy notice does not specify the hosting region.
Transfer of data: where personal data is transferred outside the European Economic Area, the transfer takes place on the basis of the standard contractual clauses adopted by the European Commission (SCC).
Privacy notice: https://gridaly.com/privacy-policy
2. Stripe Payments Europe, Limited – online payment gateway
Registered office: One Wilton Park, Wilton Place, Dublin 2, D02 FX04, Ireland
Company registration number (CRO): 513174
Data protection contact: dpo@stripe.com
Data processing activity: processing of credit and debit card payments; transmission and processing of the transaction amount, the transaction identifier and the customer’s email address. Payment card details are entered directly into the payment interface operated by the data processor; the Data Controller neither accesses nor stores them.
Stripe Payments Europe, Limited is the Stripe contracting entity for merchants established in the European Economic Area.
Transfer of data to the United States: to Stripe, LLC on the basis of the EU–US Data Privacy Framework, under which Stripe, LLC is certified, supplemented by the standard contractual clauses adopted by the European Commission (SCC).
Privacy notice: https://stripe.com/privacy
3. Three Hearts Digital Ltd (trading as EmailOctopus) – newsletter and email marketing
Registered office: 86–90 Paul Street, London, EC2A 4NE, United Kingdom
Companies House registration number: 09897211
Contact: contact@emailoctopus.com
Data processing activity: operation of the newsletter distribution system. The Data Processor assists in the sending of newsletters pursuant to a contract concluded with the Data Controller, and in doing so processes the Data Subject’s name and email address, together with the related delivery and engagement data, to the extent necessary for sending the newsletter.
Data storage: Amazon Web Services, Ireland – subscriber data is stored within the European Economic Area.
Transfer of data: the Data Processor is established in the United Kingdom; the transfer takes place on the basis of the adequacy decision adopted by the European Commission in respect of the United Kingdom. The Data Processor’s personnel and certain of its service providers may access the data from outside the European Economic Area, in which case appropriate safeguards apply.
Website: https://emailoctopus.com
4. Lovable Labs Incorporated – operation of the Event website
Registered office: 1111B South Governors Avenue, Dover, DE 19904, United States (incorporated in Delaware)
Representative in the European Union (Article 27 GDPR): Lovable Labs AB, Regeringsgatan 25, 111 53 Stockholm, Sweden
Data protection contact: dpo@lovable.dev; privacy@lovable.dev
Data processing activity: hosting and operation of the Event website, including the technical data generated during use of the Website and the data submitted through the forms available on the Website.
Transfer of data: on the basis of the standard contractual clauses adopted by the European Commission (Decision (EU) 2021/914, Modules Two and Three), supplemented by the UK Addendum and the Swiss amendment.
Data processing agreement: https://lovable.dev/data-processing-agreement
Sub-processors: https://trust.lovable.dev
5. Zapier, Inc. – automated transfer of data between systems
Registered office: 548 Market St. #62411, San Francisco, CA 94104-5401, United States
Representative in the European Union (Article 27 GDPR): DP-Dock GmbH, Attn: Zapier Inc., Ballindamm 39, 20095 Hamburg, Germany (zapier@gdpr-rep.com)
Data protection contact: privacy@zapier.com
Data processing activity: automated transfer of registration, ticketing and contact data between the systems listed above, in accordance with the workflows configured by the Data Controller.
Data storage: Amazon Web Services, United States.
Transfer of data to the United States: on the basis of the EU–US Data Privacy Framework and, as a supplementary safeguard, the standard contractual clauses adopted by the European Commission (SCC), together with the UK Addendum and the Swiss amendment.
Sub-processors: https://zapier.com/legal/subprocessors
Privacy notice: https://zapier.com/privacy
Transfer of personal data outside the European Economic Area
Personal data relating to newsletter subscriptions is stored within the European Economic Area (Ireland). Where a data processor transfers personal data to a third country, such transfer takes place exclusively on the basis of an adequacy decision of the European Commission, the standard contractual clauses adopted by the European Commission, or the EU–US Data Privacy Framework, as set out for each data processor above. The Data Subject may request further information on the safeguards applied, and a copy of the relevant documents, using the contact details set out in section 3.
The Data Controller keeps the list of data processors up to date and publishes any change on the Website. Beyond the data processors listed above, the Data Controller does not transfer personal data to third parties, save where required by law.
