Privacy Policy
As of 1 July 2026
Attendees
Organizers & Website
Privacy Policy for Attendees
You can register for events on this website.
The following explains which data is collected as part of the registration for an event and during participation in an event, and for which purposes this data is processed.
If you have any questions regarding an event and, in particular, regarding the processing of your personal data in connection with the registration and participation in an event (including the exercise of your data subject rights), you can contact the respective Organizer directly.
1. CONTROLLER
The controller within the meaning of data protection law is the Organizer named during the event registration. The contact details of the Organizer can also be found during the registration process.
If the Organizer is legally required to appoint a data protection officer or has voluntarily appointed one, you can contact them using the contact details provided by the Organizer.
doo GmbH is engaged as a technical service provider for the technical provision of the website, the registration process and attendee management. doo GmbH generally processes personal data on behalf of and in accordance with the instructions of the Organizer pursuant to Art. 28 GDPR.
2. REGISTRATION FOR AN EVENT
If you register to attend in an event, the Organizer will generally process the data you provide during registration in order to enable your attendance in the event, in particular to send you a registration confirmation, where applicable for identification at event entry, and where applicable for the processing of payment transactions in the case of paid events. The categories of data processed include master data (name, company, position), contact data (email, telephone number), event-related data (booked sessions, participation times, interactions), communication data (messages within the platform) and technical data (IP address, log files).
The legal basis for this is Art. 6 (1) lit. b) GDPR; the processing of your data is necessary for the performance of the contract regarding your participation in the event.
If the Organizer collects additional data that is not strictly necessary for the performance of the contract with you, such data collection serves the optimization of the event or your event experience, for example to adapt and optimize the event according to the interests of the attendees and the target group, as well as for the preparation, evaluation and analysis of the event.
The legal basis for this processing is Art. 6 (1) lit. f) GDPR, the overriding legitimate interest of the Organizer in the optimization, evaluation and analysis of the event.
If, as part of the registration process, you also give your explicit consent for the processing of certain data for specific purposes, the legal basis for this processing is your consent, which may be revoked at any time, pursuant to Art. 6 (1) lit. a) GDPR.
3. PAYMENT INFORMATION
If you register for a paid event, your data and payment information will be processed for the purpose of carrying out the payment either by NovalNet AG in Germany as the payment service provider or by a payment service provider selected by the Organizer. The payment service provider acts as the controller for such payment data and payment information.
If the Organizer has outsourced payment processing, the processing is carried out with the involvement of the payment service provider used and, where applicable, other parties involved in the payment processing.
The legal basis is Art. 6 (1) lit. b) GDPR and Art. 6 (1) lit. f) GDPR for security checks.
Detailed information on data processing and data protection at NovalNet AG can be found here: https://www.novalnet.de/datenschutz.
4. CONTACT
If you contact the Organizer by email, telephone or via a contact form in order to ask questions about the event or request information, the information you provide will be processed and stored for the purpose of handling the respective enquiry. The information requested in the course of such contact is required in order to process your enquiry, address you correctly and provide you with a response.
As far as your enquiry relates to the conclusion or performance of a contract, the processing is carried out for the performance of pre-contractual measures or for the performance of a contract (Art. 6 (1) lit. b) GDPR). Otherwise, the processing is based on the legitimate interest in the proper handling of enquiries and efficient communication with attendees and prospective attendees (Art. 6 (1) lit. f) GDPR). This interest includes, in particular, responding to enquiries, clarifying organizational matters and ensuring the smooth running of the event.
5. ATTENDANCE AT AN EVENT
When attending an event, data may be collected and processed. During admission control, the data relating to the person of the ticket holder stored on the ticket may be collected and processed. Where applicable, data relating to the time of entry and, where applicable, the time of leaving the event may also be stored.
The legal basis for this is Art. 6 (1) lit. b) GDPR; the processing of your data is necessary for the performance of the contract regarding your attendance at the event.
If, in the context of attending the event, you provide your data, in particular by reading an RFID tag or scanning the QR code on your name badge at an exhibition stand, this data will be transmitted by the Organizer to the respective operator of the exhibition stand at which you provided your data. In this case, the further processing and use of your data lies with the operator of the exhibition stand as the controller.
5.1 PHOTOGRAPHY
Photo and video recordings may be made during the event. These photo and video recordings may show attendees and make them identifiable. These photo and video recordings may be used for public relations purposes and for documenting the event. The publication of such recordings may take place both offline (print) and online, in particular on the Organizer's website or on the Organizer's pages on various social media platforms (e.g. fan pages on Facebook).
The legal basis for this processing is Art. 6 (1) lit. f) GDPR, the overriding legitimate interest of the Organizer in documenting the event and using photo and video recordings of the event for public relations purposes. You will be informed separately on site about such recordings.
5.2 FEEDBACK AFTER AN EVENT
After attending an event, you may be contacted by email in order to obtain your feedback on the event. You may object to such contact at any time by contacting the respective Organizer using the contact details provided for the Organizer. If you provide your feedback on the event via the website, the information you provide will be used exclusively for the evaluation of the event and the optimization of future events.
The legal basis for contacting you to request your feedback is Art. 6 (1) lit. f) GDPR or Art. 6 (1) lit. a) GDPR, if explicit consent has been obtained from you in individual cases. The overriding legitimate interest of the Organizer is the evaluation of the event and the optimization of future events.
6. INVITATIONS TO FURTHER EVENTS
If you have registered for an event, the Organizer may use the email address provided during registration to send you invitations to similar events organized by the Organizer by email, provided that you have not objected to such use. You may object to the use of your email address at any time without incurring any costs other than the transmission costs according to the basic tariffs by using the unsubscribe link contained in every email or by contacting the respective Organizer using the contact details provided for the Organizer.
The Organizer has a legitimate interest in informing existing attendees about comparable offers and maintaining existing business relationships. In doing so, it is ensured that communication is limited to similar events and that you are given the opportunity to object to such use at any time. The legal basis is Art. 6 (1) lit. f) GDPR in conjunction with Section 7 (3) German Act Against Unfair Competition (UWG).
7. DATA RETENTION
Your personal data will only be processed for the period necessary to achieve the purpose of the processing and for the subsequent follow-up of the event. Once the purpose no longer applies, the data will be deleted or anonymized, unless further statutory retention obligations apply.
8. TRANSFER TO THIRD COUNTRIES
To the extent that personal data is transferred to countries outside the European Union or the European Economic Area, this will only take place in compliance with the statutory requirements and on the basis of appropriate safeguards, in particular the EU Standard Contractual Clauses. In addition, transfers to the United States are based on the EU-U.S. Data Privacy Framework, provided that the recipient is certified under this framework. Furthermore, additional measures may be implemented where necessary to ensure an adequate level of data protection.
