Page
Privacy
Preamble
With this privacy policy we inform you which types of your personal data (hereinafter also “data”) we process, for which purposes and to what extent. This policy applies to all processing of personal data that we carry out, both in the course of providing our services (in particular ticket sales and running HanaCon) and on our websites (hanacon.de, verein.hanacon.de, ticket.hanacon.de, sso.hanacon.de and the short-link domain hnc.li), as well as within external online presences such as our social media profiles (together, the “online offering”).
The terms used are gender-neutral.
Last updated: 30 September 2026
Table of contents
- Preamble
- Controller
- Data Protection Officer
- Overview of processing
- Legal bases
- Security measures
- Disclosure of personal data
- International data transfers
- General information on data retention and deletion
- Rights of data subjects
- Tasks under our bylaws (members, donations)
- Ticket shop and ticket management
- Payment methods
- Attending the event, youth protection, photos and video
- User accounts and single sign-on
- Applications and registrations for programme and participation areas
- Presentation of team and crew members
- Communication by email and phone
- Internal crew communication (Discord)
- Provision of the online offering and web hosting
- Use of cookies and browser storage
- Newsletter and electronic notifications
- Web analytics (Matomo)
- Embedded content (YouTube, Google Maps)
- Presences in social networks (social media)
- Privacy information for whistleblowers
- Changes and updates
- Definitions
Controller
HanaCon e.V.
Baumgartenstraße 22
30419 Hannover
Germany
Authorised representatives:
1st Chairperson: Joshua Bauer – ;
2nd Chairperson: Tanja Krüger –
Register of associations: Amtsgericht Hannover (Local Court), VR 203762
Email:
Phone: +49 176 79019578
Legal notice: https://hanacon.de/en/legal-notice/
Data Protection Officer
Overview of processing
The following overview summarises the types of data processed, the purposes of processing and the data subjects concerned.
Types of data processed
- Master data (e.g. names, addresses).
- Contact data (e.g. email addresses, phone numbers).
- Contract and order data (e.g. ticket type, order number, payment status).
- Payment data.
- Membership data.
- Content data (e.g. messages, application documents, photos).
- Usage data (e.g. pages visited, clicks, time spent).
- Meta, communication and procedural data (e.g. IP addresses, timestamps, device and browser information).
- Log data.
- Special categories of personal data: information on a severe disability (mark “B”) when obtaining a free companion ticket.
Categories of data subjects
- Ticket buyers, ticket holders and visitors.
- Members, crew and team members.
- Prospects and newsletter subscribers.
- Applicants (e.g. artists, show acts, vendors, content creators).
- Communication partners.
- Users of our online offering.
- Business and contractual partners.
- Donors.
- Minor visitors and their legal guardians.
- Whistleblowers and persons named in reports.
Purposes of processing
- Providing contractual services and fulfilling contractual obligations (ticket sales, admission).
- Communication.
- Security measures and youth protection.
- Direct marketing (newsletter).
- Audience measurement and optimisation of our online offering.
- Organisational and administrative procedures (association and membership administration, accounting).
- Provision of our online offering and user-friendliness.
- IT infrastructure.
- Fundraising.
- Public relations and information.
- Whistleblower protection.
Legal bases
Legal bases under the GDPR: The following is an overview of the legal bases of the GDPR on which we process personal data. Please note that, in addition to the GDPR, national data protection rules of your or our country of residence or seat may apply. Where more specific legal bases apply in an individual case, we state them in this policy.
- Consent (Art. 6(1)(1)(a) GDPR) – The data subject has given consent to the processing of their personal data for one or more specific purposes.
- Explicit consent to processing special categories of data (Art. 9(2)(a) GDPR) – The data subject has explicitly consented to the processing of special categories of personal data (e.g. health data).
- Performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR) – Processing is necessary for the performance of a contract to which the data subject is party, or for taking steps prior to entering into a contract at the data subject’s request.
- Legal obligation (Art. 6(1)(1)(c) GDPR) – Processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Art. 6(1)(1)(f) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or a third party, except where such interests are overridden by the interests, fundamental rights and freedoms of the data subject which require protection of personal data.
- Membership contract (bylaws) (Art. 6(1)(1)(b) GDPR) – Processing is necessary to fulfil the membership relationship with the association.
National data protection rules in Germany: In addition to the GDPR, national data protection rules apply in Germany, in particular the Federal Data Protection Act (BDSG). The BDSG contains special provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, transfers, and automated individual decision-making including profiling. State data protection laws may also apply.
Data protection for cookies and similar technologies: Section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG) additionally applies to storing information on your device and accessing it. Unless strictly necessary to provide a service you have expressly requested, we obtain your consent (Section 25(1) TDDDG). Technically necessary access is based on Section 25(2) no. 2 TDDDG.
Security measures
In accordance with the legal requirements, and taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
These measures include in particular safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as access, input, disclosure, availability and separation. At our association these include, in particular, central identity management with role-based access rights, regular data backups and monitoring of our systems. We have also set up procedures to ensure the exercise of data subject rights, the deletion of data and responses to data threats. Furthermore, we take the protection of personal data into account already when developing or selecting hardware, software and procedures, in line with the principles of data protection by design and by default.
