Privacy Policy for the German Congress of Geography 2027

1. Scope

This Privacy Policy provides information about the processing of personal data in connection with the German Congress of Geography 2027 – dkg’27, which will take place in Bonn from 13 to 17 September 2027.

It applies in particular to:

– the use of the Converia conference portal;
– the creation and use of a user account;
– the submission, review and administration of sessions, presentations, posters and other academic contributions;
– registration for the congress and additional events;
– payment and invoicing;
– communication before, during and after the congress;
– the organisation and delivery of the congress, including admission control and the issuance of certificates of attendance;
– the creation and use of photographs, video recordings and audio recordings.

Additional privacy notices may apply to the general website at www.geographie.de and www.geographie.de/dkg.

2. Controller

The controller within the meaning of the General Data Protection Regulation is:

German Society for Geography
Deutsche Gesellschaft für Geographie e.V.
represented by its President, Prof. Dr Ute Wardenga

Postal address:
P.O. Box 31 01 51
86062 Augsburg
Germany

Address for service:
Bei den Schmidäckern 7
86420 Diedorf
Germany

Email: dgfg@geographie.de
Website: www.dgfg.org

Register of Associations: Bonn Local Court, registration number VR 3337

For questions concerning the processing of your personal data or the exercise of your data protection rights, you may contact us using the contact details provided above.

3. General Legal Bases

We process personal data only where there is a legal basis for doing so.

Depending on the processing activity, the following legal bases may apply in particular:

– Article 6(1)(a) GDPR, where you have consented to the processing;
– Article 6(1)(b) GDPR, where processing is necessary for the performance of a contract or in order to take steps prior to entering into a contract;
– Article 6(1)(c) GDPR, where processing is necessary for compliance with a legal obligation;
– Article 6(1)(f) GDPR, where processing is necessary for the purposes of the legitimate interests pursued by the DGfG or a third party and such interests are not overridden by the interests or rights of the data subject;
– Article 9(2)(a) GDPR, where you have given explicit consent to the processing of special categories of personal data.

Where processing is based on legitimate interests, these interests include, in particular, the secure, efficient and organisationally structured delivery of the congress, the development of the academic programme, the documentation of the event and the establishment, exercise or defence of legal claims.

4. Use of the Converia Conference Management Software

We use the Converia software for conference management. The provider is:

Converia GmbH
Kaufstraße 2–4
99423 Weimar
Germany

Converia is used in particular for:

– providing and hosting the conference portal;
– creating and managing user accounts;
– submitting and reviewing academic contributions;
– programme planning;
– registration and booking administration;
– preparing booking confirmations, invoices and tickets;
– managing payments and cancellations;
– sending event-related emails;
– check-in and admission control;
– creating name badges and certificates of attendance;
– maintenance, technical support and user support.

Converia GmbH generally processes personal data as a processor acting on the instructions of the DGfG in accordance with Article 28 GDPR. The DGfG has concluded a data processing agreement with Converia.

According to Converia, event data are stored in a data centre in Germany and are transmitted in encrypted form.

5. Provision of the Conference Portal and Server Logs

5.1 Data Processed

Whenever the conference portal is accessed, the following data may be processed automatically:

– IP address of the accessing device;
– date and time of access;
– page or file accessed;
– volume of data transferred;
– access status;
– browser type and browser version;
– operating system used;
– previously visited page, where this information is transmitted by the browser.

5.2 Purposes and Legal Basis

The data are processed in order to:

– provide the conference portal technically;
– ensure the stability and functionality of the system;
– analyse technical errors;
– identify and prevent unauthorised access and attacks.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in the secure and reliable operation of the conference portal.

5.3 Retention Period

The IP address required to provide the conference portal is generally processed only for the duration of the relevant usage session. Server logs are generally deleted or anonymised no later than 14 days after they are created.

Data may be stored for a longer period where there are specific indications of an attack, misuse or technical malfunction. In such cases, the relevant data will be stored until the matter has been conclusively resolved.

