Data Protection

Last updated: 2 June 2026

Data protection information from Messe Düsseldorf GmbH

1. Introduction

2. Public register of processing activities

2.1 Name of the data controller

2.2 Management (as representative of the data controller)

2.3 Contact details of the data controller

2.4 Contact details of the Data Protection Officer

2.5 Purpose of data collection, processing or use / legitimate interests of Messe Düsseldorf GmbH

2.6 Description of the groups of data subjects and the relevant data or categories of data

2.7 Recipients or categories of recipients to whom the data may be disclosed

2.8 Change of purpose

2.9 Criteria for data erasure

2.10 Transfer of data abroad

3. Cookies

3.1 Essential cookies

3.2 Functional cookies

3.3 Marketing cookies

3.4 Google Advanced Consent Mode

3.5 Retention period

3.5.1 Session cookies

3.5.2 Persistent cookies

3.5.2.1 Stay logged in

3.6. Third-party providers

3.7. Third countries

3.8 Use of the Usercentrics Consent Management Platform

4. Video surveillance on the exhibition grounds

5. Data protection for specific applications

5.1 Online orders

5.1.1 Visitor registration / Exhibitor staff registration / Ticket Shop

5.1.2 Online registration (OA)

5.1.3 Online Order System (OOS) for exhibitors

5.1.4 Payment processing in the Online Order System (OOS) and in the Ticket Shop

5.2 Stand Builder

5.3 Surveys

5.3.1 Panels

5.3.2 Market research

5.4 Electronic newsletters

5.5 Competitions, loyalty programmes

5.6 novomind

5.7 VIP Hosted Buyer Programme

6. Further visitor services

6.1 Fair Match

6.2 Web sessions

6.3 Vehicle registration number search / Messe Düsseldorf GmbH car parks

7. Sanctions list screening

8. Additional information regarding the use of our app

8.1 Downloading the app

8.2 Using the app

8.2.1 Functionality of the app

8.2.2 Registration and ‘stay logged in’

8.2.3 Push notifications

8.2.4 My tickets

8.2.5 My recommendations

8.3 Cookies in the app

8.3.1 General information

8.3.2 Cookies used in the app

8.3.3 Technically necessary cookies

8.3.4 Google Analytics 4

8.3.5 Matomo

8.3.6 Google Firebase

8.3.7 Use of the Usercentrics Consent Management Platform

8.4 Data processing by third parties

8.4.1 Categories of recipients

8.4.2 Legal obligation to transfer certain data

9. Candidate management

9.1 Application process

9.2 Job alerts

10. Your rights as a data subject

10.1 Right of access / Right to erasure / restriction of processing

10.2 Right to lodge a complaint

10.3 Right to object

10.4 Exercising your legal rights

Privacy information in plain language

I. Introduction
II. Who is responsible for data protection?
III. What data do we collect?
IV. Why do we need your data?
V. How is your data used?
VI. How do we protect your data?
VII. Advertising and opting out
VII. Cookies
IX. How long do we retain your data?
X. Your rights
XI. Contact
XII. Data Protection Officer

1. Introduction

This privacy policy explains how we handle personal data, in particular the use, storage and protection of such data, as well as the rights to which data subjects are entitled. The Messe Düsseldorf GmbH website is primarily a marketplace for conducting business. Although much of the information is also available to anonymous users, we may occasionally need to collect data from users – which may relate to either the company or the individual – to ensure they receive the services they require. Personal data is protected in our systems in accordance with internationally applicable data protection standards, the General Data Protection Regulation (Regulation (EU) 2016/679, GDPR) of the European Union (hereinafter referred to as the ‘GDPR’) and national data protection regulations. We want users to be able to rely on their data being handled responsibly and confidentially.

Personal data is used only for the purposes specified in this privacy policy or expressly stated at the time of subsequent data collection. This privacy policy relates to data processing on our website and our trade fair-specific websites (including the mobile application), our social media channels and any other forms of communication used. It does not apply to other websites to which we merely provide a hyperlink. As we bear no responsibility for the information provided on those sites, we recommend that you carefully review the privacy policies available there. Whenever content is requested from our website, personal data (e.g. name of the file requested, date/time, volume of data transferred) relating to this transaction is stored in a log file. We use this to track user behaviour across the entire website. However, this information is not combined with data relating to individual users without their prior express consent. We categorise the overall usage statistics according to the user’s domain name, browser type and MIME type, which are extracted from the browser string (the information contained in each user’s browser). We track and catalogue the search terms entered by users in search engines; however, this tracking is never linked to individual users.

Encryption methods are used to ensure the secure transmission of payment data. This means that the communication between the user’s browser and our system is not readable by other parties on the internet.

2. Public Record of Processing Activities

2.1 Name of the data controller

Messe Düsseldorf GmbH

2.2 Management (as representatives of the data controller)

Wolfram N. Diener (Chairman of the Management Board)
Marius Berlemann
Bernhard J. Stempfle

2.3 Contact details of the data controller

Address: Messeplatz, Stockumer Kirchstraße 61, D-40474 Düsseldorf, Germany
Telephone: +49 211 4560-01
Fax: +49 211 4560-66
Email: info[at]messe-duesseldorf.de
Website: https://www.messe-duesseldorf.de/

2.4 Contact details of the Data Protection Officer

Data Protection Officer at Messe Düsseldorf GmbH
c/o migosens GmbH
Wiesenstr. 35
45473 Mülheim an der Ruhr
Email: dsb-messe-duesseldorf[at]migosens.net

2.5 Purpose of data collection, processing or use / legitimate interests of Messe Düsseldorf GmbH

The purpose of Messe Düsseldorf GmbH is to promote the economy by organising trade fairs and exhibitions in Germany and abroad, by organising or running congresses and conferences, and through all activities related to the trade fair, exhibition, congress and conference business. The organisation of specialist trade fairs, which are aimed at narrowly defined target groups based on their respective specialist and professional focus, forms the core of our activities. To fulfil this purpose, we maintain trade fair and exhibition facilities as well as conference and meeting venues, which we use for events or let out for a reasonable fee. To this end, we process personal data, in particular from exhibitors, trade fair visitors, trade fair visitors, journalists, service providers, suppliers, cooperation partners (or, in each case, their employees, governing bodies or other authorised representatives), as well as from individuals who have a close personal connection to our company. The processing of personal data takes place either on the basis of consent (e.g. Article 6(1)(a) of the GDPR) from the data subject (in particular in the case of direct marketing measures by electronic means or the use of photographs and videos for advertising purposes) or on the basis of other legal grounds under the GDPR for the purposes stated by the company, in particular for organising our events, managing business processes, and ensuring and improving the quality of our trade fair events, including providing information to our customers (see below Section 2.6, Categories A, B, F) before and after an event, as well as regarding follow-up events. In doing so, we pursue the legitimate interest of restricting access to our specialist events exclusively to visitors with a professional connection to the specific topic of the event in question. This serves to promote the quality of professional exchange. Follow-up events may also include other events organised or run by us in Germany and abroad that are thematically related to the event in question.

Members of trade fair clubs also receive promotional information from partner companies via us regarding offers that correspond to their stated interests.

