Privacy Policy of MOTORRADWELT BODENSEE

Status: September 2026

Privacy Notice at a Glance (Summary)

Who is responsible?

Messe Friedrichshafen GmbH
Neue Messe 1
88046 Friedrichshafen
Germany

Email: info@messe-fn.de

Data Protection Officer: datenschutz@messe-fn.de

What data do we process?

When you visit our website, we process in particular:

  • technical connection data (e.g. IP address, browser type, time of access)
  • server log files
  • Information from contact forms
  • Data provided when contacting us by email
  • Data relating to booking appointments
  • Data when purchasing tickets
  • Cookie and usage data, provided you have given your consent

What do we use your data for?

We process personal data in particular for:

  • the provision and security of our website
  • processing your enquiries
  • Processing ticket orders
  • arranging appointments
  • analysing and optimising our online offering
  • measuring the effectiveness of our marketing activities
  • Displaying embedded content such as videos or maps

Cookies and consent

Our website uses technically necessary cookies and – subject to your consent – analytics, marketing and convenience features.
Your consents are managed via the Usercentrics consent management platform. You may withdraw your consent at any time with future effect.

Which service providers do we use?

To provide and optimise our services, we use, amongst other things:

  • Platform.sh (hosting)
  • Usercentrics (consent management)
  • Friendly Captcha (protection against spam and bots)
  • Google Analytics
  • Microsoft Clarity
  • Google Ads
  • LinkedIn Insight Tag
  • Meta Pixel and Meta Conversions API
  • Stape.io (hosting of the server-side tracking infrastructure)
  • Calendly
  • Axess Ticket Shop
  • Vimeo
  • YouTube
  • Instagram
  • Google Maps
  • Mapbox
  • OpenStreetMap
  • TikTok

Is data transferred to third countries?

Some of the services used may transfer data to recipients outside the European Union, in particular to the USA.
Where necessary, this is carried out exclusively in accordance with the legal requirements set out in Articles 44 et seq. of the GDPR and with the implementation of appropriate safeguards.

How long is data stored?

We store personal data only for as long as is necessary for the respective purposes or as required by statutory retention obligations. The data is subsequently deleted or anonymised.

Your rights

You have the right to:

  • Access
  • Rectification
  • Erasure
  • Restriction of processing
  • Data transferability
  • Objection to processing
  • Withdrawal of consent
  • Lodging a complaint with a data protection supervisory authority

Right to lodge a complaint

Competent supervisory authority:
The State Commissioner for Data Protection and Freedom of Information in Baden-Württemberg (LfDI BW)
https://www.baden-wuerttemberg.datenschutz.de

You can find detailed information on the processing of your personal data in the privacy policy below.

Privacy Policy for the MOTORRADWELT BODENSEE 

Date: September 2026

 

1. General information

The protection of your personal data is a matter of great importance to Messe Friedrichshafen GmbH. We treat your personal data as confidential and process it exclusively in accordance with the applicable data protection regulations, in particular the General Data Protection Regulation (GDPR), the Federal Data Protection Act (BDSG), the Telecommunications and Digital Services Data Protection Act (TDDDG) and other relevant statutory provisions.
This privacy policy provides you with comprehensive information on what personal data is processed when you visit our website, the purposes for which the processing takes place, the legal basis on which the processing is carried out, who may receive your data, how long your data will be stored, what rights you have as a data subject, and what technical and organisational measures we implement to protect your data.

This privacy policy applies exclusively to the websites of Messe Friedrichshafen GmbH at www.motorradwelt-bodensee.de, including all associated sub-pages and online services.
Where our website contains references to or links to websites operated by other providers, the privacy policies of the respective operators apply exclusively to these external websites. Despite careful monitoring, we accept no responsibility for the content or data protection practices of external websites.
We are constantly developing our website. Similarly, legal requirements, technical procedures or the services we use may change. For this reason, it may be necessary to update this privacy policy from time to time. The current version published on our website shall always apply.

 

2. Data controller

The data controller within the meaning of Article 4(7) of the GDPR is:
Messe Friedrichshafen GmbH, Neue Messe 1, 88046 Friedrichshafen, Germany
Telephone: +49 (0)7541 708-0
Email: info@messe-fn.de

Data Protection Officer 
If you have any questions regarding data protection or the processing of your personal data, you can contact our Data Protection Officer at any time.
Email: datenschutz@messe-fn.de

 

3. Definitions

This privacy policy uses the definitions set out in the General Data Protection Regulation (GDPR). To make it easier to understand, we explain the key terms below.

Personal data 
Personal data is any information relating to an identified or identifiable natural person. This includes, for example: name, address, telephone number, email address, IP address, location data, online identifiers, customer or ticket numbers.

Processing 
Processing refers to any operation or set of operations performed on personal data, whether or not by automated means. This includes, in particular: collection, recording, storage, organisation, structuring, transmission, retrieval, use, erasure and destruction.

Data subject 
A data subject is any natural person whose personal data is being processed.

Data controller 
The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.

Data processor 
A data processor is a natural or legal person who processes personal data exclusively on behalf of the data controller.

 

4. Principles of data processing

The processing of personal data is carried out exclusively in accordance with the principles set out in Article 5 of the GDPR. In particular, we observe the following principles:
Lawfulness, processing in good faith and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability.
We take appropriate technical and organisational measures to protect personal data against loss, manipulation, unauthorised access or other unlawful processing.

 

5. Provision of the website and server log files

Every time you visit our website, the browser you are using automatically transmits information to our website’s server. This information is temporarily stored in what are known as server log files.

Nature and scope of processing 
In particular, the following information may be processed:
IP address of the requesting device, date and time of access, name and URL of the file accessed, referrer URL (previously visited website), browser used and browser version, operating system used, hostname of the accessing computer, amount of data transferred, HTTP status code, access status.
This data is not, as a matter of principle, combined with other data sources.

Purposes of processing 
Data is processed to ensure the website connects without disruption, to guarantee system security and stability, to analyse errors and resolve faults, to defend against attempts at misuse and attacks, and for the technical administration of the website.

Legal basis 
Processing is carried out on the basis of Article 6(1)(f) of the GDPR.
Our legitimate interest lies in the secure, stable and efficient provision of our online services.

Retention period 
Server log files are generally only stored for as long as is necessary to fulfil the stated purposes. The data is then deleted or anonymised, provided there are no statutory retention obligations to the contrary.

 

6. Hosting provider

Our website is hosted on the hosting platform of Platform.sh GmbH or its affiliated companies.

