Skip to content

Legal

Privacy policy

Information on the processing of personal data in accordance with the GDPR for the German Legal Tech Summit conference and exhibition on 3 December 2026 in Hannover.

English version

This English version is provided for convenience. In case of any discrepancy, the German version is legally binding. Read the German version

Draft – to be legally reviewed before publication

As of 25 September 2026: adapted to the new website; legal review is still pending.

Contents · 24 sections

of German Legal Tech Summit GmbH · As of 25 September 2026

§ 1 Controller and scope

  1. The controller within the meaning of the General Data Protection Regulation (GDPR) for the processing of personal data in connection with the German Legal Tech Summit conference and exhibition on 3 December 2026 in Hannover and the related digital and organisational services is:
    German Legal Tech Summit GmbH
    Hans-Böckler-Allee 26
    30173 Hannover
    Germany

    Phone: +49 (0)511 547 47 49 46
    Email: info@germanlegaltechhub.com
    Website: www.germanlegaltechsummit.com
    – hereinafter referred to as the “Organiser” or “German Legal Tech Summit GmbH”.
  2. This privacy policy applies to the processing of personal data of exhibitors, sponsors, visitors, participants, speakers, stand staff, employees and other persons involved in the event or communicating with the Organiser.
  3. It applies in particular to the processing of personal data
    1. during sign-up and registration for the event,
    2. in the running and organisation of the conference and exhibition,
    3. in connection with exhibitor and sponsor contracts,
    4. in the issuing and use of personalised participant and exhibitor badges,
    5. in communication with participants, exhibitors, sponsors and speakers,
    6. in connection with digital or virtual event components,
    7. in the taking of photographs and film and audio recordings,
    8. in the use of the Organiser’s website, and
    9. to safeguard the statutory, contractual and legitimate interests of the Organiser.
  4. The Organiser processes personal data exclusively within the framework of the applicable data protection provisions, in particular the GDPR, the German Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG) and – where applicable – the German Telecommunications and Digital Services Data Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, TDDDG).

§ 2 Categories of personal data

  1. In the course of preparing, running and following up the event, the following categories of personal data in particular may be processed:
    1. master data, in particular first name and surname,
    2. contact data, in particular email address, telephone number and postal address,
    3. professional data, in particular company, role, position and field of activity,
    4. registration and event data, in particular sign-up, ticket, attendance, admission and badge data,
    5. contract and billing data of exhibitors and sponsors,
    6. communication data from email, telephone and other communication with the Organiser,
    7. technical data arising from the use of digital event services,
    8. data on consents and their withdrawal,
    9. photographs and film and audio recordings, insofar as such recordings are made in the course of the event,
    10. where applicable, further data that the data subject voluntarily provides to the Organiser.
  2. The provision of personal data is generally voluntary. Where certain data are required for the conclusion or performance of a contract, for registration, for admission to the event or for the provision of a requested service, failure to provide them may mean that the service concerned cannot be provided, or cannot be provided in full.

§ 3 Purposes and legal bases of processing

  1. The Organiser processes personal data in particular for the following purposes:
    1. to prepare, organise and run the conference and exhibition,
    2. to process sign-ups and registrations,
    3. to issue personalised participant and exhibitor badges,
    4. to organise admission and access authorisations,
    5. to perform and administer contracts with exhibitors, sponsors and other contractual partners,
    6. to communicate with participants, exhibitors, sponsors, speakers and service providers,
    7. to provide booked services and digital event components,
    8. for invoicing and payment processing,
    9. to ensure security and the proper running of the event,
    10. to comply with statutory retention, documentation and other obligations,
    11. to establish, exercise or defend legal claims,
    12. to provide information about the event and – where legally permissible – about future events,
    13. for public relations and reporting on the event, and
    14. for the technical and organisational development of the event and the digital services.
  2. Where processing is necessary for the performance of a contract or in order to take steps prior to entering into a contract, it is based on Art. 6(1)(b) GDPR. This applies in particular to registration for the event, the performance of exhibitor and sponsor contracts and the provision of booked services. The Terms and Conditions expressly provide for the processing of personal data for the performance of the contract.
  3. Where the Organiser is required to process personal data by virtue of a legal obligation, processing is based on Art. 6(1)(c) GDPR.
  4. Where processing is necessary for the purposes of the legitimate interests pursued by the Organiser or by a third party and such interests are not overridden by the interests or fundamental rights and freedoms of the data subject, processing is based on Art. 6(1)(f) GDPR. Legitimate interests may include, in particular, the efficient organisation of the event, communication with participants and business partners, public relations, documentation of the event, IT security and the establishment, exercise and defence of legal claims.
  5. Where the Organiser processes personal data on the basis of consent, this is done on the basis of Art. 6(1)(a) GDPR. Consent may be withdrawn at any time with effect for the future.