8. Legal basis for data processing
Data processing is carried out on the basis of a voluntary declaration by users of the Website, made on the basis of adequate information, which declaration contains the Data Subject’s explicit consent to the use of their personal data provided whilst using the Website.
Data processing carried out by the Data Controller is governed by Act CXII of 2011 on the Right to Self-Determination in Information and Freedom of Information (hereinafter: Info.tv.) Section 5(1)(a) of Act CXII of 2011 on the right to self-determination in relation to information and freedom of information, and in accordance with Act CVIII of 2001 on certain issues relating to electronic commerce services and information society services.
The person providing the data, the Data Subject or the contracting party, is solely responsible for the accuracy of the data provided. By providing their email address, any Data Subject also accepts responsibility for ensuring that only they use the service via the email address provided. In view of this undertaking, all liability relating to logins made using a given email address rests solely with the Data Subject who registered that email address.
9. Rights of the Data Subject
9.1 Right to information The Data Subject is entitled at any time to request information regarding their personal data processed by the Data Controller.
Upon the Data Subject’s request, the Data Controller shall provide information regarding the data relating to them that it processes, the data processed by the Data Controller or by a data processor commissioned by it in accordance with its instructions, the source of such data, the purpose, legal basis and duration of the data processing, as well as the name and address of the data processor and their activities in connection with the data processing, the circumstances and effects of any data protection incident and the measures taken to remedy it; and – in the event of the transfer of the Data Subject’s personal data – the legal basis for the data transfer and the recipient thereof. The Data Controller shall provide the requested information in writing within 30 days of the submission of the request.
The Data Subject may contact the Data Controller with any questions or comments regarding data processing via the email addressinfo@crossbordersummit.eu .
The Data Controller – if it has an internal data protection officer, through that officer – shall keep a record for the purpose of monitoring measures relating to the data protection incident and informing the Data Subject; this record shall include the scope of the Data Subject’s personal data, the scope and number of Data Subjects affected by the data protection incident, the date of the data protection incident, its circumstances, its effects and the measures taken to remedy it, as well as any other information specified in the legislation governing data processing.
9.2. The Data Subject may request the erasure, rectification or blocking of their data. The Data Subject is entitled at any time to request the rectification or erasure of any data recorded incorrectly by contacting us via one of the contact details provided below. The Data Controller shall erase the data within 5 working days of receiving the request; in such cases, the data cannot be restored. The erasure does not apply to data processing required by law (e.g. accounting regulations); the Data Controller shall retain such data for the necessary period.
The Data Subject may also request that their data be blocked. The Data Controller shall block personal data if the Data Subject so requests, or if, based on the information available to it, it can be assumed that erasure would infringe the Data Subject’s legitimate interests. Personal data blocked in this way may only be processed for as long as the purpose of data processing that precluded the erasure of the personal data remains valid.
The Data Subject, as well as all those to whom the data was previously transferred for the purposes of data processing, must be notified of any rectification, blocking or erasure. Notification may be omitted if, having regard to the purposes of the data processing, this does not infringe the Data Subject’s legitimate interests.
If the Data Controller does not comply with the Data Subject’s request for rectification, blocking or erasure, it shall, within 30 days of receiving the request, provide in writing the factual and legal grounds for rejecting the request for rectification, blocking or erasure.
9.3 The Data Subject may object to the processing of their personal data The Data Subject may object to the processing of their personal data. The Data Controller shall examine the objection as soon as possible after the request is submitted, but within a maximum of 15 days, shall decide on the merits of the objection , and shall inform the applicant of its decision in writing.
9.4 Means of redress The Data Subject is entitled at any time to request information from the Data Controller regarding the processing of their personal data, using the following contact details:
Postal address: 1046 Budapest, Kiss Ernő utca 3/A; email: info@crossbordersummit.eu
The Data Subject may, pursuant to the Info.tv. and the Civil Code (Act V of 2013),
- to the National Authority for Data Protection and Freedom of Information (1055 Budapest, Falk Miksa utca 9–11; postal address: 1363 Budapest, P.O. Box 9; email: ugyfelszolgalat@naih.hu; https://naih.hu) or
- enforce your rights before the courts. The court will deal with the matter as a matter of priority.
© ECOMMERCE TRADE Kft.
All rights reserved!