Provider 
Platform.sh GmbH, Augsburger Straße 746, 70329 Stuttgart, Germany

Nature and scope of processing 
As part of the hosting service, the following data in particular is processed: server log files, IP addresses, technical usage data, communication data, website content, and system and diagnostic data. This processing is carried out solely for the purposes of the technical provision, maintenance, administration and security of our website.

Data processing on behalf of the controller 
A data processing agreement has been concluded with the hosting service provider in accordance with Article 28 of the GDPR.

 

7. Content Delivery Networks (CDN)

So-called Content Delivery Networks (CDNs) may be used to optimise our website’s loading times, availability and security. A CDN is a network of geographically distributed servers through which our website’s content can be delivered to users more quickly. These services are used as technical infrastructure for providing the website and process personal data exclusively on our behalf.

Provider 

Fastly, Inc., 475 Brannan Street, Suite 300, San Francisco, CA 94107, USA

and

Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg

Amazon CloudFront is used in particular for the technical provision of the CDN service.

Nature and scope of processing 
When using a CDN, the following data in particular may be processed: IP address, browser information, device information, timestamps, requested content and files, referrer URL, usage data, technical connection data, log and diagnostic data.

The data is processed in order to deliver content from our website more quickly via geographically distributed servers, to improve the availability of our online services, and to detect and prevent attacks and unauthorised access to our IT infrastructure.

Purposes of processing

  • Improving the website’s loading speed and performance
  • Optimising availability and reliability
  • Protection against overload and cyber-attacks
  • Secure and efficient delivery of website content
  • Technical fault analysis and system monitoring

Legal basis 
Processing is carried out on the basis of Article 6(1)(f) of the GDPR.
Our legitimate interest lies in the secure, stable and high-performance provision of our website.

Transfers to third countries 
In connection with the use of Fastly and Amazon CloudFront, the processing of personal data in third countries, in particular the USA, cannot be ruled out.

Where personal data is transferred to third countries, this is done exclusively in accordance with Articles 44 et seq. of the GDPR and with appropriate safeguards in place, in particular on the basis of adequacy decisions by the European Commission or appropriate contractual safeguards.

Privacy notices of the providers 
https://www.fastly.com/privacy
https://aws.amazon.com/privacy/

 

8. Cookies and similar technologies 

Our website uses cookies and similar technologies to store information on your device or to access information already stored there.
Cookies are small text files stored by your browser.
In addition, similar technologies may be used, such as: local storage, session storage, pixel technologies, web beacons, tags, SDKs, and similar identification and tracking technologies.

8.1 Types of cookies

8.1.1 Technically necessary cookies 
These cookies are strictly necessary for the website to function.
In particular, they enable: page navigation, security functions, form functions, load balancing and the storage of privacy settings.
Without these cookies, the website cannot function properly.

8.1.2 Analytics cookies 
Analytics cookies help us to better understand how our website is used and to continuously improve our service.

8.1.3 Marketing cookies 
Marketing cookies enable us to display personalised adverts and measure the success of advertising campaigns.

8.1.4 Functional cookies 
Functional cookies are used to provide additional convenience and personalisation features.

8.2 Retention period

Cookies may either:

  • be deleted at the end of the browser session (session cookies)
  • or remain stored on the device for a defined period (persistent cookies)

The specific retention period depends on the service used.

 

9. Consent Management

We obtain the necessary consent from users prior to the activation of certain cookies, analytics and marketing services.
We use the Usercentrics consent management platform to manage and document the consents given by users.

Provider 
Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, Germany

Nature and scope of processing 
As part of consent management, the following data in particular may be processed: consent status, date and time of the decision, IP address, device information, browser information, consent ID, log data.

Purposes of processing 
Obtaining valid consent, providing evidence of consent given, fulfilling statutory record-keeping obligations, managing withdrawals of consent.

Legal basis 
Processing is carried out on the basis of Article 6(1)(c) of the GDPR, Article 6(1)(f) of the GDPR and Section 25 of the TDDDG.

Withdrawal of consent 
Consent once given may be withdrawn at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal.

 

10. General legal bases for data processing

Unless a more specific legal basis is stated in this privacy policy, the processing of personal data is carried out on the basis of one or more of the following legal bases:

  • Article 6(1)(a) of the GDPR: consent of the data subject.
  • Article 6(1)(b) of the GDPR: performance of a contract or the implementation of pre-contractual measures.
  • Article 6(1)(c) of the GDPR: compliance with legal obligations.
  • Article 6(1)(f) of the GDPR: the legitimate interests of our company or of third parties, unless the interests or fundamental rights of the data subject take precedence.

 

11. Analytics, tag management and marketing services

In order to continuously improve our website, measure its reach, monitor the effectiveness of advertising campaigns and tailor our website to your needs, we use analytics, tracking and marketing services from various providers – where technically necessary and subject to your consent.
As a general rule, these services are only used if you have consented to the relevant data processing via our consent management system, provided there is no other legal basis.
Depending on the service, personal data may be transferred to servers within or outside the European Union. Where data is transferred to a third country, this is done exclusively in accordance with the requirements of Articles 44 et seq. of the GDPR.

11.1 Google Consent Mode

Nature and scope of processing 
We use Google Consent Mode to technically transmit the data protection and cookie settings you have selected via our consent management system to the Google services we use.

Google Consent Mode enables us to control the use of analytics and marketing services in accordance with your consent decision. This ensures that functions requiring consent are only used within the scope of the consent you have given.

In doing so, information about your consent decision as well as technical information such as browser data, device information, timestamps and technical connection data may be processed.

Purposes of processing 
Processing is carried out for the following purposes: implementing your consent decisions; managing analytics and marketing services in accordance with data protection regulations; verifying and administering consents; and optimising the technical functionality of our website.

Legal basis 
Processing is carried out on the basis of Article 6(1)(c) of the GDPR to fulfil data protection obligations, and on the basis of Article 6(1)(f) of the GDPR on the grounds of our legitimate interest in the data protection-compliant and technically efficient management of the services used.

Where personal data is processed by associated analytics or marketing services, this is done exclusively on the basis of your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG.

Recipients 
The recipient of the data may be Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Transfers to third countries 
A transfer of personal data to Google LLC in the USA cannot be ruled out. Where such a transfer takes place, it is carried out in accordance with Article 44 et seq. of the GDPR.

Further information can be found at: https://policies.google.com/privacy

11.2 Google Analytics

Provider 
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA).

Nature and scope of processing 
Google Analytics is a web analytics service used to statistically analyse the use of our website.
In particular, the following data may be processed: truncated IP address (where IP anonymisation is enabled), browser information, device information, operating system, language settings, screen resolution, referrer URL, pages visited, time spent on the site, click paths, scrolling behaviour, session duration, interactions, cookie IDs, online identifiers.
Google Analytics uses this data to create pseudonymised user profiles.