§ 4 Sign-up and registration

  1. When signing up for the conference and exhibition, the personal data required to process the sign-up and to run the event are collected.
  2. These may include, in particular, first name and surname, company, role, email address, billing data, ticket or registration data and, where applicable, further voluntary information.
  3. In the case of exhibitors and sponsors, personal data of contact persons, of named stand staff and of other participants may also be processed.
  4. The Terms and Conditions expressly provide that stand staff must be named in advance via the designated registration system and that personalised exhibitor badges are not transferable.
  5. Registration/ticketing service provider: Peppermint Digital GmbH, Boulevard der EU 8, 30539 Hannover

§ 5 Payment and billing data

  1. Where payments are to be made for participation or for exhibitor or sponsorship services, the Organiser processes the contract, invoice and payment data required for this purpose.
  2. This may include, in particular, name, company, address, billing address, invoice amount, payment status and other information required for invoicing.
  3. Where external payment service providers are used, the data required for this purpose are transmitted to the respective payment service provider. Payment service provider: Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland
  4. Statutory retention obligations remain unaffected.

§ 6 Management of participants, exhibitors and sponsorship

  1. In order to run the conference and exhibition properly, the Organiser processes personal data of participants, exhibitors, sponsors, speakers and stand staff.
  2. This includes, in particular, assigning persons to companies, exhibition stands, sponsorship packages, talks, programme items and other event services.
  3. Processing is carried out in particular to organise the event, for access control, for communication and to fulfil contractual obligations.
  4. Where exhibitors or sponsors transmit personal data of employees or other persons to the Organiser, the respective contractual partner must ensure that the necessary data protection requirements are met and that the data subjects have been properly informed.

§ 7 Digital and virtual event components

  1. Where the event includes additional digital services, personal data may be processed when these services are used. This may include, in particular:
    1. registration and access data,
    2. login data,
    3. technical connection data,
    4. usage and interaction data,
    5. data on participation in digital programme items,
    6. where applicable, communication and networking data.
  2. The Terms and Conditions expressly provide for additional digital services such as online presences, virtual exhibition stands, streaming slots and access to networking platforms.
  3. The specific data processing operations depend on the technical platforms and service providers used in each case.
  4. Where consent is required for certain functions, it will be obtained before the processing concerned begins.

§ 8 Website, server log files and technical data

  1. When the Organiser’s website is accessed, technically necessary data may be processed that are required for the provision, security and stability of the website. These may include, in particular, the IP address, the date and time of access, the resources requested, the referrer URL, the browser type, the operating system and other technical information.
  2. Where necessary, processing is carried out for the technical provision and security of the website and to safeguard the Organiser’s legitimate interests in a secure and functional online service.
  3. Hosting: The website is operated on a server of Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany, in the Falkenstein data centre (Germany) (processing on behalf under Art. 28 GDPR). No form entries are stored on this server; forms and bookings are forwarded directly to the Organiser’s management system (§ 11).
  4. Where log data are no longer needed and there are no statutory retention obligations or legitimate grounds for longer storage, they are deleted or anonymised.
  5. In-house audience measurement without cookies: In order to understand which content on the website is used, the Organiser counts page views using its own method. No cookies are set, and no information is stored on or read from the end device beyond what is transmitted anyway when a page is accessed. The following are recorded: the page accessed (without parameters), the time, the length of stay, the referring website (its domain only), campaign parameters (utm) where applicable, the device type, the browser and operating system (as a general category), the screen width, the browser language and clicks on links to other websites. The approximate location (city or country) is determined from the IP address. The IP address itself is not stored: to distinguish visits, an irreversible checksum is generated from the IP address and the browser identifier together with a random value that changes daily. The random value is deleted after one day, after which the checksum can no longer be attributed to any person or IP address. Visitors are not recognised across several days. The data are processed in the system of German Legal Tech Hub GmbH (the Organiser’s parent company, processor under Art. 28 GDPR) on servers of the processor Supabase in Frankfurt am Main (EU) and are not passed on to third parties. The legal basis is the Organiser’s legitimate interest in designing its service in line with demand (Art. 6(1)(f) GDPR). The location is determined using the “IP to City Lite” database from DB-IP (db-ip.com, licence CC BY 4.0); no data are transmitted to DB-IP in the process.

