INTRODUCTION
E-GROUP ICT SOFTWARE Private Company Limited by Shares (registered seat: Alsó Törökvész út 2., 1022 Budapest, Hungary; company registration number: Cg. 01-10-045390; registering court: Company Court of the Budapest-Capital Regional Court; tax number: 13665908-2-41; EU VAT number: HU13665908; official electronic contact: ) – hereinafter “E-GROUP”, the “Controller”, the “Operator” – as the operator and data controller of the HeliX project website sets out in this Privacy and Data Protection Notice (the “Notice”) its principles and practices regarding the processing of personal data.
HeliX (Health Ecosystem for Learning and Innovation Across Sovereign Data Space) is an EU-supported project aimed at unlocking the potential of European healthcare data for AI-driven research and clinical advancement, using secure Federated Learning (FL) and privacy-enhancing technologies. The HeliX platform connects health data holders (hospitals, biobanks) and secondary data users (pharma, researchers) in such a way that the data never physically leave the data holder’s environment (“the data does not move”).
The HeliX project is delivered by a consortium of organisations from several EU Member States (Hungary, Poland, Italy, Portugal). For certain processing operations, alongside E-GROUP, consortium members may act as independent controllers, joint controllers or processors; the precise allocation of roles depends on the nature of the processing and the consortium arrangements (see Section 8).
By using the HeliX website and its services (e.g. the contact form), you take note of this Notice. E-GROUP acknowledges this Notice as binding upon itself and undertakes that its processing complies with applicable law and with this Notice.
E-GROUP reserves the right to amend this Notice; the version in force at any given time is published on the website.
1. THE CONTROLLER AND THE DATA PROTECTION OFFICER
Controller: E-GROUP ICT SOFTWARE Informatikai Zrt.
- Registered seat: Alsó Törökvész út 2., 1022 Budapest, Hungary
- Company registration number: Cg. 01-10-045390 (Company Court of the Budapest-Capital Regional Court)
- Tax number: 13665908-2-41; EU VAT number: HU13665908
- E-mail: | Phone: +36-1-371-2555
- Website: https://www.egroup.hu, https://helix.egroup.hu
Data Protection Officer (DPO): András Nagy | E-mail: | Postal address: Alsó Törökvész út 2., 1022 Budapest, Hungary. Data subjects may contact the DPO directly regarding the processing of their personal data and the exercise of their rights under this Notice.
For processing related to the HeliX platform that involves health data, the controller/processor roles and responsible contacts are set out in the consortium and data-processing (joint-controller or processor) agreements; information about these is available at the contacts above.
2. DEFINITIONS
GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data (General Data Protection Regulation).
personal data: any information relating to an identified or identifiable natural person (data subject).
health data: personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about their health status (Article 4(15) GDPR; Act XLVII of 1997 on the processing and protection of health-related and associated personal data – the “Health Data Act”). Health data constitute a special category of personal data under Article 9 GDPR.
processing / controller / processor / recipient / third party / consent / personal data breach: have the meaning set out in Article 4 GDPR.
Federated Learning: a machine-learning approach in which the AI model is trained locally at the organisation holding the data, and only the model parameters/updates – not the raw (personal or health) data – are shared and aggregated at a central coordinating node.
pseudonymisation / anonymisation: pseudonymisation within the meaning of Article 4(5) GDPR, and the process resulting in data that can no longer be attributed to an identified or identifiable natural person (anonymous data, which falls outside the scope of the GDPR).
3. PRINCIPLES OF PROCESSING
E-GROUP processes personal data in accordance with the principles set out in Article 5 GDPR: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. The HeliX platform architecture follows the principle of data protection by design and by default (Article 25 GDPR), primarily by keeping raw data at the data holder and, where possible, processing only pseudonymised or anonymised data or model parameters.
4. PROCESSING RELATED TO THE WEBSITE
4.1. Contact form
The website allows you to submit a contact form. Data processed: name, organisation, e-mail address, and the content of the message (which may contain further personal data).