Personal data is not disclosed to third parties for advertising purposes, unless this forms part of the services we provide. This applies, for example, when scanning admission tickets (regardless of their form), exhibitor badges and press badges (admission tickets, exhibitor badges and press badges hereinafter collectively referred to as ‘badges’). The badges may be scanned by exhibitors, Messe Düsseldorf GmbH or other third parties (e.g. organisers of special forums). This is subject to the condition that the visitor, the exhibitor or the press representative consents to the scanning of the barcode contained on their badge. The aforementioned groups of people therefore decide independently on the disclosure of their personal data. The information contained on the badges, which is provided during registration, may be read upon presentation of the badge and stored and used for the exhibitor’s, Messe Düsseldorf GmbH’s or other third parties’ own purposes. Should Messe Düsseldorf GmbH pass on your personal data to third parties in connection with the scanning of badges, you will be explicitly informed of this. In such a case, the third party’s data protection policy applies under their own responsibility.

2.6 Description of the data subject groups and the relevant data or data categories

To fulfil the purposes set out in section 2.5, the following personal data is collected, processed and used for each data subject group:

Group of data subjectsDataCategory
Representatives of exhibiting companiesCompany data including addresses, contact names and contact details, information on industry sector, product data, contractual and billing dataA
Trade fair visitors (representatives of companies visiting trade fairs)Registration data such as company details including addresses, contact names and contact details, where applicable, health-related data, whether a ticket voucher has been redeemed and whether entry has been granted, industry affiliation information, product interests, as well as contract and billing dataB
Trade fair visitors (public events without trade visitor status)Name, address, contact details, exhibitor interests, payment details, whether an admission voucher has been redeemed and whether entry has been grantedC
Prospective exhibitors (potential new customers)Company details including addresses, contact names and contact details, industry sector information, product data, interestsD
Contact persons at suppliers, service providers, other business partnersCompany data or data from institutions, including addresses, contact names and contact details, service information, contract and billing dataE
Club membersName, address, contact details, exhibition interests, payment details, personal data (date of birth, household income, purchasing behaviour)F

2.7 Recipients or categories of recipients to whom the data may be disclosed

  • Public authorities where there are overriding legal provisions (Categories A–F) / Legal basis for data transfer: Article 6(1)(c) of the GDPR;
  • Companies within the Messe Düsseldorf Group (Categories A, B, C, F) / the data transfer takes place within the framework of data processing on behalf of a controller pursuant to Article 28 of the GDPR;
  • Businesses that acquire a trade fair event, shares in the company or assets from Messe Düsseldorf GmbH, or event partners of Messe Düsseldorf (Categories A–F) / Legal basis for data transfer: Article 6(1)(f) of the GDPR;
  • Foreign representations, provided that the person visiting the trade fair is resident abroad (Categories A, B, C, D, F) / the data transfer takes place within the framework of data processing on behalf of a controller pursuant to Article 28 of the GDPR;
  • Other data processors of Messe Düsseldorf GmbH (Categories A–D, F) / data is transferred within the framework of data processing on behalf of the controller in accordance with Article 28 of the GDPR;
  • Service providers for trade fair-related services, insofar as the individual has requested such services from Messe Düsseldorf (Categories A–D, F) / Legal basis for data transfer: Article 6(1)(b) of the GDPR;
  • Businesses that have issued visitor vouchers will have the visitor data (name, address, contact details) relating to the redeemed vouchers (re)transmitted to them, provided this has been contractually agreed (Categories B, C, F) / Legal basis for data transfer: Article 6(1)(f) of the GDPR;
  • Sponsors or partners who contribute to the financing or other organisation of separate exhibition areas and/or formats will receive the visitor data (Categories A, B) / Legal basis for the data transfer: Article 6(1)(f) of the GDPR;
  • In addition, we may offer exhibitors or other third parties the service of electronically processing the personal data of visitors, exhibitors and members of the press. This service is provided on the condition that the visitor, the exhibitor or the press representative consents to the exhibitor, the third party or Messe Düsseldorf GmbH scanning the barcode contained on their badge (see section 2.5). The aforementioned persons therefore decide for themselves whether the data stored on their badge personal data relating to the exhibitor, the third party or Messe Düsseldorf GmbH (Categories A, B, C, F) / Legal basis for the data transfer: Article 6(1)(a) of the GDPR.

 

In all the cases listed above, the transfer of data serves the purposes set out in section 2.5.

2.8 Change of purpose

Your personal data will only be processed for purposes other than those described where permitted by law and/or where you have consented to the amended purpose of data processing. In the event of further processing for purposes other than those for which the data was originally collected, we will inform you of these other purposes prior to such further processing and provide all further relevant information in this regard.

2.9 Criteria for data erasure

In principle, all personal data is erased as soon as it is no longer necessary for the purposes for which it was collected or otherwise processed. Data is also erased in cases where erasure is required by law and in cases where the data subject has withdrawn their consent to the processing of their personal data or has objected to such processing. This does not apply if and to the extent that, despite the withdrawal of consent or the objection to data processing, there is another legal basis or overriding legitimate grounds for processing the data. This may be the case, for example, where statutory retention obligations apply (such as those relating to commercial correspondence or accounting documents).

2.10 Transfer of data abroad

In order to provide the best possible support to our customers and business partners worldwide, we transfer personal data relating to individuals within the companies of the Messe Düsseldorf Group. In order to fulfil contractual purposes or to carry out pre-contractual measures with companies from third countries that are interested in exhibiting or are exhibiting, as well as with companies from third countries that are interested in visiting or are visiting, it is essentially necessary to transfer data to the foreign representative office of the relevant third country. To this end, the relevant data, as listed under 2.6, is transferred to the competent diplomatic mission. In the case of representatives of companies from third countries visiting a trade fair, the visitor’s name may also be provided to the relevant diplomatic mission, provided there is no objection to such transfer. The registration data of a company whose representative visits an exhibitor at their stand may – provided the visitor does not object to their data being scanned from the barcode on their admission ticket – – be transferred to the exhibitor they have visited, regardless of whether that exhibitor is based in Germany, the EU or a third country. In all cases where we ourselves arrange for the transfer of personal data to third countries that do not have an adequate level of data protection enshrined in law, the transfer shall only take place if the data recipient undertakes contractually to comply with data protection and data security standards equivalent to our own.

3. Cookies

We use cookies. Cookies are small files that are stored during your visit. To this end, we use a server-side tracking method (known as ‘server-side tracking’). In this process, tracking data is not processed in the data subject’s browser, but via a server controlled by us. Server-side collection enables us to collect, filter and, where necessary, pseudonymise individual tracking signals (e.g. page views, clicks, technical information such as browser type and device type) in a privacy-friendly manner, and, where appropriate, to forward them in pseudonymised form to downstream tools for web analytics or performance measurement.

You can view and change your cookie settings at any time under ‘Cookie Settings’ in the Usercentrics consent management tool. There you will find an overview of all providers used, along with the respective purposes of processing. Consent for functional cookies and marketing cookies may be refused, granted on a case-by-case or general basis, and withdrawn at any time with future effect.

Users may also prevent the storage of cookies by adjusting the settings on their browser or device, for example by selecting ‘do not accept cookies’. Stored cookies can also be deleted there at any time. Please note that if cookies are disabled, the functionality of our websites may be restricted.

Details of the cookies used can be found in the following explanations.

3.1 Essential cookies

These cookies are strictly necessary for the use of our websites and cannot be disabled. The legal basis for the processing of personal data using these cookies is – provided a contractual relationship exists – Article 6(1)(b) of the GDPR or Article 6(1)(c) of the GDPR. In other cases, however, it is also based on our legitimate interest pursuant to Article 6(1)(f) of the GDPR. This legitimate interest arises from the purposes for which the cookies are used.