Purpose 
Data is processed, in particular, for the purposes of statistical analysis of the website, optimising our online offering, improving user-friendliness, measuring the performance of individual content, analysing errors and measuring reach.

Legal basis 
Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG

Retention period 
The retention period is determined by the settings we have selected in our Google Analytics account. Once the relevant period has expired, personal data is automatically deleted or anonymised.

Transfers to third countries 
It cannot be ruled out that personal data may be transferred to servers operated by Google LLC in the USA.
Where data is transferred to the USA, this is done on the basis of an adequacy decision by the European Commission (EU-US Data Privacy Framework), provided the recipient is duly certified, or on the basis of appropriate safeguards in accordance with Article 46 of the GDPR.

Withdrawal 
You may withdraw your consent at any time with future effect via our consent management system.

The provider’s privacy policy: https://policies.google.com/privacy

11.3 Google Tag Manager

Google Tag Manager itself does not process user profiles or store analytics data, but is used solely for the technical integration of other services.

Provider 
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA).

Legal basis 
The use of Google Tag Manager is based on Article 6(1)(f) of the GDPR.

Our legitimate interest lies in the efficient, secure and centralised management of the scripts and tags used on our website.

Where analytics, marketing or other services requiring consent are integrated via Google Tag Manager, these are activated only once the necessary consent has been given in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG.

Privacy Notice: https://policies.google.com/privacy

11.3.1 Google Tag Manager (server-side)

Provider 
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA).

Nature and scope of processing 
We use a server-side implementation of Google Tag Manager (server-side tagging) to manage the technical processing and forwarding of measurement, analytics and marketing events via a server-side infrastructure.

The server-side Google Tag Manager is used for the technical processing and forwarding of data to the analytics and marketing services we use.

The service itself does not, as a rule, create independent user profiles and is not used for the independent analysis of user behaviour.

Purposes of processing: technical management of tracking and marketing services, improvement of data quality, optimisation of security and data protection measures, centralised management of tags and interfaces, efficient forwarding of event data to integrated services.

Legal basis 
The operation of the server-side Google Tag Manager is based on Article 6(1)(f) of the GDPR.

Our legitimate interest lies in the secure, efficient and more privacy-friendly technical management of the analytics and marketing services used.

Where analytics, marketing or tracking services are activated via the server-side Google Tag Manager, the relevant data processing takes place exclusively on the basis of the consent required for this purpose in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG.

Recipients 
Recipients may be the analytics, tracking and marketing service providers we use, to whom event data is forwarded via the server-side Google Tag Manager.

Transfers to third countries 
The transfer of personal data to the USA or other third countries cannot be ruled out.

Where data is transferred to a third country, this is done exclusively in accordance with Articles 44 et seq. of the GDPR and with appropriate safeguards in place.

The provider’s privacy notice: https://policies.google.com/privacy

11.3.2 Server-side data transmission (server-side tracking)

We use a server-side tracking infrastructure for the technical implementation of our analytics and marketing measures. For the operation of this infrastructure, we use the service provider Stape Europe OÜ, Sepapaja tn 6, 15551 Tallinn, Estonia (Stape.io). The parent company is Stape, Inc., 8 The Green, Suite #12892, Dover, Delaware 19901, USA.

Processing takes place via a server-side Google Tag Manager (sGTM). Tracking and event data are first processed via a server-side infrastructure that we use and are then transmitted to the analytics and marketing services you have authorised.

The use of the server-side infrastructure serves, in particular, to improve data quality and technical security, as well as to ensure a controlled and more privacy-friendly transmission of tracking data.

Server-side processing serves the following purposes in particular: improving data quality and measurement accuracy, reducing technical transmission losses, optimising data security, centralised control and management of tracking and marketing services, and monitoring the data transmitted to third-party providers.

The following data, in particular, may be processed as part of server-side processing: IP address, browser and device information, HTTP headers, referrer URL, timestamps, page views, interaction and event data, online identifiers, conversion and transaction information.

Server-side processing takes place exclusively for those analytics and marketing services to which you have given your consent via our consent management system.

The legal basis for the processing is your consent in accordance with Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG.

Where personal data is transferred to providers based outside the European Union or the European Economic Area, this is carried out exclusively in accordance with Articles 44 et seq. of the GDPR.

11.4 Microsoft Clarity 

Provider 
Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland

Nature and scope of processing 
Microsoft Clarity enables the creation of pseudonymised session recordings (session replays) and heatmaps. The data processed may include, amongst other things: mouse movements, scrolling behaviour, click paths, dwell time, page views, browser information, screen size, device type, IP address (truncated or pseudonymised), and technical usage data.
It is not the intention to directly identify individual visitors.

Purpose 
To improve user-friendliness, analyse website usage, identify technical issues, optimise navigation and improve conversion rates.

Legal basis 
Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG

Retention period 
The data is stored in accordance with the configuration of our Clarity account and is subsequently deleted or anonymised.

Transfers to third countries 
Personal data may be transferred to the USA.
Microsoft implements appropriate safeguards in accordance with Article 44 et seq. of the GDPR.

Privacy Notice: https://privacy.microsoft.com/de-de/privacystatement

11.5 Google Ads and conversion tracking 

Provider 
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA).

Nature and scope of processing 
We use Google Ads, including conversion tracking, to promote our events and offers. The following data may be processed: IP address, cookie ID, device information, browser data, interaction data, ad impressions, conversion events.

Purpose 
Displaying interest-based advertising, measuring the success of advertising campaigns, conversion tracking, reach analysis.

Legal basis 
Article 6(1)(a) of the GDPR

Transfers to third countries 
The transfer of personal data to the USA or other third countries cannot be ruled out.

Privacy Notice: https://policies.google.com/technologies/ads

11.6 Google Remarketing

Provider 
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA).

Purpose 
Visitors to our website may be shown interest-based adverts again on other websites within the Google advertising network.
Data processed: cookie ID, browser information, device information, usage behaviour, pages visited

Legal basis 
Article 6(1)(a) of the GDPR

11.7 Meta Pixel and Meta Conversions API

Provider 
Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland

Nature and scope of processing 
We use the Meta Pixel and the Meta Conversions API from Meta Platforms Ireland Limited (‘Meta’) on our website. These technologies enable us to measure the success of our advertising campaigns on Facebook and Instagram, analyse user interactions and optimise our marketing activities.

In doing so, conversion events are processed both on the browser side via the Meta Pixel and on the server side via the Meta Conversions API, and transmitted to Meta.

If you arrive at our website via an advert on Facebook or Instagram, Meta can recognise which actions have been carried out on our website (e.g. page views, downloads, form submissions or other conversion events). This enables us to measure and improve the effectiveness of our advertising activities.

