NETLOCK Kft.

Data Processing Notice

regarding the use of the NETLOCK NLToken web signing module (browser extension and native background application)

Effective from 1 September 2026

1. Introduction

This Data Processing Notice (the “Notice”) provides information, pursuant to Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council (the General Data Protection Regulation; “GDPR”) and Act CXII of 2011 on Informational Self-Determination and Freedom of Information (the “Information Act”), about the processing of personal data carried out during, or in connection with, the use of the NETLOCK NLToken web signing module (the “NLToken” or the “Module”) – including the browser extension installed in supported browsers and the native background application (netlock.nltoken, netlock.nlcert) installed on the user's device.

The purpose of this Notice is to enable data subjects, in accordance with the principle of transparency under Article 5(1)(a) GDPR, to understand what processing is involved in the operation of the Module, who carries it out, and in what capacity.

This Notice covers only the data processing information relating to the use of the NLToken Module. The data processing notice concerning personal data processed in connection with entering into an agreement with NETLOCK Kft. and with NETLOCK Kft.'s trust service activities is available here.

2. Identification of the Data Controller

Data Controller
NETLOCK Informatikai és Hálózatbiztonsági Szolgáltató Kft. (hereinafter: the Data Controller or NETLOCK Kft.)
Registered seat
1101 Budapest, Hungária körút 17-19., Hungary
Company registration number
01-09-563961
Tax number
12201521-2-42
Registration number issued by the National Media and Infocommunications Authority
B/2021/002407
Website
netlock.hu or netlock.com
E-mail
info@netlock.hu or info@netlock.com
Phone number
+36 1 437 6655
E-mail address of the Data Protection Officer
dpo@netlock.hu

The scope of NETLOCK's capacity as data controller is set out in Section 5 of this Notice. Depending on the context in which a signature is initiated through the Module, the identity of the data controller may differ (see Section 5).

3. Brief Technical Description of the Service

NLToken is a browser-side add-on (extension) that, through a native communication channel (Native Messaging) from supported browsers, enables the use of smart-card-based key storage devices, electronic signing/authentication using a key available in the local operating system's key store, as well as key generation and the production of certificate requests.

Cryptographic operations that are not directly accessible from the browser are carried out by the native background application installed on the user's device. The extension calls exclusively NETLOCK's own background applications (netlock.nltoken, netlock.nlcert); the native manifest accepts only NETLOCK's extension identifier.

The extension's content script does not read or modify the content of the page; its sole function is to make a helper object available on the page initiating the signing or certificate request operation, and to relay messages between the page and the background application. If the page does not initiate an operation, the extension performs no activity and does not collect, store, or transmit any data.

4. Categories of Personal Data Processed

The operation of the Module involves the processing of the following – partly personal – data. The data flows exclusively on the user's device, between the page and the local background application.

1. Signer's / applicant's certificate data

Categories of data
The content of the selected electronic signing or seal certificate (e.g., the signer's name, the certificate's serial number, issuer, and validity). Where the signer is a natural person, this is personal data [Article 4(1) GDPR].
Source
Local key store / smart card.
Place and nature of processing
Read locally; relayed between the page and the background application; not stored by the extension.

2. Hash to be signed

Categories of data
The cryptographic hash generated from the document to be signed. It cannot in itself be converted back into the document, but it may relate to a document containing personal data.
Source
The page initiating the operation.
Place and nature of processing
Processed locally; relayed; not stored.

3. Certificate request fields

Categories of data
The request data provided for key generation and the certificate request (e.g., the applicant's name and the identification data given in the request). Personal data.
Source
The initiating page / the user.
Place and nature of processing
Generated locally; relayed; not stored by the extension.

4. Signing audit log of the background application

Categories of data
The native background application keeps an audit log of the signing operations performed, recording the time of signing, the initiating website, the certificate used, the cryptographic hash of the document (hash), and the resulting signature. The log is generated as a plain text file in the temporary (temp) directory of the user's device. Where the signer is a natural person, part of this data is personal data [Article 4(1) GDPR].
Source
Local background application.
Place and nature of processing
Stored exclusively on the user's device, in a local text file; NETLOCK has no access to this log and does not process or transmit it.

The private (signing) key does not leave the key store; it is neither transmitted nor copied by the Module.

5. Actors Involved in the Processing and the Capacity of Data Controller

The core functions of the Module perform client-side (local) processing: the extension relays the data described in Section 4 exclusively on the user's device, between the page and the local background application; it does not store such data and does not transmit it to an external server – including NETLOCK's servers. Consequently, the mere operation of the Module does not, in itself, give rise to any server-side processing for which NETLOCK would be the controller. The capacity of data controller [Article 4(7) GDPR] depends on the specific context of use:

5.1. Signature Initiated Within a Third Party's (Partner's) System

Where the signature is initiated by a system operated on the domain of a NETLOCK partner (integrator), the purposes and means of the processing are determined by that partner or by the user's own organisation. Accordingly, for that particular signing operation, the data controller within the meaning of Article 4(7) GDPR is the partner or the user's organisation. In this context, NETLOCK acts merely as the provider of the client-side software (the Module) and has no access to the data described in Section 4.