§ 9 Cookies and similar technologies

  1. The website sets no cookies and does not integrate any third-party analytics, advertising or marketing services. Audience measurement takes place without cookies (§ 8(5)).
  2. The browser only stores settings that you make yourself (the browser’s local storage, “localStorage”): the chosen display (light, dark or automatic), the accessibility settings and your decision on external media in the privacy notice. These details remain on your device, are not transmitted to the Organiser and are strictly necessary for the service you have expressly requested (Section 25(2) no. 2 TDDDG). You can delete them at any time via your browser settings.
  3. External media are only loaded with your consent – either generally via the privacy notice (“External media”) or in individual cases by clicking on the respective content:
    1. Google Maps (“Plan your visit” page): the provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When the map is loaded, your IP address and browser information in particular are transmitted to Google.
    2. YouTube (videos such as the aftermovie): the provider is also Google Ireland Limited. Videos are loaded in privacy-enhanced mode (youtube-nocookie.com) and only after you click on the video.
    Data may be transferred to Google LLC in the USA; this takes place on the basis of the EU-U.S. Data Privacy Framework, in which Google participates. Further information: policies.google.com/privacy. The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). You can withdraw it at any time with effect for the future via “Cookie settings” in the footer of the website.
  4. Fonts are loaded from the website’s own server; there is no connection to Google Fonts or other font providers.

§ 10 Newsletter and electronic advertising

  1. Where the Organiser offers a newsletter or comparable electronic information, personal data are processed in order to provide the respective communication service.
  2. Promotional contact by email takes place, where required, on the basis of consent or another applicable statutory legal basis.
  3. Consent may be withdrawn at any time with effect for the future. In particular, the unsubscribe option provided in each email may be used for this purpose.
  4. Sign-up for the newsletter uses the double opt-in procedure: after signing up, you will receive an email containing a confirmation link. You will only be added to the mailing list once you have confirmed. As proof of consent (Art. 7(1) GDPR), we store the email address, the time of sign-up and of confirmation, and the IP address used when signing up. The legal basis is Art. 6(1)(a) GDPR.
  5. The sign-up data are stored in our management system (Hub OS). The database is operated by Supabase Inc. as processor on servers in Frankfurt am Main (EU), supabase.com/privacy.
  6. To send the emails, we use Resend, a service of Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA, resend.com/legal/privacy-policy. In the process, the email address and the content of the email are transferred to the USA. The transfer is based on the EU-U.S. Data Privacy Framework, in which Resend participates, and on the EU Standard Contractual Clauses.

§ 11 Communication with participants and business partners

  1. When the Organiser is contacted by email, telephone, contact form or any other means of communication, the personal data transmitted in the process are processed.
  2. Processing is carried out to handle and respond to the respective enquiry and – where necessary – to take steps prior to entering into a contract or to perform a contract.
  3. Communications may be stored to document business transactions and to comply with statutory retention obligations.
  4. Contact and enquiry forms: the details entered in the website’s forms (name, email address and – optionally – company, mobile number, topic and message) are transmitted to the Organiser’s management system (Hub OS), where they are stored and handled as an enquiry; the sender is created as a contact or matched to an existing contact. The IP address is not stored. Hub OS is operated by German Legal Tech Hub GmbH (the Organiser’s parent company) as processor under Art. 28 GDPR; the database is hosted by Supabase Inc. as processor on servers in Frankfurt am Main (EU). The legal basis is Art. 6(1)(b) GDPR where the enquiry relates to a contract, and otherwise Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries).
  5. Booking meetings with exhibitors: anyone who books a meeting with an exhibitor via the website provides their first and last name, email address and – optionally – company, telephone number and topic. The booking is stored in Hub OS and confirmed by email. Where a booking requires a ticket, a check is made as to whether a ticket exists for the email address provided. With your consent, the details are passed on to the chosen exhibitor so that the meeting can take place. The legal basis is Art. 6(1)(b) GDPR (booking) and Art. 6(1)(a) GDPR (disclosure to the exhibitor).

