A warm welcome to our website!

We place the highest value on the protection of your data and privacy. Therefore, below we inform you about the collection and use of personal data when using our website.

What are the purposes of data processing?

The personal data collected via the website – e.g. through registration forms – are required for the planning and execution of the MEX. For this purpose, the consent to data processing (Art. 6 para. 1 sentence 1a GDPR) is obtained from the persons whose data are collected. Separate consent is obtained from the data subject for later contact (Art. 6 para. 1 sentence 1f GDPR).

Security measures

In accordance with Article 32 GDPR, taking into account the state of the art, implementation costs and the type, scope, circumstances and purposes of the processing as well as the varying likelihood of occurrence and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organizational measures to ensure a level of protection appropriate to the risk.

The measures include in particular ensuring the confidentiality, integrity and availability of data by controlling physical access to the data, as well as the access concerning them, input, transfer, safeguarding, availability and their separation. Furthermore, we have established procedures that ensure the exercise of data subject rights, deletion of data and response to threats to data.

Cooperation with processors and third parties

If, within the scope of our processing, we disclose data to other persons and companies (processors or third parties), transmit it to them or otherwise grant them access to the data, this only takes place on the basis of a legal permission (e.g. if a transfer of the data to third parties, such as payment service providers, is required pursuant to Art. 6 para. 1 lit. b GDPR for the fulfillment of the contract), you have consented, a legal obligation provides for this or on the basis of our legitimate interests (e.g. when using agents, web hosts, etc.).

If we commission third parties to process data on the basis of a so-called “data processing agreement”, this is done on the basis of Art. 28 GDPR.

External payment service providers

We use external payment service providers via whose platforms the users and we can carry out payment transactions (e.g., each with a link to the privacy policy, Paypal (https://www.paypal.com/de/webapps/mpp/ua/privacy-full), Klarna (https://www.klarna.com/de/datenschutz/), Skrill (https://www.skrill.com/de/fusszeile/datenschutzrichtlinie/), Giropay (https://www.girocard.eu/datenschutz-girocard/), Visa (https://www.visa.de/nutzungsbedingungen/visa-globale-datenschutzmitteilung.html), Mastercard (https://www.mastercard.de/de-de/datenschutz.html), American Express (https://www.americanexpress.com/us/legal-disclosures/website-rules-and-regulations.html?inav=en_us_legalfooter_terms_of_service)

Within the scope of fulfilling contracts, we use the payment service providers on the basis of Art. 6 para. 1 lit. b GDPR. Otherwise, we use external payment service providers on the basis of our legitimate interests pursuant to Art. 6 para. 1 lit. f GDPR in order to offer our users effective and secure payment options.

The data processed by the payment service providers include inventory data, such as the name and address, bank data, such as account numbers or credit card numbers, passwords, TANs and checksums as well as contract, amount and recipient-related information. The information is required in order to carry out the transactions. However, the entered data are only processed and stored by the payment service providers. This means that we do not receive any account- or credit card-related information, but only information confirming or rejecting the payment. Under certain circumstances, the data may be transmitted by the payment service providers to credit agencies. This transmission is intended for identity and creditworthiness checks. In this regard, we refer to the GTC and privacy notices of the payment service providers.

The terms and conditions and the privacy notices of the respective payment service providers apply to the payment transactions, which can be accessed within the respective websites or transaction applications. We also refer to these for further information and the assertion of revocation, information and other data subject rights.

Anonymous data collection

You can visit our websites without providing any personal information. In this context, we do not store any personal data whatsoever. In order to improve our services, we only evaluate statistical data that do not allow any conclusions to be drawn about your person.

Collection and processing when using the contact and application forms

When using the contact form, we collect personal data (individual information about the personal or factual circumstances of a specific or identifiable natural person) only to the extent provided by you. We use the email address only for processing your inquiry.

Use of the email address for sending direct advertising

We use your email address independently of the contract processing exclusively for our own advertising purposes for sending direct advertising for our own similar goods or services. If you do not agree with this, you may object to the use at any time. The objection can be declared using any means of communication, not only by email. However, it must reach us in order to become effective. No costs other than the transmission costs according to the basic rates will arise for this. You will find the contact details for exercising your objection in the legal notice. Your data will not be passed on to third parties without your express consent.

