General Data Protection Notice
The Controllers as defined under the data protection laws are
- Koelnmesse GmbH
- Gesellschaft zur Förderung der Dental-Industrie (GFDI) mbH
Aachener Str. 1053–1055
The Data Protection Officer of Koelnmesse GmbH can be contacted as follows: firstname.lastname@example.org
For trade fairs outside Germany, our Data Protection Officer can be contacted as follows: email@example.com
2. Your rights as data subject
If your personal data are processed, you are a data subject as defined in the GDPR and you have the following rights with respect to the Controller:
Right of objection
You have the right to file an objection at any time against processing of your personal data, carried out on the basis of Art. 6 (1) sentence 1 lit. e) or f) GDPR, for reasons resulting from your particular situation. This also applies to any Profiling based on these provisions.
The Controllers will then no longer process your personal data, unless You can demonstrate compelling reasons for the processing warranting protection, and these prevail over your interests, rights and liberties, or if the processing is for the purpose of asserting, exercising or defence of legal entitlements.
If your personal data are processed in order to carry out direct advertising, you have a right to file an objection at any time against the processing of your personal data for the purpose of such advertising. This also applies to Profiling insofar as it is connected with such direct advertising.
If you object to processing for the purpose of direct advertising, your personal data will no longer be processed for these purposes.
In connection with the use of services of the information society and notwithstanding Directive 2002/58/EC, you have the possibility of exercising your right of objection via automated procedures that use technical specifications.
You can demand information on whether we process personal data concerning you. If such processing is carried out, you can demand further information on this processing, in particular the purposes, categories of personal data, recipients or the categories of recipients, planned storage duration etc.
You have a right to correction and/or completion of your data.
You can demand the restriction of the processing of your personal data under certain circum-stances: If the processing of your personal data has been restricted, these data — with the excep-tion of their storage — can only be processed with your consent, or for the assertion, exercise or defence of legal entitlements, or to protect the rights of another natural or legal person, or for reasons of an important public interest on the part of the EU or a member state.
Under certain circumstances, you can demand the erasure of the personal data concerning you. If the Controllers have made your personal data public and are obliged to erase them, he shall, with consideration for the available technology and implementation costs, take appropriate measures, including of a technical nature, to inform Controllers, responsible for the data processing and processing the personal data, that you, as data subject, have demanded that they delete all links to these personal data, or have demanded the deletion of copies or replications of these personal data.
If you have asserted the right of rectification, erasure or restriction of processing with respect to one of the Controllers, the latter is obliged to inform all recipients, to whom your personal data have been disclosed, of this rectification or erasure of the data or of the restriction of processing, unless this proves to be impossible or involves disproportionate expense. You have a right with respect to the Controller to be informed of these recipients.
You have a right to receive your personal data, provided by you, in a structured, commonly-used and machine-readable format. You also have a right to insist that these data be transferred directly to another controller, insofar as this is technically possible. Liberties and rights of other persons must not be impaired as a result.
You have the right to revoke your data protection declaration of consent at any time. Revocation of the consent shall not affect the legality of the processing, carried out on the basis of the consent, up until the revocation.
Within certain limits, you have the right not to be subjected to a decision, based exclusively on automated processing — including Profiling — that is legally effective against you or that significantly impairs you in a similar manner.
3. Right to complain to a supervisory body
Notwithstanding any other administrative-law or judicial remedy, you have a right to complain to a supervisory authority, in particular in the member state of your residence, your place of work or the place of the suspected violation, if you are of the opinion that the processing of your personal data violates the GDPR.
The supervisory body with which the complaint has been filed, will inform the complainant of the status and the results of the complaint, including the possibility of a judicial remedy pursuant to Art. 78 GDPR.
4. Information in the event of data collection via third parties
If we collect your personal data via third parties, this can involve the following categories of personal data: name, contact data as well as further information, for example concerning your responsibilities.
If we do not receive these contact data directly from you, we receive them from the company for which you work and/or with which we are in contact. This can involve in particular an exhibitor or another cooperation partner with which we exchange services.
