Convention

Privacy

Protection of personal data in connection with this event website and the COMNEXX platform

  • Data controller (event operator): Example Event GmbH, Sample Street 1, 10115 Berlin, Germany. Contact: privacy@example-event.com, phone: +49 30 1234567
  • Data protection officer (if appointed): Sample Data Protection Officer, privacy@example-event.com
  • Software operator / processor: BEEFTEA group GmbH, Schlüterstr. 36, 10629 Berlin, Germany. Contact: info@comnexx-speakermanagement.de

1. Scope

This privacy policy applies to the public event website, the speaker portal, administrator access and related services operated with COMNEXX for Example Event GmbH. It describes how personal data is processed when you visit the website, use a login, manage speaker or program data, give consents or communicate with us by e-mail.

2. Categories of personal data

Depending on your role and use of the platform, we may process in particular:

  • Account and login data: e-mail address, password (stored only in hashed form), login timestamps, selected role, theme preference, session identifiers, IP address and browser information (user agent)
  • Speaker and participant data: title, first and last name, gender, company, function/role, telephone number, profile photo, social media profiles, ticket codes, session assignments, presentation/video/link status, uploaded files, internal notes of organizers, release status for publication
  • Consent data: granted or declined consents, time of consent, consent texts displayed, reminders sent
  • Event and program data linked to persons: session names, descriptions, dates, locations, functions in sessions, schedule exports
  • Communication data: content of system and reminder e-mails, mail footers, delivery-related metadata
  • Administrator data: agreement to usage/confidentiality terms, version and time of consent, activity in the administration area
  • Activity and change logs: who changed which records, when, in which role, including impersonation context where applicable
  • Custom attributes: additional fields configured for people or sessions
  • FAQ, sponsor and frontend content: only personal data if entered there by administrators

3. Purposes and legal bases

We process personal data for the following purposes:

  • Planning, administration and publication of the event program and speakers (Art. 6 (1) (b) GDPR, performance of pre-contractual/contractual measures; Art. 6 (1) (f) GDPR, legitimate interest in organizing the event)
  • Operation of login areas for speakers and administrators (Art. 6 (1) (b) GDPR; Art. 6 (1) (f) GDPR, IT security)
  • Management and documentation of consents (Art. 6 (1) (c) GDPR where required; Art. 6 (1) (a) GDPR for voluntary consents)
  • Publication of released speaker and session information on the public website (Art. 6 (1) (a) GDPR with consent or Art. 6 (1) (f) GDPR with balancing of interests)
  • Sending system, reminder and organizational e-mails (Art. 6 (1) (b) GDPR; Art. 6 (1) (f) GDPR for operational communication)
  • Auditability of administrative changes and troubleshooting (Art. 6 (1) (f) GDPR)
  • API-based integration where enabled by the event operator (Art. 6 (1) (b) or (f) GDPR)

4. Public event website

Speaker profiles, session information, sponsor information and other frontend content are displayed publicly only if released by authorized administrators. Please do not enter personal data in public content fields unless publication is intended.

5. Cookies, sessions and local storage

We use technically necessary cookies and session storage to maintain logins, CSRF protection, navigation state and theme preferences. These are required for secure operation of the platform. No advertising or profiling cookies are used by default.

6. Recipients and processors

Access to personal data is limited to authorized administrators and, where applicable, the speakers concerned. We use BEEFTEA group GmbH as processor for hosting and operating the COMNEXX software. Further recipients may include e-mail delivery providers, IT support and consultants bound by confidentiality, but only where necessary.

7. Transfers to third countries

Data is generally processed within the European Union / European Economic Area. Transfers to third countries only occur if necessary for individual services and appropriate safeguards exist.

8. Retention

We store personal data only as long as necessary for the purposes stated above, unless statutory retention obligations apply. Account, speaker, consent and log data are deleted or anonymized when no longer required for event operations and legal compliance.

9. Your rights

Data subjects have the right to access, rectification, erasure, restriction of processing, data portability and objection, as well as to withdraw consent at any time with future effect. Requests should be sent to the controller contact above. You also have the right to lodge a complaint with a supervisory authority.