- Purpose: responding to the enquiry and keeping in contact.
- Legal basis: your voluntary, explicit consent [Article 6(1)(a) GDPR], given by ticking the checkbox on the form.
- Duration: until the enquiry is handled or – if a client relationship or contractual negotiation arises – until the related claims become time-barred; otherwise until you withdraw your consent.
Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
4.2. Newsletter and project news (Resources & News)
If you subscribe to HeliX project news/newsletter, E-GROUP processes your name and e-mail address to send informational and professional content.
- Legal basis: your voluntary consent [Article 6(1)(a) GDPR; Section 6 of Act XLVIII of 2008 on the basic conditions of commercial advertising].
- Duration: until withdrawal of consent; you may unsubscribe free of charge at any time via the link in any newsletter or at .
4.3. Cookies and consent management
The website uses cookies. Strictly necessary (technical) cookies are essential for the operation of the website and may be used without your consent. Statistical/analytics and marketing cookies are used only with your prior consent, which you can give and change at any time via the cookie banner and the “Consent Preferences” interface on the website.
- Legal basis for non-essential cookies: your consent [Article 6(1)(a) GDPR; Section 155 of Act C of 2003 on electronic communications].
- Legal basis for technical cookies: the Operator’s legitimate interest [Article 6(1)(f) GDPR].
4.4. Log files
When you use the website, the system may automatically log the visitor’s IP address, the browser and operating system type, and the time of the visit and activity on the website.
- Purpose: ensuring the secure operation of the website, preventing abuse, and statistical analysis.
- Legal basis: the Operator’s legitimate interest [Article 6(1)(f) GDPR], supported by a balancing test.
- Duration: up to 90 days from creation.
4.5. “Get Involved” – partner and interest enquiries
Contact data (name, organisation, contact details) of organisations wishing to participate or cooperate are processed by E-GROUP for the purpose of contact and preparing cooperation, on the basis of your consent or steps prior to entering into a contract [Article 6(1)(a) and (b) GDPR].
5. PROCESSING RELATED TO THE HELIX PLATFORM (HEALTH DATA)
Notice: the following provisions describe processing related to the operation of the HeliX Federated Learning platform. The specific operations, the exact scope of data, the roles (controller/processor/joint controller) and the safeguards depend on the architecture of the given research/use project and the relevant agreements, and are in all cases subject to a data protection impact assessment (Article 35 GDPR).
5.1. How Federated Learning works
The HeliX platform uses Federated Learning: AI models are trained locally at the organisation holding the health data (the data holder). Raw health data are not transmitted to the platform; only the parameters/updates of the locally trained model (typically aggregated information not directly suitable for identification) are shared and aggregated. This architecture significantly reduces the risk to data subjects and serves the principles of data minimisation and data protection by design.
5.2. Roles and responsibility
- Data holders (hospitals, biobanks): with respect to their source data – including patients’ health data – they typically act as independent controllers under the applicable national law (in Hungary, the Health Data Act) and the GDPR.
- HeliX platform / E-GROUP: as operator of the platform, depending on the nature of the processing, it may act as a processor (Article 28 GDPR) or – where it jointly determines the purposes and means with the data holder/secondary user – as a joint controller (Article 26 GDPR).
- Secondary data users (researchers, pharma): they use the results of the federated model for scientific research and development; they may act as independent or joint controllers.
In cases of joint controllership, the allocation of responsibility for the exercise of data subjects’ rights is set out in an arrangement under Article 26 GDPR, the essence of which is made available to data subjects.
5.3. Legal basis for processing special category (health) data
Where processing related to the platform extends to health (special category) data, its lawfulness requires, in addition to a legal basis under Article 6 GDPR, a condition under Article 9(2) GDPR, in particular:
- the data subject’s explicit consent [Article 9(2)(a) GDPR]; or
- scientific research purposes, with appropriate safeguards under Article 89(1) GDPR (pseudonymisation, data minimisation) [Article 9(2)(j) GDPR]; or, where justified,
- public interest in the area of public health [Article 9(2)(i) GDPR], or the provision of health care [Article 9(2)(h) GDPR].