Securing online connections with TLS/SSL encryption (HTTPS): To protect the data of users transmitted via our online services from unauthorised access, we use TLS/SSL encryption. These technologies encrypt the information transmitted between the website and the user’s browser (or between two servers), protecting the data from unauthorised access. A website secured by an SSL/TLS certificate is indicated by HTTPS in the URL.
Disclosure of personal data
In the course of processing personal data, data may be transmitted or disclosed to other bodies, companies, legally independent organisational units or persons. Recipients may include, for example, IT service providers, payment service providers, banks, tax and legal advisers, or providers of services and content embedded in a website. In such cases we comply with the legal requirements and in particular conclude appropriate contracts or agreements with the recipients of your data that serve to protect your data.
Disclosure within the organisation: Within the association, only members and crew members receive access to personal data that they need for their respective task (e.g. ticketing, admission, programme, finance). Data is shared on the basis of our legitimate interests in orderly association work, the performance of contractual obligations, or consent or legal permission.
International data transfers
Data processing in third countries: If we transfer data to a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or if this happens in the course of using third-party services or disclosing or transferring data to other persons, bodies or companies (which can be recognised from the provider’s postal address or where this policy expressly refers to a transfer to third countries), this always takes place in compliance with the legal requirements.
For transfers to the USA, we primarily rely on the Data Privacy Framework (DPF), which was recognised as a secure legal framework by an adequacy decision of the EU Commission of 10 July 2023. In addition, the respective providers have generally concluded standard contractual clauses that comply with the requirements of the EU Commission and set out contractual obligations to protect your data. The DPF is the primary layer of protection; the standard contractual clauses serve as additional security and a fallback should the legal framework of the DPF change.
For each service provider we tell you whether it is certified under the DPF. Further information on the DPF and a list of certified companies can be found on the website of the US Department of Commerce at https://www.dataprivacyframework.gov/.
For transfers to other third countries, corresponding safeguards apply, in particular standard contractual clauses, explicit consent, or legally required transfers. Information on third-country transfers and applicable adequacy decisions is available from the EU Commission: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en.
General information on data retention and deletion
We delete personal data that we process in accordance with the legal provisions as soon as the underlying consents are withdrawn or there is no further legal basis for processing. This applies where the original purpose of processing no longer applies or the data is no longer needed. Exceptions apply where statutory obligations or special interests require longer retention or archiving.
In particular, data that must be retained for commercial or tax law reasons, or whose storage is necessary for legal enforcement or to protect the rights of other natural or legal persons, must be archived accordingly.
Our privacy notices contain additional information on retention and deletion that applies specifically to certain processing operations.
Where several retention or deletion periods are stated for a data item, the longest period always applies. Data that is no longer retained for its original purpose but because of legal requirements or other reasons is processed by us exclusively for the reasons that justify its retention.
Retention and deletion: The following general periods apply to retention and archiving under German law:
- 10 years – books and records, annual accounts, inventories, management reports, opening balance sheets, and the work instructions and other organisational documents needed to understand them (Section 147(1) no. 1 with (3) German Fiscal Code (AO), Section 257(1) no. 1 with (4) German Commercial Code (HGB)).
- 8 years – accounting vouchers, such as invoices and expense receipts (Section 147(1) nos. 4 and 4a with (3) sentence 1 AO, Section 14b(1) German VAT Act (UStG) and Section 257(1) no. 4 with (4) HGB).
- 6 years – other business records: received commercial or business letters, copies of sent commercial or business letters, and other documents to the extent relevant for taxation (Section 147(1) nos. 2, 3, 5 with (3) AO, Section 257(1) nos. 2 and 3 with (4) HGB).
- 3 years – data needed to take potential warranty and damages claims or similar contractual claims and rights into account and to handle related enquiries is stored for the regular statutory limitation period of three years (Sections 195, 199 German Civil Code (BGB)).
Start of the period at the end of the year: If a period does not expressly start on a specific date and is at least one year long, it automatically starts at the end of the calendar year in which the triggering event occurred. In the case of ongoing contractual relationships in the context of which data is stored, the triggering event is the time at which the termination or other end of the legal relationship takes effect.
Rights of data subjects
Rights of data subjects under the GDPR: As a data subject you have various rights under the GDPR, in particular under Articles 15 to 21 GDPR:
- Right to object: You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is based on Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on those provisions. Where personal data concerning you is processed for direct marketing, you have the right to object at any time to the processing of personal data concerning you for such marketing; this also applies to profiling to the extent it is related to such direct marketing.
- Right to withdraw consent: You have the right to withdraw consent at any time with effect for the future. The lawfulness of processing carried out before withdrawal remains unaffected.
- Right of access: You have the right to obtain confirmation as to whether data concerning you is being processed, and access to that data as well as further information and a copy of the data in accordance with the law.
- Right to rectification: In accordance with the law, you have the right to have data concerning you completed or inaccurate data concerning you rectified.
- Right to erasure and restriction of processing: In accordance with the law, you have the right to demand that data concerning you be erased without delay or, alternatively, that processing of the data be restricted.
- Right to data portability: You have the right to receive data concerning you that you have provided to us in a structured, commonly used and machine-readable format or to have it transmitted to another controller, in accordance with the law.
