Name and Address of the Responsible Party
The responsible party within the meaning of the General Data Protection Regulation and other national data protection laws of the Member States as well as other data protection provisions is:
Hamburg University of Technology
Am Schwarzenberg-Campus 1
21075 Hamburg
Germany
Website: www.tuhh.de
Name and Address of the Data Protection Officer
The data protection officer of the responsible party is:
External Data Protection Officer of TU Hamburg
datenschutz nord GmbH
Konsul-Smidt-Straße 88
28217 Bremen
Web: www.dsn-group.de
E-Mail: office@datenschutz-nord.de
General Information on Data Processing
1. Scope of the Processing of Personal Data
We process the personal data of our users basically only insofar as this is necessary to provide a functional website as well as our content and services. The processing of personal data of our users generally only takes place after the user’s consent. An exception applies in cases where prior consent cannot be obtained for factual reasons and the processing of the data is permitted by statutory provisions.
2. Legal Basis for the Processing of Personal Data
Insofar as we obtain consent from the data subject for processing operations of personal data, Art. 6 para. 1 lit. a of the EU General Data Protection Regulation (GDPR) serves as the legal basis.
For the processing of personal data which is necessary for the performance of a contract to which the data subject is party, Art. 6 para. 1 lit. b GDPR is the legal basis. This also applies to processing operations necessary for the implementation of pre-contractual measures.
If the processing of personal data is necessary to comply with a legal obligation to which our company is subject, Art. 6 para. 1 lit. c GDPR is the legal basis.
If processing is necessary to protect the vital interests of the data subject or another natural person, Art. 6 para. 1 lit. d GDPR is the legal basis.
Where processing is necessary for the purposes of the legitimate interests pursued by our company or a third party, and the interests, fundamental rights and freedoms of the data subject do not override those interests, Art. 6 para. 1 lit. f GDPR is the legal basis for the processing.
3. Data Deletion and Storage Period
The personal data of the data subject will be deleted or blocked as soon as the purpose of storage no longer applies. Storage may also occur if prescribed by the European or national legislator in EU regulations, laws or other provisions to which the responsible party is subject. Blocking or deletion also takes place when a storage period prescribed by these norms expires, unless further storage is necessary for the conclusion or performance of a contract.
Information on Order Processing
This website uses the conference management software Converia, which is provided by Converia GmbH. Converia GmbH hosts the software and provides further services for the organizer, such as software maintenance and support. Therefore, Converia GmbH may come into contact with personal data stored in the software during the course of these activities and is considered a processor.
A contract on order processing according to Art. 28 GDPR has been concluded with Converia GmbH. (Company details see section “List of Processors” in this document).
Provision of the Website and Creation of Log Files
1. Description and Scope of Data Processing
Each time our website is accessed, our system automatically collects data and information from the computer system of the requesting computer. The following data are collected:
• Information about the browser type and version used
• The user’s operating system
• The user’s internet service provider
• The user’s IP address
• Date and time of access
2. Legal Basis for Data Processing
The legal basis for the temporary storage of the data and log files is Art. 6 para. 1 lit. f GDPR.
3. Purpose of Data Processing
The temporary storage of the IP address by the system is necessary to deliver the website to the user’s computer. For this purpose, the IP address must be stored for the duration of the session.
Storing the data in log files is done to ensure the functionality of the website. Furthermore, the data are used to optimize the website and ensure the security of our information technology systems. Analysis of data for marketing purposes does not take place in this context.
Our legitimate interest in data processing according to Art. 6 para. 1 lit. f GDPR lies in these purposes.
4. Duration of Storage
Data will be deleted as soon as they are no longer required for the purpose of collection. In the case of data collected for website provision, this is the case when the session ends.
Data stored in log files are deleted after at most ten days. Further storage beyond this period is possible; in this case, IP addresses will be deleted or anonymized so that no assignment to calling clients is possible anymore.
5. Objection and Removal Options
Data collection for website provision and storage in log files is absolutely necessary for the operation of the website. Therefore, users have no option to object.
Use of Cookies
1. Description and Scope of Data Processing
Our website uses cookies. Cookies are text files stored by the internet browser on the user’s computer system. When a user visits a website, a cookie may be stored on the user’s operating system. The cookie contains a characteristic string which enables unique identification of the browser when visiting the website again.
We categorize cookies as follows:
Necessary Cookies (Type 1)
These cookies are essential so that websites and their functions can work properly. Without these cookies, services such as participant registration cannot be provided.
Functional Cookies (Type 2)
These cookies enable improving comfort and performance of websites and provide various functions. For example, language settings can be stored in functional cookies.
Performance Cookies (Type 3)
These collect information on how you use websites. Performance cookies help identify particularly popular areas of our internet offering. Thus, we can tailor website content better to your needs and improve our offering. The information collected with these cookies is non-personal. More information on data collection and analysis can be found in the section “Evaluation of Usage Data”.