Where contact details are transmitted as part of individual conversion events, this is done exclusively in hashed form. The transmission serves to improve the attribution of conversion events and to measure the success of advertising campaigns.

Data processed 
Depending on the specific event, the following data in particular may be processed: IP address, browser and device information, pages visited and interactions, referrer URL, timestamps, event data (e.g. lead, download, contact enquiry, purchase), Facebook identifiers such as _fbp and _fbc, and, where applicable, hashed identifiers (e.g. email address), provided these are used to improve the attribution of conversions.

Purposes of processing 
Measuring the success of advertising campaigns, conversion tracking, reach analysis, creating target groups, remarketing, optimising our marketing activities.

Legal basis 
Data processing is carried out exclusively on the basis of your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG.
Consent is obtained via our consent management system, Usercentrics. Neither the Meta Pixel nor the Meta Conversions API will be activated for marketing purposes without your consent.

Recipient 
The recipient of the data is Meta Platforms Ireland Limited.

Transfers to third countries 
A transfer of personal data to Meta Platforms, Inc. in the USA cannot be ruled out.
Where data is transferred to countries outside the European Union or the European Economic Area, this is done in accordance with the data protection safeguards provided by Meta and in compliance with Articles 44 et seq. of the GDPR.

Further information on data processing by Meta can be found at: https://www.facebook.com/privacy/policy/

11.8 Google Marketing Platform

Provider 
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA).

Purpose 
The Google Marketing Platform is used to manage, deliver and measure the success of digital marketing campaigns.
Data processed: cookie IDs, IP address, browser data, device information, usage data, campaign data.

Legal basis 
Article 6(1)(a) of the GDPR

Transfers to third countries 
The transfer of personal data to the USA or other third countries cannot be ruled out.

Privacy Notice: https://policies.google.com/privacy

11.9 LinkedIn Insight Tag (campaigns and remarketing)

Provider 
LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland

Nature and scope of processing 
Provided you have given your consent, we use the LinkedIn Insight Tag on our website. This is an analytics and marketing service provided by LinkedIn Ireland Unlimited Company.
The LinkedIn Insight Tag enables us to obtain statistical information about the use of our website and the success of our advertising campaigns on LinkedIn. In addition, visitors to our website can be targeted with adverts on the LinkedIn platform (remarketing).
When using the LinkedIn Insight Tag, the following personal data in particular may be processed: IP address, device information, browser information, cookie IDs, timestamps, referrer URL, pages visited, click and interaction data, conversion data, and pseudonymous online identifiers.
LinkedIn processes some of this information in pseudonymised form and provides us exclusively with aggregated statistical analyses. We do not directly identify individual visitors.

Purposes of processing 
Data is processed for the following purposes: measuring the performance of LinkedIn advertising campaigns, conversion tracking, reach analysis, optimising our marketing activities, creating remarketing audiences, and serving interest-based advertising on LinkedIn.

Legal basis 
Processing is carried out exclusively on the basis of your consent in accordance with
Article 6(1)(a) of the GDPR, in conjunction with Section 25(1) of the TDDDG.
Where LinkedIn provides aggregated statistics and insights, joint controllership in accordance with Article 26 of the GDPR may apply to these processing operations.

Recipients 
The recipient of the data is LinkedIn Ireland Unlimited Company and, where applicable, affiliated companies of LinkedIn Corporation.

Transfers to third countries 
The transfer of personal data to third countries, in particular to the USA, cannot be ruled out.
Where data is transferred to a third country, this is done exclusively in accordance with Articles 44 et seq. of the GDPR. Where applicable, LinkedIn relies on the European Commission’s adequacy decision (EU-US Data Privacy Framework) or on appropriate safeguards such as the European Commission’s standard contractual clauses.

Retention period 
The retention period depends on LinkedIn’s settings and the configurations we have made. Personal data is deleted or anonymised as soon as it is no longer required for the stated purposes or unless there are statutory retention obligations to the contrary.

Withdrawal of consent 
You may withdraw your consent at any time with future effect via our consent management system.

The provider’s privacy policy: https://www.linkedin.com/legal/privacy-policy

 

12. Contact, communication and contract fulfilment

Our website offers you various ways to get in touch with us or to make use of our services. These include, in particular, contact forms, email correspondence, booking appointments, ordering tickets and other digital services.
Your personal data will be processed only to the extent necessary and solely for the purposes described below.

12.1 Contact form

Nature and scope of processing 
When you use our contact form, we process the personal data you enter.
These include, in particular: title, first name and surname, company (optional), email address, telephone number (optional), subject, content of your message, date and time of the enquiry, technical metadata (e.g. IP address, browser information)
Mandatory fields are marked accordingly in the relevant form.

Purposes of processing 
Processing is carried out in particular to handle your enquiry, contact you, answer your questions, prepare for or carry out pre-contractual measures, and document the communication.

Legal basis 
Depending on the content of your enquiry, processing is carried out on the basis of:
Article 6(1)(b) of the GDPR, insofar as the enquiry relates to the conclusion or performance of a contract;
Article 6(1)(f) of the GDPR, insofar as we have a legitimate interest in the efficient processing of general enquiries.

Recipients 
Within our organisation, access to your data is restricted to those departments that require it to process your enquiry.
Where necessary, IT and hosting service providers may be engaged as data processors in accordance with Article 28 of the GDPR.

Retention period 
Your data will be deleted as soon as the processing of your enquiry has been completed and there are no statutory retention obligations or legitimate interests preventing its deletion.

12.2 Contact via email

Nature and scope of processing 
If you contact us by email, we will process the personal data you provide. This may include, in particular: name, email address, signature data, the content of communications, attachments, the time of the communication, and technical transmission data.

Purpose 
The processing is carried out to handle your enquiry and to facilitate the requested communication.

Legal basis 
Article 6(1)(b) of the GDPR, Article 6(1)(f) of the GDPR

Note 
Please note that sending unencrypted emails may pose security risks. Where possible, confidential information should only be sent via suitable, encrypted communication channels.

12.3 CAPTCHA to prevent misuse 

We use Friendly Captcha to protect our forms against fraudulent or automated submissions.

Provider 
Friendly Captcha GmbH, Am Anger 3–5, 82237 Wörthsee, Germany

Nature and scope of processing 
When using Friendly Captcha, technical connection data – in particular the IP address, browser and device information, as well as security-related challenge and verification data – may be processed. This processing is carried out to protect against automated submissions, spam and misuse of our forms.