3.2 Functional cookies

Functional cookies are used to analyse website usage. Some of these cookies are set by third parties, that is, by service providers we have carefully selected. By using such cookies, we can, for example, count the number of visits to our website and track which other websites referred visitors to our site. This analysis provides us with insights into which parts of our website are most popular, which are used the least, and how visitors navigate our website. This enables us to improve the website’s performance and optimise its content.

Data processing via cookies takes place exclusively on the basis of voluntary consent in accordance with Article 6(1)(a) of the GDPR. If consent is given, cookies for analysis purposes are set when our website is accessed or when an offer provided via the website is accessed. Express reference is made to the information provided in section 3.4.

3.3 Marketing cookies

Marketing cookies are used to provide interest-based content and adverts. This enables more accurate reports on campaign performance to be generated. Some of these cookies are set by third-party providers. These providers receive information about the user’s use of our website and may combine this information with other data they may have obtained elsewhere. This enables us, with the help of selected partners, to target visitors who have shown an interest in content and offers on our website with advertising tailored to their interests (retargeting / remarketing). Advertisements are displayed on our partners’ marketing and social media websites based on an analysis of previous usage behaviour on our website.

According to the information provided by the providers of the retargeting/remarketing services we use, the creation of such usage profiles is carried out in part on an anonymous or pseudonymous basis. We do not use data collected in this way to personally identify users, and it is never combined with the personal data we hold.

We use these cookies, for example, to target interested users with relevant information and thus continuously optimise our marketing communications with visitors to our website, in order to display relevant advertising content to them, including outside our websites. Data processing takes place exclusively on the basis of voluntary consent in accordance with Article 6(1)(a) of the GDPR. If users give us their consent to this, marketing cookies will be set when they visit our website or access an offer provided via it, and users will also be able to see interest-based advertising from us on other websites and social media platforms. We expressly refer to the information provided in section 3.4.

3.4 Google Advanced Consent Mode

We use Google Advanced Consent Mode (Version 2) provided by Google Ireland Limited, based in Dublin, Ireland, to manage data collection by Google services (e.g. Google Analytics and Google Ads) in a manner that complies with data protection regulations.

Consent Mode is used when no consent, or only limited consent, has been given for certain Google services via our consent management tool (Usercentrics).

If no consent has been given for statistical or marketing cookies:

  • no such cookies will be set,
  • no information will be stored on or read from the end device within the meaning of Section 25 of the TDDDG (Telecommunications and Digital Services Data Protection Act),
  • only so-called ‘consent pings’ will be transmitted to Google.

 

These pings contain exclusively technical and context-related information, such as:

  • timestamp of the page request,
  • truncated IP address,
  • information on the browser and operating system used (user agent),
  • referrer URL,
  • consent status,
  • and, where applicable, aggregated or modelled campaign information.

 

Individual users are not directly identified in this process. The data is used by Google exclusively for the creation of aggregated and modelled metrics.

The legal basis for this processing is Article 6(1)(f) of the GDPR. Our legitimate interests lie in:

  • ensuring an economically viable and functional website,
  • measuring reach statistically,
  • optimising our marketing activities,
  • improving the user experience.

 

Google also processes some data in the USA. For data transfers to third countries, Google relies on the EU-US Data Privacy Framework and on standard contractual clauses in accordance with Article 46 of the GDPR.

3.5 Retention period

Cookies can be categorised according to their retention period as session cookies and permanent cookies.

3.5.1 Session cookies

Most cookies are only required for the duration of the current service request or session and are deleted or expire as soon as users leave our website or their current session ends (so-called ‘session cookies’). These are used, for example, to maintain your login for our ticket shop.

3.5.2 Persistent cookies

These cookies are stored for a longer period of time so that we can recognise users when they revisit the website at a later date and retrieve their saved settings. This enables users, for example, to access the website more quickly and conveniently, or to avoid having to reconfigure certain settings. Permanent cookies are automatically deleted after 180 days.

3.5.2.1 Stay logged in

Where technically possible on the website, we offer users the option to ‘stay logged in’ for their account upon logging in, which they may choose to use on a voluntary basis. If users do not wish to use the login service, they are free to use the website without the “stay logged in” option. However, if they return to the site after their session (browser session) has ended, they will need to log in again. If you select the ‘stay logged in’ option, you will not need to do this again; you will remain logged in. For this purpose, we use an IDP cookie, which automatically recognises users when they revisit the website. As part of this process, a session ID is stored. This is linked to the user’s account. The browser only stores the IDP cookie; the IP address is not stored. We base the processing of personal data carried out in this context on the granting of consent in accordance with Article 6(1)(a) of the GDPR, for which you must actively tick the box provided for this purpose. To deselect the ‘stay logged in’ option and withdraw the consent given for the future, users must click on ‘log out’. The IDP cookie used has a duration of eight weeks. This means that, after a certain period of time, users will need to log in again, even if they have opted for the ‘stay logged in’ option and have not logged out since then. Users will also need to log in again if they change their password. Finally, we strongly recommend that you do not use the ‘stay logged in’ option on devices that are not used exclusively by you. Otherwise, there is an increased risk of unauthorised access to your account by third parties.

3.6 Third-party providers

We also integrate third-party functions into our website in order to use their services. These functions use third-party cookies, which are stored directly on your device by these services. You will be informed about the use of these cookies via the consent management tool.

3.7 Third-country

Data processing generally takes place on servers within the European Union. Data is only transferred to third countries (e.g. the USA) if this is necessary for the use of certain services (e.g. Google Analytics 4 or Google Ads) and appropriate safeguards within the meaning of Art. 44 et seq. of the GDPR.

3.8 Use of the Usercentrics Consent Management Platform

We use the Usercentrics Consent Management Platform to fulfil the legal obligation under Article 7(1) of the GDPR. The operator is Usercentrics GmbH, Rosental 4, 80331 Munich. The Usercentrics Consent Management Platform collects log file data, user agent information (device, browser type, browser language, browser version, resolution) and consent data (consent yes/no, timestamp, data scope, data attributes, ControllerID, ProcessorID, ConsentID) via a JavaScript script. This JavaScript enables Usercentrics GmbH to inform the user about specific tags and web technologies on our website and to obtain, manage and document their consent. The legal basis for the processing of the data is Article 6(1)(c) of the GDPR, as we are legally obliged to provide evidence of consent (in accordance with Article 7(1) of the GDPR). The aim is to understand our users’ preferences, implement them accordingly and document them in a legally compliant manner. The data will be deleted as soon as it is no longer required for our record-keeping purposes and provided there are no statutory retention obligations to the contrary. Visitors may permanently disable the execution of JavaScript at any time by adjusting the relevant settings in their browser, which would also prevent Usercentrics from executing the JavaScript.

4. Video surveillance on the exhibition grounds

Video surveillance is in operation on our exhibition grounds. This is carried out to enforce our rights as proprietors, to prevent criminal offences and to secure evidence in the event of criminal offences. It is also carried out for logistical reasons relating to traffic management, in particular to manage parking, prevent traffic congestion, coordinate coach transport and manage lorry traffic. The legal basis for video surveillance is Article 6(1)(f) of the GDPR, with the legitimate interests pursued by us arising from the aforementioned purposes. If and to the extent that a video recording is made, it will be deleted after 72 hours, unless longer storage is necessary to fulfil the aforementioned legitimate interests. In the latter case, deletion will only take place once the purpose of processing no longer applies.

