Privacy Notice at a Glance (Summary)
Who is responsible?
Messe Friedrichshafen GmbH, Neue Messe 1, 88046 Friedrichshafen, Germany
Email: info@messe-fn.de
Data Protection Officer: datenschutz@messe-fn.de
What data do we process?
When you visit our website, we process in particular:
- technical connection data (e.g. IP address, browser type, time of access)
- server log files
- Information from contact forms
- Data provided when contacting us by email
- Data relating to booking appointments
- Data when purchasing tickets
- Cookie and usage data, provided you have given your consent
What do we use your data for?
We process personal data in particular for:
- the provision and security of our website
- processing your enquiries
- processing ticket orders
- to arrange appointments
- analysing and optimising our online services
- measuring the effectiveness of our marketing activities
- Displaying embedded content such as videos or maps
Cookies and consent
Our website uses technically necessary cookies and – subject to your consent – analytics, marketing and convenience features.
Your consents are managed via the Usercentrics consent management platform. You may withdraw your consent at any time with future effect.
Which service providers do we use?
To provide and optimise our services, we use, amongst others:
- Platform.sh (hosting)
- Usercentrics (consent management)
- Friendly Captcha (protection against spam and bots)
- Google Analytics
- Microsoft Clarity
- Google Ads
- LinkedIn Insight Tag
- Meta Pixel und Meta Conversions API
- Stape.io (hosting the server-side tracking infrastructure)
- Calendly
- Axess Ticket Shop
- YouTube
- Google Maps
- Mapbox
- OpenStreetMap
Is data transferred to third countries?
Some of the services used may transfer data to recipients outside the European Union, in particular to the USA.
Where necessary, this is done exclusively in accordance with the legal requirements of Articles 44 et seq. of the GDPR and with the implementation of appropriate safeguards.
How long is data stored?
We store personal data only for as long as is necessary for the respective purposes or as required by statutory retention obligations. The data is subsequently deleted or anonymised.
Your rights
You have the right to:
- Access
- Rectification
- Erasure
- Restriction of processing
- Transferability
- Objection to processing
- Withdrawal of consent
- Lodging a complaint with a data protection supervisory authority
Right to lodge a complaint
Competent supervisory authority:
The State Commissioner for Data Protection and Freedom of Information in Baden-Württemberg (LfDI BW)
https://www.baden-wuerttemberg.datenschutz.de
You can find detailed information on the processing of your personal data in the privacy policy below.
Privacy Policy for the INTERBOOT (interboot.com, interboot.de)
Date: July 2026
1. General information
The protection of your personal data is a matter of great importance to Messe Friedrichshafen GmbH. We treat your personal data as confidential and process it exclusively in accordance with the applicable data protection regulations, in particular the General Data Protection Regulation (GDPR), the Federal Data Protection Act (BDSG), the Telecommunications and Digital Services Data Protection Act (TDDDG) and other relevant statutory provisions.
This privacy policy provides you with comprehensive information on what personal data is processed when you visit our website, the purposes for which the processing takes place, the legal basis on which the processing is carried out, who may receive your data, how long your data will be stored, what rights you have as a data subject, and what technical and organisational measures we implement to protect your data.
This Privacy Policy applies exclusively to the INTERBOOT website at www.interboot.de, including all associated subpages and online services.
Where our website contains references to or links to websites operated by other providers, the privacy policies of the respective operators apply exclusively to these external sites. Despite careful monitoring, we accept no responsibility for the content or data protection practices of external websites.
We are constantly developing our website. Similarly, legal requirements, technical procedures or the services we use may change. For this reason, it may be necessary to update this privacy policy from time to time. The current version published on our website shall always apply.
2. Data Controller
The data controller within the meaning of Article 4(7) of the GDPR is:
Messe Friedrichshafen GmbH, Neue Messe 1, 88046 Friedrichshafen, Germany
Telephone: +49 (0)7541 708-0
Email: info@messe-fn.de
Data Protection Officer
If you have any questions regarding data protection or the processing of your personal data, you can contact our Data Protection Officer at any time.
Email: datenschutz@messe-fn.de
3. Definitions
This privacy policy uses the definitions set out in the General Data Protection Regulation (GDPR). To make it easier to understand, we explain the key terms below.
Personal data
Personal data is any information relating to an identified or identifiable natural person. This includes, for example: name, address, telephone number, email address, IP address, location data, online identifiers, customer or ticket numbers.
Processing
Processing refers to any operation or set of operations performed on personal data, whether or not by automated means. This includes, in particular: collection, recording, storage, organisation, structuring, transmission, retrieval, use, erasure, destruction.
