Privacy policy

The name and address of the person responsible:

Technische Universität Ilmenau
Legally represented by the president
Ehrenbergstraße 29
98693 Ilmenau

Data protection officer

TU Ilmenau | Universitätsrechenzentrum
Helmholtzplatz 7
98693 Ilmenau
Germany
Phone: +49 3677 69-2524
E-Mail: datenschutz@tu-ilmenau.de

General Information on Data Processing

1. Scope of Personal Data Processing

We process personal data of our users only to the extent necessary to provide a fully functional website and our services. Processing of personal data generally occurs only with the user’s consent. Exceptions apply where obtaining prior consent is not feasible and processing is permitted by law.

2. Legal Basis for Processing Personal Data

  • Where consent is obtained, the legal basis is Art. 6(1)(a) GDPR (General Data Protection Regulation).
  • Where processing is necessary for the performance of a contract or pre-contractual measures, the legal basis is Art. 6(1)(b) GDPR.
  • Where processing is necessary to comply with a legal obligation, the legal basis is Art. 6(1)(c) GDPR.
  • Where processing is necessary to protect vital interests of the data subject or another person, the legal basis is Art. 6(1)(d) GDPR.
  • Where processing is necessary to pursue legitimate interests, the legal basis is Art. 6(1)(f) GDPR, provided these do not override the rights and freedoms of the data subject.

3. Data Deletion and Retention

Personal data will be deleted or blocked once the purpose of storage no longer applies. Data may be retained if required by EU or national law. Deletion or blocking also occurs when legally required retention periods expire, unless continued storage is necessary for contract fulfillment.

Use of Processors

This website uses the conference management software Converia, provided by Converia GmbH. The software is hosted by TU Ilmenau; maintenance and support are provided by Converia GmbH.

For card payments (direct debit, girocard, credit cards), Converia GmbH cooperates with Nexi Germany GmbH, Helfmann-Park 7, 65760 Eschborn, and Computop GmbH, Schwarzenbergstraße 2, 96050 Bamberg. In this context, payment amounts, dates, and card data are transmitted to these companies.

All payment data are retained only as long as necessary for payment processing (including handling chargebacks and debt collection) and fraud prevention. Typically, data are deleted no later than 13 months after collection. Further retention may occur to comply with legal obligations or for investigation of fraud. The legal basis for this processing is Art. 6(1)(f) GDPR.

For questions regarding data processing by Nexi or Computop, or to exercise your rights, please contact the data protection officer via the provided address or by email at DPO-DACH@nexigroup.com and dataprotection@computop.com.

Provision of the Website and Logfile Creation

1. Description and Scope

Each time our website is accessed, the system automatically collects data and information from the user’s computer, including: - Browser type and version - User’s operating system - Internet service provider - IP address - Date and time of access

2. Legal Basis

The temporary storage of data and logfiles is based on Art. 6(1)(f) GDPR.

3. Purpose

Temporary storage of the IP address is required to deliver the website content. Logfiles ensure website functionality, help optimize the site, and protect our IT systems. Data are not analyzed for marketing purposes.

4. Retention

Data are deleted when no longer needed. Logfiles are deleted after 14 days.

5. Objection and Deletion

Collection of these data is essential for website operation; no user objection is possible.

Use of cookies

1. Description and Scope

Our website uses cookies—text files stored in your browser. Cookies include unique identifiers to recognize the browser on return visits.

Cookie types:

  • Necessary Cookies (Type 1): Required for website functionality (e.g., participant registration).
  • Functional Cookies (Type 2): Improve comfort and store settings (e.g., language preference).
  • Performance Cookies (Type 3): Collect non-personal usage statistics to improve content.
  • Third-Party Cookies (Type 4): Set by third parties, e.g., social networks.

2. Legal Basis

Processing of data via cookies is based on Art. 6(1)(f) GDPR.

3. Purpose

We use cookies such as:

Name des Cookies Purpose Typ
PHPSESSID Identification of a user session 1
Converia_SID Identification of a frontend user 1

4. Retention and Control

Cookies can be controlled or deleted via browser settings. Disabling cookies may affect website functionality.

Registration & Use of Conference Management Software

1. Scope

Users can register by providing personal data, which are stored in the system. Mandatory fields must be completed; otherwise, registration is denied. Users must actively confirm the data protection agreement before storage.

Typical activities requiring registration include: - Event participation - Submission and review of scientific contributions - Session chairing - Use of planner favorites

Data collected may include: - Login credentials (username, password) - Address and email - Shopping cart and billing data - Contribution information - Conference schedule data - Membership and verification data (e.g., student ID) - Optional fields (pre-registration data, custom fields)

Company/institution name suggestions are automatically provided to ensure consistency; no personal data are disclosed through this feature.

Payment Processing

Various payment options are offered (invoice, transfer, credit card). Sensitive payment data are not stored in the conference system but processed by certified payment providers. Users are redirected to the providers’ sites. Data collected include: - Selected payment method - Invoice amount - Amounts paid - Billing information

Legal basis: Art. 6(1)(a) GDPR if consent is given; Art. 6(1)(b) GDPR if required for contract execution.

Data are deleted once no longer needed, usually within 2 years for login/address data if used for subsequent events. Users may delete or correct data and withdraw registration, unless legal or contractual obligations prevent deletion.

Data Subject Rights

You are a data subject under the GDPR and have the following rights: 1. Right of Access: Request confirmation and details of data processing. 2. Right to Rectification: Correct incomplete or inaccurate personal data. 3. Right to Restrict Processing: Under certain conditions (e.g., accuracy disputed, unlawful processing, pending legal claims, objection to processing). 4. Right to Erasure: Delete data under specific conditions with certain exceptions. 5. Right to Notification: Inform recipients of corrections, deletions, or restrictions. 6. Right to Data Portability: Receive data in a structured, machine-readable format and transmit to another controller. 7. Right to Object: Object to processing based on legitimate interests or public tasks, including profiling. 8. Right to Withdraw Consent: Withdraw consent at any time. 9. Right to Lodge a Complaint: File complaints with a supervisory authority.

List of Processors

Company Address Type of Processing
Converia GmbH Kaufstr. 2-4, 99423 Weimar Maintenance and support
Computop GmbH Schwarzenbergstr. 2, 96050 Bamberg Payment processing