Purpose 
Protection against spam, detection of automated access, ensuring system security, ensuring the proper use of our forms

Legal basis 
Article 6(1)(f) of the GDPR
Friendly Captcha processes technical connection data and security-related information for the purpose of bot detection. According to the provider, no tracking cookies are used for advertising or analytical purposes.

Transfers to third countries 
Processing generally takes place within the European Union.

12.4 Appointment booking via Calendly 

Provider 
Calendly LLC, Atlanta, Georgia, USA

Nature and scope of processing 
We may use the Calendly service to arrange consultancy meetings or appointments.
When booking an appointment, the following personal data in particular may be processed: first name and surname, email address, telephone number (optional), company, preferred appointment date, time zone, communication content, technical metadata.

Purpose 
Organising appointments, conducting consultation meetings, preparing business contacts, communicating with prospective clients, exhibitors and visitors

Legal basis 
Article 6(1)(b) of the GDPR, Article 6(1)(f) of the GDPR

Transfers to third countries 
The transfer of personal data to the USA cannot be ruled out. Where data is transferred to third countries, this is done in accordance with Articles 44 et seq. of the GDPR.

Privacy Notice: https://calendly.com/privacy

12.5 Ticket Shop

The sale and administration of admission tickets are handled by our ticketing service provider, Axess. Axess is a provider of visitor management, ticketing and access solutions for exhibition and conference centres, as well as other event venues.

Provider 
Axess AG, Hofgasse 12, A-5630 Bad Hofgastein, Austria

Nature and scope of processing 
When ordering, managing and using tickets, the following personal data in particular may be processed: first name and surname, billing address, delivery address (if different), email address, telephone number, payment details, order details, ticket details, booking history, customer number, event details, and admission and usage information relating to the use of the ticket. The provision of data marked as mandatory fields is required for the conclusion and execution of the ticket purchase. Without this information, no contract of sale can be concluded.

Purpose 
The processing is carried out in particular for the following purposes: processing the ticket purchase, contract fulfilment, payment processing, creation and dispatch of electronic tickets, visitor and access management, customer communication, handling of complaints and support enquiries, and compliance with statutory retention obligations.

Legal basis 
Article 6(1)(b) of the GDPR, Article 6(1)(c) of the GDPR

Recipients 
The recipients of the data are Axess AG and, where applicable, technical service providers, payment service providers and other partners engaged by Axess that are necessary for the performance of the contract.

Where personal data is processed on behalf of a third party, this is done on the basis of appropriate agreements in accordance with Article 28 of the GDPR.

Retention period 
Data is stored in accordance with the statutory retention periods under commercial and tax law, and for as long as is necessary for the performance and fulfilment of the relevant contractual relationship.

The provider’s privacy policy: https://teamaxess.com/de/privacy-policy

12.6 Customer communication

Within the framework of existing contractual relationships or in response to enquiries, communication may take place via various channels, in particular via: email, telephone, contact form, post, video conference (where available).
Data processing is carried out solely for the purpose of conducting the relevant communication and is based on the applicable legal grounds under the GDPR.

12.7 Registration of stand staff

Nature and scope of processing 
We provide systems for the registration of stand staff to enable exhibitors to take part in trade fair. In particular, the following data may be processed: first name and surname, company, role, contact details, exhibitor allocation and information regarding access authorisation.

Purpose of processing 
To run the event, manage access authorisations, issue exhibitor passes, and ensure the organisation and security of the trade fair.

Legal basis 
Article 6(1)(b) of the GDPR; Article 6(1)(f) of the GDPR.

12.8 Exhibitor and Contract Partner Portal

Nature and scope of processing 
Messe Friedrichshafen provides its exhibitors and contractual partners with an online portal to manage their participation in trade fairs. In the course of using this portal, master data, contact details, company details, order and booking information, stand details and communication content may be processed.

Purpose of processing 
Contract fulfilment, administration of trade fair participation, ordering of goods and services, communication with exhibitors and contractual partners, and the organisation of the event.

Legal basis 
Article 6(1)(b) of the GDPR; Article 6(1)(f) of the GDPR.

12.9 Axess LEADS (Lead Management)

Nature and scope of processing 
Axess LEADS provides exhibitors with a digital solution for recording visitor contact details. Once a visitor’s ticket has been scanned, the relevant visitor data – subject to the visitor’s consent – is processed and made available to the respective exhibitor.
Data is only transmitted if the visitor actively initiates the scan or authorises the release of their data.

Purpose of processing 
To provide the booked lead management services, to supply visitor information to exhibitors, and to establish and maintain business contacts.

Legal basis 
Article 6(1)(b) of the GDPR; Article 6(1)(f) of the GDPR.

12.10 Visitor registration systems

Nature and scope of processing 
Electronic visitor tracking and analysis systems may be used at trade fairs and events. This may include, in particular, ticket numbers, times of entry, access areas and event-related usage data, which may be analysed statistically.

Purpose of processing 
Visitor management, evaluation of the event, optimisation of the event programme, and security and organisational purposes.

Legal basis
Article 6(1)(b) of the GDPR; Article 6(1)(f) of the GDPR.

12.11 Event newsletter for exhibitors

Nature and scope of processing 
Within the framework of existing contractual relationships with exhibitors and contractual partners, we use the contact details collected in connection with participation in the trade fair, in particular email addresses, to send event-related information and newsletters. The information relates exclusively to similar events, services and offerings provided by Messe Friedrichshafen.

Purpose of processing 
Information on the current status of the event, organisational details, services, deadlines, updates and event-related offers. Consent to the use of your email address may be withdrawn at any time with future effect.

Legal basis
Article 6(1)(f) of the GDPR; Section 7(3) of the Unfair Competition Act (UWG), provided that the legal requirements are met.

You may object to the use of your email address for sending event-related information at any time with future effect. You will not incur any costs other than the transmission costs in accordance with standard rates.

12.12 Event newsletters / newsletter subscription

Provider and mailing service provider 
We use the service provider Inxmail GmbH, Wentzingerstraße 17, 79106 Freiburg im Breisgau, Germany, to send our newsletters.

Nature and scope of processing 
When you subscribe to our newsletter, we process the personal data you provide in the registration form. This includes, in particular, your email address, voluntary information (e.g. name or title, where requested), the date and time of registration, your IP address at the time of registration, information required to confirm your registration (double opt-in procedure), and technical information relating to the distribution of the newsletter.

Purposes of processing 
The processing is carried out in particular for the following purposes:

  • Sending the requested newsletter
  • Providing information on events, offers, services and news
  • Providing evidence of lawful subscription to the newsletter
  • Managing subscriptions and unsubscriptions
  • Ensuring reliable newsletter delivery

Legal basis 
Processing is carried out on the basis of your consent in accordance with Article 6(1)(a) of the GDPR.