5. Data protection for specific applications

5.1 Online bookings

We offer exhibitors and exhibitor representatives (the natural person behind the exhibitor or the exhibitor’s contact person) as well as visitors the option to book services online.

5.1.1 Visitor Registration / Exhibitor Staff Registration / Ticket Shop

By using the online registration system for visitors (trade visitors and general visitors) and for exhibitor representatives (all the aforementioned groups of persons hereinafter collectively referred to as ‘user’ or ‘data subject’), we collect the data necessary to process ticket orders in the Ticket Shop. The legal basis is Article 6(1)(b) of the GDPR. The data collected during registration may be corrected or amended by users at any time, even retrospectively, by clicking on the ‘Edit’ link in their user profile, with the exception of surnames and first names. Trade fair visitors (i.e. visitors to public events without trade visitor status) have the option, by using a guest account, to book services online without registering and without providing any additional data beyond that strictly necessary for the processing of the contract. By requesting additional data as part of the registration process to be completed by trade fair trade visitors (i.e. visitors with trade visitor status) and exhibitor representatives – for example, regarding specific professional interests or the mode of travel – we pursue the legitimate interest in identifying market-relevant trends and shifts in opinion, and better tailoring our trade events to the professional interests and needs of the visitors and exhibitors at the event in question, or offering digital exchange services amongst all users. This also enables us to provide users with targeted specialist information even before a subsequent event takes place. The classification of a data subject as either a tradetrade visitor or a trade fair visitor is determined either by the fact that certain events are accessible exclusively to trade visitors, or because the user utilises guest access to the ticket shop, or on the basis of a corresponding enquiry. All of this serves to promote the quality of professional exchange, which is essential for the successful organisation of trade fairs, exhibitions, congresses and conferences, and is therefore also in the interests of both trade fair visitors and exhibitor representatives. The legal basis for this is Article 6(1)(f) of the GDPR. There do not appear to be any interests of the data subjects that would override the aforementioned legitimate interests of Messe Düsseldorf GmbH in this regard. When redeeming admission voucher codes for free or discounted tickets, we base both the registration process and the collection of information described above – which goes beyond the mere processing of the ticket order – on the fact that the services provided to visitors are paid for in full or in part, or exchanged (in part) for the personal data requested. The legal basis for the data processing is Article 6(1)(b) of the GDPR. We will also send users who have booked a service online advertising for similar goods and/or services offered by our organisation via electronic means (e.g. by email). Should users not wish to receive such advertising, they may object to the processing of their data for this purpose at any time by sending an email to , privacy@messe-duesseldorf.de or, or via an unsubscribe link in every email, without incurring any costs other than the transmission costs in accordance with standard rates. The legal basis is Section 7(3) of the German Unfair Competition Act (UWG) in conjunction with Article 6(1)(f) of the GDPR.

Where special categories of personal data are processed in accordance with Article 9(1) of the GDPR (e.g. requesting health-related data in order to obtain a free ticket for a companion), we will expressly draw your attention to this at the relevant points.

5.1.2 Online Registration (OA)

The Online Registration (OA) service enables you to book an exhibition stand online as an exhibitor at a trade fair (web application and associated database). In doing so, personal data relating to the exhibitor’s representatives is also processed. The legal basis is Article 6(1)(f) of the GDPR (balancing of interests). The legitimate interest we pursue lies in the proper processing of orders, for which a natural person is required as a contact person at the exhibitor’s organisation, for example to be able to discuss queries or other details. If, in individual cases, the exhibitor is the same natural person who places an order themselves as a contracting party of Messe Düsseldorf GmbH, the latter is based on Article 6(1)(b) of the GDPR, namely on the conclusion or performance of a contract to which the data subject is a party. We will also send advertising for similar goods and services offered by the exhibitor’s company electronically to the exhibitor’s email address provided by the exhibitor’s representative (contact person) for the purpose of processing the trade fair registration. If you do not wish to receive such promotional material, you may object to the processing of your data for this purpose at any time by sending an email to , privacy@messe-duesseldorf.de or, or by clicking the unsubscribe link in any email, without incurring any costs other than the transmission costs charged at standard rates. The legal basis for data processing is Section 7(3) of the German Unfair Competition Act (UWG) in conjunction with Article 6(1)(f) of the General Data Protection Regulation (GDPR).

5.1.3 Online Order System (OOS) for exhibitors

We operate the Online Order System (OOS) to accept orders and conclude subsequent contracts via the internet as an online shop for exhibitors. This is a web application and database for the purchase of trade fair-related items and services in addition to the exhibition stand space itself. A login is required to use the OOS. The providers are Messe Düsseldorf GmbH and its affiliated service partners. We base the processing of personal data carried out here on the grounds of legitimate interests, following a balancing of interests in accordance with Article 6(1)(f) of the GDPR. The legitimate interest we pursue lies in the proper processing of orders, for which a natural person is required as a contact person at the exhibitor’s stand, for example, to discuss queries or other details. If the Where the exhibitor is the same natural person who places an order as a contracting party / contracting party to Messe Düsseldorf GmbH, the latter relies on Article 6(1)(b) of the GDPR, namely on the conclusion or performance of a contract to which the data subject is a party.

5.1.4 Payment processing in the Online Order System (OOS) and in the ticket shop

The data controller has integrated components from Novalnet AG www.novalnet.de into this website. Novalnet AG is a full-service payment provider which, amongst other things, handles payment processing. If the data subject selects a payment method during the ordering process in the online shop, the data subject’s data is automatically transmitted to Novalnet AG. By selecting a payment option, the data subject consents to this transmission of personal data for the purpose of processing the payment.
The personal data transmitted to Novalnet may include first name, surname, address, gender, email address, IP address and, where applicable, date of birth, telephone number, mobile phone number, as well as other data necessary for processing a payment. Personal data relating to the relevant order is also required to fulfil the contract of sale. In particular, this may involve the mutual exchange of payment details, such as bank account details, card number, expiry date and CVC code, as well as details of goods and services and prices.
The purpose of transferring this data is, in particular, identity verification, payment administration and fraud prevention. The data controller will transfer personal data to Novalnet AG in particular where there is a legitimate interest in doing so. The personal data exchanged between Novalnet AG and the data controller may be transferred by Novalnet AG to credit reference agencies. The purpose of this transfer is to carry out identity and credit checks.
Novalnet AG also passes on personal data to service providers or subcontractors insofar as this is necessary to fulfil contractual obligations or where the data is to be processed.
The data subject has the right to withdraw their consent to the processing of personal data at any time by notifying Novalnet AG. Such withdrawal does not affect personal data which must be processed, used or transferred for the purposes of (contractual) payment processing.

5.2 Stand Construction Configurator

On our website, specifically in the stand construction configuration section, we use 3D configurators provided by redPlant GmbH of Düsseldorf (further information on redPlant GmbH can be found at: https://redplant.de/). The 3D configurators serve as planning software. Depending on how you use the 3D configurators, the following personal data relating to you will be processed: browser type and version, operating system used, device type used, time of access, IP address and your contact details. You can find the specific contact details processed in the contact form within the stand construction configurator. The temporary processing of this data by the 3D configurators is necessary in order to provide you with the basic functionalities of the planning software from a technical perspective. This data is not combined with other data sources. The information is processed solely for your use of the stand construction configurator. The legal basis is therefore Article 6(1)(f) of the GDPR. Furthermore, where consent has been given, Article 6(1)(a) of the GDPR may serve as the legal basis, as may Article 6(1)(b) of the GDPR may apply where a (pre-)contractual obligation is being fulfilled. The aforementioned personal data will be erased, subject to any relevant statutory provisions, once the underlying purpose no longer applies.