9. YOUR RIGHTS
You have the right to request information at any time about the personal data stored about you. You also have the right to rectification of inaccurate data, deletion of your data or restriction of processing, provided that no statutory retention obligations prevent this. You may object to the processing of your data based on legitimate interests and assert your right to data portability.
If you have given consent to the processing of your data, you may withdraw such consent at any time with effect for the future.
Furthermore, you have the right to lodge a complaint with a competent data protection supervisory authority.
To exercise these rights, you may contact the Organizer or, where applicable, its data protection officer at any time without formal requirements.
Privacy Policy for Event Organizers and Website Visitors
The doo GmbH (hereinafter “doo”) provides a platform for the management of events, which enables organisers of events to organise events, sell tickets for their events and manage the associated communication and administration.
At doo, we take the protection of your personal data very seriously. We process your personal data in accordance with applicable data protection laws and these data protection provisions.
With these data protection provisions, we would like to inform you about which personal data is collected and processed for which purposes via our website and via our event management platform.
We distinguish between the following areas:
- Visiting our website
- Creation of events using the doo event management platform
- CUSTOMER SERVICE REGISTRATION
- Contact and contact database (CRM)
- Use of artificial intelligence (AI) in communication
- Newsletter
- Blog
- TRADE FAIR CONTACTS AND RECORDINGS AT TRADE FAIRS
- ONLINE MEETINGS AND WEBINARS
- Job offers and applications
- MERGERS AND ACQUISITIONS (M&A)
- AGE RESTRICTION
- RECIPIENTS OF DATA
- DATA SUBJECT RIGHTS
- MANDATORY INFORMATION AND PROFILING
- RETENTION AND DELETION
- INFORMATION SECURITY
- AMENDMENT OF THIS PRIVACY POLICY
Controller
The controller is doo GmbH (hereinafter “doo”), Hultschiner Straße 8, 81677 Munich, Germany, Phone: +49 (0)89 2488 153-0, Email:
kontakt@doo.net.
DATA PROTECTION OFFICER
Our data protection officer is attorney-at-law Christian Schmoll, Email: c.schmoll@compliance.one. If you have any questions or suggestions regarding data protection, you can contact our data protection officer directly.
1. VISTING OUR WEBSITE
1.1 LOG FILES
Each time our website is accessed, our system automatically collects data and information from the computer system of the accessing device. In order for the website to be displayed in your browser, the IP address of your device must be processed. In addition, further information about your browser is collected.
For the purpose of ensuring the confidentiality and integrity of the personal data processed by our IT systems, the following data is logged:
- IP address of the accessing device
- Operating system of the accessing device
- Browser version
- Name of the retrieved file
- Date and time of access
- Amount of data transferred
- Referring URL
The data is also used to resolve technical issues on the website.
Our website is hosted by a service provider within the European Economic Area. A data processing agreement in accordance with Art. 28 GDPR is in place.
The legal basis for this data processing is our legitimate interest pursuant to Art. 6 (1) lit. f GDPR. Our legitimate interest lies in operating the website and ensuring the confidentiality, integrity and availability of the data.
1.2 COOKIES
Cookies are used on the website. Cookies are pieces of information that are transferred from our web server or third-party web servers to the browser of the website visitor and stored there for later retrieval. Cookies can be small files or other types of information storage. Information is stored in cookies that is generated in connection with the specific end device used. Cookies contain a characteristic string of characters that enables the browser to be uniquely identified when the website is called up again. A cookie also contains information about its origin and the storage period. However, this does not mean that the identity of the website visitor can be obtained directly from a cookie.
When you visit the website, cookies are set that are absolutely necessary for the operation of the website. These absolutely necessary cookies may, for example, be cookies that are required to display the website with a content management system, that are used to recognize language settings or that are used to document whether consent has been given to the setting of further (optional) cookies or whether such storage has been rejected. The strictly necessary cookies, including their purpose and storage or deletion period, are explained below and also in the cookie banner that is displayed when the website is accessed.
Optional cookies are also used, for example, to collect additional information about the interests of visitors to the website or their usage behavior in order to analyze and optimize the website and customer interactions in general.
Optional cookies, including their purpose and storage or deletion period, are explained below and also in the banner that is displayed when the website is accessed. Optional cookies are only set if you have expressly consented to the setting of optional cookies.
To the extent that we use cookies or similar technologies to store information on your device or to access information stored on your device, the legal basis for this is your express consent. This does not apply to technologies that are strictly necessary for the provision of services expressly requested by you.
The legal basis for this data processing is the express consent of the website visitors, which can be revoked at any time.
1.3 CONSENT MANAGEMENT (PIWIK PRO)
The Consent Management Platform ("CMP") Piwik PRO Consent Manager provided by Piwik PRO S.A. in Poland is used on the website. The provider acts as a data processor on the basis of a data processing agreement.
Piwik PRO Consent Manager is used to inform website visitors about the cookies and tracking technologies used and to request and, if necessary, document consent to the use of optional cookies. A permanent cookie is stored in the browser to save the consent.
The following data is logged automatically: IP address in anonymized form (if activated), date and time of consent, user agent (information on the end device), URL on which the consent was collected, and the status of consent (which categories of cookies were consented to).
The legal basis for this data processing is initially the Controller's legitimate interest in obtaining the consent of website visitors to the storage of optional cookies as part of the provision of the website. If such consent has been given, the legal basis for the processing of the data for consent is the fulfilment of the legal obligation to obtain and document such consent.
1.4 RETARGETING-/REMARKETING-SERVICES
These marketing services enable us to display advertisements for and on our website in a targeted manner, so that you are only shown advertisements that are potentially of interest to you.
A cookie is used to store information in your browser about which websites on which such marketing services are active you have visited and which content you were interested in. In addition, further information is collected, such as IP address, browser, operating system, timestamp and referring website.
If you subsequently visit other websites on which such marketing services are active, advertisements tailored to your interests may be displayed to you.
The legal basis for the processing of personal data in the context of the use of retargeting/remarketing services is your explicit consent pursuant to Art. 6 (1) lit. a GDPR.
1.4.1 LINKEDIN ADS
We use the retargeting service LinkedIn Ads of LinkedIn Ireland Unlimited Company, Ireland. LinkedIn uses cookies for this purpose.