Third-Party Cookies (Type 4)
These cookies are set by third parties, e.g. social networks. They are mainly used to integrate social media content such as social plugins on our site. Information on how we use social plugins can be found in the section “Social Plugins” in the privacy statement.
2. Legal Basis for Data Processing
The legal basis for processing personal data using cookies is Art. 6 para. 1 lit. f GDPR.
3. Purpose of Data Processing
We use the following cookies on our pages:
Name of Cookie | Purpose | Type
PHPSESSID | Identification of a user session | 1
Converia_SID | Identification of a frontend user | 1
4. Storage Duration, Objection, and Removal Options
Cookies are stored on the user’s computer and transmitted by the user’s browser to our site. Therefore, users have full control over cookie use. By changing your browser settings, you can deactivate or restrict cookie transmission. Already stored cookies can be deleted at any time, also automatically. If cookies are disabled, some website functions may no longer be fully available.
Registration & Use of Conference Management Software Features
1. Description and Scope of Data Processing
The conference management software offers users the option to register by providing personal data. The data are entered into an input mask, transmitted, and stored by us.
Mandatory registration data may be requested. These must be complete and accurate; otherwise, registration will be rejected.
The system requires active acceptance of a data protection agreement prior to storing personal data in the software.
Registration is typically necessary for the following activities:
• Registration as a participant at an event
• Submission of a scientific contribution in the system
• Review of scientific contributions
• Actions as a speaker or session chairperson
• Use of the favorites function in the conference planner
The following data are collected and stored during registration and use of software functions:
• Access data (username, password)
• Address data
• Email address
• Shopping cart data
• Billing information
• Information about submitted contributions
• Temporal and spatial planning data (conference schedule)
• Information on memberships
• Information on certificates (e.g. student ID)
• Optional data:
o Data from pre-registration
o Other custom fields (EAV fields)
Payment Processing
For payment processing during participant registration at an event, various payment options are offered (e.g. invoice/bank transfer, credit card, PayPal). Sensitive payment information is not stored in the conference management system itself. Certified payment service providers handle data processing and storage. The user is redirected directly to the providers’ sites. Further information on data protection can be found on each provider’s website.
The following data are collected during payment processing:
• Selected payment method
• Invoice amount
• Paid amounts
• Billing data
Additional information on payment service providers is provided at the end of this privacy statement under “Data Protection Information”.
2. Legal Basis for Data Processing
The legal basis for data processing is Art. 6 para. 1 lit. a GDPR if user consent exists.
If registration serves to fulfill a contract to which the user is a party or to carry out pre-contractual measures, Art. 6 para. 1 lit. b GDPR also applies as a legal basis.
3. Purpose of Data Processing
User registration is necessary to fulfill a contract with the user or to carry out pre-contractual measures.
4. Storage Duration
Data is deleted as soon as it is no longer necessary for the purposes for which it was collected.
This applies to data collected during registration for contract fulfillment or pre-contractual measures once the data is no longer needed to perform the contract. Even after contract completion, data retention may be necessary to meet contractual or legal obligations.
Since access data including address data may be reused for further events (e.g., follow-up events), these data are generally removed from the system within 2 years after the last login.
5. Objection and Removal Options
Users may cancel their registration at any time and request modification of their stored data.
Please contact the responsible party by email or phone (see above for contact details).
If data are necessary to fulfill a contract or pre-contractual measures, early deletion is only possible insofar as contractual or legal obligations to retain data do not prevent deletion.
Rights of the Data Subject
If personal data concerning you are processed, you are the data subject within the meaning of the GDPR and have the following rights against the responsible party:
1. Right of Access
You can request confirmation from the responsible party as to whether personal data concerning you are being processed.
If such processing exists, you can request information about:
(1) The purposes of the processing.
(2) The categories of personal data processed.
(3) The recipients or categories of recipients to whom your personal data have been or will be disclosed.
(4) The planned retention period for your personal data or, if not possible, criteria used for determining the retention period.
(5) The existence of the right to rectification or erasure of personal data concerning you, the right to restriction of processing, or the right to object to such processing.
(6) The existence of a right to lodge a complaint with a supervisory authority.
(7) All available information on the origin of the data if the personal data were not collected from you.
(8) The existence of automated decision-making including profiling in accordance with Art. 22 paras. 1 and 4 GDPR, and – at least in these cases – meaningful information about the logic involved as well as the significance and envisioned consequences for you.
You also have the right to request whether your personal data are transferred to a third country or an international organization. In this respect, you can request information about appropriate safeguards pursuant to Art. 46 GDPR in connection with the data transfer.