5.3 Surveys

We enable participation in interactive surveys, so that users can easily share their opinions with other users. Surveys also serve the purpose of tailoring our content and services even more specifically to our customer base. We use a system to ‘mark’ users after they have cast their vote, so that they can only vote once on a particular question. There is no link between this marking and information about individual users. At our discretion, we pass on the demographic information gathered in these surveys to other users of the relevant trade fair-specific website; however, we never disclose any personal data. The legal basis for this is Article 6(1)(a) of the GDPR.

5.3.1 Panels

As part of our Trend Reports, we regularly conduct surveys of industry experts from manufacturers, suppliers and service providers on current market issues and assessments (so-called ‘panels’). The aim is to identify and subsequently present the latest trends and relevant topics in the relevant sector. Participants can register for the panels either via our website or by agreeing to the information email we have sent them. The legal basis for data processing is Article 6(1)(a) of the GDPR. Where necessary (e.g. for the evaluation of responses and the preparation of a report), the relevant data is forwarded to our service provider. A corresponding contractual relationship exists with the respective service providers.

5.3.2 Market research

We regularly conduct surveys as part of market research on relevant topics from various areas of the trade fair industry. The purpose of this is to identify market trends and the wishes of our contractual partners and users, and to be able to respond to them. Registration for the survey takes place via the information email sent to us, which also specifies the relevant types of data (these are usually: name, email address and telephone number). In some cases, we also work with market research companies or external service providers under a data processing arrangement in accordance with Article 28 of the GDPR, meaning that personal data is passed on to them. Whether such collaboration takes place is indicated in the relevant information email. The legal basis for data processing is therefore Article 6(1)(f) of the GDPR. Our legitimate interest arises from the aforementioned purpose. Your data will only be stored for as long as is necessary for the purposes set out above.

5.4 Electronic newsletters

We offer the option to subscribe to electronic newsletters on various topics. To this end, we collect the email addresses of users who voluntarily register as subscribers. The legal basis for sending the newsletter(s) is Article 6(1)(a) of the GDPR in conjunction with Section 7(2)(2) of the UWG (consent). We use the so-called double opt-in procedure for subscribing to our newsletter. This means that, after signing up for the newsletter, users will receive an email at the address provided, asking them to confirm their subscription. Users may withdraw their consent to receive the newsletter at any time with future effect by clicking on the unsubscribe link found in every newsletter or by sending an email to , privacy@messe-duesseldorf.de, or

5.5 Competitions, loyalty programmes

Where we run loyalty programmes or competitions, all rules and information regarding the relevant procedure and the use of personal data during the programme’s duration will be clearly set out in the respective terms and conditions. The information collected is also used to verify the user’s identity and to notify the winners or prize recipients. Here too, we do not pass on information relating to specific individuals to third parties.

5.6 novomind

We use an AI application (hereinafter referred to as ‘AI’) from novomind AG, based in Hamburg, Germany, on our websites. The AI provides you, as a user, with answers to your questions regarding the respective event. To do this, the AI accesses publicly available information from our event-specific websites as well as from publicly accessible websites (e.g. those of exhibitors at the event). The personal data published on the aforementioned websites, as well as your IP address, are therefore processed. The legal basis for the data processing is Article 6(1)(f) of the GDPR. Our legitimate interest lies in providing customer support and improving your trade fair experience. In addition, personal data is also processed if you enter it into the AI yourself. In this case, processing is carried out on the basis of your consent in accordance with Article 6(1)(a) of the GDPR. Further information on novomind AG can be found at: https://www.novomind.com/.

5.7 VIP Hosted Buyer Programme

Messe Düsseldorf GmbH offers participants in the VIP Hosted Buyer Programme (hereinafter referred to as the ‘Programme’) exclusive benefits for visiting and taking part in trade fairs organised by the company. Participation requires prior application and registration via the relevant landing page. Registration is completed by clicking the ‘Apply now’ button and filling in and submitting the form provided. The data requested in the form, such as first name, surname, email address, postal address and details from an identity document (e.g. business licence), are necessary to process the application and carry out the pre-contractual steps. The legal basis for the processing is Article 6(1)(b) of the GDPR, as the processing is necessary for the assessment of the application, the implementation of pre-contractual measures and the use of the customer account. The data will be stored for the duration of the registration and the initiation or implementation of the programme, and will subsequently be deleted unless there are statutory retention obligations or a legitimate interest, such as the assertion or defence of legal claims, precludes this.

Once the application has been successfully assessed, the participant will receive an email containing further information and a request to complete a travel form via the ‘Asana’ tool used by Messe Düsseldorf GmbH. Additional data required for the organisation and implementation of the programme is collected there, such as first name, surname, email address, travel dates (e.g. arrival and departure times), date of birth or passport number. The legal basis for this processing is also Article 6(1)(b) of the GDPR, as this information is necessary to enable participation in the VIP Hosted Buyer Programme and to fulfil the associated contractual obligations. The ‘Asana’ tool is provided by Asana Inc., a company based in the USA. The processing of personal data may therefore also take place on servers in the USA. An adequacy decision by the European Commission has been issued for the USA in accordance with Article 45(3) of the GDPR. Asana Inc. is certified under the EU-US Data Privacy Framework, thereby ensuring an adequate level of protection for the data transferred. Further information on data processing by Asana Inc. can be found in its privacy policy at , https://asana.com/de/terms/privacy-statement, and

. In order to run the programme, it is necessary to pass on personal data to tour operators or other service providers involved in organising the trip. The legal basis for this transfer is Article 6(1)(b) of the GDPR. The transfer serves to ensure the efficient organisation of the travel services and the proper implementation of the programme, and is therefore necessary for the performance of the contract.

Personal data will only be stored for as long as is necessary for the implementation and administration of the VIP Hosted Buyer Programme. Relevant accounting or tax-related data will be retained in accordance with statutory retention periods (usually six to ten years). Identity and travel data, such as passport numbers, will be deleted as soon as they are no longer required for the organisation and documentation of the trip.

There is no automated decision-making or profiling in accordance with Article 22(1) and (4) of the GDPR.

6. Further visitor services

6.1 Fair Match

Fair Match is a platform for participants at events organised by Messe Düsseldorf GmbH. The Fair Match platform facilitates subject-specific exchanges between visitors and exhibitors, as well as amongst the respective groups of people themselves. The Fair Match Engine used calculates, on the basis of registration data, which individuals are most relevant to the user of the Fair Match services and displays them. We process the following types of data provided by the user themselves in the exhibitor application or visitor registration: first name and surname, sector, job title and stated interests. In addition, other personal data specifically entered by the user may also be processed, such as the profile picture uploaded and communication details. Participation in Fair Match is also indicated in the public exhibitor profile by means of a corresponding button. We base the processing of personal data in connection with the provision of Fair Match services on Article 6(1)(f) of the GDPR. Our legitimate interest lies in enhancing the trade fair experience for the benefit of our exhibitors and visitors. Personal data is transferred to our data processor, dimedis GmbH, based in Cologne. Users may object to the processing at any time and without giving reasons with effect for the future, or directly upon registration. Further information on the rights of data subjects can be found in section 10 of this privacy policy. The personal data processed as part of the Fair Match services, as well as the associated account, are generally deleted at the end of the respective follow-up event. Once the respective follow-up event has ended, the participants concerned will be contacted once more before the data is deleted and asked whether they wish to remain on Fair Match. If the data subject consents to this, their personal data will continue to be stored and processed within the Fair Match platform. In this case, further processing takes place on the basis of Article 6(1)(a) of the GDPR (consent). Consent may be withdrawn at any time with future effect and without giving reasons (see section 10 of this privacy notice). Data will be stored until consent is withdrawn. If there is no activity within three years, the data will be deleted at the latest upon expiry of this period.