Further information on data protection at LinkedIn can be found in the LinkedIn Privacy Policy: https://www.linkedin.com/legal/privacy-policy.
You can prevent the storage of cookies by adjusting your browser settings. You can also object to the analysis of your usage behaviour by LinkedIn and the display of interest-based recommendations here: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
Personal data may be transferred to third countries that do not provide an adequate level of data protection. In such cases, appropriate safeguards pursuant to Art. 46 GDPR are implemented to ensure an adequate level of data protection. Evidence of such safeguards will be provided upon request.
The legal basis for this data processing, including the transfer of data to LinkedIn, is your explicit and revocable consent pursuant to Art. 6 (1) lit. a GDPR.
1.4.2 FACEBOOK CUSTOM AUDIENCES
We also use the retargeting service Facebook Custom Audiences of Facebook, Inc., USA. Facebook Custom Audiences uses a so-called tracking pixel. This pixel is loaded from a Facebook URL with specific parameters when our website is accessed and transmits information to Facebook, which Facebook uses to display targeted advertising.
However, no individual persons are addressed, but only groups of users with similar behaviour. Facebook uses a hashing process in which personal data is encrypted in such a way that it can no longer be assigned to individual users.
Further information can be found in Facebook’s privacy policy: https://www.facebook.com/about/privacy
When using Facebook Custom Audiences, personal data may be transferred to third countries that do not provide an adequate level of data protection. In such cases, appropriate safeguards pursuant to Art. 46 GDPR are implemented.
The legal basis for this data processing is your explicit and revocable consent pursuant to Art. 6 (1) lit. a GDPR.
1.4.3 GOOGLE-MARKETING-SERVICES
We also use marketing services of Google Ireland Limited, such as Google Ads, Conversion Tracking, AdSense and Google Marketing Platform. Google uses cookies and so-called web beacons.
You can prevent the storage of cookies by adjusting your browser settings. If you wish to object to interest-based advertising by Google, you can use the settings and opt-out options provided by Google: http://www.google.com/ads/preferences
Further information on data usage by Google, settings and objection options can be found here:
- https://www.google.com/policies/privacy
- https://www.google.com/intl/de/policies/privacy/partners
- http://www.google.com/policies/technologies/ads
- http://www.google.de/settings/ads
Personal data may be transferred to third countries that do not provide an adequate level of data protection. In such cases, appropriate safeguards pursuant to Art. 46 GDPR are implemented.
The legal basis for this data processing is your explicit and revocable consent pursuant to Art. 6 (1) lit. a GDPR.
1.5 WEBANALYTICS
We use web analytics services to analyse and regularly improve the use of our website. In this context, cookies are used that enable an analysis of your use of the website. The information generated in this way is used to evaluate the use of the website and to compile reports on website activities.
The legal basis for the processing of personal data in the context of web analytics is your consent pursuant to Art. 6 (1) lit. a GDPR.
Personal data may be transferred to third countries that do not provide an adequate level of data protection. In such cases, appropriate safeguards pursuant to Art. 46 GDPR are implemented.
1.5.1 GOOGLE ANALYTICS
We use the web analytics service Google Analytics with IP anonymisation. Google Analytics is a web analytics service provided by Google Ireland Limited. In the context of Google Analytics, cookies are set.
Within the scope of IP anonymisation, the collected IP addresses of users are shortened by Google within the European Economic Area before being transmitted to the USA. Only in exceptional cases is the full IP address transmitted to Google in the USA and shortened there. The transmitted IP addresses are not combined with other data held by Google.
You can prevent the storage of cookies by adjusting your browser settings accordingly. In addition, you can prevent the collection of data generated by the cookie and relating to your use of the online service (including your IP address) and the processing of this data by Google by downloading and installing the browser plugin available at the following link, which informs Google Analytics via JavaScript that no data and information about visits to websites may be transmitted to Google Analytics: http://tools.google.com/dlpage/gaoptout?hl=de
Accordingly, personal data may be transferred to third countries that do not provide an adequate level of data protection. In such cases, it is ensured that appropriate safeguards pursuant to Art. 46 GDPR are in place to ensure an adequate level of data protection. Evidence of such appropriate safeguards will be provided by the controller upon request.
The legal basis for this data processing is the explicit and revocable consent pursuant to Art. 6 (1) lit. a) GDPR of the visitors to the website.
1.5.2 LINKEDIN ANALYTICS
We also use the web analytics service LinkedIn Analytics of LinkedIn Ireland Unlimited Company in Ireland. LinkedIn Analytics uses cookies.
Further information on data protection at LinkedIn can be found in the LinkedIn Privacy Policy at https://www.linkedin.com/legal/privacy-policy. It is also described there how you can object at any time, with effect for the future, to the collection and storage of data for the purpose of web analytics by LinkedIn. You can also prevent the storage of cookies by adjusting your browser settings accordingly.
In this context, personal data may be transferred to third countries that do not provide an adequate level of data protection. In such cases, it is ensured that appropriate safeguards pursuant to Art. 46 GDPR are in place to ensure an adequate level of data protection. Evidence of such appropriate safeguards will be provided by the controller upon request.
The legal basis for this data processing is the explicit and revocable consent pursuant to Art. 6 (1) lit. a) GDPR of the visitors to the website.
1.6 SOCIAL MEDIA-BUTTONS
Social media buttons of the social media networks Facebook, X, LinkedIn and Xing are integrated on our website.
If you click on one of these social media buttons, you will be redirected to our pages on the respective social media network. In this case, the provider of the respective social media network receives the information that your browser has accessed the corresponding page of our website, even if you do not have a profile with the respective social media network or are not logged in there. This information (including your IP address) is transmitted directly from your browser to a server of the respective provider. If you click on a social media button and are either logged in to the respective social media network or log in on the page of the respective social media network, the transmitted information may be assigned to your account with the social media network.
Information on the purpose and scope of the data collection and processing by the providers of the respective social media networks, the provider identification, contact options and your rights and settings options for data protection can be found in the respective data protection information of the providers of the social media networks.
The legal basis for the integration and use of the social media buttons is our legitimate interest pursuant to Art. 6 (1) lit. f) GDPR. Our overriding legitimate interest is the marketing of our offers and our website.
1.7 SOCIAL MEDIA-PAGES
We maintain publicly accessible profiles on the social media networks Facebook, X, LinkedIn and Xing (“social media pages”).
If you visit one of our social media pages and are logged in to the respective social media network, the provider of the respective social media network may analyse your user behaviour and assign the information collected to your account with the social media network and enrich it there. Even if you are not logged in or if you do not have an account with the respective social media network, personal data may be collected by the provider of the respective social media network, for example your IP address or data collected via a cookie.