6. Cookies and Similar Technologies

The conference portal uses technically necessary cookies. These cookies are required in particular to:

– maintain a session;
– identify logged-in users;
– provide the login area;
– assign entries within a booking or submission process;
– implement security functions.

In the standard Converia configuration, session cookies such as “Converia_SID” or “PHPSESSID” may be used. These cookies are used for technical session management and are generally stored until the end of the session or until the user logs out.

Technically necessary cookies are used on the basis of Section 25(2)(2) of the German Telecommunications Digital Services Data Protection Act. The associated processing of personal data is based on Article 6(1)(b) or Article 6(1)(f) GDPR.

Analytics, marketing or other non-essential cookies will only be used where you have given prior consent. Where such services are activated, you will receive additional information through the consent management system.

You can delete or block cookies in your browser settings. If technically necessary cookies are blocked, parts of the conference portal may not function or may only function to a limited extent.

7. Creation and Use of a User Account

7.1 Data Processed

The following data may be processed for the creation and administration of a user account:

– form of address, title, first name and surname;
– email address;
– encrypted password or password hash;
– preferred language;
– institution or organisation;
– professional or private contact details;
– date of registration and most recent login;
– changes to account data;
– submissions, bookings and functions assigned to the account.

7.2 Purposes and Legal Basis

The user account enables users in particular to:

– submit and edit academic contributions;
– register for the congress;
– manage personal information;
– access booking confirmations, invoices and tickets;
– communicate about submissions and bookings.

The legal basis is Article 6(1)(b) GDPR.

7.3 Retention Period

The user account will be deleted when it is no longer required for the stated purposes and where there are no statutory retention obligations or legitimate interests requiring continued storage.

As a general rule, user accounts are deleted no later than 24 months after the most recent login. Data that must be retained for longer due to tax, commercial or association law requirements will be stored separately and blocked from use for other purposes.

8. Registration and Participation in the Congress

8.1 Data Processed

The following data may be processed in connection with registration:

– name, title and contact details;
– institution, organisation and professional role;
– billing address and, where applicable, a different invoice recipient;
– ticket category booked;
– membership or discount status;
– additional events booked;
– voucher and discount information;
– booking, invoice and payment data;
– cancellations and changes of participant;
– correspondence with the congress office;
– check-in and attendance information;
– information required for the name badge and certificate of attendance.

8.2 Purposes

The data are processed in order to:

– accept the registration and perform the participation contract;
– verify eligibility to participate;
– administer additional events booked;
– issue invoices and booking confirmations;
– allocate payments;
– process cancellations and changes of participant;
– create name badges, tickets and certificates of attendance;
– organise admission and capacity planning;
– send event-related information.

8.3 Legal Bases

Where the participant is also the DGfG’s contractual partner, processing is based on Article 6(1)(b) GDPR.

Where registration is made by a university, company, public institution or another organisation, the processing of the participant’s data may additionally be based on Article 6(1)(f) GDPR. The legitimate interest lies in carrying out the registration initiated by the organisation and in the proper delivery of the congress.

Data relevant to taxation and invoicing are additionally processed on the basis of Article 6(1)(c) GDPR.

8.4 Requirement to Provide Data

Information marked as mandatory is required for the conclusion of the contract and for participation in the congress. Without this information, a registration cannot be processed or can only be processed to a limited extent.

Voluntary information is identified as such.

9. Payment Processing

Depending on the selected payment method, payment data will be processed by the DGfG, Converia, the financial institutions involved or an appointed payment service provider.

The following information may be processed:

– name and billing address;
– invoice number and booking reference;
– amount payable;
– payment method;
– IBAN or other payment information;
– transaction number;
– time and status of the payment;
– information concerning returned direct debits or chargebacks.

Processing is carried out for the performance of the participation contract on the basis of Article 6(1)(b) GDPR and for compliance with statutory record-keeping and documentation obligations on the basis of Article 6(1)(c) GDPR.