Cookies

Our websites use so-called cookies in several places. Cookies are small text files that are stored on your computer and saved by your browser. They serve to make our services more user-friendly, effective and secure. Our cookies are not used for tracking purposes – your browser is not recognized. Cookies do not contain any personal data.

Use of Piwik Analytics

For the creation of access statistics on our website, we use the software Piwik. Piwik (internal service) is supplied by us with log files that do not contain any personal data and therefore do not allow any conclusions to be drawn about your person. An approximate location estimate (federal state or city) is carried out in order to better reach our target groups. The data generated and collected by us are not shared with third parties.

Log files

The IT systems of MEX (web server & email server) generate entries in a so-called log file with every access. These entries contain: time of communication, IP address of the counterpart (you) & URL (web server) or email address(es) (email server). The log files serve system optimization and security. The IP addresses in the log files are anonymized after 24 hours (xxx.xxx.xxx.xxx).

Tracking of the user session or personalization via log files or our services does not take place. It is not possible for us to trace back users.

Archiving / Backups

Our system creates encrypted backups of its data at regular intervals. Personal data may also be archived in the process – manual deletion is not possible here, as otherwise the backup would become inconsistent. Our systems automatically overwrite the oldest backup point at regular intervals. The backups of our systems are no more than 6 months old.

Data location

All IT systems of MEX (including email services, web services) are located in German data centers and are therefore subject to German law. Our systems may communicate data to other countries (e.g. when sending an email to GMAIL) – however, they do not independently store data there.

How long are the personal data stored?

The personal data are stored for as long as they are required for the implementation, planning and follow-up of the event.

Information, correction, blocking and deletion of data

You have the right at any time to free information about your stored data as well as the right to correction, deletion or blocking. Contact us upon request. You will find the contact details in our Legal Notice. However, deletion of the data can only take place if it does not conflict with current legislation – e.g. retention obligations.

Comments and contributions

If users leave comments or other contributions, their IP addresses may be stored for 7 days on the basis of our legitimate interests within the meaning of Art. 6 para. 1 lit. f GDPR. This is done for our security in case someone leaves unlawful content in comments and contributions (insults, prohibited political propaganda, etc.). In this case, we ourselves may be held liable for the comment or contribution and are therefore interested in the identity of the author.

Furthermore, we reserve the right, on the basis of our legitimate interests pursuant to Art. 6 para. 1 lit. f GDPR, to process the users’ information for the purpose of spam detection.

On the same legal basis, we reserve the right, in the case of surveys, to store the IP addresses of the users for their duration and to use cookies in order to prevent multiple votes.

The data provided within the framework of the comments and contributions are stored permanently by us until the users object.

Retrieval of profile pictures via Gravatar

Within our online offering, and especially in the blog, we use the Gravatar service of Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA.

Gravatar is a service where users can register and store profile pictures and their email addresses. If users leave contributions or comments with the respective email address on other online presences (especially in blogs), their profile pictures can then be displayed next to the contributions or comments. For this purpose, the email address provided by the users is transmitted in encrypted form to Gravatar for the purpose of checking whether a profile is stored for it. This is the sole purpose of transmitting the email address and it is not used for any other purposes, but is deleted afterwards.

The use of Gravatar is based on our legitimate interests within the meaning of Art. 6 para. 1 lit. f) GDPR, as with the help of Gravatar we offer contribution and comment authors the possibility to personalize their contributions with a profile picture.

By displaying the images, Gravatar obtains the IP address of the users, as this is necessary for communication between a browser and an online service. Further information on the collection and use of data by Gravatar can be found in the privacy notices of Automattic: https://automattic.com/privacy/.

If users do not want an avatar linked to their email address at Gravatar to appear in the comments, they should use an email address for commenting that is not stored with Gravatar. We also point out that it is possible to use an anonymous email address or no email address at all if users do not wish their own email address to be transmitted to Gravatar. Users can completely prevent the transmission of data by not using our comment system.

Hosting and email dispatch

The hosting services we use serve to provide the following services: infrastructure and platform services, computing capacity, storage space and database services, email dispatch, security services as well as technical maintenance services, which we use for the purpose of operating this online offering.