Double opt-in procedure 
Subscription to our newsletter is carried out using the so-called double opt-in procedure. After you have subscribed, you will receive an email in which you must confirm your subscription. This procedure serves to verify that the subscription was actually made by the owner of the email address provided.

Withdrawal and unsubscription 
You may withdraw your consent to receive the newsletter at any time with future effect. To do so, you can use the unsubscribe link included in every newsletter. Alternatively, you can contact us via the contact details provided in this privacy policy.
The lawfulness of the processing carried out up to the point of withdrawal remains unaffected by this.

Recipient 
The recipient of the data is Inxmail GmbH, acting as the technical service provider for the distribution of the newsletter. Where personal data is processed on our behalf, this is done on the basis of a data processing agreement in accordance with Article 28 of the GDPR.

Retention period 
Your data will be stored for as long as your newsletter subscription remains active. Once you unsubscribe, your data will be deleted, provided that there are no statutory retention obligations or other legitimate reasons preventing its deletion.

The provider’s privacy policy: https://www.inxmail.de/datenschutz

12.12.1 Newsletter tracking and personalised performance measurement

Nature and scope of processing 
We analyse the usage of our newsletters. To do this, we use the analytics functions provided by our newsletter service provider, Inxmail.
In particular, the following data may be processed: newsletter open rates, the time at which the newsletter is accessed, clicks on links contained therein, information about the device and browser used, technical usage data, and personal or pseudonymised recipient identifiers for the purpose of attributing opens and clicks.

Purposes of processing 
Processing is carried out in particular for the following purposes: analysing the usage behaviour of our newsletter recipients, measuring the reach and effectiveness of our newsletters, optimising content, topics and dispatch times, improving the way we address users, and tailoring future information and marketing measures to meet needs.

Legal basis 
Processing is carried out exclusively on the basis of your consent in accordance with Article 6(1)(a) of the GDPR.

Personalised analysis 
Provided you have given your consent, opens and clicks can be attributed to individual newsletter recipients. This enables us to analyse the use of our newsletters at a personal level and to better tailor content to the interests of our recipients in future.

Withdrawal of consent 
You may withdraw your consent to newsletter tracking at any time with future effect. To do so, you can use the relevant unsubscribe link in the newsletter or contact us via the contact details provided in this privacy policy.
Withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal.

Retention period 
The data collected as part of newsletter tracking will only be stored for as long as is necessary for the purposes stated, or until you withdraw your consent. The data will then be deleted or anonymised, provided there are no statutory retention obligations to the contrary.

The provider’s privacy notice: https://www.inxmail.de/datenschutz

12.13 Press distribution list, media accreditation and press communications

Media representatives can apply for accreditation via the Online Service Centre for press and media services. Accreditation is processed via the Online Service Centre of our event management software.

Nature and scope of processing 
In the context of accreditation and inclusion in the press distribution list, the following personal data in particular may be processed: first name and surname, media outlet, publisher or editorial office, professional contact details, email address, telephone number, role or function as a media representative, accreditation and supporting documents, communication data, date and time of registration.

Provider of the accreditation system 
infoteam Software AG, Bunsenstraße 4, 10589 Berlin, Germany
Where personal data is processed on behalf of Messe Friedrichshafen GmbH, this is done on the basis of a data processing agreement in accordance with Article 28 of the GDPR.

Mailing service provider for press releases 
We use the service provider Inxmail GmbH, Wentzingerstraße 17, 79106 Freiburg im Breisgau, Germany, to send press releases, press information and other information to media representatives.
Where personal data is processed by Inxmail on our behalf, this is done on the basis of a data processing agreement in accordance with Article 28 of the GDPR.

Purposes of processing 
Processing is carried out in particular for the following purposes: reviewing and processing accreditation applications; managing press and media contacts; adding recipients to the press distribution list; sending out press releases, press information and event-related media information; communicating with media representatives before, during and after the event; and organising press appointments and press events.

Legal basis 
Processing is carried out on the basis of Article 6(1)(b) of the GDPR, insofar as the processing is necessary for the purpose of carrying out the requested media accreditation.
The sending of press information to accredited media representatives listed on the press distribution list is carried out on the basis of Article 6(1)(f) of the GDPR. Our legitimate interest lies in press and public relations work, as well as in informing media representatives about our events and corporate activities.

Unsubscribing from the press mailing list 
You may object to receiving press releases at any time with future effect. To do so, you can use the unsubscribe link contained in the relevant emails or contact us via the contact details provided in this privacy policy.
Once we have received your objection, your data will no longer be used for sending press releases.

Retention period 
Your data will be stored for as long as you remain on the press mailing list or as long as this is necessary for the purposes of media accreditation. Once you have unsubscribed from the press mailing list or the purpose for processing the data no longer applies, the data will be deleted, provided there are no statutory retention obligations to the contrary.

Recipients 
The recipients of the data are the departments at Messe Friedrichshafen GmbH responsible for press and public relations, infoteam Software AG as the operator of the RUBIN accreditation system, and Inxmail GmbH as the technical service provider for the distribution of press releases.

Data protection notices from the providers

  • infoteam Software AG: https://www.infoteam.de/datenschutz
  • Inxmail GmbH: https://www.inxmail.de/datenschutz

 

13. Embedded content and external services

Content from external providers may be embedded on our website for the display of multimedia content, interactive maps and digital documents.
Depending on the technical implementation, a connection to the respective provider’s servers may be established as soon as a page containing embedded content is accessed. In doing so, personal data – in particular the IP address – as well as technical information about the device and browser used may be processed.
Where your consent is required for the integration of these services, processing will take place exclusively following your prior consent via our consent management system.

13.1 YouTube

Provider 
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA).

Nature and scope of processing 
Content from the YouTube platform may be used to embed videos.
When a page containing an embedded YouTube video is accessed, the following data in particular may be processed: IP address, browser information, device information, referrer URL, date and time of page access, usage data, cookie IDs (where permitted), interaction data (e.g. starting or pausing a video).
Depending on the type of embedding, the so-called ‘enhanced privacy mode’ may be used. However, data may still be transferred to Google.

Purpose 
Provision of multimedia content, improvement of user-friendliness, and clear presentation of information and events.

Legal basis 
Article 6(1)(a) of the GDPR, in conjunction with Section 25(1) of the TDDDG

Transfers to third countries 
Personal data may be transferred to Google LLC in the USA. Where necessary, this is carried out on the basis of appropriate safeguards in accordance with Article 44 et seq. of the GDPR.

