Privacy Notice for Participants in the “µ-Symposium 2026” Event on November 13, 2026, in Dresden
The entity responsible for processing your data is:
GWT-TUD GmbH
Freiberger Str. 33
01067 Dresden
The Data Protection Authority is:
Dresdner Institut für Datenschutz (DiD)
Hospitalstraße 4
01097 Dresden
Email: datenschutz@g-wt.de
Further information about the DiD can be found at www.dids.de.
-
Scope of Processing and Type of Data
This privacy notice informs you about the processing of your personal data that we carry out in connection with your participation in the event. The processing of your personal data is conducted in compliance with applicable data protection regulations. According to Article 4(1) of the General Data Protection Regulation (GDPR), personal data refers to any information relating to an identified or identifiable natural person.
-
Purpose of Data Processing
Your personal data will be processed for the following purposes:
2.1 Event Registration
As part of the registration process for the event, we collect the following mandatory information:
- Last name, first name, email address, company/institution
The mandatory information is processed to identify you as a participant in the event, to verify the plausibility of the data entered, to reserve your spot if necessary, and to establish and fulfill the contract for your participation.
In addition, you may voluntarily provide further information. Providing this voluntary data enables us to plan and conduct the event in a way that aligns with your interests.
Data processing is based on your registration and is necessary, in accordance with Article 6(1), first sentence, letter b) of the GDPR, for the stated purposes of fulfilling the participation contract and carrying out pre-contractual measures.
We use your email address to inform you in the future about similar events we organize, provided that you have expressly consented to such use or we have separately informed you of this when collecting your email address and have pointed out your right to object to this use at any time. In these cases, we use your email address together with your first and last name so that we can address you appropriately. Unless this use is based on your consent, the processing is carried out pursuant to Article 6(1), first sentence, (f) of the GDPR. Our legitimate interest lies in informing our participants about other events we organize.
If the data is no longer necessary for the fulfillment of the aforementioned purposes, it will be deleted on a regular basis, unless its continued processing for a limited period is required (due to statutory retention periods). For paid events, the personal data we collect in connection with the event is generally stored until the expiration of the standard statute of limitations of 3 years following the end of the year in which the event took place, after which it is deleted. For free events, we delete the personal data we have collected no later than six months after the event has taken place. If data processing is based on consent, we will delete the relevant personal data if you withdraw your consent and no other legal basis applies. If data processing is based on our legitimate interest, we will delete the relevant personal data if you have objected to the data processing.
2.2 Photographs
Photographs will be taken to document the event visually. It cannot be ruled out that you may be directly or indirectly identifiable in the photographs, meaning that they constitute personal data. The photographs will be used for news items directly related to the event and for internal and external reporting on our website. This processing is necessary, in particular, to document and promote our event. Data processing is based on Article 6(1)(f) of the GDPR. The purposes mentioned constitute legitimate interests within the meaning of that provision.
-
Disclosure of Data to Third Parties
Your data will only be disclosed to third parties if this is permitted by law and necessary for the fulfillment of the contractual relationship with you. The disclosed data may be used by the third party exclusively for the stated purposes.
-
Rights of Data Subjects
Data subjects may at any time request access to the personal data concerning them, as well as, where applicable, request the correction, deletion, or restriction of processing, or object to processing. They also have the right to data portability. Furthermore, if data processing is based on consent, such consent may be withdrawn at any time with future effect. To exercise your rights, please contact our Data Protection Officer using the contact information provided above.
-
Right to File a Complaint with the Supervisory Authority
Pursuant to Article 77 of the GDPR, every data subject has the right to file a complaint with a data protection supervisory authority if they suspect that the processing of their personal data is unlawful.
-
Information on Data Processing
This website uses the conference management software Converia, which is provided by Converia GmbH (Kaufstr. 2-4, 99423 Weimar).