Data subject
A data subject is any natural person whose personal data is being processed.
Data controller
The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.
Data processor
A data processor is a natural or legal person who processes personal data exclusively on behalf of the data controller.
4. Principles of data processing
The processing of personal data is carried out exclusively in accordance with the principles set out in Article 5 of the GDPR. In particular, we observe the following principles: Lawfulness, processing in good faith and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, accountability
We implement appropriate technical and organisational measures to protect personal data against loss, manipulation, unauthorised access or other unlawful processing.
5. Provision of the website and server log files
Every time you visit our website, information is automatically transmitted to our website’s server by the browser you are using. This information is temporarily stored in so-called server log files.
Nature and scope of processing
In particular, the following information may be processed: IP address of the requesting device, date and time of access, name and URL of the file accessed, referrer URL (previously visited website), browser used and browser version, operating system used, hostname of the accessing computer, amount of data transferred, HTTP status code, access status.
This data is not, as a matter of principle, combined with other data sources.
Purposes of processing
The data is processed for the following purposes: Ensuring the website connects without disruption, ensuring system security and stability, analysing errors and resolving faults, defending against attempts at misuse and attacks, and the technical administration of the website
Legal basis
Processing is carried out on the basis of Article 6(1)(f) of the GDPR.
Our legitimate interest lies in the secure, stable and efficient provision of our online services.
Retention period
Server log files are generally only stored for as long as is necessary to fulfil the stated purposes. The data is then deleted or anonymised, provided there are no statutory retention obligations to the contrary.
6. Hosting provider
Our website is hosted on the hosting platform of Platform.sh GmbH or its affiliated companies.
Provider
Platform.sh GmbH, Augsburger Straße 746, 70329 Stuttgart, Germany´
Nature and scope of processing
As part of the hosting service, the following data in particular is processed: server log files, IP addresses, technical usage data, communication data, website content, and system and diagnostic data.
Processing is carried out exclusively for the technical provision, maintenance, administration and security of our website.
Data processing on behalf of the controller
A data processing agreement has been concluded with the hosting service provider in accordance with Article 28 of the GDPR.
7. Content Delivery Networks (CDN)
We use Content Delivery Networks (CDN) to optimise our website’s loading times, availability, reliability and security.
Provider
Fastly, Inc., 475 Brannan Street, Suite 300, San Francisco, CA 94107, USA
and
Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg
Amazon CloudFront is used in particular for the technical provision of the CDN service.
Nature and scope of processing
When using a CDN, the following data in particular may be processed: IP address, browser information, device information, timestamps, requested content and files, referrer URL, usage data, technical connection data, log and diagnostic data.
The data is processed in order to deliver content from our website more quickly via geographically distributed servers, to increase the availability of our online service, and to detect and ward off attacks and unauthorised access to the IT infrastructure.
Purposes of processing
- Improving the website’s loading speed and performance
- Optimising availability and reliability
- Protection against overload and cyber-attacks
- Secure and efficient delivery of website content
- Technical fault analysis and system monitoring
Legal basis
Processing is carried out on the basis of Article 6(1)(f) of the GDPR.
Our legitimate interest lies in the secure, stable and high-performance provision of our website.
Transfers to third countries
In connection with the use of Fastly and Amazon CloudFront, the processing of personal data in third countries, in particular the USA, cannot be ruled out.
Where personal data is transferred to third countries, this is carried out exclusively in accordance with Articles 44 et seq. of the GDPR and with appropriate safeguards in place, in particular on the basis of adequacy decisions by the European Commission or appropriate contractual safeguards.
Privacy policies of the providers
https://www.fastly.com/privacy
https://aws.amazon.com/privacy/
Content Delivery Networks (CDNs) may be used to optimise our website’s loading times, availability and security.
A CDN is a network of geographically distributed servers that enables content from our website to be delivered to users more quickly.
8. Cookies and similar technologies
Our website uses cookies and similar technologies to store information on your device or to access information that has already been stored. Cookies are small text files stored by your browser.
In addition, similar technologies may be used, such as: local storage, session storage, pixel technologies, web beacons, tags, SDKs, and similar identification and tracking technologies
Types of cookies
Technically necessary cookies
These cookies are strictly necessary for the website to function. In particular, they enable: page navigation, security features, form functions, load balancing, the storage of privacy settings.
Without these cookies, the website cannot function properly.
Analytics cookies
Analytics cookies help us to better understand how our website is used and to continuously improve our service.
Marketing cookies
Marketing cookies enable the display of personalised advertising and the measurement of the success of advertising campaigns.