§ 12 Photographs, film and audio recordings

  1. Photographs and film and audio recordings may be made during the conference and exhibition.
  2. The purpose of the recordings is in particular to document and report on the event, as well as the Organiser’s public relations and the promotion of future events.
  3. The Terms and Conditions provide that recordings in which stands, company logos or staff of the contractual partner are recognisable may be used for reporting and for promoting future events in print and online media, provided that no overriding legitimate interests conflict with this.
  4. Where processing is based on the Organiser’s legitimate interests, the interests and fundamental rights of the data subjects are taken into account. Recordings are used for other purposes only where there is an appropriate legal basis for doing so.
  5. For recordings in which individual persons are the deliberate and individual focus, separate consent is obtained in advance where required.
  6. Persons who do not wish to be recorded may generally contact the event staff. However, at a public event it cannot be guaranteed in every case that recordings are avoided entirely.

§ 13 Speakers, presenters and presentations

  1. In the case of speakers and presenters, in addition to general participant data, professional information, roles, company affiliation, presentation topics and photographs and film and audio recordings in particular may be processed.
  2. Where talks are recorded, streamed live or subsequently made available online, this is done only where there is a legal basis for doing so.
  3. Where consent is required for the publication of a talk or of recordings, it will be obtained separately.
  4. English version of the website: the public texts of the website – for speakers, for example, their role, profile text and talk topic, but not contact details – are machine-translated for the English version. For this purpose, only these texts, which are published anyway, are transmitted to the AI service Claude of Anthropic PBC, 548 Market Street, PMB 90375, San Francisco, CA 94104, USA. The transfer is based on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR); under Anthropic’s contractual terms, the data are not used to train AI models. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in an event website in German and English).

§ 14 Recipients of personal data

  1. Personal data are generally transmitted to third parties only where there is a legal basis for doing so and the transmission is necessary for the respective purpose.
  2. Possible recipients or categories of recipients include in particular:
    1. technical service providers and hosting providers,
    2. registration and ticketing service providers,
    3. payment service providers,
    4. IT and software service providers,
    5. service providers for event organisation and admission management,
    6. security and event service providers,
    7. service providers for photo, film and media production,
    8. communication and newsletter service providers,
    9. tax advisers, auditors and other professional advisers,
    10. lawyers and other service providers engaged to enforce rights,
    11. authorities and other public bodies, where there is a legal obligation to do so.
  3. Where service providers process personal data on behalf of the Organiser, the requirements of Art. 28 GDPR are observed.
  4. Personal data are passed on to exhibitors, sponsors or other participants only where there is an appropriate legal basis for doing so, in particular where consent has been given or where disclosure is necessary to provide a requested event service.

§ 15 Transfers to third countries

  1. Personal data are transferred to countries outside the European Union or the European Economic Area only if the requirements of Art. 44 et seq. GDPR are met.
  2. Where data are transferred to a third country in connection with individual service providers, the relevant safeguards and legal bases are taken into account.
  3. This currently concerns Resend (sending emails, § 10), Anthropic (translation of public website texts, § 13) and – only with your consent – Google (map and videos, § 9). The Hub OS database (Supabase) is located in Frankfurt am Main (EU).

§ 16 Storage period and erasure

  1. Personal data are stored only for as long as is necessary for the respective purpose of processing.
  2. Once the respective purpose no longer applies, the data are erased unless statutory retention obligations or other legal bases require further storage.
  3. Data from contractual and billing relationships may be stored beyond the duration of the event, in particular because of retention obligations under commercial and tax law.
  4. Where personal data are required to establish, exercise or defend legal claims, they may be stored until the relevant limitation periods have expired.
  5. The following erasure periods apply in particular to individual categories of data:
    Registration data:
    Until the end of the event or until the registration has been finally processed. Data are stored beyond this only where statutory retention obligations, the establishment, exercise or defence of legal claims or another legal basis so require.
    Participant data:
    Generally until the end of the event and the subsequent organisational wind-up. Where the data are required to comply with statutory retention obligations or to establish, exercise or defend legal claims, they are stored beyond this for the relevant period.
    Invoice and accounting data:
    In accordance with retention obligations under commercial and tax law, generally six, eight or ten years, depending on the type of document.
    Photographs, film and audio recordings:
    Generally for as long as they are necessary for the stated purpose. Where processing is based on consent, the recordings are erased once consent has been withdrawn, unless there is another legal basis or there are legitimate grounds for further storage.
    Newsletter data:
    Until consent is withdrawn or the recipient unsubscribes from the newsletter. After unsubscribing, proof of the consent given and of its withdrawal may be stored for the duration of the relevant statutory limitation and retention periods.
    Server log data:
    Generally for a maximum of 7 days, unless longer storage is necessary in an individual case to maintain security, to investigate security incidents or to establish, exercise or defend legal claims.
    Records of consent:
    For as long as the consent may need to be evidenced, in particular until the relevant statutory limitation periods have expired.