6.2 Web sessions

Depending on the event organised by Messe Düsseldorf GmbH, web sessions are offered by Messe Düsseldorf GmbH as well as third parties (such as exhibitors or associations). Web sessions are seminars, events or conferences in which people can take part via the internet. These are used to present, for example, the latest products, processes or general industry-relevant topics to the registered trade audience. For this purpose, we use the “Zoom X” platform provided by Telekom Deutschland GmbH, based in Bonn. It is not necessary to download the aforementioned platform or to register in order to take part in the web session. Before taking part, you simply need to register on the relevant trade fair website or via the ticket shop for the respective trade fair in order to receive access authorisation and details for the web session. The personal data processed there can be found in the relevant registration details. In ‘Zoom X’ itself, only your first name, surname and email address are required. This personal data is also forwarded to the aforementioned platform. We base the processing of personal data in this respect on the fact that the data transfer is in the data subject’s interest. In particular, as ‘Zoom X’ is technically particularly well-suited to conducting the web sessions in order to offer participants an informative and high-quality online experience, there is a close and significant link between the data transfer and the contract concluded between Messe Düsseldorf GmbH and the provider of ‘Zoom X’ in the interests of the participants. The relevant legal basis is therefore Article 6(1)(f) of the GDPR. Should the use of ‘Zoom X’ be necessary for the performance of a contract, the legal basis for data processing is Article 6(1)(b) of the GDPR.

Participation requires the download and successful installation of the ‘Zoom’ conferencing software provided by Zoom Video Communications, Inc., 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113 (USA). It is also necessary to register successfully with the aforementioned provider of this software. Each interested participant must carry out this registration independently. When logging in to a web session following successful registration, the types of data required for participation – namely surname, first name (which the data subject may also replace with a pseudonym) and email address, to the aforementioned provider of ‘Zoom’, with whom Messe Düsseldorf GmbH has a corresponding contractual relationship. We base the processing of personal data in this respect on the fact that the data transfer is in the data subject’s interest. In particular, as ‘Zoom’ is technically particularly well-suited to conducting the web sessions in order to offer participants an informative and high-quality web experience, there is a close and significant link between the data transfer and the contract concluded between Messe Düsseldorf GmbH and the provider of ‘Zoom’ in the interests of the participants. The relevant legal basis is therefore Article 49(1)(c) of the GDPR.

By participating in a web session, the personal data (namely surname, first name, email address, company affiliation, professional position, country) of the respective participant will be passed on to the presenting exhibitor or the presenting association, in particular for their own marketing purposes. We base the processing of personal data in this respect on Article 6(1)(b) and Article 6(f) of the GDPR (where applicable, in conjunction with Articles 44 et seq. of the GDPR). Our legitimate interest lies in the provision of free services (“Pay with Data”).

6.3 Vehicle owner enquiries / Messe Düsseldorf GmbH car parks

We operate paid car parks for motor vehicles available for hire. In cases where motor vehicles have been parked in paid car parks and the maximum parking duration has been exceeded or no valid parking ticket has been purchased, we carry out a vehicle owner enquiry with the Federal Motor Transport Authority. This is done to enforce claims for parking fees in accordance with the terms and conditions of use for the car parks, as displayed on site. Where the vehicle owner and the person renting the parking space are the same person, we rely on the legal basis of Section 39(1) of the Road Traffic Act (StVG) in conjunction with Article 6(1)(b) of the General Data Protection Regulation (GDPR); otherwise (where the vehicle owner and the person using the parking space are not the same person), on the legal basis of Section 39(1) of the Road Traffic Act (StVG) in conjunction with Article 6(1)(f) of the General Data Protection Regulation (GDPR) (pursuit of legitimate interests following a balancing of interests). The vehicle owner enquiry is both necessary and essential for the assertion, safeguarding or enforcement of, or for the satisfaction or defence against, legal claims in connection with the assertion of outstanding parking fee claims. This is because it is the only suitable means of enforcing the law. This, together with the assessment made by the legislator in Section 39 of the StVG, means that our interest in carrying out the vehicle owner enquiry outweighs the vehicle owner’s interest in avoiding the associated infringement of their personal rights.

7. Sanctions list screening

We screen the personal data of representatives of (exhibiting) companies. Screening against sanctions lists is carried out to comply with legal requirements. The purpose of this check is to ensure that no business dealings or relationships exist with individuals, organisations or companies listed on national or international sanctions lists. The processing of your personal data is carried out on the basis of Article 6(1)(c) of the GDPR, as it is necessary for compliance with a legal obligation. The following personal data is processed as part of the screening: first name and surname, nationality, place of residence/address and any other data required for identification. The data collected is derived from information provided by the data subject or from publicly available sources. The data is used exclusively for internal purposes or, where necessary, passed on to the relevant authorities or to the contracted service provider acting in the capacity of a data processor. Specifically, this refers to the company Rausoft GmbH, based in Leonberg, Germany. Further information on data protection at Rausoft GmbH can be found at www.rausoft.de. Data will only be transferred to third countries if an adequate level of data protection exists there or if appropriate safeguards are in place. Personal data will only be stored for as long as is necessary to fulfil legal obligations, or until the data subject no longer has any connection to requirements relevant to sanctions.

8. Additional information regarding the use of our app

Below you will find information that is exclusively relevant to the use of our respective trade fair-specific app.

8.1 Downloading the app

When you download the apps, the necessary information is transmitted to the relevant app store (Apple App Store and Google Play Store). This includes, in particular, your username, email address, the time of download, payment details where applicable, and your device’s unique identifier. In addition, the respective app store independently collects various data and provides you with analysis results. We have no influence over this data processing and refer you to the respective privacy policies of the relevant app store provider, which are their sole responsibility.

8.2 Use of the app

In order to provide you with the benefits of our app, certain personal data required for the app’s operation is collected when you use it. We collect this data only where it is necessary for the performance of the contract between you and us (Article 6(1)(b) of the GDPR). Furthermore, we collect this data where we have a legitimate interest and your interest in the protection of your personal data does not override that interest (Article 6(1)(f) of the GDPR) or where you consent to the processing (Article 6(1)(a) of the GDPR). Where the processing of the data requires the storage of information in your Where access to the terminal equipment or to information already stored on the terminal equipment is required, Section 25(1) and (2) of the TDDDG provides the legal basis for this.

8.2.1 Functionality of the app

When using the app, personal data is collected that is technically necessary for the functionality, stability and security of our app. This includes the following personal data:

  • IP address
  • Content of the request (specific page)
  • Amount of data transferred
  • Operating system
  • Language

The legal basis for data processing is therefore Article 6(1)(f) of the GDPR in conjunction with Section 25(2)(2) of the TDDDG. Our legitimate interest lies in ensuring the aforementioned purposes.