The possibility also exists of us receiving your contact data from commercial agents working for us.
5. Purposes and legal basis of the processing
a) If you conclude a contract with us, we process your data for contract initiation, execution and settlement. This concerns the purchase of tickets as well as the contractual relationship as exhibitor, if you are acting as a natural person, for ex-ample businessman, in this respect. This also includes the creation of user accounts on the platforms offered by us, unless a separate data protection notice on the handling of your data is provided there. The data processing can also be for the purpose of administering your participation in an event or competition.
The legal basis for the handling of your data is Art. 6 (1) sentence 1 lit. b) GDPR, if this handling concerns the contractual exchange of services with you.
b) We may possibly also process data on you even if you yourself are not a customer, but rather a contact person of a business or cooperation partner.
In this respect, the legal basis for the handling of your data is Art. 6 (1) sentence 1 lit. f) GDPR.
c) We process your data in order to provide you with the accreditation for this event. If you have given your consent during accreditation, your data will be used to send you press information. To do so, your data will be stored in our database even after the event is over.
The legal basis for the handling of your data is Art. 6 (1) sentence 1 lit. b) GDPR, if this handling concerns the contractual exchange of services with you. Insofar as you have given your consent to the sending of press information, Art. 6 (1) sentence 1 lit. a) GDPR is the legal basis for the han-dling of your data. You can revoke such consent at any time with effect for the future.
d) We also process data for other purposes that are in our interests, specifically in order to:
- provide you with product information concerning relevant products and services.
- carry out measures aimed at improving and developing services and products, so as to be able to approach you individually with customised offers and products.
- carry out market and opinion research, or have this carried out by market and opinion research institutes. This enables us to obtain an overview of the transparency and quality of our products, services and communication, and to align or design these in the interests of our customers.
The legal basis for this handling of your data is Art. 6 (1) sentence 1 lit. f) GDPR, § 7 (3) UWG as well as Art. 6 (1) sentence 1 lit. a) GDPR, provided you have issued consent. You can revoke any such consent at any time with effect for the future.
e) As far as your data are collected exclusively for the purpose of traceability of new infections with the Coronavirus SARS-CoV-2, the legal basis for the handling of your data is § 2a Corona¬SchVO NRW.
f) The data processing is also carried out on the basis of an agreement between jointly responsi-ble parties pursuant to Article 26 GDPR. The essential features of this agreement are:
|Obligations resulting from the GDPR||Koelnmesse||GFDI|
|Determining the purpose and the means of the data processing||X||X|
|Determining the type of the personal data||X||X|
|Art. 26 (1): Determining in a transparent manner their respective responsibilities for compliance with the obligations under this regulation. The arrangement shall duly reflect the respective roles and relationships of the joint controllers vis-à-vis the data subjects.||X||X|
|Art. 26 (2): The essence of the arrangement shall be made available to the data subject.||X||X|
|Art. 13: Information to be provided where personal data are collected.||X|
|Art. 14: Information to be provided where personal data have not been obtained from the data subject.||X|
|Art. 15: Processing of requests to obtain information.||X|
|Art. 16: Processing of requests to obtain rectification.||X|
|Art. 17 or 18: Processing of requests for the erasure or restriction of processing and Art. 19 Notification obligation regarding erasure of personal data.||X|
|Art. 20: Processing of requests to receive personal data concerning the data subject (data portability).||X|
|Art. 21: Process objections.||X|
|Art. 24 (1) in connection with Art. 32: Determining the technical and organisational measures after carrying out risk assessment and insofar as necessary data protection impact assessment (Art. 35) and consultation with a supervisory authority/transfer of the necessary information (Art. 36 (3)).||X|
|Art. 24 (1) Documentation of the choice of the technical and organisational measures (as demonstration of compliance).||X|
|Art. 24 (1) Review und updating of the measures.||X|
|Art. 28: Use of processors and other (third-party) processors and their review.||X||X|
|Art. 30: Maintaining the record of processing activities.||X|
|Art. 33, 34: Process in the event of a data breach subject to obligatory notification.||X|
|Art. 37: Designation of a data protection officer.||X|
6. Justified interest
If we use data within the framework of the above weighing-up of interests, our justified interest lies in enabling direct advertising (see Recital 47 GDPR), provided your privacy-law interests do not outweigh our advertising interests in each individual case.