10. Security

We implement appropriate technical and organizational measures to protect personal data, including access controls, password hashing, permission-based authorization and logging of administrative changes.

11. Changes

We may update this privacy policy when the platform, legal requirements or event processes change. The current version is always available on this page.


Datenschutzerklärung

Schutz personenbezogener Daten im Zusammenhang mit dieser Event-Website und der COMNEXX-Plattform

  • Verantwortlicher (Veranstalter): Example Event GmbH, Sample Street 1, 10115 Berlin, Deutschland. Kontakt: privacy@example-event.com, Telefon: +49 30 1234567
  • Datenschutzbeauftragter (falls bestellt): Sample Data Protection Officer, privacy@example-event.com
  • Softwarebetreiber / Auftragsverarbeiter: BEEFTEA group GmbH, Schlüterstr. 36, 10629 Berlin, Deutschland. Kontakt: info@comnexx-speakermanagement.de

1. Geltungsbereich

Diese Datenschutzerklärung gilt für die öffentliche Event-Website, das Speaker-Portal, Administrator-Zugänge und damit zusammenhängende Dienste, die mit COMNEXX für die Example Event GmbH betrieben werden. Sie beschreibt die Verarbeitung personenbezogener Daten beim Besuch der Website, bei Login-Nutzung, bei der Verwaltung von Speaker- und Programmdaten, bei Einwilligungen und bei E-Mail-Kommunikation.

2. Kategorien personenbezogener Daten

Abhängig von Rolle und Nutzung verarbeiten wir insbesondere:

  • Konto- und Login-Daten: E-Mail-Adresse, Passwort (nur gehasht gespeichert), Login-Zeitpunkte, gewählte Rolle, Theme-Einstellung, Session-Kennungen, IP-Adresse und Browser-Informationen (User Agent)
  • Speaker- und Teilnehmerdaten: Titel, Vor- und Nachname, Geschlecht, Unternehmen, Funktion/Rolle, Telefonnummer, Profilfoto, Social-Media-Profile, Ticket-Codes, Session-Zuordnungen, Präsentations-/Video-/Link-Status, hochgeladene Dateien, interne Organisator-Notizen, Freigabestatus für Veröffentlichung
  • Einwilligungsdaten: erteilte oder abgelehnte Einwilligungen, Zeitpunkt, angezeigte Einwilligungstexte, versendete Erinnerungen
  • Event- und Programmdaten mit Personenbezug: Session-Namen, Beschreibungen, Termine, Locations, Funktionen in Sessions, Ablaufplan-Exporte
  • Kommunikationsdaten: Inhalte von System- und Reminder-Mails, Mail-Footer, versandbezogene Metadaten
  • Administrator-Daten: Zustimmung zu Nutzungs-/Vertraulichkeitsbedingungen, Version und Zeitpunkt, Aktivitäten im Administrationsbereich
  • Aktivitäts- und Änderungsprotokolle: wer welche Datensätze wann in welcher Rolle geändert hat, ggf. einschließlich Impersonation-Kontext
  • Individuelle Attribute: zusätzlich konfigurierte Felder für Personen oder Sessions
  • FAQ-, Sponsor- und Frontend-Inhalte: nur dann personenbezogen, wenn dort personenbezogene Daten durch Administratoren eingetragen werden

3. Zwecke und Rechtsgrundlagen

Wir verarbeiten personenbezogene Daten zu folgenden Zwecken:

  • Planung, Administration und Veröffentlichung von Event-Programm und Speakern (Art. 6 Abs. 1 lit. b DSGVO; Art. 6 Abs. 1 lit. f DSGVO, berechtigtes Interesse an der Veranstaltungsorganisation)
  • Betrieb von Login-Bereichen für Speaker und Administratoren (Art. 6 Abs. 1 lit. b DSGVO; Art. 6 Abs. 1 lit. f DSGVO, IT-Sicherheit)
  • Verwaltung und Dokumentation von Einwilligungen (Art. 6 Abs. 1 lit. c DSGVO soweit erforderlich; Art. 6 Abs. 1 lit. a DSGVO für freiwillige Einwilligungen)
  • Veröffentlichung freigegebener Speaker- und Session-Informationen auf der öffentlichen Website (Art. 6 Abs. 1 lit. a DSGVO mit Einwilligung oder Art. 6 Abs. 1 lit. f DSGVO mit Interessenabwägung)
  • Versand von System-, Reminder- und Organisations-Mails (Art. 6 Abs. 1 lit. b DSGVO; Art. 6 Abs. 1 lit. f DSGVO für betriebliche Kommunikation)
  • Nachvollziehbarkeit administrativer Änderungen und Fehlerbehebung (Art. 6 Abs. 1 lit. f DSGVO)
  • API-basierte Integration, sofern durch den Veranstalter aktiviert (Art. 6 Abs. 1 lit. b oder f DSGVO)

4. Öffentliche Event-Website

Speaker-Profile, Session-Informationen, Sponsor-Informationen und andere Frontend-Inhalte werden nur dann öffentlich angezeigt, wenn sie von berechtigten Administratoren freigegeben wurden. Bitte tragen Sie keine personenbezogenen Daten in öffentliche Inhaltsfelder ein, wenn keine Veröffentlichung beabsichtigt ist.

5. Cookies, Sessions und lokale Speicherung

Wir verwenden technisch notwendige Cookies und Session-Speicher, um Logins, CSRF-Schutz, Navigationszustand und Theme-Einstellungen aufrechtzuerhalten. Diese sind für den sicheren Betrieb der Plattform erforderlich. Standardmäßig werden keine Werbe- oder Profiling-Cookies eingesetzt.

6. Empfänger und Auftragsverarbeiter

Der Zugriff auf personenbezogene Daten ist auf berechtigte Administratoren und ggf. betroffene Speaker beschränkt. Wir setzen die BEEFTEA group GmbH als Auftragsverarbeiter für Hosting und Betrieb der COMNEXX-Software ein. Weitere Empfänger können E-Mail-Dienstleister, IT-Support und vertraulichkeitspflichtige Berater sein, jedoch nur soweit erforderlich.

7. Übermittlungen in Drittländer

Daten werden grundsätzlich innerhalb der EU/des EWR verarbeitet. Übermittlungen in Drittländer erfolgen nur, wenn dies für einzelne Dienste erforderlich ist und geeignete Garantien bestehen.

8. Speicherdauer

Wir speichern personenbezogene Daten nur so lange, wie es für die genannten Zwecke erforderlich ist, sofern keine gesetzlichen Aufbewahrungspflichten entgegenstehen. Konto-, Speaker-, Einwilligungs- und Protokolldaten werden gelöscht oder anonymisiert, wenn sie für den Event-Betrieb und die Rechtskonformität nicht mehr benötigt werden.

9. Ihre Rechte

Betroffene haben das Recht auf Auskunft, Berichtigung, Löschung, Einschränkung der Verarbeitung, Datenübertragbarkeit und Widerspruch sowie das Recht, eine erteilte Einwilligung jederzeit mit Wirkung für die Zukunft zu widerrufen. Anfragen richten Sie bitte an den oben genannten Verantwortlichen. Sie haben zudem das Recht, sich bei einer Aufsichtsbehörde zu beschweren.

10. Sicherheit

Wir setzen angemessene technische und organisatorische Maßnahmen zum Schutz personenbezogener Daten ein, einschließlich Zugriffskontrollen, Passwort-Hashing, rollenbasierter Berechtigungen und Protokollierung administrativer Änderungen.

11. Änderungen

Wir können diese Datenschutzerklärung aktualisieren, wenn sich Plattform, Rechtslage oder Event-Prozesse ändern. Die jeweils aktuelle Fassung ist auf dieser Seite abrufbar.

Convention

Powered by Convention – speaker and program management for events.

Convention — 5 November 2026 · Berlin Legal · Privacy