2. Right to Rectification
You have the right to request correction and/or completion of inaccurate or incomplete personal data concerning you without undue delay.
3. Right to Restriction of Processing
You may request restriction of processing under the following conditions:
(1) When you dispute the accuracy of your data for a period enabling the responsible party to verify its accuracy;
(2) When processing is unlawful and you oppose erasure and instead request restriction;
(3) When the responsible party no longer needs the data but you require them to assert, exercise or defend legal claims;
(4) When you have objected to processing pursuant to Art. 21 para. 1 GDPR and it is not yet established whether the legitimate grounds of the responsible party override yours.
Restricted data may only be processed with your consent or for enforcement of legal claims or to protect rights of others or important public interests.
You will be informed before the restriction is lifted.
4. Right to Erasure
a) Obligation to Delete
You may request deletion of your personal data without undue delay if one of the following conditions applies:
(1) The data are no longer necessary for the purposes collected or otherwise processed.
(2) You withdraw consent on which the processing is based and there is no other legal basis.
(3) You object to processing pursuant to Art. 21 para. 1 GDPR and no overriding legitimate grounds exist, or you object pursuant to Art. 21 para. 2 GDPR.
(4) The data were unlawfully processed.
(5) Deletion is legally required under EU or member state law applicable to the controller.
(6) The data were collected based on consent from children under Art. 8 para. 1 GDPR.
b) Information to Third Parties
If the responsible party made your data public and is obligated to delete them, reasonable measures including technical means will be taken to inform data processors of your request to delete any links or copies of personal data.
c) Exceptions
The right to erasure does not apply when processing is necessary:
(1) For exercising the right of freedom of expression and information;
(2) For compliance with a legal obligation or for the performance of a public interest task or public authority;
(3) For public health reasons;
(4) For archiving, research or statistical purposes insofar as deletion would thwart the purpose;
(5) For the assertion, exercise or defense of legal claims.
5. Right to Notification
If you have requested rectification, erasure or restriction, the responsible must inform recipients of your data of the correction, erasure or restriction unless impossible or involves disproportionate effort. You have the right to be informed about these recipients.
6. Right to Data Portability
You have the right to receive personal data you provided in a structured, commonly used and machine-readable format and to transfer those data to another controller without hindrance when:
(1) Processing is based on consent or contract, and
(2) Processing is carried out by automated means.
You may request direct transmission between controllers if technically feasible. However, this must not impair rights and freedoms of others.
The right does not apply to processing necessary for public interest or official authority tasks.
7. Right to Object
You have the right to object at any time for reasons related to your particular situation to processing based on Art. 6 para. 1 lit. e or f GDPR, including profiling based on these provisions. The controller will cease processing unless compelling legitimate grounds prevail or processing is for legal claims.
If personal data are processed for direct marketing, you may object any time to such processing including profiling related to direct marketing. Upon objection, data will no longer be processed for these purposes.
You may exercise your objection right through automated means when using information society services.
8. Right to Withdraw Consent
You have the right to withdraw your consent to data processing anytime. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal.
9. Right to Complain to a Supervisory Authority
You may complain to a supervisory authority, especially in your member state of residence, employment, or alleged infringement, if you believe data processing violates the GDPR. The supervisory authority will inform you about complaint status and outcomes including legal remedies.
List of Processors
Converia GmbH
Kaufstr. 2-4
99423 Weimar
Type of Processing:
• Hosting and operation of the conference management software Converia
• Maintenance and support
Data Protection Information
For payment processing, we use the payment service provider secupay AG, Goethestraße 6, 01896 Pulsnitz, Germany. secupay AG is a payment institution authorized by the German Federal Financial Supervisory Authority (BaFin).
Secupay processes your personal data independently within the scope of its data protection responsibilities (§ 1 para. 1 sentence 2 no. 6 Payment Services Supervision Act in conjunction with Art. 6 para. 1 lit. b, c and f GDPR) exclusively to execute the payment transaction.
During payment processing, the following data are processed in particular:
• Payment information (e.g., IBAN, credit card number, verification digits, payment amount)
• Transaction data (e.g., timing, reference number, purpose)
• Possibly contact details (e.g., name, address, email address)
The data processing serves secure and reliable payment processing and compliance with legal obligations such as fraud prevention, anti-money laundering, and record keeping.
Legal basis:
• Art. 6 para. 1 lit. b GDPR (contract performance)
• Art. 6 para. 1 lit. c GDPR (legal obligation)
• Art. 6 para. 1 lit. f GDPR (legitimate interest in secure payment processing)
Data transmission is limited to recipients necessary for payment processing, such as banks, financial institutions, and, if applicable, commissioned IT service providers.
Data storage lasts only as long as necessary for the processing purpose. After its end, secupay deletes or anonymizes your data in accordance with statutory requirements.