For online payments, the information required for the selected payment method will be transmitted to the payment service provider identified during the payment process. The payment service provider may act as an independent controller in relation to the actual processing of the payment.

Full credit card details or online banking login details are generally processed directly by the relevant payment service provider and cannot be accessed by the DGfG.

The payment service provider actually used will be identified during the relevant payment process. The provider’s supplementary privacy information will apply.

10. Discounts and Membership Rates

Where a discounted participation fee or membership rate is claimed, we process the information and supporting documents required to verify eligibility.

This may include:

– name;
– membership organisation;
– membership number;
– status as a student, doctoral candidate or member of another eligible group;
– period of validity of the supporting document.

Where necessary, the DGfG may verify the stated membership status with the relevant membership organisation. Only the data required for the verification will be transmitted.

The legal basis is Article 6(1)(b) GDPR. Where the registered person is not the contractual partner, processing is additionally based on Article 6(1)(f) GDPR. Our legitimate interest lies in preventing the unauthorised use of discounted rates.

Supporting documents will be deleted once verification has been completed and no further enquiries or legal disputes are expected. Tariff information required for invoices will be stored in accordance with statutory retention periods.

11. Submission and Review of Academic Contributions

11.1 Data Processed

The following data may be processed in connection with the submission and review of sessions, presentations, posters and other contributions:

– names, titles and contact details of the submitting person;
– names and institutional affiliations of presenters, session chairs, moderators and co-authors;
– ORCID or similar academic identifiers, where provided voluntarily;
– contribution titles, abstracts, keywords and subject areas;
– information on the preferred format;
– information concerning conflicts of interest;
– correspondence relating to the contribution;
– evaluations, comments and decisions made by reviewers;
– assignment to sessions, rooms and times;
– acceptance, rejection, withdrawal or modification of a contribution.

11.2 Purposes

The data are processed in particular for:

– carrying out the submission procedure;
– academic review;
– selecting and curating the academic programme;
– communicating with submitting persons and contributors;
– assigning contributions to sessions;
– preparing and publishing the congress programme;
– documenting the selection procedure.

11.3 Legal Bases

For submitting and presenting persons, processing is generally based on Article 6(1)(b) GDPR.

The processing of data relating to co-authors, reviewers and other academic contributors is based on Article 6(1)(f) GDPR. Our legitimate interests lie in academic quality assurance, the transparent attribution of academic contributions and the preparation of an appropriate academic programme.

11.4 Access to Submissions

Access to submission and review data is restricted to persons involved in the review, selection, curation or administrative processing.

These persons may include:

– members of the Academic Advisory Board;
– reviewers;
– session chairs;
– employees and contractors involved in congress management;
– technically authorised Converia employees.

Reviews and internal evaluations will not be made publicly accessible.

11.5 Publication in the Congress Programme

For accepted contributions, the following information may be published in printed and digital congress programmes and on congress websites:

– first name and surname;
– academic title;
– institution or organisation;
– role in the programme;
– title and short description of the contribution;
– names and institutions of co-authors;
– time and location of the programme item.

Publication of this information is part of participation in the academic programme. Without publication of the information required for this purpose, an accepted contribution generally cannot be included in the programme.

Portrait photographs, CVs or detailed biographical information provided voluntarily will only be published where separate consent or an appropriate agreement is in place.

The published congress programme may remain available online on a long-term basis for academic documentation and as part of the historical record of the congress.

12. Data Relating to Co-Authors and Other Persons Named by Third Parties

Submitting persons may provide data relating to co-authors, presenters, session chairs or other contributors through the conference portal.

In these cases, we do not obtain the data directly from the data subject. The data are generally provided by the submitting or registering person.

The following data may be processed:

– name;
– title;
– institutional affiliation;
– email address;
– role in the contribution or programme.

The submitting person is required to provide accurate information and to inform the persons concerned about the transfer of their data and this Privacy Policy.