Converia GmbH hosts the software and provides additional services to GWT-TUD GmbH, such as software maintenance and support. Consequently, in the course of performing these tasks, Converia GmbH may come into contact with personal data stored in the software and is therefore to be regarded as a data processor.
A data processing agreement in accordance with Article 28 of the GDPR has been concluded with Converia GmbH.
-
Hosting of the Website and Creation of Log Files by Converia GmbH
7.1. Description and Scope of Data Processing
Each time the website is accessed, the system automatically collects data and information from the computer system of the accessing device.
The following data is collected in this process:
- Information about the browser type and version used
- The user’s operating system
- The user’s Internet service provider
- The user’s IP address
- Date and time of access
7.2. Legal Basis for Data Processing
The legal basis for the temporary storage of data and log files is Article 6(1)(f) of the GDPR.
7.3. Purpose of Data Processing
The system’s temporary storage of the IP address is necessary to enable the website to be delivered to the user’s computer. For this purpose, the user’s IP address must be stored for the duration of the session.
The data is stored in log files to ensure the website functions properly. In addition, the data is used to optimize the website and to ensure the security of the IT systems. The data is not analyzed for marketing purposes in this context.
These purposes also constitute the legitimate interest in data processing pursuant to Article 6(1)(f) of the GDPR.
7.4. Duration of Storage
The data is deleted as soon as it is no longer necessary to achieve the purpose for which it was collected. In the case of data collected to provide the website, this occurs when the respective session ends.
In the case of data stored in log files, this occurs after ten days at the latest. Storage beyond this period is possible. In this case, users’ IP addresses are deleted or anonymized so that the accessing client can no longer be identified.
7.5. Right to Object and Right to Erasure
The collection of data for the purpose of providing the website and the storage of data in log files is absolutely necessary for the operation of the website. Consequently, the user has no right to object.
-
Use of Cookies
8.1. Description and Scope of Data Processing
This website uses cookies. Cookies are text files that are stored in the web browser or by the web browser on the user’s computer system. When a user visits a website, a cookie may be stored on the user’s operating system. This cookie contains a unique string of characters that enables the browser to be uniquely identified when the website is visited again.
Cookies are divided into the following categories:
Necessary Cookies (Type 1)
These cookies are strictly necessary for websites and their functions to work properly. Without these cookies, services such as user login cannot be provided.
Functional Cookies (Type 2)
These cookies make it possible to improve the convenience and performance of websites and to provide various features. For example, language settings can be stored in functional cookies.
Performance Cookies (Type 3)
These cookies collect information about how you use websites. Performance cookies help, for example, to identify particularly popular areas of the website. This allows the website content to be tailored more specifically to your needs, thereby improving the user experience for you. The information collected by these cookies is not personally identifiable.
Third-Party Cookies (Type 4)
These cookies are set by third parties, such as social networks. They are primarily used to integrate social media content, such as social plugins, into the website.
8.2. Legal Basis for Data Processing
The legal basis for the processing of personal data using cookies is Article 6(1)(f) of the GDPR.
.
8.3. Purpose of Data Processing
The following cookies are used:
Cookie Name Purpose Type
PHPSESSID Identification of a user session 1
Converia_SID Identification of a front-end user 1
8.4. Duration of Storage, Right to Object, and Option to Delete
Cookies are stored on the user’s computer and transmitted from there to the website. As a user, you therefore have full control over the use of cookies. By changing the settings in your web browser, you can disable or restrict the transmission of cookies. Cookies that have already been stored can be deleted at any time. This can also be done automatically. If cookies are disabled for the website, it may no longer be possible to use all of the website’s features to their full extent.
-
Registration & Use of the Conference Management Software’s Features
9.1. Description and Scope of Data Processing
The conference management software offers users the option to register by providing personal data. The data is entered into a form, transmitted to Converia GmbH, and stored.
Certain fields may be marked as mandatory during registration. These must be filled out completely and correctly. If this is not the case, the registration will be rejected.