The operators of the social media networks can create user profiles based on this data. Based on your user profile, interest-based advertisements may then be displayed to you both on the websites of the social media network and on other websites.
If you visit one of our social media pages, we are jointly responsible with the provider of the social media network for the collection and processing of your personal data that takes place there. For information on the collection and processing of your personal data that takes place there, we refer you to the privacy policy of the respective social media network.
You can assert your data subject rights (right to information, correction, deletion, restriction of processing, data portability, etc.) both against us and against the provider of the respective social media network. In this context, we would like to point out that we can only influence the processing of personal data and the implementation of data subject rights within the framework of our social media pages within the scope of the possibilities made available to us by the respective provider.
The legal basis for our use of social media pages is our legitimate interest pursuant to Art. 6 (1) lit. f) GDPR. Our overriding legitimate interest is the presence and marketing of our products and services on the internet.
1.8 SOCIAL SHARING
Social sharing buttons make it possible to publish a link to certain content of our website, for example to an article in our blog, directly on your respective page on the social media networks (Facebook, X, LinkedIn, Xing). The social sharing buttons are provided by the provider of the respective social media network. Each time a website is accessed on which such a social sharing button is integrated, the social sharing button is loaded by the provider of the respective social media network. By integrating the plugins, the providers receive the information that your browser has accessed the corresponding page of our website, even if you do not have a profile with the respective social media network or are not logged in there. This information (including your IP address) is transmitted directly from your browser to a server of the respective provider.
If you click on a social sharing button and are either logged in to the respective social media network or log in in the window that opens, the transmitted information may be assigned to your account with the social media network.
Information on the purpose and scope of the data collection and processing by the providers of the respective social media networks, the provider identification, contact options and your rights and settings options for data protection can be found in the data protection information of the providers of the social media networks:
- Facebook: http://www.facebook.com/policy.php
- X: https://x.com/de/privacy
- LinkedIn: https://www.linkedin.com/legal/privacy-policy
- Xing: https://www.xing.com/privacy
The legal basis for this data processing in the integration and use of the social sharing buttons is Art. 6 (1) lit. f) GDPR. Our legitimate interest is the marketing of our offers and our website.
1.9 FONTS
In order to display the content of our website correctly across browsers and in a visually appealing manner, we use font and script libraries on this website, e.g. the font library of MyFonts, Inc. Accessing font and font libraries automatically triggers a connection to the operator of the respective library. In this process, it is possible that your personal data, in particular your IP address, is collected.
You can prevent the use of such libraries and the associated data transmission by installing a JavaScript blocker (e.g. www.noscript.net).
Due to the licensing terms of MyFonts, Inc., we use the MyFonts Counter, a web analytics service that performs page view tracking, whereby the number of visits to the website is counted for statistical purposes and transmitted to MyFonts. Further information on MyFonts Counter can be found in the MyFonts privacy policy: http://www.myfonts.com/info/terms-and-conditions/#Privacy.
The legal basis for this data processing when using such libraries is Art. 6 (1) lit. f) GDPR. Our legitimate interest is the analysis, optimisation and economic operation of our website and our customer interactions.
1.10 RECAPTCHA
The tool reCAPTCHA of the provider Google Ireland Limited in Ireland is used on the website. The provider acts as a processor on the basis of a data processing agreement.
reCAPTCHA is used to determine whether a specific input in a form is made by a person or by a computer. Google checks on the basis of the following data whether the input is made by a person or a computer: IP address of the device used, the website that is visited and on which the captcha is integrated, the date and duration of the visit to the website, information about the browser and operating system type used, the Google account if the user is logged in to Google, mouse movements on the reCAPTCHA areas as well as tasks in which images must be identified.
The use of the reCAPTCHA tool is necessary in order to be able to provide the website securely. The legal basis for the described data processing is the legitimate interest of the controller in the security of the website and in particular the protection against automated inputs and attacks. If consent has been obtained, the legal basis is the explicitly given and revocable consent.
When using reCAPTCHA, personal data may be transferred to third countries that do not provide an adequate level of data protection. In this case, it is ensured that appropriate safeguards pursuant to Art. 46 GDPR are in place to ensure an adequate level of data protection. Evidence of such appropriate safeguards will be provided by the controller upon request.
1.11 VIDEO (VIMEO)
Videos are embedded on the website. This functionality is made available via a plugin provided by Vimeo, LLC, in the USA. The provider acts as a data processor on the basis of a data processing agreement.
When you visit a website that is equipped with such a Vimeo plugin, a connection to Vimeo is established and your IP address is transmitted to Vimeo. Even if you start a video by clicking on it, this information is transmitted to Vimeo. If you are logged in to Vimeo, the transmitted information may be linked to your Vimeo account.
Further information on the scope and purpose of data processing by Vimeo and the processing and use of your data by Vimeo as well as your setting options for protecting your privacy in this regard can be found in Vimeo's privacy policy at https://vimeo.com/privacy. Additional information on the use of cookies by Vimeo can be found here in the Vimeo Cookie Policy at https://vimeo.com/cookie_policy.
Personal data may be transferred to third countries that do not offer an adequate level of data protection. In this case, it is ensured that appropriate safeguards are provided for such a transfer in order to ensure an adequate level of data protection. The Controller will provide evidence of these appropriate safeguards on request.
The legal basis for this data processing is the Controller's legitimate interest in the integration of videos and the associated optimization of the interactivity of the website and customer interactions. If consent has been obtained, the expressly granted consent, which can be revoked at any time, constitutes the legal basis.
2. CREATION OF EVENTS USING THE DOO EVENT MANAGEMENT PLATFORM
Below we inform you about which personal data is collected and processed when using the doo event management platform to create events as an organizer ("Organizer").
2.1 ACCOUNT
When you create an account to use the doo event management platform as an event organizer, we collect and process your personal data as the data controller. We do not collect and process this data on your behalf or at your instruction, but rather to enable you to use the doo event management platform.
In addition to the data categories described in section 1, we collect and process the data you provided during registration (surname, first name, email address, telephone number). This information is mandatory, as we require it to fulfill the contract.
You can delete your customer account at any time. Please contact us using the contact details provided for the responsible department.
2.2 PAYMENT INFORMATION
If you make use of paid services, the data required for payment processing (e.g. name, contact details, payment and transaction information) will be processed for the performance of the contract pursuant to Art. 6 (1) lit. b) GDPR.