In doing so, we, or our hosting provider, process inventory data, contact data, content data, contract data, usage data, meta and communication data of customers, interested parties and visitors to this online offering on the basis of our legitimate interests in an efficient and secure provision of this online offering pursuant to Art. 6 para. 1 lit. f GDPR in conjunction with Art. 28 GDPR (conclusion of a data processing agreement).

Integration of third-party services and content

Within our online offering, we use content or service offerings from third-party providers on the basis of our legitimate interests (i.e. interest in the analysis, optimization and economic operation of our online offering within the meaning of Art. 6 para. 1 lit. f GDPR) in order to integrate their content and services, such as videos or fonts (hereinafter uniformly referred to as “Content”).

This always requires that the third-party providers of this content become aware of the users’ IP address, as without the IP address they would not be able to send the content to their browser. The IP address is therefore required for the display of this content. We endeavor to use only such content whose respective providers use the IP address solely for the delivery of the content. Third-party providers may also use so-called pixel tags (invisible graphics, also referred to as “web beacons”) for statistical or marketing purposes. The “pixel tags” can be used to evaluate information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the users’ device and may contain, among other things, technical information about the browser and operating system, referring websites, visit time and further information on the use of our online offering, as well as be linked with such information from other sources.

Youtube

We embed the videos of the platform “YouTube” of the provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy Policy: https://www.google.com/policies/privacy/, Opt-Out: https://adssettings.google.com/authenticated.

Google Maps

We embed the maps of the service “Google Maps” of the provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. The processed data may include in particular IP addresses and location data of the users, which are, however, not collected without their consent (as a rule carried out within the settings of their mobile devices). The data may be processed in the USA. Privacy Policy: https://www.google.com/policies/privacy/, Opt-Out: https://adssettings.google.com/authenticated.

ReCaptcha:

We embed the function “ReCaptcha” for the detection of bots, e.g. in entries in contact forms. The behavioral information of the users (e.g. mouse movements or queries) is evaluated in order to distinguish humans from bots. Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, Parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://www.google.com/recaptcha/; Privacy Policy: https://policies.google.com/privacy; Privacy Shield (ensuring the level of data protection when processing data in the USA): https://www.privacyshield.gov/participant?id=a2zt0000000TRkEAAW&status=Active; Objection option (Opt-Out): Opt-Out plugin: http://tools.google.com/dlpage/gaoptout?hl=de, Settings for the display of advertisements: https://adssettings.google.com/authenticated.

At the event

Dear visitors,

according to the information obligation pursuant to Art. 14 GDPR, we inform you that photographs and video recordings will be made during this event. We use these for the purposes of reporting and public relations. For this purpose, the recordings are published in various local and social media, such as the website (www.mex-berlin.de) and our social media channels.

The legal basis for the processing of your photo and video data is Art. 6 para. 1 (f) GDPR, as there is a legitimate interest in informing the public about the activities of MEX Veranstaltungs-GmbH and documenting our activities. Deletion of the data, provided that it is processed in online media under our control, generally takes place after five years as part of the annual revision.

Recipients of this data are therefore internally the members of our company responsible for public relations and externally the regional press as well as editorial offices and editorial systems of print media, online media and internationally operating social media providers.

The controller under data protection law is MEX Veranstaltungs-GmbH, represented by the managing board: JONAS MEIERDIRKS (Board), FABIAN SIEWERT (Board), who can be contacted at info@mex-berlin.de.

Please also contact them to exercise your data subject rights pursuant to GDPR, such as your right to information, correction, deletion, restriction of processing, objection or data portability. You also have the right to lodge a complaint with a data protection authority. You can contact the data protection authority responsible for your place of residence or your federal state or the data protection authority responsible for us. This is:
The Berlin Commissioner for Data Protection and Freedom of Information, Office address:
Friedrichstr. 219, 10969 Berlin / Telephone: 030 13889-0 / E-mail: mailbox@datenschutz-berlin.de

You can view the complete data protection information of MEX Veranstaltungs-GmbH here digitally at the ticket desk or read it in the data protection policy on our homepage (www.mex-berlin.de).

Sources: Elke Liebrich (Certified Data Protection Officer)
Joachim Hindennach (WLSB Legal Counsel)