Functional cookies
Functional cookies are used to provide additional convenience and personalisation features.
Retention period
Cookies may either:
- be deleted at the end of the browser session (session cookies)
- or remain stored on the device for a defined period (persistent cookies)
The retention period depends on the service in question.
9. Consent Management
We obtain the necessary consent from users prior to the activation of certain cookies, analytics and marketing services. We use the Usercentrics consent management platform to manage and document the consents given by users.
Provider
Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, Germany
Nature and scope of processing
As part of consent management, the following data in particular may be processed: Consent status, date and time of the decision, IP address, device information, browser information, consent ID, log data.
Purposes of processing
Obtaining valid consents, providing evidence of consents given, fulfilling statutory record-keeping obligations, managing withdrawals of consent.
Legal basis
Processing is carried out on the basis of:
Article 6(1)(c) of the GDPR
Article 6(1)(f) of the GDPR
Section 25 of the TDDDG
Withdrawal of consent
Consent that has been given may be withdrawn at any time with effect for the future. Such withdrawal does not affect the lawfulness of any processing carried out prior to the withdrawal.
10. General legal bases for data processing
Unless a more specific legal basis is stated in this privacy policy, the processing of personal data is carried out on the basis of one or more of the following legal bases:
Article 6(1)(a) of the GDPR
Consent of the data subject.
Article 6(1)(b) of the GDPR
Performance of a contract or the implementation of pre-contractual measures.
Article 6(1)(c) of the GDPR
Compliance with legal obligations.
Article 6(1)(f) of the GDPR
Protection of the legitimate interests of our company or third parties, provided that the interests or fundamental rights of the data subject do not take precedence.
11. Analytics, tag management and marketing services
In order to continuously improve our website, measure its reach, monitor the effectiveness of advertising campaigns and tailor our website to your needs, we use analytics, tracking and marketing services from various providers – where technically necessary and subject to your consent.
These services are generally only used if you have consented to the relevant data processing via our consent management system, provided there is no other legal basis.
Depending on the service, personal data may be transferred to servers within or outside the European Union. Where data is transferred to a third country, this is done exclusively in accordance with the requirements of Articles 44 et seq. of the GDPR.
11.1 Google Analytics
Provider
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Parent company:
Google LLC, 1600 Amphitheatre Parkway, Mountain View, California, USA
Nature and scope of processing
Google Analytics is a web analytics service used to statistically analyse the use of our website.
In particular, the following data may be processed: truncated IP address (where IP anonymisation is enabled), browser information, device information, operating system, language settings, screen resolution, referrer URL, pages visited, time spent on the site, click paths, scrolling behaviour, session duration, interactions, cookie IDs, online identifiers.
Google Analytics uses this data to create pseudonymised user profiles.
Purpose
The processing is carried out in particular for the purposes of statistical analysis of the website, optimising our website, improving user-friendliness, measuring the success of individual content, error analysis and measuring reach.
Legal basis
Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG
Retention period
The retention period is determined by the settings we have selected in our Google Analytics account. Once the relevant period has expired, personal data is automatically deleted or anonymised.
Transfers to third countries
The transfer of personal data to servers operated by Google LLC in the USA cannot be ruled out.
Where data is transferred to the USA, this is done on the basis of an adequacy decision by the European Commission (EU-US Data Privacy Framework), provided the recipient is certified accordingly, or on the basis of appropriate safeguards in accordance with Article 46 of the GDPR.
Withdrawal
You may withdraw your consent at any time with future effect via our consent management system.
The provider’s privacy policy
https://policies.google.com/privacy
11.2 Microsoft Clarity
Provider
Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland
Nature and scope of processing
Microsoft Clarity enables the analysis of user behaviour on our website.
The following data, amongst other things, may be processed: mouse movements, scrolling behaviour, click paths, time spent on the site, page views, browser information, screen size, device type, IP address (truncated or pseudonymised), technical usage data.
It is not our intention to directly identify individual visitors.
Purpose
To improve user-friendliness, analyse website usage, identify technical issues, optimise navigation and improve conversion rates
Legal basis
Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG
Retention period
The data is stored in accordance with the configuration of our Clarity account and is subsequently deleted or anonymised.
Transfers to third countries
Personal data may be transferred to the USA.
Microsoft implements appropriate safeguards in accordance with Article 44 et seq. of the GDPR.
Privacy Notice
https://privacy.microsoft.com/de-de/privacystatement
11.3 Google Tag Manager
Provider
Google Ireland Limited
Legal basis
The use of Google Tag Manager is based on Article 6(1)(f) of the GDPR.