For payment processing, the payment service provider NovalNet AG, Germany, is used. The data required for the payment will be transmitted to NovalNet AG, which processes this data under its own responsibility under data protection law.
If the Organiser has outsourced payment processing to doo, the processing is carried out with the involvement of the payment service provider used as well as other parties involved in the payment processing.
Further information on data processing by NovalNet AG can be found at: https://www.novalnet.de/datenschutz.
2.3 ATTENDEE AND INVITEE DATA
doo processes the data of attendees in your events who register for your event via the doo event management platform or whose data is processed in other forms using the doo event management platform (for example, data collected "onsite" at an event), and the data of the recipients of your marketing campaigns, for example, the list of recipients of your email marketing campaigns that you send via the doo event management platform, and other data that you store for processing in the doo event management platform ("invitee data"), as a data processor on your behalf and according to your instructions.
This data processing is governed by our Data Processing Agreement (DPA), which you can access here.
3. CUSTOMER SERVICE REGISTRATION
You can register in our customer service portal. You can then access your enquiries submitted to customer service at any time and check their status. The data provided during registration is used for the purpose of using the customer service portal. The mandatory information requested during registration must be provided in full; all other information in your profile, for example the upload of a profile picture, is voluntary. The email address provided during registration is verified by sending a confirmation email in which you must confirm your email address by clicking on a link.
The legal basis for this storage and processing is our legitimate interest pursuant to Art. 6 (1) lit. f) GDPR. Our legitimate interest is the maintenance of our customer relationships. If the contact is aimed at the conclusion of a contract or takes place within the framework of an existing contractual relationship, the additional legal basis for the processing is the necessity of the processing for the performance of a contract pursuant to Art. 6 (1) lit. b) GDPR.
You can have the data you provided during registration for the customer service portal deleted at any time. If you delete your registration, the data relating to the respective account will be deleted, unless their retention is required for commercial or tax law reasons. Please contact us for the deletion of your account using the contact details provided for the controller.
4. CONTACT AND CONTACT DATABASE (CRM)
4.1 CONTACT AND REQUEST FOR INFORMATION AND OFFERS
If you contact us by email, via contact forms or our live chat, for example to request information or an offer or for other enquiries in connection with the doo event management platform, the information you provide will be stored for the purpose of processing the enquiry. The information requested in the contact form on the website is required in order to process your enquiry, address you correctly and provide you with a response.
The legal basis for this data processing is our legitimate interest pursuant to Art. 6 (1) lit. f) GDPR. Our legitimate interest is communication with customers and prospective customers.
If the contact is aimed at the conclusion of a contract, the additional legal basis for the processing is the necessity of the processing for the performance of a contract pursuant to Art. 6 (1) lit. b) GDPR.
For our contact form and our chat function on the website, we use an external service provider as a processor on the basis of a data processing agreement pursuant to Art. 28 GDPR. Personal data may be transferred to third countries that do not provide an adequate level of data protection. In this case, it is ensured that appropriate safeguards pursuant to Art. 46 GDPR are in place to ensure an adequate level of data protection. Evidence of such appropriate safeguards will be provided by the controller upon request.
4.2 CUSTOMER DATABASE AND DIRECT MARKETING
Enquiries and orders are generally stored in our CRM system. This data may be used by us for direct marketing purposes. You may object to such use for direct marketing at any time. Details of your right to object can be found below under “Your rights”.
The CRM system is regularly reviewed to determine whether data can be deleted. If data is no longer required in the context of a customer or prospective customer relationship or if a conflicting interest of the customer prevails, we will delete the data concerned, provided that no statutory retention obligations prevent this.
The legal basis for this storage and processing is our legitimate interest pursuant to Art. 6 (1) lit. f) GDPR. Our legitimate interest is the maintenance of our customer relationships and the implementation of direct marketing measures.
4.3 DISCLOSURE OF YOUR DATA TO SPONSORS
In the context of our own doo events, we transmit the following personal data of all registered attendees to our event sponsors: first and last name, company/organisation, position, contact details. The disclosure is made for the purpose of contacting you by the sponsors for advertising purposes and for the presentation of products and services, insofar as these are related to the event.
The legal basis for this is our legitimate interest pursuant to Art. 6 (1) lit. f) GDPR in order to be able to offer you a free or low-cost event and to finance our event through sponsor contributions. You have the right to object to the disclosure of your data to the sponsors at any time (“opt-out”). Such an objection can be made by informal notification by email to marketing@doo.net or directly as part of your online registration. If an objection is made, your data will not be passed on to the sponsors. A withdrawal after the disclosure has taken place will result in your data having to be deleted by the sponsors.
5. USE OF ARTIFICIAL INTELLIGENCE (AI) IN COMMUNICATIONS
To support employees in their daily work and improve the quality and consistency of communication, the Controller uses AI applications, including ChatGPT from OpenAI, Microsoft Copilot, Google Gemini for Workspace, and Claude from Anthropic. These applications are particularly helpful in drafting or summarizing emails and documents.
The use of AI is strictly limited to internal productivity purposes, such as helping employees prepare responses or extracting relevant content from previous communications. The AI applications used only have access to content that employees themselves can access. Decisions are never made solely by AI; all results and suggestions are always reviewed by employees before being shared externally.
We ensure, through contractual agreements with the AI providers as well as through technical configurations (e.g. the use of enterprise versions or closed API interfaces), that personal data entered into the AI systems is not used by the providers for training or improving their own base models. Data sovereignty remains fully with us.
AI is used on the basis of the Controller‘s legitimate interest, as this support enables employees to respond more efficiently and effectively to inquiries and communications. Careful consideration has been given to ensuring that the interests and fundamental rights of the data subjects are not affected by this use. This is ensured in particular by the fact that the use of AI is clearly defined, strictly limited, and always subject to human control. In addition, the Controller implements comprehensive internal security measures, including clear internal guidelines on the use of AI, regular employee training, and appropriate data protection controls. This ensures that processing is fair, proportionate, and respectful of privacy.
6. NEWSLETTER
6.1 REGISTRATION FOR THE NEWSLETTER
You can register on our website to receive a newsletter by email. When registering, the data from the input form, the IP address of the accessing device and the date and time of registration are transmitted to us. Your consent to the processing of the data is obtained as part of the registration process and reference is made to these data protection provisions.
In order to verify that a registration for the newsletter is carried out by the actual owner of an email address, we use the so-called “double opt-in” procedure. After registering an email address, a confirmation email is sent to the registered email address. The registration for the newsletter is only completed once a confirmation link contained in the confirmation email has been activated. In this context, the IP address of the accessing device and the date and time of activation of the confirmation link are also transmitted to us.
