Preamble
With the following Privacy Policy, we would like to inform you about the types of your personal data (hereinafter also referred to as “data”) that we process, the purposes for which we process it, and the scope of such processing. This Privacy Policy applies to all processing of personal data carried out by us, both in connection with the provision of our services and, in particular, on our websites, in mobile applications, and within external online presences, such as our social media profiles (hereinafter collectively referred to as “Online Services”).
The terms used are not gender-specific.
As of July 14, 2026
Table of Contents
Data Controller
C3 Expo GmbH
Hans-Thoma-Straße 100
68163 Mannheim
Authorized representatives: Daniel Beyerle
Email address: info@c3expo.de
Phone: 062149094250
Legal notice:
https://c3-expo.de/impressum/
Overview of Data Processing Activities
The following overview summarizes the types of data processed and the purposes of processing and refers to the affected individuals.
Types of Data Processed
- Master data.
- Employee data.
- Contact data.
- Content data.
- Usage data.
- Meta, communication, and process data.
- Log data.
Categories of Data Subjects
- Service recipients and clients.
- Employees.
- Users.
- Third parties.
- Whistleblowers.
Purposes of Processing
- Communication.
- Security measures.
- Feedback.
- Provision of our online services and user-friendliness.
- IT infrastructure.
- Whistleblower protection.
- Public relations.
Applicable Legal Bases
Applicable Legal Bases under the GDPR: The following provides an overview of the legal bases under the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations may apply in your country of residence or in our country of residence or registered office. If more specific legal bases apply in individual cases, we will inform you of these in the Privacy Policy.
- Consent (Art. 6(1), first sentence, subparagraph (a) of the GDPR) – The data subject has given consent to the processing of personal data concerning them for a specific purpose or several specific purposes.
- Legal obligation (Art. 6(1), first sentence, subparagraph (c) of the GDPR) – Processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR) – Processing is necessary to safeguard the legitimate interests of the controller or a third party, provided that the interests, fundamental rights, and fundamental freedoms of the data subject requiring the protection of personal data do not take precedence.
National Data Protection Regulations in Germany: In addition to the data protection regulations of the GDPR, national data protection regulations apply in Germany. These include, in particular, the Act on the Protection Against the Misuse of Personal Data in Data Processing (Federal Data Protection Act – BDSG). The BDSG contains specific provisions regarding the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, data transfers, and automated decision-making in individual cases, including profiling. In addition, state data protection laws of the individual federal states may apply.
Security Measures
We implement appropriate technical and organizational measures in accordance with legal requirements, taking into account the state of the art, the costs of implementation, and the nature, scope, circumstances, and purposes of processing, as well as the varying likelihood and severity of threats to the rights and freedoms of natural persons, in order to ensure a level of security appropriate to the risk.
These measures include, in particular, ensuring the confidentiality, integrity, and availability of data by controlling physical and electronic access to data, as well as access to, input of, and disclosure of data, ensuring availability, and maintaining separation of data. Furthermore, we have established procedures that ensure the exercise of data subject rights, deletion of data, and responses to data breaches. We also consider the protection of personal data from the very beginning when developing and selecting hardware, software, and processes, in accordance with the principle of data protection through technical design and privacy-friendly default settings.
Securing Online Connections Using TLS/SSL Encryption Technology (HTTPS): To protect user data transmitted via our online services from unauthorized access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the Internet. These technologies encrypt information transmitted between the website or app and the user’s browser (or between two servers), thereby protecting the data from unauthorized access. TLS, as the more advanced and secure version of SSL, ensures that all data transmissions meet the highest security standards. If a website is secured by an SSL/TLS certificate, this is indicated by the presence of HTTPS in the URL. This serves as an indicator to users that their data is transmitted securely and encrypted.
Transfer of Personal Data
As part of our processing of personal data, such data may be transferred to or disclosed to other entities, companies, legally independent organizational units, or individuals. Recipients of this data may include, for example, service providers contracted to perform IT tasks or providers of services and content integrated into a website. In such cases, we comply with legal requirements and, in particular, enter into appropriate contracts or agreements with the recipients of your data to ensure the protection of your data.
International Data Transfers
Data Processing in Third Countries: If we transfer data to a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)), or if this occurs in connection with the use of third-party services or the disclosure or transfer of data to other individuals, entities, or companies (which can be identified based on the provider’s postal address or where the Privacy Policy explicitly refers to data transfers to third countries), this is always carried out in accordance with legal requirements.
For transfers of data to the United States, we primarily rely on the Data Privacy Framework (DPF), which was recognized as a secure legal framework through an adequacy decision of the European Commission dated July 10, 2023. In addition, we have concluded standard contractual clauses with the respective providers that comply with the requirements of the European Commission and establish contractual obligations to protect your data.