In Hungary, the processing of health data is also governed by the Health Data Act, in line with Article 9(4) GDPR, which allows Member States to maintain further conditions for health, genetic and biometric data.
For processing for scientific research purposes, Section 21 of the Health Data Act lays down further safeguards: stored health data may be accessed for scientific research purposes only with the permission of the head of the institution or the data protection officer; health and personal identification data may not appear in scientific publications in a manner enabling the identification of the data subject; and records must be kept of such access.
5.4. Anonymisation and pseudonymisation
The platform primarily works with anonymised or pseudonymised data and aggregated model parameters. Where the outcome is truly anonymous data, it falls outside the scope of the GDPR. Pseudonymised data remain personal data and are subject to this Notice and the GDPR.
5.5. The European Health Data Space (EHDS)
HeliX aligns with the emerging European framework for the secondary use of health data – Regulation (EU) 2025/327 on the European Health Data Space (EHDS). The EHDS entered into force on 26 March 2025 and applies in stages (the secondary-use rules generally from 2029, and for certain data categories – such as genetic and clinical trial data – from 2031). E-GROUP takes the EHDS requirements into account in developing and operating the platform.
5.6. Related EU legal framework
- Regulation (EU) 2022/868 on data governance (Data Governance Act), setting out the framework for data intermediation services and data altruism;
- Regulation (EU) 2024/1689 on artificial intelligence (AI Act), laying down requirements for AI systems – including health-related, potentially high-risk AI systems;
- Regulation (EU) 2023/2854 (Data Act), where relevant.
6. CHILDREN’S DATA
The website and the HeliX platform are not services offered to children. For information society services offered directly to children, the consent of a minor who has reached the age of 16 is lawful; for a child under 16, the consent of the holder of parental responsibility is required (Article 8 GDPR). Where health data are processed for research purposes, further safeguards concerning minors are determined by the applicable law and the data protection impact assessment.
7. AUTOMATED DECISION-MAKING, PROFILING AND AI MODELS
In operating the website, E-GROUP does not carry out decision-making based solely on automated processing – including profiling – that produces legal effects concerning the data subject or similarly significantly affects them (Article 22 GDPR). AI model training within the HeliX platform serves scientific research and development purposes and does not, in itself, constitute automated individual decision-making concerning the data subject. Should such decision-making be introduced in the future, data subjects will be informed in advance and their rights under Article 22(3) GDPR will be ensured.
8. PROCESSORS AND RECIPIENTS
E-GROUP may use processors for the processing of personal data (e.g. hosting and server services, web analytics, newsletter system). Processors act on E-GROUP’s written instructions, under a processor agreement pursuant to Article 28 GDPR.
- Hosting/server services: on E-GROUP’s own or contracted providers’ infrastructure; servers are firewall-protected and in a secure environment.
- Web analytics: where the website uses Google Analytics, it is provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), solely on the basis of your consent.
- Social media / pixel (Meta): where the Meta (Facebook) pixel is used, Meta Platforms Ireland Limited (Merrion Road, Dublin 4, Ireland) may act as a joint controller under Article 26 GDPR for collection and transmission, solely on the basis of your consent.
- HeliX consortium members: for processing related to the platform, the consortium partners from the 4 Member States (HU, PL, IT, PT) act according to their respective roles.
E-GROUP reserves the right to use further processors; their name and seat will be made available no later than the start of the processing.
9. TRANSFERS TO THIRD COUNTRIES (OUTSIDE THE EEA)
The HeliX consortium members and the primary processors operate within the European Economic Area (EEA). If, in the context of certain services (e.g. some technology providers), personal data were transferred outside the EEA – typically to the United States – this would take place only with the safeguards under Chapter V (Articles 44–49) GDPR: primarily an adequacy decision of the European Commission (including the EU–US Data Privacy Framework, DPF, where the recipient holds a valid certification), failing which the Standard Contractual Clauses (SCC) or other appropriate safeguards and, where necessary, supplementary measures. As a rule, health data are not transferred to third countries in this project.