Privacy notice: https://policies.google.com/privacy

13.2 Vimeo

Provider 
Vimeo Inc., 330 West 34th Street, New York, NY 10001, USA

Nature and scope of processing 
Videos from the Vimeo platform may be used to embed video content. When you access a page containing a Vimeo video, the following data in particular may be processed: IP address, browser data, device information, referrer URL, usage data, interaction data, cookie information (subject to your consent).

Purpose 
Provision of video content, improvement of user-friendliness, presentation of trade fair and event content.

Legal basis 
Article 6(1)(a) of the GDPR, in conjunction with Section 25(1) of the TDDDG

Transfers to third countries 
Data may be transferred to third countries, in particular to the USA.

Privacy Notice: https://vimeo.com/privacy

13.3 Instagram

Provider 
Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland

Nature and scope of processing 
Content from our Instagram page may be embedded on our website.
When such content is loaded, the following data in particular may be processed: IP address, browser data, device information, cookie IDs, usage behaviour, interaction data.

Purpose 
Display of current content, corporate communications, marketing, increasing reach.

Legal basis 
Article 6(1)(a) of the GDPR, in conjunction with Section 25(1) of the TDDDG

Privacy Notice: https://privacycenter.instagram.com/policy

13.4 LinkedIn (embedded content)

Provider 
LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland

Nature and scope of processing 
Content from our LinkedIn company profile may be embedded on our website. When this content is accessed, the following data may be processed: IP address, browser information, device information, usage data, referrer URL, interaction data.

Purpose 
Corporate communications, display of current posts, information about events and news.

Legal basis 
Article 6(1)(a) of the GDPR, in conjunction with Section 25(1) of the TDDDG

Privacy Notice: https://www.linkedin.com/legal/privacy-policy

13.5 Yumpu

Provider 
i-magazine AG (Yumpu)

Nature and scope of processing 
The Yumpu service may be used to display digital catalogues, brochures or magazines. In particular, the following data may be processed: IP address, browser information, device information, usage data, referrer URL.

Purpose 
Provision of digital publications, improvement of user-friendliness, presentation of trade fair documentation.

Legal basis 
Article 6(1)(a) of the GDPR, in conjunction with Section 25(1) of the TDDDG

Privacy notice: https://www.yumpu.com/de/info/privacy_policy

13.6 Google Maps

Provider 
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA).

Nature and scope of processing 
Google Maps may be used to display interactive maps and to make it easier to find our event venues. When the maps are loaded, the following data in particular may be processed: IP address, location information (if shared), browser data, device information, usage data.

Purpose 
Map display, route planning, location information.

Legal basis 
Article 6(1)(a) of the GDPR, in conjunction with Section 25(1) of the TDDDG

Privacy notice: https://policies.google.com/privacy

13.7 Mapbox

Provider 
Mapbox Inc., Washington, DC, USA

Nature and scope of processing 
Mapbox map services may be used as an alternative to or in addition to Google Maps. The following data may be processed: IP address, browser data, device information, location data (where shared), usage data.

Purpose 
Map display, navigation, optimisation of user-friendliness.

Legal basis 
Article 6(1)(a) of the GDPR, in conjunction with Section 25(1) of the TDDDG

Privacy Notice: https://www.mapbox.com/legal/privacy

13.8 OpenStreetMap

Provider 
OpenStreetMap Foundation, St John’s Innovation Centre, Cowley Road, Cambridge, United Kingdom

Nature and scope of processing 
Data from OpenStreetMap may be used to display map material. In particular, the following may be processed: IP address, browser information, device information, usage data, technical connection data.

Purpose 
Provision of map data, display of event venues, improvement of user-friendliness.

Legal basis 
Article 6(1)(a) of the GDPR, in conjunction with Section 25(1) of the TDDDG

Privacy Notice: https://wiki.openstreetmap.org/wiki/Privacy_Policy

13.9 Information on external content

External content is incorporated solely to enhance the information and services we provide. Despite carefully selecting the providers, we have no influence over the nature and scope of data processing carried out by the respective third-party providers.
For further information on the processing of personal data, please refer to the privacy notices of the respective providers.

13.10 Digital Asset Management

Providers 
Bynder B.V., Max Euweplein 46, 1017 MB Amsterdam, Netherlands

Nature and scope of processing 
We use the Bynder digital asset management platform to manage and provide images, videos, documents and other media content.

When accessing content provided via Bynder, the following data in particular may be processed: IP address, browser information, device information, referrer URL, timestamps, usage data and technical connection data.

Purpose 
Data processing is carried out for the following purposes: the provision of digital media content; the management of image and video material; the technical delivery of downloads and multimedia content; and the optimisation of the availability and performance of our website.

Legal basis 
Article 6(1)(f) of the GDPR

Our legitimate interest lies in the efficient and secure provision of media content on our website.

Where Bynder uses cookies or similar technologies for the storage or delivery of content, their use is governed exclusively by the relevant statutory provisions.

The provider’s privacy policy: https://www.bynder.com/de/legal/privacy-policy/

13.11 Social media presence

We maintain publicly accessible profiles on social media networks and video platforms to provide information about our events, services, products and business activities, and to communicate with interested parties, visitors, exhibitors, media representatives and business partners.

Our company and event profiles are maintained on the following platforms:

  • LinkedIn
  • Facebook
  • Instagram
  • YouTube
  • Vimeo
  • TikTok

When you visit our social media pages, personal data is processed not only by us but, in particular, by the respective platform operators. We have only limited influence over this.
The data processed may include, in particular:

  • Username and profile details
  • Communication content (comments, messages, posts)
  • Interaction data (likes, shares, follower activity)
  • Device and browser information
  • IP address
  • Location data, where shared by the user
  • Reach, usage and statistical data (insights, analytics)

The processing is carried out in particular for the following purposes:

  • Corporate and event communications
  • Responding to enquiries
  • Publication of information, press releases and event content
  • Measuring the reach and monitoring the effectiveness of our communications
  • Analysing the use of our social media platforms
  • Improving our information and marketing activities

The legal basis for processing is Article 6(1)(f) of the GDPR. Our legitimate interest lies in conducting modern public relations work, communicating with our target groups and presenting our company and our events. Where contact is made with a view to concluding or performing a contract, processing is also carried out on the basis of Article 6(1)(b) of the GDPR.

We sometimes receive statistical reports from platform operators regarding the use of our company profiles. These reports are generally provided in aggregated form and are used to analyse reach, target audiences and interactions.
Data may also be processed by the respective platform operators outside the European Union or the European Economic Area, in particular in the USA. Where personal data is transferred to third countries in this context, this is carried out, according to the respective providers, in compliance with Articles 44 et seq. of the GDPR.
Data subjects’ rights may, in principle, be exercised both against us and against the respective platform operator. However, as the direct processing of personal data is predominantly carried out by the platform operators, we recommend that requests for access, erasure or other data protection enquiries also be addressed directly to the respective provider.