This dual protection ensures comprehensive protection of your data: The DPF serves as the primary level of protection, while the Standard Contractual Clauses provide additional security. Should changes occur within the framework of the DPF, the Standard Contractual Clauses serve as a reliable fallback option. This ensures that your data remains adequately protected at all times, even in the event of political or legal changes.
For the individual service providers, we inform you whether they are certified under the DPF and whether standard contractual clauses are in place. Further information on the DPF and a list of certified companies can be found on the website of the U.S. Department of Commerce at
https://www.dataprivacyframework.gov/ (in English).
For data transfers to other third countries, appropriate safeguards apply, in particular standard contractual clauses, explicit consent, or transfers required by law. Information on transfers to third countries and applicable adequacy decisions can be found on the European Commission’s website:
https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de.
General Information on Data Storage and Deletion
We delete the personal data we process in accordance with legal requirements as soon as the underlying consents are withdrawn or there are no longer any legal grounds for processing. This applies in cases where the original purpose of processing no longer applies or where the data is no longer required. Exceptions to this rule apply where legal obligations or specific interests require the data to be retained or archived for a longer period.
In particular, data that must be retained for commercial or tax law reasons, or whose storage is necessary for the enforcement of legal claims or the protection of the rights of other natural or legal persons, must be archived accordingly.
Our Privacy Policy contains additional information on the retention and deletion of data that applies specifically to certain processing operations.
If several statements are provided regarding the retention period or deletion deadlines for specific data, the longest period shall always apply. Data that is no longer retained for the originally intended purpose but due to legal requirements or other reasons will only be processed for the purposes that justify its retention.
Data Retention and Deletion: The following general retention and archiving periods apply under German law:
- 10 years – Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets, as well as work instructions and other organizational documents necessary for their understanding (§ 147(1)(1) in conjunction with (3) AO, § 14b(1) UStG, § 257(1)(1) in conjunction with (4) HGB).
- 8 years – Accounting documents, such as invoices and expense receipts (§ 147(1)(4) and (4a) in conjunction with § 147(3), sentence 1 AO, and § 257(1)(4) in conjunction with § 257(4) HGB).
- 6 years – Other business documents: received commercial or business correspondence, copies of sent commercial or business correspondence, other documents insofar as they are relevant for tax purposes, e.g. hourly wage records, operating statement forms, cost calculation documents, price labels, as well as payroll documents insofar as they are not already accounting documents, and cash register receipts (§ 147(1)(2), (3), (5) in conjunction with paragraph 3 AO, § 257(1)(2) and (3) in conjunction with paragraph 4 HGB).
- 3 years – Data required to address potential warranty and compensation claims or similar contractual claims and rights, as well as to process related inquiries, based on previous business experience and standard industry practices, will be stored for the duration of the regular statutory limitation period of three years (§§ 195, 199 BGB).
Beginning of the Limitation Period at the End of the Year: If a period does not expressly begin on a specific date and lasts at least one year, it automatically begins at the end of the calendar year in which the event triggering the period occurred. In the case of ongoing contractual relationships in which data is stored, the triggering event is the date on which termination or another form of ending the legal relationship becomes effective.
Rights of Data Subjects
Rights of Data Subjects under the GDPR: As a data subject, you have various rights under the GDPR, which arise in particular from Articles 15 to 21 of the GDPR:
- Right to Object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data carried out pursuant to Article 6(1)(e) or (f) of the GDPR; this also applies to profiling based on these provisions. If your personal data is processed for the purpose of direct marketing, you have the right to object at any time to the processing of your personal data for such marketing purposes; this also applies to profiling to the extent that it is related to such direct marketing.
- Right to Withdraw Consent: You have the right to withdraw your consent at any time.
- Right of Access: You have the right to request confirmation as to whether personal data concerning you is being processed and to request access to this data, as well as further information and a copy of the data in accordance with legal requirements.
- Right to Rectification: In accordance with legal requirements, you have the right to request the completion of your personal data or the correction of inaccurate personal data concerning you.
- Right to Erasure and Restriction of Processing: In accordance with legal requirements, you have the right to request that personal data concerning you be deleted without delay or, alternatively, to request a restriction of the processing of such data.
- Right to Data Portability: You have the right to receive personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format, in accordance with legal requirements, or to request that such data be transferred to another controller.
- Complaint to a Supervisory Authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work, or the place of the alleged infringement, if you believe that the processing of your personal data violates the provisions of the GDPR.