The system includes a feature requiring active confirmation of a data protection agreement before personal data is stored in the software.
A registration process is generally required for the following activities, among others:
- Registration as a participant in an event
- Submission of an academic paper via the system
- Review of academic papers
- Activities as a speaker or session chair
- Use of the “Favorites” feature in the conference planner
The following data is collected and stored as part of the registration process and the use of the software’s features:
- Login credentials (username, password)
- Adress information
- Email address
- Shopping cart data
- Billing information
- Information on submitted papers
- Temporal and spatial scheduling data (conference schedule)
- Information on memberships
- Information on proof of status (e.g., proof of student status)
- Optional data: Data from pre-registration
Payment Processing
Various payment options are offered to process payments when a participant registers for an event (e.g., invoice/bank transfer, credit card, PayPal). Sensitive payment information is not stored in the conference management system itself. Instead, specially certified payment service providers are used to handle data processing and storage. Users are redirected directly to the websites of the respective providers for this purpose. Further information on data protection can be found on the websites of the respective service providers.
The following data is collected as part of the payment processing:
- Selected payment method
- Invoice amount
- Amounts paid
- Billing information
Additional information about the payment service provider:
The payment service provider secupay AG, Goethestraße 6, 01896 Pulsnitz, Germany, is used to process payments. secupay AG is a payment institution licensed by the German Federal Financial Supervisory Authority (BaFin).
Secupay acts under its own responsibility with regard to data protection (Section 1(1), Sentence 2, No. 6 of the German Payment Services Act (ZAG) in conjunction with Article 6(1)(b), (c), and (f) of the GDPR) and processes your personal data exclusively for the purpose of executing and processing the respective payment transaction.
In particular, the following data is processed as part of the payment process:
- Payment information (e.g., IBAN, credit card number, security code, payment amount)
- Transaction data (e.g., date and time, reference number, payment description)
- Contact information, if applicable (e.g., name, address, email address)
Data processing is carried out for the purpose of secure and reliable payment processing and to fulfill legal obligations regarding fraud prevention, anti-money laundering, and record-keeping requirements.
Legal basis for processing:
- Art. 6(1)(b) GDPR (performance of a contract),
- Art. 6(1)(c) GDPR (legal obligation),
- Art. 6(1)(f) GDPR (legitimate interest in secure payment processing).
Data is transferred exclusively to recipients necessary for payment processing, in particular banks, credit institutions, and, where applicable, contracted IT service providers.
Data is stored only for as long as necessary for the purpose of processing. Secupay deletes or anonymizes your data in accordance with legal requirements once the purpose of processing no longer applies.
9.2. Legal Basis for Data Processing
The legal basis for processing the data is Article 6(1)(a) of the GDPR, provided the user has given consent.
If registration serves to fulfill a contract to which the user is a party or to take steps prior to entering into a contract, the additional legal basis for data processing is Article 6(1)(b) of the GDPR.
9.3. Purpose of Data Processing
User registration is necessary to fulfill a contract with the user or to take steps prior to entering into a contract.
9.4. Duration of Storage
The data will be deleted as soon as it is no longer necessary to achieve the purpose for which it was collected.
For data collected during the registration process to fulfill a contract or to take pre-contractual measures, this is the case when the data is no longer necessary for the performance of the contract. Even after the contract has been concluded, it may still be necessary to store the contractual partner’s personal data in order to comply with contractual or legal obligations.
Since login credentials, including address information, may be used for future events—such as follow-up events—this data is generally removed from the system within 2 years of the last login.
9.5. Right to Object and Right to Erasure
As a user, you may cancel your registration at any time. You may have the data stored about you modified at any time. To do so, please contact the data controller by email or phone (see the information above).
If the data is necessary for the performance of a contract or for the implementation of pre-contractual measures, early deletion of the data is only possible to the extent that no contractual or legal obligations preclude such deletion.