Our legitimate interest lies in the efficient, secure and centralised management of the scripts and tags used on our website.
Where analytics, marketing or other services requiring consent are integrated via Google Tag Manager, these are activated only after the necessary consent has been given in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG.
Privacy Notice
https://policies.google.com/privacy
11.3a Google Tag Manager (server-side)
Provider
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Parent company:
Google LLC, 1600 Amphitheatre Parkway, Mountain View, California 94043, USA
Nature and scope of processing
We use a server-side implementation of Google Tag Manager (server-side tagging) to control the technical processing and transmission of measurement, analytics and marketing events via a server-side infrastructure.
Hosting of the Server-Side Infrastructure
For the operation of our server-side tracking infrastructure, we use the following service provider:
Stape Technologies Ltd. (Stape.io)
Processing is carried out in part via a Server-Side Google Tag Manager (sGTM). In this process, tracking information is first processed through a server endpoint operated by us or on our behalf and is subsequently transmitted to the respective analytics and marketing services used.
The use of server-side tracking serves, in particular: to improve data quality, to enhance technical security, to enable more privacy-friendly management of tracking processes, to ensure controlled data transmission to connected services.
Where Stape processes personal data on our behalf, such processing is carried out on the basis of a data processing agreement pursuant to Art. 28 GDPR.
In particular, the following data may be processed in the course of this use: IP address, browser information, device information, HTTP headers, timestamps, Online identifiers, Event data, referrer URL, technical connection data, usage and interaction data.
The server-side Google Tag Manager is used for the technical processing and forwarding of data to the analytics and marketing services we use.
The service itself does not, as a rule, create independent user profiles and is not used for the independent analysis of user behaviour.
Purposes of processing
- technical management of tracking and marketing services
- Improvement of data quality
- Optimisation of security and data protection measures
- Centralised management of tags and interfaces
- Efficient forwarding of event data to integrated services
Legal basis
The operation of the server-side Google Tag Manager is based on Article 6(1)(f) of the GDPR.
Our legitimate interest lies in the secure, efficient and more privacy-friendly technical management of the analytics and marketing services used.
Where analytics, marketing or tracking services are activated via the server-side Google Tag Manager, the respective data processing takes place exclusively on the basis of the consent required for this purpose in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG.
Recipients
Recipients may be the analytics, tracking and marketing service providers we use, to whom event data is forwarded via the server-side Google Tag Manager.
Transfers to third countries
A transfer of personal data to the USA or other third countries cannot be ruled out.
Where a transfer to a third country takes place, this is carried out exclusively in accordance with Articles 44 et seq. of the GDPR and with the use of appropriate safeguards.
The provider’s privacy policy
https://policies.google.com/privacy
11.4 Google Ads and conversion tracking
Nature and scope of processing
We use Google Ads, including conversion tracking, to promote our events and offers.
The following data may be processed: IP address, cookie ID, device information, browser data, interaction data, ad impressions, conversion events.
Purpose
Serving interest-based advertising, measuring the effectiveness of advertising campaigns, conversion tracking, reach analysis
Legal basis
Article 6(1)(a) of the GDPR
Transfer to third countries
Possible to the USA.
Privacy notice
https://policies.google.com/technologies/ads
11.5 Google Remarketing
Purpose
Visitors to our website may be shown interest-based adverts again on other websites within the Google advertising network.
Data processed: cookie ID, browser information, device information, usage behaviour, pages visited
Legal basis
Article 6(1)(a) of the GDPR
11.6 Meta Pixel and Meta Conversions API
Provider
Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland
Nature and Scope of Processing
We use the Meta Pixel and the Meta Conversions API provided by Meta Platforms Ireland Limited ("Meta") on our website. These technologies enable us to measure the success of our advertising campaigns on Facebook and Instagram, analyze user interactions, and optimize our marketing activities.
If you access our website via a Facebook or Instagram advertisement, Meta may recognize which actions are performed on our website (e.g., page views, downloads, form submissions, or other conversion events). This allows us to measure and improve the effectiveness of our advertising activities.
Processed Data
Depending on the respective event, the following data may be processed in particular: IP address, Browser and device information, Pages visited and interactions performed, Referrer URL, Timestamps, Event data (e.g., lead, download, contact request, purchase), Facebook identifiers such as _fbp and _fbc, Where applicable, hashed identifiers (e.g., email address) if used to improve the attribution of conversions.
Purposes of Processing
- Measuring the success of advertising campaigns
- Conversion tracking
- Reach and performance analysis
- Audience creation
- Remarketing
- Optimization of our marketing activities
Legal Basis
Processing is carried out exclusively on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG.