The DGfG may contact the person concerned directly, in particular in order to:

– confirm the information provided;
– assign a user account;
– provide information about the submission or programme role;
– obtain necessary organisational information.

The legal basis is Article 6(1)(f) GDPR. The legitimate interest lies in the proper administration of the academic submission and programme procedure.

13. Event-Related Communication

We use the contact details provided to send event-related information.

This includes in particular:

– confirmations relating to account creation;
– information about submissions and review decisions;
– booking confirmations and invoices;
– payment and cancellation information;
– changes to the programme or booked events;
– organisational information concerning travel, check-in and the event schedule;
– safety-related or other important event information;
– certificates of attendance;
– necessary information concerning post-event administration.

Processing is based on Article 6(1)(b) GDPR or Article 6(1)(f) GDPR.

Contact details will only be used for promotional newsletters or information about other events where there is a separate legal basis, in particular voluntary consent under Article 6(1)(a) GDPR.

Invitations to voluntary evaluations or surveys may be based on our legitimate interest in quality assurance. Participation in such evaluations or surveys is voluntary.

14. Participant Lists and Networking Functions

A participant list accessible to the general public is not planned.

Where a participant list or networking function is offered within the protected area of the conference portal, inclusion will take place only on the basis of voluntary consent under Article 6(1)(a) GDPR.

Depending on the selected settings, the following information may be visible to other registered persons:

– name;
– institution or organisation;
– professional role;
– contact option.

Inclusion in a participant list is not a condition of participation in the congress.

Consent may be withdrawn at any time with effect for the future. Where technically available, visibility can be disabled through the user account or by contacting dgfg@geographie.de.

15. Name Badges, QR Codes, Check-In and Certificates of Attendance

15.1 Name Badges

The following information may be used for the congress pass or name badge:

– first name and surname;
– institution or organisation;
– function or special role at the congress;
– booked events or access-related information;
– individual QR code or barcode.

15.2 QR Codes and Barcodes

The QR code or barcode is used to assign the badge to the relevant booking. It may be scanned at check-in or when entering booked events.

The following data may be processed:

– booking or participant identifier;
– time of the scan;
– admission status;
– booked event;
– attendance status, where applicable.

Processing is carried out for the performance of the participation contract on the basis of Article 6(1)(b) GDPR and for capacity, safety and misuse controls on the basis of Article 6(1)(f) GDPR.

Check-in data will generally be deleted no later than six months after the end of the congress, unless they are required for longer in connection with certificates of attendance, accounting, safety documentation or the establishment, exercise or defence of legal claims.

15.3 Scans by Exhibitors or External Organisations

Contact details will not be transmitted to exhibitors or other external organisations solely on the basis of congress registration.

Where voluntary contact sharing by means of a badge scan is offered, data will only be transmitted through a deliberate action by the participant. Before transmission, participants will be informed which organisation will receive the data and for what purpose the data will be processed.

The receiving organisation will generally process the transmitted data as an independent controller.

15.4 Certificates of Attendance

The participant’s name, institution, congress dates and attendance status may be processed in order to issue and, where necessary, subsequently provide a certificate of attendance.

These data will generally be stored until the expiry of the standard statutory limitation period.

16. Information Concerning Accessibility, Support Requirements, Catering and Health

Information concerning accessibility, assistance requirements, mobility, allergies or health-related requirements is generally provided voluntarily.

We do not request diagnoses or medical details unless such information is exceptionally necessary for the safe delivery of an event.

Where voluntary information reveals data concerning a person’s health, we will process such data only on the basis of explicit consent under Article 9(2)(a) GDPR.

The information will be used exclusively to:

– arrange necessary support;
– reduce barriers;
– create safe participation conditions;
– take particular catering requirements into account;
– enable participation in field trips or other special events.

Access is restricted to persons or service providers who require the information to perform the relevant task.