8.2.2 Registration and ‘stay logged in’

We offer you the option to create a user account in our app. Creating a user account is voluntary and not strictly necessary for using the app. However, some functions (such as MyOrganiser) are only available to users with an account. A prerequisite for creating a user account is registration with the ticket shop of the relevant trade fair, unless this has already been done. The personal data processed there (surname, first name, address, etc.) can be found on the relevant registration form. The login details provided during registration must be used to log in to the app. The legal basis for using the data entered in the ticket shop for the user account in the app is Article 6(1)(f) of the GDPR. The legitimate interest lies in preventing the existence of multiple accounts with Messe Düsseldorf GmbH and thus serves the purpose of data minimisation.

The account in the ticket shop for the relevant trade fair, and consequently the user account in the app, can be deleted at any time without giving reasons and with effect for the future. To do so, please send an email requesting deletion to privacy@messe-duesseldorf.de. Alternatively, the request for deletion can also be submitted to here or by post (Messe Düsseldorf GmbH, G2-RV, PF 101006, 40001 Düsseldorf, Germany). Please note that deleting your account will irrevocably remove all your personal data and content. Please ensure you have backed up all necessary information before proceeding.

Once you have logged in using your login credentials, you will remain logged in until you log out yourself or until the period specified below expires. To this end, your login credentials are stored in a local database on the device following a successful login. The legal basis for data processing is Article 6(1)(f) of the GDPR. The legitimate interest lies in ensuring barrier-free access to services and facilitating a straightforward login process. After 60 days (sixty days) have elapsed, you will be automatically logged out. This means that, after a certain period of time, you will need to log in again, even if you have not logged out in the meantime. If you change your password, you will also need to log in again.

8.2.3 Push notifications

Push notifications containing general information about the relevant trade fair (e.g. trends and topics, event tips, etc.) will be displayed if you have given your consent to this. The legal basis for data processing is Article 6(1)(a) of the GDPR. You may withdraw your consent at any time with future effect, without giving any reason, via the app’s settings or the settings on your mobile device. For further information regarding your other data subject rights, please refer to section 9 of this privacy policy.

8.2.4 My Tickets

Purchased tickets are automatically loaded into the app and are available there for admission to the relevant event. The tickets are requested from the app via a REST API route to the ticket shop of the relevant trade fair. Authentication takes place via the IDP session and an encrypted HTTPS connection. The QR codes are cached in the app and are therefore also available offline. The legal basis for data processing is Article 6(1)(b) of the GDPR.

8.2.5 My Recommendations

Preferences can be derived from the structural data provided during registration in the ticket shop. These can be used to display rule-based and/or personalised recommendations (e.g. exhibitors, products, contact persons or events) that are particularly relevant to you and make your visit to the trade fair more appealing. The legal basis for data processing is Article 6(1)(f) of the GDPR. The legitimate interest lies in improving the trade fair experience and making it easier for you to find trade fair content that is relevant to you. The information from the structural data is not passed on to third parties.

8.3 Cookies in the app

8.3.1 General information

Cookies are used in our app. Cookies are small text files that are placed and stored on your mobile device. On the one hand, they ensure the technical functionality of the app. On the other hand, they enable us to improve user-friendliness, as well as effectiveness and security. Insofar as the cookies serve the technical operation of the website and are strictly necessary for its technical operation, data processing takes place on the legal basis set out in Article 6(1)(f) of the GDPR. The legitimate interest arises from the above. Cookies that are not strictly necessary for the operation of the app are processed on the basis of consent in accordance with Article 6(1)(a) of the GDPR.

8.3.2 Cookies used in the app

Below you will find an overview of the cookies used in the app, together with a brief description. Further information on the cookies used, in particular regarding retention periods, can be found in the Cookie Consent Manager.

Please note that you may change your cookie settings in the Cookie Consent Manager at any time and without giving reasons, with effect for the future, irrespective of your rights under section 9 of this privacy policy.

8.3.3 Technically necessary cookies

These cookies must always be set to enable the basic functions and proper use of our app. The legal basis for data processing is Article 6(1)(f) of the GDPR in conjunction with Section 25(2)(2) of the TDDDG.

8.3.4 Google Analytics 4

We use the web analytics service Google Analytics 4 provided by Google Ireland Ltd. in Ireland. Google Analytics 4 is software used to measure the return on investment (‘ROI’) from advertising and to track user behaviour. Cookies are used for this purpose. The information generated by the cookies is transferred to Google’s servers in the USA. Please note that an adequacy decision by the European Commission (EU-US Data Privacy Framework) is in place for the USA. Google is also certified under the EU-US Data Privacy Framework. The legal basis for data processing using Google Analytics 4 cookies is Article 6(1)(a) of the GDPR in conjunction with Article 45(1) of the GDPR. Further information about Google can be found at: https://about.google/.

8.3.5 Matomo

We use the web analytics service Matomo from InnoCraft Ltd. in New Zealand. Matomo is open-source software for the statistical analysis of visitor traffic. Cookies are used for this purpose. The information generated by the cookies regarding your use of the app is collected, stored and processed on our server in Germany and is not passed on to third parties. The IP address is automatically anonymised by obscuring parts of it. The legal basis for data processing using Matomo cookies is your consent in accordance with Article 6(1)(a) of the GDPR. Further information about InnoCraft Ltd. and Matomo can be found on the websites , https://www.innocraft.com/#aboutus, and

. 8.3.6 Google Firebase

We use Google Firebase. This is a service for the development of mobile and web applications provided by Google Ireland Ltd. based in Ireland. The information generated by the cookies is transferred to Google’s servers in the USA. Please note that an adequacy decision by the European Commission (EU-US Data Privacy Framework) is in place for the USA. Google is also certified under the EU-US Data Privacy Framework. The legal basis for data processing using Google Analytics 4 cookies is Article 6(1)(a) of the GDPR in conjunction with Article 45(1) of the GDPR. Should the service be absolutely necessary for the provision of the service, the legal basis for data processing is Article 6(1)(f) and Article 45(1) of the GDPR in conjunction with Section 25(2)(2) of the TDDDG. Further information about Google can be found at: https://about.google/.

8.3.7 Use of the Usercentrics Consent Management Platform

We use the Usercentrics Consent Management Platform provided by Usercentrics GmbH, Munich, to fulfil our legal obligation under Article 7(1) of the GDPR (proof of consent) and to inform you about certain tags and web technologies on our app, as well as to obtain, manage and document the necessary consents. The Usercentrics Consent Management Platform collects log file data, user agent information (device, app language, app version, resolution) and consent data (consent yes/no, timestamp, scope of data, data attributes, controller ID, processor ID, consent ID). The legal basis for the processing of the data is Article 6(1)(c) of the GDPR in conjunction with Article 7(1) of the GDPR.

8.4 Data processing by third parties

8.4.1 Categories of recipients

We use external service providers (e.g. in the IT sector). These service providers act solely in accordance with our instructions and are contractually obliged, within the meaning of Article 28 of the GDPR, to comply with data protection regulations.

The following categories of recipients, who are generally data processors, may have access to your personal data in connection with the app:

  • IT service providers and data centre operators. The legal basis for the disclosure is Article 6(1)(b) of the GDPR;
  • Service providers responsible for tracking and analysing the app.