Consent is obtained through our consent management platform Usercentrics. Without your consent, neither the Meta Pixel nor the Meta Conversions API will be activated for marketing purposes.
Google Consent Mode
We use Google Consent Mode. The preferences you select via our consent banner are transmitted to the tracking and marketing services we use. Marketing-related data processing will only take place if the corresponding consent has been granted.
Recipients
The recipient of the data is Meta Platforms Ireland Limited.
Third-Country Transfers
A transfer of personal data to Meta Platforms, Inc. in the United States cannot be ruled out.
Where data is transferred to countries outside the European Union or the European Economic Area, such transfer takes place in accordance with the data protection safeguards provided by Meta and in compliance with Articles 44 et seq. GDPR.
Further information on Meta's data processing practices can be found at:
https://www.facebook.com/privacy/policy/
11.7 Google Marketing Platform
Purpose
The Google Marketing Platform is used to manage, deliver and measure the success of digital marketing campaigns.
Data processed
Cookie IDs, IP address, browser data, device information, usage data, campaign data
Legal basis
Article 6(1)(a) of the GDPR
Transfers to third countries
Possible to the USA.
Privacy notice
https://policies.google.com/privacy
11.8 LinkedIn Insight Tag (campaigns and remarketing)
Provider
LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland
For certain processing operations, data may be transferred to LinkedIn Corporation in the USA.
Nature and scope of processing
Provided you have given your consent, we use the LinkedIn Insight Tag on our website. This is an analytics and marketing service provided by LinkedIn Ireland Unlimited Company.
The LinkedIn Insight Tag enables us to obtain statistical information about the use of our website and the success of our advertising campaigns on LinkedIn. In addition, visitors to our website may be targeted with advertising on the LinkedIn platform (remarketing).
When using the LinkedIn Insight Tag, the following personal data in particular may be processed: IP address, device information, browser information, cookie IDs, timestamps, referrer URL, pages visited, click and interaction data, conversion data, pseudonymous online identifiers.
LinkedIn processes some of this information in pseudonymised form and provides us exclusively with aggregated statistical analyses. We do not directly identify individual visitors.
Purposes of processing
The data is processed for the following purposes: Measuring the success of LinkedIn advertising campaigns, conversion tracking, reach analysis, optimising our marketing activities, creating remarketing audiences, and displaying interest-based advertising on LinkedIn.
Legal basis
Processing is carried out exclusively on the basis of your consent in accordance with Article 6(1)(a) of the GDPR, in conjunction with Section 25(1) of the TDDDG.
Recipients
The recipient of the data is LinkedIn Ireland Unlimited Company and, where applicable, affiliated companies of LinkedIn Corporation.
Transfers to third countries
A transfer of personal data to third countries, in particular to the USA, cannot be ruled out.
Where data is transferred to a third country, this is done exclusively in accordance with Articles 44 et seq. of the GDPR. Where applicable, LinkedIn relies on the European Commission’s adequacy decision (EU-US Data Privacy Framework) or on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
Retention period
The retention period depends on LinkedIn’s settings and the configurations we have made. Personal data will be deleted or anonymised as soon as it is no longer required for the stated purposes or unless statutory retention obligations prevent this.
Withdrawal of consent
You may withdraw your consent at any time with future effect via our consent management system.
The provider’s privacy policy
https://www.linkedin.com/legal/privacy-policy
12. Contact, communication and contract fulfilment
Our website offers you various ways to get in touch with us or to make use of our services. These include, in particular, , contact forms, email communication, booking appointments, ordering tickets and other digital services.
Your personal data will be processed only to the extent necessary and solely for the purposes described below.
12.1 Contact form
Nature and scope of processing
When you use our contact form, we process the personal data you enter.
This includes, in particular: Title, first name and surname, company (optional), email address, telephone number (optional), subject, content of your message, date and time of the enquiry, technical metadata (e.g. IP address, browser information).
Mandatory fields are marked accordingly in the relevant form.
Purposes of processing
Processing is carried out in particular for the purposes of process your enquiry, contact you, answer your questions, prepare for or carry out pre-contractual measures, and document the communication.
Legal basis
Depending on the content of your enquiry, processing is carried out on the basis of:
Article 6(1)(b) of the GDPR, insofar as the enquiry relates to the conclusion or performance of a contract;
Article 6(1)(f) of the GDPR, insofar as we have a legitimate interest in the efficient processing of general enquiries.
Recipients
Within our organisation, access to your data is restricted to those departments that require it to process your enquiry.