- Complaint to a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes the GDPR. The complaint may be lodged in particular with a supervisory authority in the member state of your habitual residence, place of work or the place of the alleged infringement. The authority responsible for us is: Die Landesbeauftragte für den Datenschutz Niedersachsen (State Commissioner for Data Protection of Lower Saxony), Prinzenstraße 5, 30159 Hannover, Germany, email: , https://www.lfd.niedersachsen.de.
To exercise your rights, an informal message to or to our Data Protection Officer (see above) is sufficient.
Tasks under our bylaws (members, donations)
We process the data of our members, supporters, donors, prospects, business partners and other persons (together “data subjects”) where we are in a membership or other business relationship with them and perform our tasks under our bylaws. Otherwise we process data of data subjects on the basis of our legitimate interests, e.g. for administrative tasks or public relations.
The data processed, the type, scope and purpose of processing and its necessity are determined by the underlying membership or contractual relationship. We delete data that is no longer required to fulfil our purposes under our bylaws and keep it as long as it may be relevant for handling the relationship and with regard to possible warranty or liability obligations. The necessity of retention is reviewed regularly; otherwise statutory retention obligations apply.
Donations: Donations can be made by bank transfer or via PayPal (PayPal.Me/hanacon). We process name, contact data, amount, payment date and the information in the payment reference in order to book the donation, issue donation receipts and meet our tax documentation obligations. For PayPal see the section “Payment methods”.
- Types of data processed: Master data (e.g. name, address); contact data (e.g. email address, phone number); membership data (e.g. membership number, date of joining, information on membership fees, participation in events and meetings); payment data (e.g. bank details, payment history, donation amount); content data (e.g. messages).
- Data subjects: Members; donors; prospects; communication partners.
- Purposes of processing: Membership and fee administration; communication; organisational and administrative procedures; fundraising and donation administration; public relations.
- Retention and deletion: Deletion in accordance with the section “General information on data retention and deletion”.
- Legal bases: Membership contract (bylaws) (Art. 6(1)(1)(b) GDPR); legal obligation (Art. 6(1)(1)(c) GDPR); legitimate interests (Art. 6(1)(1)(f) GDPR).
Ticket shop and ticket management
We sell tickets for HanaCon through our own ticket shop at ticket.hanacon.de. The shop is based on the open-source software pretix, which we run ourselves on our own servers. No third-party ticket vendor is involved. The shop is embedded on hanacon.de as a widget; when the page is loaded, a connection to our own server ticket.hanacon.de is established for this purpose.
For the order and performance of the purchase contract (see our terms and conditions (AGB, German only)) we process in particular:
- the buyer’s name and email address and invoicing details,
- first and last names of all ticket holders, because our online tickets are personalised (Section 5 AGB),
- order data (ticket type, price, order number, time), payment method and payment status,
- technical order data (e.g. IP address, session cookie of the shopping cart),
- data on transferring a ticket to another person, on cancellations and on payment reminders.
Order emails: Order confirmation, ticket, invoice, payment reminders (for bank transfer after 14 days, with a 3-day deadline) and event notices are sent as part of contract performance through our own mail server. These messages are not a newsletter.
Admission and ID check: At admission, the code of your online ticket is scanned once and exchanged for an entry wristband; the admission is recorded in the ticketing system to prevent a ticket being used more than once. To match the personalised ticket we may ask to see photo ID. The ID is only inspected; we do not copy or store it.
Free companion ticket: Persons with a severe-disability ID with mark “B” receive a free companion ticket. You present the proof voluntarily. This is health data (a special category). We only record that proof was presented and use this solely to issue the companion ticket. The legal basis is your explicit consent (Art. 9(2)(a) GDPR), which you can withdraw at any time; the companion ticket can then no longer be issued.
Block list for prohibited resale above face value: Under Section 5 e) of the AGB, reselling tickets at a higher price is prohibited. If we become aware of such a sale, we record the name and email address of the original buyer so that they can no longer purchase tickets in future and the house ban can be enforced. The legal basis is our legitimate interest in preventing ticket profiteering and in fair ticket sales (Art. 6(1)(1)(f) GDPR). We regularly review whether the entry is still required and delete it if it is not.
Minors: Please have a parent or legal guardian buy tickets for children. For youth protection see the section “Attending the event”.
- Types of data processed: Master data (e.g. names of buyers and ticket holders); contact data (email address); contract and order data; payment data (payment method and status; account data only for bank transfers to our association account); meta and communication data (e.g. IP address); health data (companion ticket only, mark “B”).
- Data subjects: Ticket buyers; ticket holders; visitors; prospects.
- Purposes of processing: Providing contractual services and fulfilling contractual obligations; communication; security measures (preventing misuse and multiple use); accounting.
- Retention and deletion: We keep order and invoice data in line with the statutory periods (see “General information on data retention and deletion”). We delete or anonymise other participant data as soon as it is no longer required.
- Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR); legal obligation (Art. 6(1)(1)(c) GDPR); legitimate interests (Art. 6(1)(1)(f) GDPR); consent (Art. 9(2)(a) GDPR) for the companion ticket.