Platform providers and data protection notices 
LinkedIn 
LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland
Privacy policy: https://www.linkedin.com/legal/privacy-policy
With regard to the compilation and provision of page statistics (‘Page Insights’), there may be joint responsibility between Messe Friedrichshafen GmbH and LinkedIn Ireland Unlimited Company in accordance with Article 26 of the GDPR. Processing is carried out in particular to provide statistical analyses of the use of our LinkedIn company profile, including information on reach, interactions and target audiences.
LinkedIn and Messe Friedrichshafen GmbH have set out their respective data protection responsibilities in an agreement in accordance with Article 26 of the GDPR. Data subjects may exercise their rights either with Messe Friedrichshafen GmbH or directly with LinkedIn.
LinkedIn provides information on this at the following address: https://legal.linkedin.com/pages-joint-controller-addendum

Facebook and Instagram 
Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland
When operating our Facebook and Instagram pages, we receive statistical analyses from Meta regarding the use of our pages (‘Page Insights’).
Insofar as Meta processes personal data for this purpose and provides us with statistical analyses, Messe Friedrichshafen GmbH and Meta Platforms Ireland Limited share joint responsibility for the creation and provision of these Page Insights in accordance with Article 26 of the GDPR.
In accordance with the agreement concluded between the parties, Meta assumes key data protection obligations in connection with the processing of Page Insights data.
Data subjects may exercise their rights both against us and directly against Meta. 
Meta makes the key provisions of the agreement available at the following address: https://www.facebook.com/legal/terms/page_controller_addendum
Privacy policy: https://www.facebook.com/privacy/policy

YouTube 
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Privacy policy: https://policies.google.com/privacy

Vimeo 
Vimeo Inc., 330 West 34th Street, New York, NY 10001, USA
Privacy policy: https://vimeo.com/privacy

TikTok 
TikTok Technology Limited, 10 Earlsfort Terrace, Dublin 2, D02 T380, Ireland, and TikTok Information Technologies UK Limited, London, United Kingdom
Privacy policy: https://www.tiktok.com/legal/privacy-policy

 

14. Recipients of personal data

14.1 Internal recipients

Within Messe Friedrichshafen GmbH, access to personal data is restricted to those departments that require it to carry out their respective duties (the ‘need-to-know’ principle).
These include, in particular: event management, customer service, sales, marketing, the IT department, financial accounting, and the legal and data protection department
Access is granted exclusively within the scope of the respective areas of responsibility and in compliance with data protection regulations.

14.2 External recipients

Where necessary to fulfil the stated purposes, personal data may be transferred to external recipients.
These include, in particular: hosting service providers, IT service providers, ticketing service providers, payment service providers, analytics and marketing service providers, cloud service providers, public authorities in accordance with legal obligations, consultants and auditors, and shipping and communications service providers.
Where external service providers process personal data on our behalf, they do so exclusively on the basis of a data processing agreement in accordance with Article 28 of the GDPR.

 

15. Transfers to third countries

Some of the services described in this privacy policy are operated by companies based outside the European Economic Area or may require the transfer of personal data to third countries.
Any such transfer takes place exclusively in accordance with Articles 44 et seq. of the GDPR.
Where necessary, the transfer of data is based on:

  • an adequacy decision by the European Commission,
  • the EU Standard Contractual Clauses (SCCs),
  • binding corporate rules,
  • or other appropriate safeguards in accordance with the GDPR.

Further information on the relevant guarantees can be found in the privacy notices of the respective providers.

 

16. Retention period

Unless otherwise specified in this privacy policy, we generally retain personal data only for as long as is necessary to fulfil the relevant processing purposes.
In addition, retention periods may arise in particular from:

  • retention obligations under commercial law,
  • tax law retention obligations,
  • statutory obligations to provide evidence,
  • limitation periods,
  • legitimate interests in the defence of legal claims.

Once the relevant time limits have expired, personal data will be deleted or anonymised.

 

17. Data security

We implement appropriate technical and organisational measures in accordance with Articles 24 and 32 of the GDPR to protect personal data against loss, destruction, manipulation and unauthorised access.
These include, in particular: transport encryption using TLS, role-based authorisation schemes, access controls, data backups, logging of security-related events, regular updates to the systems in use, measures to detect and defend against cyber attacks, and regular reviews of the technical and organisational measures.
Despite all security measures, it is not possible to guarantee completely watertight security when transmitting data over the internet.

 

18. Rights of data subjects

Under the GDPR, you have the following rights in particular:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data transferability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent (Article 7(3) of the GDPR)
  • Right not to be subject solely to automated decision-making, including profiling (Article 22 of the GDPR), provided that the legal requirements are met.

To exercise your rights, you may contact us at any time using the contact details provided in Section 2.

Where there is joint controllership in accordance with Article 26 of the GDPR, data subjects may exercise their rights both against us and directly against the relevant joint controller. Irrespective of any agreements made between the parties involved, you may exercise your rights against any controller.

18.1 Notice regarding your right to object under Article 21 of the GDPR 

Objection to processing on the basis of legitimate interests 
Where we process personal data on the basis of Article 6(1)(f) of the GDPR (legitimate interests), you have the right to object at any time to the processing of your personal data on grounds relating to your particular situation.
We will then no longer process the personal data in question, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.

Objection to direct marketing 
Where personal data is processed for the purposes of direct marketing, you have the right to object at any time to the processing of your personal data for the purposes of such marketing.
This also applies to profiling insofar as it is related to such direct marketing.
Once we have received your objection, your personal data will no longer be processed for the purposes of direct marketing.

To exercise your right to object, simply send an informal notification to:
Messe Friedrichshafen GmbH
Email: datenschutz@messe-fn.de

 

19. Right to lodge a complaint with a supervisory authority

Without prejudice to any other administrative or judicial remedies, you have the right under Article 77 of the GDPR to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes data protection regulations.

The competent data protection supervisory authority for Messe Friedrichshafen GmbH is:
The State Commissioner for Data Protection and Freedom of Information in Baden-Württemberg (LfDI BW), Lautenschlagerstraße 20, 70173 Stuttgart, Germany.

Telephone: +49 711 615541-0
Email: poststelle@lfdi.bwl.de
Website: https://www.baden-wuerttemberg.datenschutz.de

In addition, you may also contact the data protection supervisory authority in your country of habitual residence, your place of work or the location of the alleged infringement.

 

20. Changes to this Privacy Policy

We reserve the right to amend this privacy policy should this become necessary due to technical developments, changes in the law or new or amended processing of personal data.

The current version published on our website shall apply at all times.