The data will generally be deleted no later than four weeks after the end of the congress, unless a longer retention period has been expressly agreed or is required to investigate an incident.

Consent may be withdrawn at any time with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.

In a medical emergency, necessary data may be processed or disclosed to emergency and medical personnel in order to protect vital interests in accordance with Article 9(2)(c) GDPR.

17. Photographs, Video Recordings and Audio Recordings

17.1 Overview and Event Recordings

During the congress, photographs, video recordings and audio recordings may be made by the DGfG or by persons commissioned by the DGfG.

The recordings are used in particular for:

– documenting the congress;
– press and public relations activities;
– reporting on dkg’27;
– presenting the work of the DGfG;
– announcing and documenting future congresses.

Overview and event recordings in which individual persons are not specifically highlighted may be created and published on the basis of Article 6(1)(f) GDPR. Our legitimate interest lies in documenting and publicly presenting the congress and the statutory activities of the DGfG.

Where applicable, the relevant provisions of the German Art Copyright Act will also be taken into account.

17.2 Portraits and Interviews

Individual portraits, interviews, testimonials or similarly prominent depictions will generally only be published with the data subject’s prior separate consent.

The legal basis is Article 6(1)(a) GDPR.

Consent is voluntary and may be withdrawn at any time with effect for the future. The withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

17.3 Publication Channels

Recordings may be published in particular:

– on the websites of the DGfG and the congress;
– in printed and digital congress reports;
– in newsletters;
– in press releases;
– in print and online media;
– on the social media channels of the DGfG and the congress;
– in information and promotional materials for future events.

Where content is published on social networks, processing by the relevant platform outside the European Union or the European Economic Area cannot be excluded.

17.4 Notices and Objections

Participants will be informed in an appropriate manner on site that photographs, video recordings or audio recordings are being made.

Persons who do not wish to be recorded may inform the event team or the person making the recording. An objection to processing based on Article 6(1)(f) GDPR may also be submitted to dgfg@geographie.de.

When considering an objection, the particular situation of the data subject and the legitimate interests of the DGfG will be taken into account.

17.5 Recordings of Individual Programme Items

Complete presentations, discussions or other programme items will only be recorded or broadcast where the contributors concerned have been informed in advance and an appropriate legal basis exists.

18. Recipients of Personal Data

Within the DGfG, access to personal data is restricted to persons who require the data for the organisation and delivery of the congress.

Where necessary, data may also be transmitted to the following recipients or categories of recipients:

– Converia GmbH as a processor;
– subcontractors used and approved by Converia;
– banks and payment service providers;
– tax advisers, accounting services and auditors;
– the Academic Advisory Board, reviewers and session chairs;
– the University of Bonn, event venues and local organising bodies;
– providers of event technology, admission control, security, name badges and printed materials;
– field trip, transport and event service providers;
– photographers, film crews and media service providers;
– membership organisations for the verification of membership rates;
– public authorities and other public bodies where there is a legal obligation to disclose data;
– courts, legal advisers and insurers where necessary for the establishment, exercise or defence of legal claims.

Service providers will only receive the data required for the performance of their respective tasks.

19. Transfers to Third Countries

Conference data processed by Converia are generally stored in Germany.

The transfer of non-public registration, payment or submission data to countries outside the European Union or the European Economic Area is generally not intended.

Information included in the academic programme and published online can be accessed worldwide.

Where recordings or contributions are published on social networks, platform providers may also process personal data in third countries. The privacy policies of the respective platforms will apply in addition.

If other services involving transfers to third countries are used, the persons concerned will be informed separately. Where required, appropriate safeguards in accordance with Articles 44 et seq. GDPR will be implemented.

20. Retention Periods

We store personal data only for as long as they are required for the relevant purpose or where statutory retention obligations apply.