§ 17 Data security

  1. The Organiser takes appropriate technical and organisational measures to protect personal data against loss, destruction, alteration, unauthorised disclosure or unauthorised access.
  2. The scope and nature of the measures taken depend in particular on the state of the art, the scope and purposes of the processing and the respective risk to the rights and freedoms of natural persons.
  3. In the case of digital event components, one hundred per cent availability or absolute security of digital services cannot be guaranteed, despite appropriate technical and organisational measures.

§ 18 Rights of data subjects

  1. Subject to the statutory requirements, data subjects have in particular the following rights:
    a) Right of access
    Data subjects may request confirmation as to whether and which personal data concerning them are being processed, together with the further information provided for by law.
    b) Right to rectification
    Data subjects may request the rectification of inaccurate personal data and, where applicable, the completion of incomplete data.
    c) Right to erasure
    The erasure of personal data may be requested under the statutory conditions.
    d) Right to restriction of processing
    The restriction of processing may be requested under the statutory conditions.
    e) Right to data portability
    Where the statutory requirements are met, there is a right to receive personal data in a structured, commonly used and machine-readable format or to request that they be transmitted to another controller.
    f) Right to withdraw consent
    Consent may be withdrawn at any time with effect for the future. The lawfulness of processing based on consent before its withdrawal remains unaffected.
    g) Right to object
    Where processing is based on Art. 6(1)(e) or (f) GDPR, there is a right to object under the statutory conditions. Objection may be made at any time to the processing of personal data for direct marketing purposes.
  2. To exercise these rights, a message to the following address is generally sufficient:
    German Legal Tech Summit GmbH
    Hans-Böckler-Allee 26
    30173 Hannover
    Germany
    Email: info@germanlegaltechhub.com

§ 19 Right to lodge a complaint with a supervisory authority

  1. Without prejudice to any other administrative or judicial remedy, there is a right to lodge a complaint with a data protection supervisory authority.
  2. The complaint may be lodged in particular with the data protection supervisory authority responsible for the Organiser or with another competent supervisory authority.
  3. The supervisory authority responsible for the Organiser is:
    Der Landesbeauftragte für den Datenschutz Niedersachsen (LfD Niedersachsen – State Commissioner for Data Protection of Lower Saxony)
    Prinzenstraße 5
    30159 Hannover
    Germany
    Phone: 0511 120-4500
    Email: poststelle@lfd.niedersachsen.de
    Website: www.lfd.niedersachsen.de

§ 20 No automated decision-making

  1. As a rule, no automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place in connection with the event.
  2. Should automated decision-making processes be used in future, this privacy policy will be supplemented with the legally required information before or at the time of the processing concerned.

§ 21 Processing of personal data of exhibitors and sponsors

  1. For exhibitors and sponsors, the respective contractual agreements and the General Terms and Conditions of German Legal Tech Summit GmbH apply in addition.
  2. Personal data of contact persons, stand staff and other persons named by the contractual partner are processed in particular to perform the respective contractual relationship, to organise the event and for communication.
  3. The Terms and Conditions oblige contractual partners to comply with applicable data protection law.
  4. Where a contractual partner transmits personal data of its employees, agents or other persons to the Organiser, the contractual partner is responsible for the lawfulness of its own transmission and for providing the necessary information to the data subjects, insofar as required by law.

§ 22 External service providers and processing on behalf of the Organiser

  1. The Organiser may engage external service providers to run the conference and exhibition.
  2. Where these service providers process personal data on behalf of the Organiser, processing takes place on the basis of appropriate data protection agreements.
  3. The Organiser remains the controller under data protection law for the processing operations for which it is responsible.
  4. The specific service providers may come in particular from the fields of registration, ticketing, hosting, IT, payment processing, streaming, networking, newsletters, event organisation and photo, film and media production.

§ 23 Changes to this privacy policy

  1. The Organiser reserves the right to amend this privacy policy where this becomes necessary as a result of legal, technical or organisational changes.
  2. The version published at the time of use or of the collection of personal data applies in each case.
  3. In the event of material changes affecting the rights or interests of data subjects, the Organiser will provide separate information where required by law.

§ 24 Final provisions

  1. Should individual provisions of this privacy policy be or become invalid, the validity of the remaining provisions remains unaffected.
  2. The applicable statutory data protection provisions apply, in particular the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and – where applicable – the German Telecommunications and Digital Services Data Protection Act (TDDDG).

As of 25 September 2026