Where necessary, IT and hosting service providers may be engaged as data processors in accordance with Article 28 of the GDPR.
Retention period
Your data will be deleted as soon as the processing of your enquiry has been completed and there are no statutory retention obligations or legitimate interests preventing its deletion.
12.2 Contact via email
Nature and scope of processing
If you contact us by email, we will process the personal data you provide.
This may include, in particular: Name, email address, signature data, content of communications, attachments, time of communication, technical transmission data.
Purpose
The processing is carried out to handle your enquiry and to facilitate the requested communication.
Legal basis
Article 6(1)(b) of the GDPR
Article 6(1)(f) of the GDPR
Note
Please note that sending unencrypted emails may pose security risks. Where possible, confidential information should only be sent via suitable, encrypted communication channels.
12.3 CAPTCHA to prevent misuse
We use Friendly Captcha to protect our forms against fraudulent or automated submissions.
Provider
Friendly Captcha GmbH, Am Anger 3–5, 82237 Wörthsee, Germany
Nature and scope of processing
When using Friendly Captcha, technical connection data – in particular the IP address, browser and device information, as well as security-related challenge and verification data – may be processed. This processing is carried out to protect against automated submissions, spam and misuse of our forms.
Purpose
Protection against spam, detection of automated access, ensuring system security, ensuring the proper use of our forms
Legal basis
Friendly Captcha processes technical connection data and security-related information for the purpose of bot detection. According to the provider, no tracking cookies are generally used for advertising or analytical purposes.
Art. 6(1)(f) GDPR
Article 6(1)(a) of the GDPR
Section 25(1) of the TDDDG
Transfers to third countries
Processing generally takes place within the European Union.
12.4 Booking appointments via Calendly
Provider
Calendly LLC, Atlanta, Georgia, USA
Nature and scope of processing
We may use the Calendly service to arrange consultancy meetings or appointments.
When booking an appointment, the following personal data in particular may be processed: First name and surname, email address, telephone number (optional), company, preferred appointment, time zone, communication content, technical metadata
Purpose
Organising appointments, conducting consultation meetings, preparing for business contacts, communicating with prospective clients, exhibitors and visitors
Legal basis
Article 6(1)(b) of the GDPR
Article 6(1)(f) of the GDPR
Transfers to third countries
The transfer of personal data to the USA cannot be ruled out. Where data is transferred to third countries, this is carried out in accordance with Articles 44 et seq. of the GDPR.
Privacy Notice
https://calendly.com/privacy
12.5 Ticket shop
The sale and administration of tickets are handled by our ticketing service provider, Axess.
Axess is a provider of visitor management, ticketing and access solutions for exhibition and conference centres, as well as other event venues.
Provider
Axess AG, Hofgasse 12, A-5630 Bad Hofgastein, Austria
Nature and scope of processing
When ordering, managing and using admission tickets, the following personal data in particular may be processed: First name and surname, billing address, delivery address (if different), email address, telephone number, payment details, order details, ticket details, booking history, customer number, event details, and admission and usage information relating to the use of the ticket.
Purpose
Processing is carried out in particular for the following purposes: Processing ticket purchases, fulfilling contractual obligations, processing payments, creating and sending electronic tickets, managing visitors and access, communicating with customers, handling complaints and support enquiries, and complying with statutory retention obligations.
Legal basis
Article 6(1)(b) of the GDPR
Article 6(1)(c) of the GDPR
Recipients
The recipients of the data are Axess AG and, where applicable, technical service providers, payment service providers and other partners engaged by Axess that are necessary for the performance of the contract.
Where personal data is processed on behalf of Axess, this is done on the basis of appropriate agreements in accordance with Article 28 of the GDPR.
Retention period
Data is retained in accordance with the statutory retention periods under commercial and tax law, and for as long as is necessary for the performance and fulfilment of the relevant contractual relationship.
The provider’s privacy notice
https://teamaxess.com/de/privacy-policy
12.6 Customer communication
Within the framework of existing contractual relationships or in response to enquiries, communication may take place via various channels, in particular via: email, telephone, contact form, post, video conference (where available)
Data processing is carried out solely for the purpose of conducting the relevant communication and on the basis of the applicable legal grounds under the GDPR.
13. Embedded content and external services
To display multimedia content, interactive maps and digital documents, content from external providers may be embedded on our website.
Depending on the technical implementation, a connection to the respective provider’s servers may be established as soon as a page containing embedded content is accessed. In doing so, personal data – in particular the IP address and technical information about the device and browser used – may be processed.