Registration for the newsletter can be terminated at any time by using the unsubscribe link contained in every newsletter or by contacting us using the contact details provided for the controller.
The legal basis for the processing of data after registration for the newsletter is your consent pursuant to Art. 6 (1) lit. a) GDPR.
6.2 EMAIL NEWSLETTER IN THE CONTEXT OF AN EXISTING CUSTOMER RELATIONSHIP
If you register as a user of the doo event management platform and provide your email address, this email address may subsequently be used by us to send you an email newsletter, provided that you have not objected to such use. In such a case, only direct advertising for our own similar goods or services will be sent via the email newsletter. You may object to the use of your email address at any time without incurring any costs other than the transmission costs according to the basic tariffs by using the unsubscribe link contained in every newsletter or by contacting us using the contact details provided for the controller.
The legal basis for sending the newsletter following the sale of goods or services is our legitimate interest pursuant to Art. 6 (1) lit. f) GDPR (in Germany in conjunction with Section 7 (3) UWG).
6.3 NEWSLETTER ANALYSIS
Our newsletters may include a statistical evaluation of usage data. For this purpose, we may record both the opening of emails and internal clicks. This information serves the purpose of measuring and optimising the success of our newsletter campaigns by making the content of the newsletters more relevant for our target group.
The legal basis for this analysis is our legitimate interest pursuant to Art. 6 (1) lit. f) GDPR. Our legitimate interest is the evaluation and optimisation of communication with customers and prospective customers.
6.4 NEWSLETTER SERVICE PROVIDER
We use an external service provider as a processor on the basis of a data processing agreement pursuant to Art. 28 GDPR for the sending and analysis of our newsletter.
Personal data may be transferred to third countries that do not provide an adequate level of data protection. In this case, it is ensured that appropriate safeguards pursuant to Art. 46 GDPR are in place to ensure an adequate level of data protection. Evidence of such appropriate safeguards will be provided by the controller upon request.
7. BLOG
In our blog, you can comment on articles. We use the comment system of the external provider DISQUS, Inc., USA.
In this context, personal data may be transferred to a third country outside the EU that does not provide an adequate level of data protection. Appropriate safeguards for the data transfer pursuant to Art. 46 GDPR are in place. We will be happy to provide you with evidence of the appropriate safeguards (standard contractual clauses) upon request at any time. Please contact us using the contact details provided above.
In order to comment on an article in the blog, you must log in. DISQUS allows such login either via a DISQUS account or via an account with Facebook, Twitter or Google Plus (“social media networks”). If you log in to the comment function using your account with a social media network, the social media network will also collect and process information about your use of the DISQUS function. Detailed information on this data collection and processing can be found in the data protection information of the respective social media network.
When you log in to the comment function, we receive your email address and your IP address, which was used when entering a comment, from DISQUS. We require and process this information exclusively for the purpose of contacting you in connection with your use of DISQUS, for example if we have questions regarding your user comment, and for security reasons in the event that third-party rights are violated or unlawful content is posted through a comment.
If you comment on an article in our blog, in addition to your comment, information about the time of commenting and, where applicable, the username (pseudonym) you have chosen will be stored and published.
The legal basis for data collection in the context of the comment function is our legitimate interest pursuant to Art. 6 (1) lit. f) GDPR. Our legitimate interest is, on the one hand, the evaluation and optimisation of communication with customers and prospective customers within the blog and, on the other hand, the protection of our rights and the ability to defend ourselves legally in the event of misuse or unlawful use of the comment function.
8. TRADE FAIR CONTACTS AND RECORDINGS AT TRADE FAIRS
We process information that has been provided to us in the context of a trade fair visit or other event (e.g. from contact registration, conversation notes, business cards, etc.) exclusively for the purpose of processing the request discussed or mentioned in the context of the respective contact. Contact is made by post, telephone or e-mail.
We use a service provider as a data processor to process trade fair contacts on the basis of a data processing agreement.
In addition, we take photos and videos at trade fairs of our presence at the fair and possibly also of visitors to our stand or in any other context related to our participation in the respective event (hereinafter referred to as “Recordings”). When Recordings are made, metadata such as the date, time and location of the Recording are also regularly collected.
We process the Recordings for the following purposes:
- Public relations and presentation of our presence at the trade fair: This includes publishing the Recordings on our website, in social and print media or in press releases to report on our activities at the trade fair and to promote our company. Even though the Recordings we create for this purpose are mainly about the respective event or our presence at the trade fair, trade fair visitors may also be depicted in these Recordings. The legal basis for this data processing is our legitimate interest in appropriate reporting on the respective event or our participation in the respective event. When using the Recordings, we take great care not to violate any legitimate interests of the persons depicted (e.g. no unflattering photos are published).
- Internal documentation and archiving: The Recordings may also be used for internal documentation of the event and long-term archiving (company chronicle). The Recordings made for this purpose also mainly concern the respective event or the trade fair appearance as such, but trade fair visitors may also be shown in these Recordings. The legal basis for this data processing is our legitimate interest in documenting our events and our participation in events.
- Individual Recordings of persons: If we want to create targeted portrait Recordings or interviews of individual persons, we will obtain explicit consent in advance. In such cases, information is provided in advance and the data subject can freely decide whether to consent. The corresponding Recordings are then used exclusively for the agreed purposes (e.g. a planned social media post or follow-up reporting).
We only store Recordings for as long as is necessary for the respective purposes. Recordings that we use for public relations work are stored for as long as they are needed for reporting and marketing purposes. We reserve the right to longer-term archiving for documentation purposes (historical archiving of our trade fair appearances). We only store portrait and individual recordings on the basis of consent until the consent is revoked or the purpose of the recording no longer applies.
9. ONLINE MEETINGS AND WEBINARS
When you participate in a video conference, webinar or online meeting etc. organized by us (hereinafter referred to as "video conferences"), we process your personal data in connection with your participation.
When participating in a video conference, various categories of data are processed. The scope of the data also depends on what information you provide before or during your participation in the video conference.
When you participate in a video conference hosted by us, you will generally need to provide at least a name during registration. You can also use a pseudonym. Your IP address will also be processed to enable your participation, and login and device/hardware information will be stored. If provided, your email address and profile picture will also be processed. If you dial in by phone, your phone number and, if applicable, your IP address will be processed.
To enable participation in the video conference, data from your device's microphone, any webcam, and, if you are sharing your screen, information from that screen share will be processed. You can disable or mute your camera or microphone at any time. You always decide whether and which parts of your screen are shared.