Payment methods
In the context of contractual and other legal relationships, we offer data subjects efficient and secure payment options and use, besides banks, further service providers for this purpose (together “payment service providers”). According to our AGB, the ticket shop offers bank transfer, PayPal and credit card. Payments are made exclusively over encrypted connections.
You enter payment data (e.g. credit card number, PayPal credentials) directly with the respective payment service provider, where it is processed. We do not receive account or credit card data, only the confirmation or rejection of the payment. For bank transfers we receive the information visible on the account statement (name, IBAN, payment reference). Payment service providers may, in certain circumstances, pass data to credit agencies for identity and credit checks; please refer to their privacy notices.
- Types of data processed: Master data; payment data; contract and order data; meta and communication data.
- Data subjects: Ticket buyers; donors; business and contractual partners.
- Purposes of processing: Providing contractual services and fulfilling contractual obligations; accounting.
- Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR); legal obligation (Art. 6(1)(1)(c) GDPR).
Further information on processing operations, procedures and services:
- PayPal: Payment services; Service provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg; Legal basis: Performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR); Website: https://www.paypal.com/en; Privacy policy: https://www.paypal.com/en/legalhub/paypal/privacy-full.
- Stripe (credit card payment): Payment services (technical connection of online payment methods); Service provider: Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland; Stripe may transfer data to Stripe, Inc., 354 Oyster Point Boulevard, South San Francisco, CA 94080, USA; Legal basis: Performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR); Website: https://stripe.com; Privacy policy: https://stripe.com/privacy; Basis for third-country transfers: Data Privacy Framework (DPF).
- Bank transfer: For payment by transfer, the association’s account-holding bank processes the payment data as an independent controller.
Attending the event, youth protection, photos and video
Entry and security checks: Security checks (e.g. bag checks) may take place when entering the venue (Section 6 AGB). No personal data is stored in the process. The check serves the safety of all visitors (Art. 6(1)(1)(f) GDPR).
Youth protection: Children up to and including 13 years old may only attend HanaCon accompanied by a parent or legal guardian or by an adult authorised under the German Youth Protection Act. We process the information required for this (e.g. names of the child and the accompanying person and the guardian’s signature on the consent form) only for checks at admission. Where we retain consent forms, we destroy them after the event. The legal bases are our legal obligation regarding youth protection and our legitimate interest in enforcing age requirements (Art. 6(1)(1)(c) and (f) GDPR).
Photo and video recordings: At HanaCon, the organiser and accredited press representatives take photos and videos to document the event and report on it publicly (e.g. on our website, on our social media channels, in aftermovies and in the press). We point this out at the entrance and in the AGB (Section 6). The legal basis is our legitimate interest in documentation and public relations (Art. 6(1)(1)(f) GDPR in conjunction with Section 23(1) no. 3 of the German Art Copyright Act (KUG), insofar as images of events are published in which the persons depicted took part). This is not based on consent. Your right to object (Art. 21 GDPR) therefore remains unaffected: if you are recognisable in an image and wish to object to its publication, write to us at ; we will then remove the image unless overriding reasons prevent this. Other visitors who take recordings are responsible for them themselves.
- Types of data processed: Master data (names); content data (photos, videos); admission data.
- Data subjects: Visitors; minors and their legal guardians; crew; artists and programme participants.
- Purposes of processing: Security measures; youth protection; public relations and information; documentation.
- Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR); legal obligation (Art. 6(1)(1)(c) GDPR).
User accounts and single sign-on
For members, crew members and other authorised persons we operate a central login system (single sign-on) at sso.hanacon.de based on the open-source software Authentik, which we run ourselves on our servers. With an account you can log in to our web services (e.g. the website, the ticketing system or internal tools, as far as released for your role). Accounts are only created for persons we have set up for this purpose.
We process username, name, email address, password (in encrypted form as a hash), group or role membership, and login and log data (e.g. time, IP address, device). Technically necessary session cookies are set for login (Section 25(2) no. 2 TDDDG). The account is deleted when the authorisation ends; for members, when membership ends.
- Types of data processed: Master data; contact data; log data; meta, communication and procedural data.
- Data subjects: Members; crew and team members; other authorised persons.
- Purposes of processing: Provision of our online offering; security measures; organisational and administrative procedures.
- Legal bases: Membership contract (bylaws) or performance of a contract (Art. 6(1)(1)(b) GDPR); legitimate interests (Art. 6(1)(1)(f) GDPR).
Applications and registrations for programme and participation areas
For applications and registrations, e.g. as an artist, show act, for the fashion area or as a content creator, we use online forms from Microsoft Forms. We process the data you provide (e.g. name, artist name, contact data, information about your offering, links to a portfolio or social media profiles, and uploaded content) in order to review your application, communicate with you and, if accepted, organise your participation. Only the responsible crew members have access. We delete data of rejected applications at the latest after the end of the event, and data of accepted applications as soon as it is no longer needed for the organisation and handling of the event, subject to statutory retention periods.
If we use other form services for further areas (e.g. crew or vendor registrations), this information applies accordingly; we will then add the relevant provider to this policy.
- Types of data processed: Master data; contact data; content data (e.g. descriptions, images, files); meta and communication data.
- Data subjects: Applicants; prospects; business and contractual partners.
- Purposes of processing: Taking pre-contractual steps; organisational and administrative procedures; communication.
- Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR); legitimate interests (Art. 6(1)(1)(f) GDPR).
- Microsoft Forms: Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; Website: https://www.microsoft.com/microsoft-365/online-surveys-polls-quizzes; Privacy policy: https://privacy.microsoft.com/privacystatement; Basis for third-country transfers: Data Privacy Framework (DPF) and standard contractual clauses.
Presentation of team and crew members
On our website (e.g. on the “Crew” page) we present our team. Where the respective team member has agreed, we publish name or nickname, photo, area of responsibility, pronouns and links or usernames to personal profiles (e.g. Instagram, Twitch, Discord). The legal basis is the consent of the person concerned (Art. 6(1)(1)(a) GDPR), which can be withdrawn at any time with effect for the future; we then remove the information without delay. For the names of the chairpersons in the legal notice and in this policy, our legal obligation applies (Art. 6(1)(1)(c) GDPR). Linked profiles are subject to the privacy policy of the respective provider.
Communication by email and phone
If you contact us by email or phone, we process the information you give us (e.g. name, contact data, content of your enquiry) to handle and answer your request. We send and receive emails through our own mail server. Data is deleted once your enquiry has been fully dealt with and no retention obligations prevent this; where a contract is involved, the statutory periods apply.
- Types of data processed: Contact data; content data; meta and communication data.
- Data subjects: Communication partners; prospects.
- Purposes of processing: Communication; organisational and administrative procedures.
- Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR); legitimate interests (Art. 6(1)(1)(f) GDPR).
Internal crew communication (Discord)
For internal coordination of the crew we use a non-public Discord server. Access is limited to members and crew members. We process the content you post there (e.g. messages, files, voice communication) and your Discord username. Discord also processes usage and device data as an independent controller under its own privacy policy. Please do not post data of ticket buyers or visitors there unless it is required for your task.
- Types of data processed: Master data (username); content data; meta, communication and procedural data.
- Data subjects: Members; crew and team members.
- Purposes of processing: Communication; organisational and administrative procedures.
- Legal bases: Membership contract (bylaws) (Art. 6(1)(1)(b) GDPR); legitimate interests (Art. 6(1)(1)(f) GDPR).
- Discord: Service provider for users in the EEA: Discord Netherlands B.V., Schiphol Boulevard 195, 1118 BG Schiphol, Netherlands; Website: https://discord.com; Privacy policy: https://discord.com/privacy; Basis for third-country transfers: Data Privacy Framework (DPF).
Provision of the online offering and web hosting
We process users’ data in order to provide our online services. For this purpose we process the user’s IP address, which is necessary to deliver the content and functions of our online services to the user’s browser or device. We load the fonts (including Google Fonts) and scripts of our website from our own servers. The exceptions are the services described in the section “Embedded content”, which you activate yourself.
- Types of data processed: Usage data; meta, communication and procedural data (e.g. IP addresses, timestamps); log data (e.g. log files on logins, data retrieval or access times).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of our online offering and user-friendliness; IT infrastructure; security measures.
- Retention and deletion: Deletion in accordance with the section “General information on data retention and deletion”.
- Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR).
Further information on processing operations, procedures and services:
- Provision on our own server hardware: Our website, the ticket shop, the login system, the mail server and other services run on servers that we operate and administer ourselves. We rent the underlying servers as dedicated servers from Hetzner (see below) at locations in Falkenstein and Nuremberg (Germany). We create regular backups of our systems; Legal basis: Legitimate interests (Art. 6(1)(1)(f) GDPR).
- Collection of access data and log files: Access to our online offering is logged in so-called “server log files”. These may include the address and name of the pages and files accessed, date and time of access, data volumes transferred, notification of successful access, browser type and version, the user’s operating system, referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. Server log files are used for security purposes, e.g. to avoid overloading the servers (in particular in the event of abusive attacks, so-called DDoS attacks), and to ensure server capacity and stability; Legal basis: Legitimate interests (Art. 6(1)(1)(f) GDPR). Deletion of data: Log file information is stored for a maximum of 30 days and then deleted or anonymised. Data whose further retention is required for evidentiary purposes is excluded from deletion until the respective incident has been finally clarified.
- Short links (hnc.li): For references in social media, print and promotional material we use our own short-link service at hnc.li. When you open a short link, your request and technical connection data (e.g. time, referrer, browser and device information) are processed and you are redirected to the target page. The service runs on our own servers; Legal basis: Legitimate interests (Art. 6(1)(1)(f) GDPR).
- Wordfence: Security plugin (firewall, malware scan, protection against brute-force attacks on logins) on hanacon.de. Wordfence logs on our server in particular IP addresses, requested addresses, browser information and login attempts including usernames, in order to detect and repel attacks. To update protection rules and block lists, the plugin exchanges data with the manufacturer’s servers; technical information such as the IP addresses of suspicious requests and our website’s address may be transmitted. Wordfence sets technically necessary security cookies for logged-in users; Service provider: Defiant, Inc. (Wordfence), 800 5th Ave Ste 4100, Seattle, WA 98104, USA; Legal basis: Legitimate interests (Art. 6(1)(1)(f) GDPR) in the security of our online offering; Website: https://www.wordfence.com; Privacy policy: https://www.wordfence.com/privacy-policy/; Data processing: https://www.wordfence.com/data-processing-addendum/; Basis for third-country transfers: Standard contractual clauses.