Where your consent is required for the integration of these services, processing will take place exclusively following your prior consent via our consent management system.
13.1 YouTube
Provider
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Parent company:
Google LLC, 1600 Amphitheatre Parkway, Mountain View, California, USA
Nature and scope of processing
Content from the YouTube platform may be used to embed videos.
When a page containing an embedded YouTube video is accessed, the following data in particular may be processed: IP address, browser information, device information, referrer URL, date and time of page view, usage data, cookie IDs (where permitted), interaction data (e.g. starting or pausing a video).
Depending on the type of embedding, the so-called ‘enhanced privacy mode’ may be used. However, data may still be transferred to Google.
Purpose
Provision of multimedia content, improvement of user-friendliness, clear presentation of information and events
Legal basis
Article 6(1)(a) of the GDPR, in conjunction with Section 25(1) of the TDDDG
Transfers to third countries
Personal data may be transferred to Google LLC in the USA. Where necessary, this is carried out on the basis of appropriate safeguards in accordance with Article 44 et seq. of the GDPR.
Privacy Notice
https://policies.google.com/privacy
13.2 Vimeo
Provider
Vimeo Inc., 330 West 34th Street, New York, NY 10001, USA
Nature and scope of processing
Videos from the Vimeo platform may be used to embed video content.
When you visit a page containing a Vimeo video, the following data may be processed in particular: IP address, browser data, device information, referrer URL, usage data, interaction data, cookie information (subject to your consent).
Purpose
Provision of video content, improvement of user-friendliness, presentation of trade fair and event content.
Legal basis
Article 6(1)(a) of the GDPR, in conjunction with Section 25(1) of the TDDDG
Transfers to third countries
Data may be transferred to third countries, in particular to the USA.
Privacy notice
https://vimeo.com/privacy
13.3 Instagram
Provider
Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland
Nature and scope of processing
Content from our Instagram page may be embedded on our website.
When loading such content, the following data in particular may be processed: IP address, browser data, device information, cookie IDs, usage behaviour, interaction data.
Purpose
Display of current content, corporate communications, marketing, increasing reach
Legal basis
Article 6(1)(a) of the GDPR, in conjunction with Section 25(1) of the TDDDG
Privacy notice
https://privacycenter.instagram.com/policy
13.5 Yumpu
Provider
i-magazine AG (Yumpu)
Nature and scope of processing
The Yumpu service may be used to display digital catalogues, brochures or magazines.
In particular, the following data may be processed: IP address, browser information, device information, usage data, referrer URL.
Purpose
Provision of digital publications, improvement of user-friendliness, display of trade fair documents.
Legal basis
Article 6(1)(a) of the GDPR, in conjunction with Section 25(1) of the TDDDG
Privacy notice
https://www.yumpu.com/de/info/privacy_policy
13.6 Google Maps
Provider
Google Ireland Limited
Nature and scope of processing
Google Maps may be used to display interactive maps and to make it easier to find our event venues.
When the maps are loaded, the following data may be processed in particular: IP address, location information (where shared), browser data, device information, usage data.
Purpose
Map display, route planning, location information
Legal basis
Article 6(1)(a) of the GDPR, in conjunction with Section 25(1) of the TDDDG
Privacy notice
https://policies.google.com/privacy
13.7 Mapbox
Provider
Mapbox Inc., Washington, DC, USA
Nature and scope of processing
Mapbox map services may be used as an alternative to or in addition to Google Maps.
The following data may be processed: IP address, browser data, device information, location data (where shared), usage data.
Purpose
Map display, navigation, optimisation of user-friendliness
Legal basis
Article 6(1)(a) of the GDPR, in conjunction with Section 25(1) of the TDDDG
Privacy notice
https://www.mapbox.com/legal/privacy
13.8 OpenStreetMap
Provider
OpenStreetMap Foundation, St John’s Innovation Centre, Cowley Road, Cambridge, United Kingdom
Nature and scope of processing
Data from OpenStreetMap may be used to display map material.
In particular, the following may be processed: IP address, browser information, device information, usage data, technical connection data.
Purpose
Provision of map data, display of event venues, improvement of user-friendliness
Legal basis
Article 6(1)(a) of the GDPR, in conjunction with Section 25(1) of the TDDDG
Privacy notice
https://wiki.openstreetmap.org/wiki/Privacy_Policy
13.9 Information on external content
External content is incorporated solely to enhance the information and services we provide. Although we select providers with care, we have no influence over the nature and scope of data processing carried out by the respective third-party providers.
For further information on the processing of personal data, please refer to the privacy policies of the respective providers.