Audio and video recordings of the video conference can be made. In this case, MP4 files of all video, audio, and presentation recordings will be processed. Attendees will always be notified if a recording is taking place, and their explicit consent will always be obtained where necessary.
You may have the option to use the chat, question, or survey functions during a video conference. In this case, the text you enter will be processed to display it in the video conference and, if necessary, to record it.
Insofar as personal data of our employees is processed, Section 26 of the German Federal Data Protection Act (BDSG) is the legal basis for the data processing, provided that German law is applicable to the processing of employee data.
If German law is not applicable to the processing of employee data, or if the processing of personal data in connection with participation in video conferences is not necessary for the establishment, execution, or termination of the employment relationship, but is nevertheless an essential component of participation in a video conference, then our overriding legitimate interest pursuant to Article 6(1)(f) GDPR is the legal basis for the data processing. In these cases, our legitimate interest lies in the effective conduct of video conferences.
Furthermore, the legal basis for data processing when conducting video conferences is Art. 6 para. 1 lit. b) GDPR, insofar as the meetings are conducted within the framework of contractual relationships or with a view to initiating a contractual relationship (for example, in video conferences with our clients in the context of carrying out a project or when participating in a webinar).
Furthermore, the legal basis for data processing in connection with your participation in a video conference organized by us is our overriding legitimate interest pursuant to Art. 6 para. 1 lit. f) GDPR. In these cases, our legitimate interest lies in the effective conduct of video conferences.
We use one or more service providers as data processors for conducting video conferences on the basis of a data processing agreement in accordance with Art. 28 GDPR.
In this context, personal data may be transferred to third countries that do not provide an adequate level of data protection. In such cases, it is ensured that appropriate safeguards pursuant to Art. 46 GDPR are in place to ensure an adequate level of data protection. Evidence of such appropriate safeguards will be provided by the controller upon request.
10. JOB OFFERS AND APPLICATIONS
10.1 Active Sourcing
We carry out so-called active sourcing measures to identify promising potential employees on the external labor market and actively contact potential applicants and employees. The purpose of data processing is recruitment, e.g. by individually drawing the attention of promising candidates to job vacancies in our company.
We collect the following categories of data for active sourcing: Surname, first name, gender, contact details, education, professional experience, qualifications, salary data, application data, non-professional experience and interests and other information resulting from public profiles on social networks, in particular LinkedIn and Xing, and/or from other publicly accessible sources on the internet.
All personal data processed in the context of active sourcing is collected from generally/publicly accessible sources on the Internet, in particular from social networks such as LinkedIn and Xing.
The legal basis for the collection and processing of publicly accessible data in the context of active sourcing is the Controller's legitimate interest in identifying, approaching and recruiting the best possible employees for the company.
10.2 Application Process
We collect and process personal data from applicants for the purpose of carrying out the application process.
When we conclude an employment contract with an applicant, the data provided will be processed for the purpose of implementing the employment relationship in accordance with the statutory provisions. If no employment contract is concluded, the application documents will be deleted immediately, at the latest 6 months after the end of the application process, provided that there is no overriding legitimate interest, such as the defense against claims or a function of preserving evidence in accordance with equal treatment and anti-discrimination laws.
The legal basis for this storage and processing is the implementation of pre-contractual measures (decision on the establishment of an employment relationship). If the data is required for legal defense or prosecution after the application process has been completed, data processing may be carried out to protect legitimate interests. In this case, our legitimate interests consist of defending against legal claims or asserting legal claims.
10.3 Internet Research as Part of the Application Process
As part of the application process, publicly available information about applicants may be viewed on the Internet. This includes, in particular, professional profiles on social networks (e.g., LinkedIn), publicly accessible profiles on other social media, and information from generally accessible sources (e.g., press articles, blogs, websites, search engine results).
Only publicly available information about the applicant will be processed. There is no systematic or automated decision-making or profiling.
The Internet search serves to supplement the application documents in order to better assess the professional suitability, career history, qualifications, and public professional presence of the applicants. This provides a sound basis for selecting suitable candidates.
The legal basis for this processing is the legitimate interest of the potential future employer in a comprehensive and well-founded assessment of the suitability of applicants for the advertised position.
10.4 Background Checks
As part of the application process, it may be necessary to carry out additional checks ("background checks"), particularly for security-related positions, management roles, activities involving financial responsibility, or access to confidential company information. These checks serve to verify the information provided in the application process and to assess the professional integrity, reliability, and suitability of the applicant for the respective position.
Depending on the type of position advertised and the requirements, information on education, professional career, qualifications, references, and, if applicable, creditworthiness information or information from public registers may be collected and processed in the course of such background checks. If the advertised position requires it or if legal requirements demand it (e.g., for activities in sensitive compliance, finance, or IT areas), the submission of an official certificate of good conduct may also be required in individual cases. In this case, processing is carried out exclusively on the basis of the documents voluntarily submitted by the applicant; we do not carry out any automated queries.
To carry out background checks, external service providers may be commissioned as processors to assist us in verifying qualifications or obtaining references, if necessary. In addition, in individual cases, previous employers, references, or educational institutions may be contacted, provided that the applicant has given their express prior consent.
The legal basis for the processing of personal data in the context of background checks is primarily the implementation of pre-contractual measures (decision on the establishment of an employment relationship), insofar as the check is necessary for the decision on the establishment of an employment relationship. The legal basis for these checks is their necessity for the employment relationship in conjunction with any applicable legal requirements. To the extent that checks go beyond this (e.g. reference checks with former employers), they are carried out exclusively on the basis of your express consent.
Before a background check is carried out, the applicant is always informed transparently about the nature, scope, and purpose of the planned check. If consent is required for certain checks, this is obtained separately in advance. Personal data will not be processed or passed on beyond the stated purpose.
10.5 Use of Automated (AI) Processes
As part of our application process, we use partially automated processes to preselect applications. The application documents submitted (e.g., resume, qualifications, professional experience) are analyzed using an AI-supported system according to specific, predefined criteria. The aim is to identify applications that are particularly well suited to the requirements of the advertised position.
The automated evaluation is used exclusively to support our HR managers. The final decision on the continuation of the application process is not made automatically, but always by a natural person.
The system used evaluates application documents based on predefined criteria (e.g., education, professional experience, language skills, qualifications). On this basis, a preliminary classification or weighting is carried out, which serves as a guide for the subsequent manual review.
This evaluation has no legal effect and does not have any comparable significant impairment.
Every applicant has the right to request a human review of the automated pre-selection, to present their point of view, and to challenge the decision.