- Hetzner: Provision of IT infrastructure (dedicated servers, network connectivity); Service provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany; Legal basis: Legitimate interests (Art. 6(1)(1)(f) GDPR); Website: https://www.hetzner.com; Privacy policy: https://docs.hetzner.com/general/company-and-policy/data-protection-at-hetzner; Data processing agreement: https://docs.hetzner.com/general/company-and-policy/data-protection-at-hetzner.
Use of cookies and browser storage
The term “cookies” refers to functions that store information on users’ devices and read it from them. Besides classic cookies this includes your browser’s Local Storage and Session Storage. We use cookies in accordance with the legal requirements. Where required, we obtain users’ consent in advance. Where consent is not necessary, we rely on our legitimate interests. This applies where storing and reading information is essential to provide content and functions you have expressly requested, for example storing settings and ensuring the functionality and security of our online offering. Consent can be withdrawn at any time.
Notes on legal bases: Whether we process personal data using cookies depends on consent. Where consent has been given, it is the legal basis (Art. 6(1)(1)(a) GDPR, Section 25(1) TDDDG). Without consent we rely on our legitimate interests (Art. 6(1)(1)(f) GDPR, Section 25(2) no. 2 TDDDG).
Storage period: The following types of cookies are distinguished by storage period:
- Temporary cookies (session cookies): Temporary cookies are deleted at the latest after a user leaves an online offering and closes their device (e.g. browser).
- Permanent cookies: Permanent cookies remain stored even after the device is closed. Unless we give users explicit information on the type and storage period of cookies, they should assume that cookies are permanent and that the storage period can be up to two years.
What we use:
- Consent management (Complianz): We store your cookie choice in a cookie with the prefix “cmplz_” (storage period: up to 365 days) so that we do not ask you again on every visit. Technically necessary (Section 25(2) no. 2 TDDDG).
- Language setting (Polylang): The cookie “pll_language” stores your chosen language (storage period: one year). Technically necessary (Section 25(2) no. 2 TDDDG).
- WordPress session and login cookies and security cookies (Wordfence): Only for logged-in users, for login and security. Technically necessary.
- Ticket shop (pretix): To manage your shopping cart and order, the ticket shop sets technically necessary session cookies.
- Display settings (Local Storage): Your choice between light and dark design and the favourites you mark in the programme schedule are stored only locally in your browser. The data is not transmitted to us. It remains stored until you delete it in your browser.
- Session Storage: For the duration of the session we remember that you have already seen the loading animation or closed the newsletter window. The data is deleted when you close the browser tab.
- Embedded content (YouTube, Google Maps, TikTok): YouTube and TikTok may use their own cookies or similar technologies only after your click or consent. When the map on hanacon.de loads, Google may store information in your browser (see the section “Embedded content”).
- Web analytics (Matomo): Cookies with the prefix “_pk_” are only set after your consent (see the section “Web analytics (Matomo)”).
General notes on withdrawal and objection (opt-out): Users can withdraw their consent at any time and also object to processing in accordance with the legal requirements, including via their browser’s privacy settings.
Cookie settings / opt-out: You can change your selection at any time using the “Manage consent” button on our website. Further information is available in our cookie policy: https://hanacon.de/cookies-eu
- Types of data processed: Meta, communication and procedural data (e.g. IP addresses, timestamps, device information); usage data.
- Data subjects: Users (e.g. website visitors).
- Legal bases: Consent (Art. 6(1)(1)(a) GDPR, Section 25(1) TDDDG); legitimate interests (Art. 6(1)(1)(f) GDPR, Section 25(2) no. 2 TDDDG).
Further information on processing operations, procedures and services:
- Complianz: Consent management (cookie banner); Service provider: The plugin runs on our own servers; no data is transmitted to the plugin’s provider; Legal basis: Legal obligation (Art. 6(1)(1)(c) GDPR); Website: https://complianz.io.
Newsletter and electronic notifications
We send newsletters, emails and other electronic notifications (hereinafter “newsletter”) only with the recipients’ consent. We use them to inform about our event, ticket sales (e.g. sale start and price tiers), the programme and news from the association. You can sign up using the form in the navigation menu or via the newsletter window that appears on the home page after you have spent some time on the page or scrolled past the ticket section. Your browser remembers that you closed the window only for the current session.
Your email address is required for signing up; you can optionally give your first name so that we can address you personally. By ticking the box you confirm that you have taken note of this privacy policy and consent to receiving the newsletter at your address. To prove your consent, we store the sign-up with time and IP address as well as your confirmation in the double opt-in procedure. The newsletter is managed with the WordPress plugin “Newsletter” on our own servers and sent through our own mail server. Data is not passed on to external newsletter services.
Newsletters may contain performance measurement functions (e.g. whether an email was opened or a link was clicked). This evaluation takes place exclusively on the basis of your consent and serves to improve our content.