Very good. Section 5 covers all embedded content and external services. These services are particularly relevant from a data protection perspective, as they frequently reload content from third-party providers and – depending on the technical implementation – may process personal data such as IP addresses or usage data.
13.10 Digital Asset Management
Provider
Bynder B.V., Max Euweplein 46, 1017 MB Amsterdam, Netherlands
Nature and scope of processing
We use the digital asset management platform Bynder to manage and provide images, videos, documents and other media content.
When accessing content provided via Bynder, the following data in particular may be processed: IP address, browser information, device information, referrer URL, timestamp, usage data, technical connection data.
Purpose
The processing is carried out for the purpose of: provide digital media content, managing image and video material, the technical delivery of downloads and multimedia content, optimising the availability and performance of our website.
Legal basis
Article 6(1)(f) of the GDPR
Our legitimate interest lies in the efficient and secure provision of media content on our website.
Where Bynder uses cookies or similar technologies for the storage or delivery of content, their use is carried out exclusively in accordance with the relevant legal provisions.
The provider’s privacy policy
https://www.bynder.com/de/legal/privacy-policy/
14. Recipients of personal data
14.1 Internal recipients
Within Messe Friedrichshafen GmbH, access to personal data is granted only to those departments that require it to fulfil their respective tasks (need-to-know principle).
These include, in particular: Event Management, Customer Service, Sales, Marketing, the IT Department, Financial Accounting, and the Legal and Data Protection Department.
Access is granted exclusively within the scope of the respective areas of responsibility and in compliance with data protection regulations.
14.2 External recipients
To the extent necessary to fulfil the aforementioned purposes, personal data may be transferred to external recipients.
These include, in particular: hosting service providers, IT service providers, ticketing service providers, payment service providers, analytics and marketing service providers, cloud service providers, public authorities in accordance with legal obligations, consultants and auditors, and delivery and communications service providers.
Where external service providers process personal data on our behalf, they do so exclusively on the basis of a data processing agreement in accordance with Article 28 of the GDPR.
15. Transfers to third countries
Some of the services described in this privacy policy are operated by companies based outside the European Economic Area or may require the transfer of personal data to third countries.
Any such transfer takes place exclusively in accordance with Articles 44 et seq. of the GDPR.
Where necessary, the transfer of data is based on:
- an adequacy decision by the European Commission,
- the EU Standard Contractual Clauses (SCCs),
- binding corporate rules,
- or other appropriate safeguards in accordance with the GDPR.
Further information on the respective safeguards can be found in the privacy notices of the relevant providers.
16. Retention period
Unless otherwise specified in this privacy policy, we generally retain personal data only for as long as is necessary to fulfil the relevant processing purposes.
In addition, retention periods may arise in particular from:
- retention obligations under commercial law,
- tax law retention obligations,
- statutory obligations to provide evidence,
- limitation periods,
- legitimate interests in legal defence.
Once the relevant time limits have expired, personal data will be deleted or anonymised.
17. Data security
We implement appropriate technical and organisational measures in accordance with Articles 24 and 32 of the GDPR to protect personal data against loss, destruction, manipulation and unauthorised access.
These include, in particular: Transport encryption using TLS, role-based authorisation models, access controls, data backups, logging of security-related events, regular updates to the systems in use, measures to detect and defend against cyber attacks, and regular reviews of technical and organisational measures.
Despite all security measures, it is not possible to guarantee completely watertight security when data is transmitted over the internet.
18. Rights of data subjects
Under the GDPR, you are entitled in particular to the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to Transferability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent (Article 7(3) of the GDPR)
- The right not to be subject solely to automated decision-making, including profiling (Article 22 of the GDPR), provided that the legal conditions are met.
To exercise your rights, you may contact us at any time using the contact details provided in Section 2.
19. Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedies, you have the right under Article 77 of the GDPR to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes data protection regulations.
The competent data protection supervisory authority for Messe Friedrichshafen GmbH is:
The State Commissioner for Data Protection and Freedom of Information in Baden-Württemberg (LfDI BW)
Lautenschlagerstraße 20, 70173 Stuttgart, Germany
Telephone: +49 711 615541-0
Email: poststelle@lfdi.bwl.de
Website: https://www.baden-wuerttemberg.datenschutz.de
In addition, you may also contact the data protection supervisory authority in your country of habitual residence, your place of work or the location of the alleged infringement.
20. Changes to this Privacy Policy
We reserve the right to amend this privacy policy should this become necessary due to technical developments, changes in the law or new or amended processing of personal data.
The current version published on our website shall apply at all times.