The legal basis for this transfer is Article 6(1)(a) of the GDPR or Article 6(1)(f) of the GDPR in conjunction with Section 25(2)(2) of the TDDDG. Where data is transferred to a third country, Article 45(1) of the GDPR also forms the legal basis for the transfer. Further information on this can be found in section 7.5 (Cookies) of this privacy policy.

8.4.2 Legal obligation to transfer certain data

We may, under certain circumstances, be subject to a specific legal or regulatory obligation to make lawfully processed personal data available to third parties, in particular public authorities. The legal basis for the processing and disclosure of this personal data is Article 6(1), first sentence, point (c) of the GDPR.

9. Candidate Management

9.1 Application Process

The data protection information set out in Section 9 applies exclusively to the application process and thus to the relationship between the applicant and Messe Düsseldorf GmbH.

Upon receipt of an online application for a specific job vacancy, a speculative application or an application following a previous recruitment interview, the applicant’s personal data will be processed for recruitment purposes. During the phase of establishing an employment contract, Messe Düsseldorf GmbH has an interest in ensuring that you possess the professional competence and personal suitability required for the vacant post. The scope of data processing, the course of the application process and the choice of methods (e.g. telephone interview, face-to-face interview, etc.) are determined by the requirements of the specific job vacancy. These factors also determine which individuals are involved in the data processing and therefore have access to your data. These individuals typically include staff from the Human Resources department and line managers, as well as, in some cases, line managers responsible for specific areas. Depending on the position, your data may also be processed by members of the works council or members of the representative bodies for employees with severe disabilities, in the exercise of their statutory co-determination rights. These individuals have received training in data protection law and are bound by a duty of confidentiality. Should any other individuals or bodies (e.g. service providers) have access to your data, this is always on the basis of a contractual agreement. The specific service providers can be found in the information for data subjects, which was sent to the applicant by email along with the confirmation of receipt of their application.

If contact is made via the social media platform LinkedIn, its privacy policy applies under its own responsibility. Please note that in this case, personal data may be transferred to a third country which may not provide an adequate level of data protection.

The data is collected, stored and used exclusively for the purposes of the recruitment process. The legal basis for data processing is therefore Article 6(1)(a) and Article 6(1)(b) of the GDPR. Should no employment relationship be established, the applicant’s personal data will be deleted after six months. Any storage of the data beyond this period will only take place with the applicant’s express consent. You may object to the use of your personal data at any time by emailing Bewerbermanagement[at]messe-duesseldorf.de. Please note that the above email address is not available for the submission of documents.

9.2 Job subscription

We also offer a so-called job subscription. This is a job-finding service linked directly to a specific job board, which keeps job seekers informed about new vacancies. Anyone interested in working at Messe Düsseldorf GmbH can set up such a job alert online. There, the interested party enters their email address and a password of their choice, and selects which types of job adverts they would like to be sent once they are published on the website. Registration takes place using the double opt-in procedure. With this job agent, the interested party’s data is stored following successful sign-up and confirmed registration until further notice and is used within the scope of the job agent’s services.

10. Your rights as a data subject

10.1 Right of access / erasure / restriction of processing

Any data subject affected by data processing has the right, upon request, to obtain confirmation as to whether personal data concerning them is being processed by us. If such processing is taking place, the data subject may request information about the personal data concerning them that we are processing. Furthermore, they may request the rectification or erasure of data, restriction of processing, data portability, and may object to the processing.

10.2 Right to lodge a complaint

Any data subject affected by the processing of data has the right to lodge a complaint with a competent supervisory authority.

10.3 Right to object

Naturally, each of our customers is free to specify the purposes for which their personal data should not be used. If you no longer wish your data to be used for a specific purpose, you can object to any further use of your data here.

10.4 Exercising your legal rights

If you exercise your legal rights regarding your personal data (see section 9 of this privacy notice), we will process the data contained in your enquiry, in addition to the personal data we already hold, in order to review your enquiry, respond to it and, where necessary, take the required measures. The legal basis for data processing is Article 6(1)(c) of the GDPR.


Privacy notice in plain language

I. Introduction

This summary is written in plain language and does not replace the full privacy notice on the Messe Düsseldorf GmbH website. If you have any important questions, you should always read the detailed information or enquire directly with Messe Düsseldorf GmbH.

Here we explain how we protect your personal data. Personal data includes, for example, your name, your email address, your postal address or your telephone number. We protect your data in accordance with the General Data Protection Regulation (GDPR) and other laws.

II. Who is responsible for data protection?

Messe Düsseldorf GmbH, based in Düsseldorf, Germany, is responsible for protecting your data. The contact details can be found at the end of this document.

III. What data do we collect?

We only collect the data we need for our work. This may include:

  • your name, address and email address (if you register)
  • information about your company (if you are an exhibitor)
  • technical data such as your IP address, browser and device type
  • Data you provide when registering for trade fairs or events
  • Data you enter when using a Messe Düsseldorf GmbH app (e.g. for your user account)

IV. Why do we need your data?

We use your data for various purposes, for example:

  • To show you the website(s) and our offers
  • To plan and organise trade fairs and events
  • To send you information and advertising, if you wish to receive it or if there is a contractual relationship
  • To improve the quality of our offers
  • To enable your registration and participation in trade fairs
  • To ensure the security and functionality of the website and app

V. How is your data used?

 

  • Your data is used only for specific purposes.
  • We sometimes pass data on to partners, such as service providers who provide us with technical support.

VI. How do we protect your data?

We use modern technology to protect your data. For example, we store it securely and encrypt important information. Furthermore, only authorised persons are permitted to access the data.

VII. Marketing and opt-out

Where a contractual relationship exists, we may send you information and marketing material about similar offers by email.

You can opt out at any time by sending an email to privacy@messe-duesseldorf.de or by using the unsubscribe link in the email. There are no additional costs.

VIII. Cookies

Cookies are small files that are stored on your computer when you visit our website. They help us to make the website more user-friendly and/or improve it. You can choose:

  • Allow all cookies.
  • Allow only certain cookies.
  • Reject all cookies.

IX. How long do we store your data?

We only store your data for as long as we need it. Once we no longer need it, we delete it securely.

X. Your rights

You have rights. This means: you have a say in what happens to your data.

You are entitled to know from us:

  • What data we hold about you (right of access);
  • You may request: Please amend my data (right to rectification);
  • You may say: ‘Please delete my data’ (right to erasure);
  • You may say: ‘Please stop using my data’ (right to object);
  • You may say: ‘Please keep my data, but do not use it at the moment’ (right to restriction of processing);
  • You may say: ‘Please give me my data so that I can pass it on to another company’ (right to data portability);
  • You may lodge a complaint. For example, if you believe your data is not being properly protected;
  • You may lodge a complaint with the data protection authority (right to lodge a complaint).

 

XI. Contact

If you have any questions or need help, you can contact us:

Messe Düsseldorf GmbH

Messeplatz, Stockumer Kirchstraße 61, 40474 Düsseldorf, Germany

Telephone: +49 211 4560-01

Email: privacy@messe-duesseldorf.de

XII. Data Protection Officer

Our Data Protection Officer (c/o migosens GmbH, Wiesenstr. 35, 45473 Mülheim an der Ruhr) will assist you with any queries regarding data protection. You can contact them by email: dsb-messe-duesseldorf@migosens.net