The following general retention periods apply:

– Server logs are generally stored for no longer than 14 days.
– User accounts are generally deleted no later than 24 months after the most recent login.
– General registration and contractual data are generally stored until the expiry of the standard statutory limitation period.
– Invoices and booking documents are generally retained for eight years in accordance with statutory retention requirements.
– Business and tax-related correspondence is generally retained for six years where a statutory retention obligation applies.
– Payment information is stored in accordance with statutory obligations and the requirements of the relevant payment service provider.
– Data relating to rejected or withdrawn submissions and internal reviews are generally stored until twelve months after the congress.
– Data relating to accepted contributions are processed for the delivery of the programme. Published programme data may be archived on a long-term basis.
– Check-in and admission data are generally deleted no later than six months after the congress.
– Data required for certificates of attendance are generally stored until the expiry of the standard statutory limitation period.
– Voluntary information relating to support or health requirements is generally deleted no later than four weeks after the congress.
– Consent records and evidence of consent are stored for the duration of the processing and subsequently in accordance with statutory documentation obligations.
– Photographs, video recordings and audio recordings are stored for as long as they are required for documentation and public relations purposes. The need for continued storage is reviewed regularly.

Data may be stored for a longer period where:

– statutory retention obligations apply;
– consent permits longer processing;
– the data are required for the establishment, exercise or defence of legal claims;
– a security, payment or data protection incident has not yet been conclusively resolved;
– published academic programme data are to be retained as permanent documentation.

Once the relevant retention period has expired, the data will be deleted, anonymised or blocked from further processing.

21. Automated Decision-Making

No decision based solely on automated processing within the meaning of Article 22 GDPR takes place.

In particular, decisions concerning the acceptance or rejection of academic contributions are not made exclusively by automated systems. Technical systems may support the allocation, administration and preparation of reviews. Academic decisions are made by authorised persons or committees.

22. Data Security

We and our service providers implement appropriate technical and organisational measures to protect personal data.

These measures include in particular:

– encrypted data transmission;
– role-based and permission-based access controls;
– secure authentication procedures;
– logging of security-relevant activities;
– backup and restoration procedures;
– contractual obligations imposed on processors;
– restriction of access to persons who require the data;
– organisational procedures for dealing with personal data breaches.

Despite appropriate security measures, complete protection cannot be guaranteed when data are transmitted electronically.

23. Rights of Data Subjects

Where the statutory requirements are met, you have the following rights in particular:

– the right of access under Article 15 GDPR;
– the right to rectification under Article 16 GDPR;
– the right to erasure under Article 17 GDPR;
– the right to restriction of processing under Article 18 GDPR;
– the right to data portability under Article 20 GDPR;
– the right to object under Article 21 GDPR;
– the right to withdraw consent under Article 7(3) GDPR;
– the right to lodge a complaint with a data protection supervisory authority under Article 77 GDPR.

To exercise your rights, you may contact dgfg@geographie.de.

To prevent the unauthorised disclosure of personal data, we may request appropriate proof of your identity.

Specific Information Concerning the Right to Object

Where we process personal data on the basis of Article 6(1)(f) GDPR, you have the right to object to the processing at any time on grounds relating to your particular situation.

We will then no longer process the relevant data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms. Processing may also continue where it is necessary for the establishment, exercise or defence of legal claims.

24. Right to Lodge a Complaint

You may lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes data protection law.

The supervisory authority generally responsible for the DGfG is:

Bavarian State Office for Data Protection Supervision
Bayerisches Landesamt für Datenschutzaufsicht
Promenade 18
91522 Ansbach
Germany

Telephone: +49 981 180093-0

You may also contact the data protection supervisory authority responsible for your habitual residence, your place of work or the place of the alleged infringement.

25. Amendments to this Privacy Policy

We may amend this Privacy Policy if there are changes to the legal requirements, the technical design of the conference portal, the service providers used, the functions offered or the organisational procedures of the congress.

The version published in the conference portal at the relevant time will apply. Significant amendments affecting persons who have already registered will be communicated in an appropriate manner.

Last updated: August 2026