10.6 Compliance/Sanctions Screening
Applicants who are shortlisted as part of the application process may be subject to an initial compliance check. The compliance check involves a comparison of the applicant's name and address with relevant sanctions lists, in particular on the basis of the EU anti-terrorism regulations.
To carry out the compliance/sanctions list screening, we use an external service provider as a data processor on the basis of a data processing agreement.
The legal basis for this storage and processing is, if there is a legal obligation to carry out a compliance/sanctions list screening, the fulfillment of the legal obligation. In individual cases, depending on a balancing of interests, compliance/sanctions list screening can also take place if there is no mandatory legal obligation. In this case, the legal basis is our legitimate interest in avoiding potential sanctions by foreign authorities.
10.7 Talent Pool
If an applicant submits an unsolicited/speculative application without reference to a specific job posting, expressing general interest in potential future employment opportunities, or if an applicant has consented to the longer retention of their data in our talent pool in the context of an application process for a specific position, we will store the data submitted as part of the application in our talent pool for a period of 2 years after receipt of the unsolicited/speculative application or after the conclusion of the application process. This storage serves the purpose of identifying potentially suitable future positions for the applicant and contacting them if applicable. After this period, the data will be deleted.
Such consent to the storage of application data in our talent pool can be withdrawn at any time for the future. To do so, please send us an email to the contact details provided above.
The legal basis for the storage of application documents in our Talent Pool is, where applicable, the explicit consent of the applicant, which can be revoked at any time.
10.8 Statistical evaluations
We process anonymized or aggregated application data in order to analyze and improve our recruiting process (e.g., to evaluate application numbers, sources, or success rates). These evaluations are carried out using anonymized/aggregated data without personal references.
11. MERGERS AND ACQUISITIONS (M&A)
If we are involved in a restructuring, acquisition, asset sale, merger, financing, transfer of services to another provider, due diligence, insolvency or receivership, your personal data may be transferred to third parties to the extent legally permitted in connection with and as part of the relevant legal process, subject to the basic principles of data protection law.
12. AGE RESTRICTION
This website is not intended or designed for use by children under the age of 16. We do not knowingly collect personal data from or about individuals under the age of 16.
13. RECIPIENTS OF DATA
Within the Controller's organization, access to data is granted to those internal departments or organizational units that need it to perform their tasks, if necessary to fulfill contracts, for data processing based on the consent of the data subject(s) or to protect overriding legitimate interests.
Data will only be passed on to third parties in accordance with legal requirements. Personal data will only be passed on to third parties if this is necessary for contractual purposes or to safeguard our overriding legitimate interest in the effective performance of our business operations.
If we use service providers or third-party providers to provide the website or other services, we take appropriate legal precautions and technical and organizational measures to ensure that personal data is adequately protected.
Data Transfers to Third Countries:
To the extent that we transfer personal data to third countries outside the European Economic Area (EEA), in particular to the United States, this is primarily based on adequacy decisions of the European Commission. With regard to the United States, we rely on the EU-US Data Privacy Framework (DPF), provided that the respective provider is certified under the DPF.
If no adequacy decision exists for the respective country or provider, the transfer is carried out on the basis of appropriate safeguards, in particular through the conclusion of EU Standard Contractual Clauses (SCC), supplemented by additional technical and organizational measures.
14. DATA SUBJECT RIGHTS
14.1 Right of Access
Data subjects have, within the scope of the legal requirements, the right to request information about the personal data processed about them.
14.2 Right to Rectification
Data subjects have, within the scope of the legal requirements, the right to request the rectification of inaccurate personal data concerning them. They also have the right to request the completion of incomplete personal data.
14.3 Right to Erasure
Data subjects have, within the scope of the legal requirements, the right to request the erasure of personal data concerning them.
14.4 Right to Restriction of Processing
Data subjects have, within the scope of the legal requirements, the right to request that the processing of personal data concerning them be restricted.
14.5 Right to Object to Processing
Data subjects have, within the scope of the legal requirements, the right to object, on grounds relating to their particular situation, at any time to processing of personal data concerning them which is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller or which is based on a legitimate interest. In this case, the data will no longer be processed unless the Controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defense of legal claims. In addition, data subjects have the right to object at any time to the processing of personal data concerning them for the purpose of direct marketing; this also applies to any profiling insofar as it is associated with such direct marketing.
14.6 Right to Withdraw Consent
Data subjects have, within the scope of the legal requirements, the right to withdraw their consent if they have given their consent for processing.
14.7 Right to Data Portability
Data subjects have, within the scope of the legal requirements, the right to receive the personal data concerning them, which they have provided to a Controller, in a structured, commonly used and machine-readable format ("data portability") and the right to transmit those data to another Controller.
14.8 Exercising the Rights
The rights of data subjects can be exercised by notifying the Controller or, where applicable, the Data Protection Officer using the contact details provided above.
If data subjects believe that the processing of personal data concerning them breaches data protection law, they have the right to lodge a complaint with a data protection supervisory authority.
15. MANDATORY INFORMATION AND PROFILING
The provision of personal data is neither legally nor contractually required. There is no obligation to provide personal data, however, the provision of personal information is necessary for the conclusion of a contract insofar as certain information is mandatory in order to conclude (and execute) a contract.
Automated decision-making, including profiling, is not carried out.
16. RETENTION AND DELETION
We adhere to the principles of data avoidance and data economy and only store your personal data for as long as is necessary to achieve the respective purpose of the data processing purposes or as stipulated by the storage periods provided by law.
If the purpose of storage no longer applies or if a storage period provided for by law expires, the personal data will be routinely anonymized or deleted in accordance with the statutory provisions.
17. INFORMATION SECURITY
We take appropriate technical and organizational measures in accordance with the state of the art to ensure a level of protection for the personal data we process that is appropriate to the risk of the respective processing and to protect the data we process against accidental or intentional manipulation, loss, destruction or against access by unauthorized persons.
Our website uses SSL encryption for security reasons and to protect the transmission of confidential content, such as orders, inquiries or payment data that you send to us.
Our employees receive regular training on data protection and information security and are committed to confidentiality and data protection.
A restrictive rights and roles concept on a "need to know" basis ensures that employees only have access to the personal data they absolutely need to perform their duties.
18. AMENDMENT OF THIS PRIVACY POLICY
We reserve the right to amend this Privacy Policy from time to time so that it always complies with current legal requirements and/or in order to implement changes to our services in the Privacy Policy, e.g. when introducing new services. When visiting the website or using our services, the current privacy policy always applies.