If we use data in the context of contract initiation or fulfilment with a business or cooperation partner, our interest when handling your data lies in enabling and maintaining a dialogue with the respective business or cooperation partner, typically within the framework of a contractual or other relationship. If you act as contact person in this respect — typically in your function as employee of these companies — you typically have no opposing interest if this interaction with us is part of your work duties.
7. Recipients of your data
If and insofar as you have issued us with corresponding consent, we shall forward your data within the limits of this consent.
We shall also forward your data to service providers who are bound by instructions and whose work supports the provision of our services for you, on our behalf and in accordance with our instructions. These can be IT service providers, print service providers, call centres if you call in, and similar service providers. In addition, we pass on your data to third parties if and insofar as this is necessary to fulfil the contract concluded with you and order processing is out of the question.
In individual cases we also forward your data to third parties who use the data on their own responsibility: finance and tax authorities, police and investigation authorities (given the existence of a legal basis), official registration bodies (if forwarding is prescribed by law), insurance companies, banks and lending institutions (payment processing), market partners, commercial agents, auditors, lawyers, accountants or similar third parties.
8. Transfer of data to a third country
The transfer of data to third countries is planned if this is necessary for fulfilment of a contract, or if you issue us with express consent to forward the data to third parties.
If we transfer your data to service providers or group companies outside the European Economic Area (EEA), the transfer will only be made if the third country has been certified by the EU Commission as having an adequate level of data protection (Art. 45 (1) GDPR), or given the existence of other adequate data protection guarantees as defined in Art. 47 GDPR.
9. Duration of the storage of your data
If we have received your data for the processing of the contractual relationship with you as ticket purchaser or as natural person, as exhibitor, or for the purpose of an advertising approach or for the processing of your participation in an event or competition, we shall store your data and shall erase these after the event or when the contractual relationship with you has ended, when all reciprocal claims have been fulfilled and if no other statutory retention obligations or statutory justifying reasons for the storage exist. If you have a user account, your user data will be stored until this user account is deleted.
If we have collected your data solely on the basis of the CoronaSchVO NRW, these data will be stored or deleted in accordance with the periods resulting from this regulation.
If you have given us your consent (e. g. to receive information on products and services or press releases), we will store your data until you revoke your consent.
Retention obligations exist in particular under the German Commercial Code (HGB) and the German Tax Code (AO). If such obligations apply and concern documents with your data, we shall erase your data upon expiry of the statutory retention obligations. As a rule therefore ten years from the end of the year in which the contractual relationship with you has ended.
If we use your data in the context of the contract initiation or fulfilment with a business or cooperation partner, we shall store your data and shall erase them as soon as these are no longer required, for example if our relationship with the business or cooperation partner ends, if you yourself no longer act as contact person or similar.
10. Necessity of providing your data
The provision of the data by you and the collection of the data by us for the processing of the contractual relationship with you as ticket purchaser or as natural person as exhibitor, is necessary for conclusion of the contract. Without the data we cannot conclude a contract with you or provide invoicable services. This also applies if you wish to create and use a user account or to be accredited as a media representative.
The same applies in cases in which you wish to be approached by us for advertising purposes, or wish to participate in events or competitions.
If we collect your data in the context of contract initiation or fulfilment with a business or cooperation partner, the provision of the data is typically necessary for the contractual relationship with the company for which you work; we would be typically unable to provide services without the data.
11. Automated decisions in individual cases or Profiling measures
No automated decision making or profiling takes place, neither for the creation and execution of the contractual relationship with you, nor for advertising approaches, nor for the processing of your participation in events or competitions.
If you have a user account on one of our platforms and are logged in there, we evaluate your interests on the basis of the actions you have taken in order to send you information on products and services tailored to your interests. An automated decision making process does not take place.