5.2. Certificate Request and Key Generation via NETLOCK's Customer Portal

Where the user carries out key generation and the production of a certificate request through NETLOCK's customer portal (Qualified or Advanced system), the request data enters NETLOCK's trust service (certificate issuance) process. For this process, the data controller within the meaning of Article 4(7) GDPR is NETLOCK, acting as a qualified trust service provider. The details of the processing carried out in this context (legal basis, retention period, recipients, etc.) are set out in NETLOCK's trust service data processing notice and its Terms of Service (available at netlock.hu/docs/adatkezeles and at netlock.hu/dokumentumtar).

5.3. Component Licensed Under LGPL v2.1

The Module incorporates the chrome-token-signing component (author: Estonian Information System Authority), which NETLOCK uses under the LGPL v2.1 license. This component, in itself, does not carry out any processing on NETLOCK's behalf; the related liability and warranty arrangements are governed by the license agreement.

7. Retention and Erasure of Data

The extension does not store the data described in Section 4; upon completion of the operation, such data does not remain in the extension. The private key remains in the local key store, and its management falls within the responsibility of the operating system and of the user or the organisation operating the device. The retention period for data related to certificate issuance is determined by NETLOCK's trust service data processing notice and the applicable legislation (eIDAS, ETSI, and the retention rules applicable to trust service providers). The retention and erasure of the signing audit log generated locally by the background application, in the temporary directory of the user's device, falls within the responsibility of the user's device or the organisation operating it; NETLOCK has no access to this log and does not determine its retention period.

8. Data Transfers, Recipients, and Transfers to Third Countries

The extension does not transmit the data described in Section 4 to any external server, and does not transfer data from the user's device to any third country or international organisation; the data flows exclusively on the given device, between the page and the local background application. Any transfers that may occur in connection with certificate issuance (e.g., to NETLOCK's contributors, or the public certificate repository) are governed by NETLOCK's trust service data processing notice. The Module (the browser extension and the native background application) does not send any telemetry or diagnostic data, and accordingly no such data transfer takes place to NETLOCK's or any third party's server.

9. Data Security and Data Protection by Design

The design of the Module follows the principle of data protection by design and by default under Article 25 GDPR, as well as the principle of data minimisation under Article 5(1)(c) GDPR. In particular:

  • a) the extension calls exclusively NETLOCK's own background applications, and the native manifest accepts only NETLOCK's extension identifier;
  • b) the content script does not read or modify the content of the page;
  • c) only the data necessary for the operation passes through the channel;
  • d) the private key does not leave the key store;
  • e) while idle, the extension does not collect, store, or transmit any data;
  • f) the Module does not include any telemetry or diagnostic data-sending functionality.

With respect to the processing falling within its scope, NETLOCK applies technical and organisational measures under Article 32 GDPR, in line with NETLOCK's information security management system certified under ISO/IEC 27001.

10. Data Subject Rights and Remedies

Under Chapter III of the GDPR, data subjects are entitled, in particular, to the right of access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20), and objection (Article 21) – against the data controller applicable at the time, to the extent corresponding to the legal basis of the given processing. Requests concerning processing within NETLOCK's scope may be submitted using the contact details given in Section 2. In the cases described in Section 5.1, the data subject may exercise these rights against the relevant controlling partner or organisation.

Data subjects may lodge a complaint concerning the processing of their personal data, or turn to the supervisory authority:

Seat of the National Authority for Data Protection and Freedom of Information (NAIH)
1055 Budapest, Falk Miksa u. 9-11., Hungary
Postal address
1363 Budapest, Pf. 9., Hungary
Phone
+36 (1) 391-1400
Website
www.naih.hu
E-mail
ugyfelszolgalat@naih.hu

Data subjects may also bring proceedings before the court having jurisdiction – at their choice – over their place of residence or habitual residence (Article 79 GDPR; Section 23 of the Information Act).

11. Applicable Legislation and Related Documents

  • a) Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR);
  • b) Act CXII of 2011 on Informational Self-Determination and Freedom of Information (the Information Act);
  • c) Regulation (EU) No 910/2014 of the European Parliament and of the Council (eIDAS), as amended by Regulation (EU) 2024/1183;
  • d) related NETLOCK documents: trust service data processing notice (netlock.hu/docs/adatkezeles); Terms of Service / General Terms and Conditions (netlock.hu/dokumentumtar); the NLToken end-user software license agreement (v2.0).

12. Amendment of this Notice

NETLOCK reserves the right to unilaterally amend this Notice, in particular where required by a change in legislation or in the operation of the Module. The version in force at any given time is available on NETLOCK's website.