Cancellation/withdrawal: You can unsubscribe from the newsletter at any time, e.g. via the unsubscribe link at the end of each email, or by sending us an informal message at . The lawfulness of processing carried out until then remains unaffected. After unsubscription we delete your data; we may only keep your email address and the proof of consent and unsubscription, on the basis of our legitimate interests in defending legal claims, until the limitation period (three years) has expired, in order to prevent renewed sending and to provide evidence.
- Types of data processed: Master data (first name); contact data (email address); meta, communication and procedural data (e.g. IP address, time of sign-up); usage data (where performance measurement is active).
- Data subjects: Communication partners; prospects; newsletter subscribers.
- Purposes of processing: Direct marketing (e.g. by email); communication; public relations and information.
- Retention and deletion: Deletion in accordance with the section “General information on data retention and deletion”.
- Legal bases: Consent (Art. 6(1)(1)(a) GDPR); legitimate interests (Art. 6(1)(1)(f) GDPR) for evidence.
- Opt-out: You can cancel receipt of our newsletter at any time, i.e. withdraw your consent or object to further receipt.
Web analytics (Matomo)
Web analytics serves to evaluate visitor flows to our online offering and includes collecting usage information of visitors in pseudonymous form. We can see when our online offering and its functions are used most, and can thus, for example, improve ticket sales and the clarity of the site.
For this purpose we use the open-source software Matomo, which we run on our own servers at analytics.hanacon.de for hanacon.de and verein.hanacon.de. The data does not leave our infrastructure and is not passed on to third parties. Matomo is activated only after your consent (category “Statistics”) in the cookie banner. Without your consent no analysis takes place.
With your consent we collect in particular: pages and page titles viewed, time, time spent, the previously visited page (referrer), screen resolution, browser, operating system and device type (including the device information provided by the browser, so-called client hints), the IP address (truncated before storage) and a pseudonymous visitor identifier stored in cookies with the prefix “_pk_”. We also measure the following interactions as events: clicks on ticket buttons and on the link to the ticket shop, reaching the ticket section, scroll depth (25/50/75/100%), first steps in the ticket widget (changing quantity, expanding variants, clicking “Add to cart”), and display, closing and submission of the newsletter window. Content you enter (e.g. your email address or order data) is not transmitted to Matomo.
- Types of data processed: Usage data; meta, communication and procedural data.
- Data subjects: Users (e.g. website visitors).
- Purposes of processing: Audience measurement (e.g. access statistics, recognition of returning visitors); optimisation of the online offering and ticket sales.
- Retention and deletion: We delete raw data of individual visits after 12 months; after that only aggregated statistics without personal reference remain. Cookies: generally up to 13 months.
- Legal bases: Consent (Art. 6(1)(1)(a) GDPR, Section 25(1) TDDDG).
- Withdrawal: You can withdraw your consent at any time with effect for the future using the “Manage consent” button.
- Matomo: Service provider: self-hosted on our servers; Website: https://matomo.org.
Embedded content (YouTube, Google Maps)
On our home page we embed a video (aftermovie) from YouTube. The preview image is stored on our own server. The video is only loaded when you click the preview; before that, no connection to YouTube or Google is made. Only with the click is a connection made to YouTube’s servers (in the privacy-enhanced variant youtube-nocookie.com), whereby, among other things, your IP address and information about your browser are transmitted to YouTube, and YouTube may use cookies or similar technologies. We have no influence on further processing by YouTube. By clicking you consent to the data transfer; if you have a Google account, YouTube may associate the use with your account.
- Types of data processed: Usage data; meta, communication and procedural data.
- Data subjects: Users (e.g. website visitors).
- Purposes of processing: Providing video content; public relations.
- Legal bases: Consent (Art. 6(1)(1)(a) GDPR, Section 25(1) TDDDG), given by clicking the preview or via the cookie banner.
- YouTube: Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Website: https://www.youtube.com; Privacy policy: https://policies.google.com/privacy; Basis for third-country transfers: Data Privacy Framework (DPF).
Google Maps
On hanacon.de, on pages that show the venue (e.g. the info page and event pages), we embed an interactive map from Google Maps. The map script is loaded asynchronously as soon as the map appears in the visible area of the page. A connection to Google’s servers is then established automatically, without you first making a separate choice. Google receives in particular your IP address, information about your browser and device, the page you are viewing and the venue address, which is queried to display the map. Google may use cookies or similar technologies and load further resources (e.g. map tiles). We have no influence on further processing by Google. You can prevent the connection by not scrolling down to the map or by blocking scripts from maps.googleapis.com in your browser. You also have a right to object under Art. 21 GDPR (see “Rights of data subjects”). On verein.hanacon.de, by contrast, Google Maps is only loaded after your consent (category “Marketing”).
- Types of data processed: Usage data; meta, communication and procedural data (e.g. IP address).
- Data subjects: Users (e.g. website visitors).
- Purposes of processing: Showing the venue and helping with travel directions.
- Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR) on hanacon.de; consent (Art. 6(1)(1)(a) GDPR, Section 25(1) TDDDG) on verein.hanacon.de.
- Google Maps: Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Website: https://cloud.google.com/maps-platform; Privacy policy: https://policies.google.com/privacy; Basis for third-country transfers: Data Privacy Framework (DPF).