10. DATA SECURITY
E-GROUP applies appropriate technical and organisational measures proportionate to the risks to protect personal data (Article 32 GDPR), in particular: access and authorisation management, encryption and pseudonymisation, firewall protection, logging, regular backup and recovery procedures, and data minimisation through the federated architecture. During the operation of the platform, raw health data remain in the data holder’s secure environment.
11. RIGHTS OF THE DATA SUBJECT
Under the GDPR you have the following rights, which you may exercise at or at the postal address above:
- access to your personal data (Article 15 GDPR);
- rectification (Article 16 GDPR);
- erasure / “right to be forgotten” (Article 17 GDPR);
- restriction of processing (Article 18 GDPR);
- data portability (Article 20 GDPR);
- objection to processing (Article 21 GDPR);
- for consent-based processing, withdrawal of consent at any time (withdrawal does not affect the lawfulness of prior processing).
We will respond to your request without undue delay and in any event within one month of receipt. This period may be extended by two further months where necessary, taking into account the complexity and number of requests, of which we will inform you before the deadline. Information is provided free of charge as a rule.
For processing for scientific research purposes, certain data subject rights may be restricted under the conditions of Article 89 GDPR and the relevant national law, insofar as the exercise of those rights would render impossible or seriously impair the achievement of the research purpose, and the restriction is necessary to achieve that purpose.
12. PERSONAL DATA BREACH
In the event of a personal data breach, E-GROUP notifies the competent supervisory authority (NAIH) without undue delay and, where feasible, within 72 hours, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the breach is likely to result in a high risk, data subjects are also informed without undue delay (Articles 33–34 GDPR).
13. REMEDIES
If you consider that the processing does not comply with the law, please first contact E-GROUP or the DPO. In addition, you may lodge a complaint with the supervisory authority or turn to the courts.
Hungarian National Authority for Data Protection and Freedom of Information (NAIH) – Postal address: 1363 Budapest, Pf. 9.; Address: Falk Miksa utca 9–11., 1055 Budapest; Phone: +36 (1) 391-1400; E-mail: ; Website: https://naih.hu
You are further informed that, under Article 77 GDPR, a complaint may also be lodged with the supervisory authority of the Member State of your habitual residence, place of work or the place of the alleged infringement; this may be particularly relevant for data subjects residing in the other Member States of the HeliX consortium (Poland, Italy, Portugal).
Judicial remedy: proceedings may also be brought before the regional court (törvényszék) competent for your place of residence or stay.
14. MAIN LEGISLATION UNDERLYING THE PROCESSING
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR);
- Act CXII of 2011 on informational self-determination and freedom of information (Info Act);
- Act XLVII of 1997 on the processing and protection of health-related and associated personal data (Health Data Act);
- Regulation (EU) 2025/327 on the European Health Data Space (EHDS);
- Regulation (EU) 2022/868 on data governance (Data Governance Act);
- Regulation (EU) 2024/1689 on artificial intelligence (AI Act);
- Regulation (EU) 2023/2854 of the European Parliament and of the Council on harmonised rules on fair access to and use of data (Data Act);
- Act CVIII of 2001 on electronic commerce services;
- Act XLVIII of 2008 on the basic conditions of commercial advertising;
- Act C of 2003 on electronic communications (in particular Section 155);
- Act C of 2000 on accounting; Act V of 2013 on the Civil Code.
15. FINAL PROVISIONS
This Notice is effective from the date indicated above. E-GROUP reviews and updates the Notice as necessary – in particular in line with the development of the HeliX platform, changes in the legal environment and the outcome of data protection impact assessments. The version in force at any given time is available on the HeliX website.