Association website (verein.hanacon.de)
On our association website verein.hanacon.de we present the association and its projects. There we additionally embed videos from YouTube (in the standard variant youtube.com) and posts from TikTok. These contents and Google Maps are only loaded after you have consented to the “Marketing” category in the cookie banner; until then a placeholder is shown. When they load, YouTube or TikTok receive your IP address and device information on their servers and may use cookies or similar technologies. The legal basis is your consent (Art. 6(1)(1)(a) GDPR, Section 25(1) TDDDG), which you can withdraw at any time via “Manage consent”. Providers and privacy policies: YouTube see above; TikTok see the section “Presences in social networks”.
Fonts and other content
We host fonts, including Google Fonts, locally on our own server. No connection to Google Fonts is made when you open our website. Linked target pages, for example to social media profiles, the venue or partners, are subject to the privacy policy of the respective provider; we have no influence on their processing. The buttons for sharing content (e.g. via WhatsApp or Telegram) are plain links: only when you click them do you leave our site, and data is transmitted to the respective provider.
Presences in social networks (social media)
We maintain online presences within social networks and process users’ data in this context in order to communicate with users active there or to offer information about us. On our website the profiles are only linked; no feeds or plug-ins of these networks are embedded (exception: individual posts on verein.hanacon.de, see “Embedded content”). Should we embed content from social networks on hanacon.de in future, we will amend this policy. Only when you click a link do you leave our website, and the privacy policy of the respective network applies.
Please note that users’ data may be processed outside the European Union. Networks generally also collect usage data for advertising purposes and create usage profiles. Where networks provide us with reach statistics (e.g. “Insights”), we are jointly responsible with the network for this processing (Art. 26 GDPR). The respective provider is responsible for all other processing on the platform; you can therefore exercise data subject rights most effectively there.
- Types of data processed: Contact data; content data (e.g. comments, messages, posts); usage data; meta, communication and procedural data.
- Data subjects: Users of the networks.
- Purposes of processing: Communication; feedback; public relations and information.
- Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR).
Further information on processing operations, procedures and services:
- Instagram: Social network; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Privacy policy: https://privacycenter.instagram.com/policy/; Basis for third-country transfers: Data Privacy Framework (DPF).
- TikTok: Social network; Service provider: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland; Privacy policy: https://www.tiktok.com/legal/page/eea/privacy-policy/en; Basis for third-country transfers: Standard contractual clauses.
- YouTube (channel): Social network and video platform; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Privacy policy: https://policies.google.com/privacy; Basis for third-country transfers: Data Privacy Framework (DPF).
- X (formerly Twitter): Social network; Service provider: X Internet Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland; Privacy policy: https://x.com/en/privacy; Basis for third-country transfers: Standard contractual clauses.
- Twitch: Live-streaming platform; Service provider: Twitch Interactive, Inc., 350 Bush Street, San Francisco, CA 94104, USA; Privacy policy: https://www.twitch.tv/p/en/legal/privacy-notice/; Basis for third-country transfers: Data Privacy Framework (DPF).
Privacy information for whistleblowers
We have set up a contact point where reports of legal violations or grievances within the association can be made, e.g. under the German Whistleblower Protection Act (HinSchG). You can send reports by email to our Data Protection Officer, Lucian Sander: .
We process the information contained in a report, in particular information on the reporting person (unless reported anonymously), on the persons named in the report and on the facts, in order to review and clarify the report and, where appropriate, take follow-up measures. The identity of the reporting person is treated confidentially and is only passed on to the persons responsible for handling the report; it is only disclosed where the law permits or requires this. The documentation is kept for three years after the procedure is concluded and then deleted, unless further retention is necessary (Section 11(5) HinSchG).
- Types of data processed: Master data; contact data; content data (information in the report).
- Data subjects: Whistleblowers; persons affected by or named in the report.
- Purposes of processing: Whistleblower protection; clarification of grievances; fulfilment of legal obligations.
- Legal bases: Legal obligation (Art. 6(1)(1)(c) GDPR in conjunction with the HinSchG); legitimate interests (Art. 6(1)(1)(f) GDPR).
Changes and updates
We ask you to inform yourself regularly about the content of our privacy policy. We will adapt the policy as soon as changes to the data processing we carry out make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g. consent) or other individual notification.
Where we give addresses and contact information of companies and organisations in this policy, please note that addresses may change over time, and please check the information before contacting them.
Definitions
This section gives you an overview of the terms used in this privacy policy. Where terms are legally defined, the legal definitions apply. The following explanations are mainly intended to aid understanding.
- Master data: Master data comprises essential information needed to identify and manage contractual partners, user accounts, profiles and similar assignments (e.g. names, contact details).
- Content data: Content data comprises information generated in the creation, editing and publication of content of any kind (e.g. texts, images, videos).
- Meta, communication and procedural data: Information about how data is processed, transmitted and managed (e.g. IP addresses, timestamps, device and browser information).
- Usage data: Information about the behaviour and interactions of users with our online offering (e.g. pages visited, clicks, time spent).
- Personal data: Any information relating to an identified or identifiable natural person.
- Pseudonymisation: Processing of personal data in such a manner that it can no longer be attributed to a specific person without the use of additional information.
- Controller: The person or body that, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Processing: Any operation performed on personal data, e.g. collecting, storing, using, transmitting or deleting.