Provision of Online Services and Web Hosting
We process users’ data in order to provide them with our online services. For this purpose, we process the user’s IP address, which is necessary to deliver the content and functions of our online services to the user’s browser or device.
- Types of data processed: Usage data (e.g., page views and time spent on the website, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, individuals involved). Log data (e.g., log files relating to logins, retrieval of data, or access times).
- Data subjects: Users (e.g., website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of our online services and user-friendliness; IT infrastructure (operation and provision of information systems and technical equipment (computers, servers, etc.)). Security measures.
- Retention and deletion: Deletion in accordance with the information provided in the section “General Information on Data Storage and Deletion”.
- Legal bases: Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR).
Additional information on processing procedures, methods, and services:
- Provision of Online Services on Leased Storage Space: To provide our online services, we use storage space, computing capacity, and software that we rent or otherwise obtain from an appropriate server provider (also referred to as a “web host”); Legal basis: Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR).
- Collection of Access Data and Log Files: Access to our online services is recorded in the form of so-called “server log files.” Server log files may include the address and name of the websites and files accessed, the date and time of access, the amount of data transferred, a notification of successful access, browser type and version, the user’s operating system, referrer URL (the previously visited page), and, as a rule, IP addresses and the requesting provider. Server log files may be used, on the one hand, for security purposes, for example to prevent server overload (particularly in the case of malicious attacks, known as DDoS attacks), and, on the other hand, to ensure server capacity and stability; Legal basis: Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR). Deletion of data: Log file information is stored for a maximum period of 30 days and is subsequently deleted or anonymized. Data whose continued retention is required for evidentiary purposes is excluded from deletion until the respective incident has been fully resolved.
Use of Cookies
The term “cookies” refers to functions that store information on users’ devices and retrieve information from them. Cookies can also be used for various purposes, such as ensuring the functionality, security, and convenience of online services, as well as creating analyses of visitor traffic. We use cookies in accordance with legal requirements. Where required, we obtain users’ consent in advance. If consent is not required, we rely on our legitimate interests. This applies where storing and retrieving information is essential to provide explicitly requested content and functions. This includes, for example, storing settings and ensuring the functionality and security of our online services. Consent can be withdrawn at any time. We provide clear information about the scope of consent and which cookies are used.
Notes on legal bases under data protection law: Whether we process personal data using cookies depends on consent. If consent has been given, it serves as the legal basis. Without consent, we rely on our legitimate interests, which are explained above in this section and in the context of the respective services and procedures.
Storage duration: With regard to the storage duration, the following types of cookies are distinguished:
- Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest after a user leaves an online service and closes their device (e.g. browser or mobile application).
- Permanent cookies: Permanent cookies remain stored even after the device has been closed. This allows, for example, login status to be saved and preferred content to be displayed immediately when the user visits a website again. Likewise, user data collected through cookies may be used for reach measurement. Unless we provide users with explicit information about the type and storage duration of cookies (e.g. as part of obtaining consent), users should assume that these cookies are permanent and may be stored for up to two years.
General information on withdrawal and objection (opt-out): Users may withdraw their consent at any time and may also object to the processing of their data in accordance with legal requirements, including through their browser’s privacy settings.
- Types of data processed: Meta, communication, and process data (e.g. IP addresses, timestamps, identification numbers, individuals involved).
- Data subjects: Users (e.g. website visitors, users of online services).
- Legal bases: Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR). Consent (Art. 6(1), first sentence, subparagraph (a) of the GDPR).
Additional information on processing procedures, methods, and services:
- Processing of cookie data based on consent: We use a consent management solution in which users’ consent to the use of cookies or to the procedures and providers specified within the consent management solution is obtained. This procedure serves to obtain, record, manage, and withdraw consent, particularly regarding the use of cookies and comparable technologies that are used to store, retrieve, and process information on users’ devices. Within this process, users’ consent is obtained for the use of cookies and the associated processing of information, including the specific processing activities and providers listed in the consent management process. Users also have the option to manage and withdraw their consent. Consent declarations are stored in order to avoid repeated requests and to provide proof of consent in accordance with legal requirements. Storage takes place on the server and/or in a cookie (so-called opt-in cookie) or through comparable technologies in order to assign consent to a specific user or their device. Unless specific information about providers of consent management services is available, the following general information applies: Consent is stored for up to two years. A pseudonymous user identifier is created and stored together with the time of consent, details regarding the scope of consent (e.g. relevant cookie categories and/or service providers), and information about the browser, system, and device used; Legal bases: Consent (Art. 6(1), first sentence, subparagraph (a) of the GDPR).
Social Media Presence
We maintain online presences within social networks and process user data in this context in order to communicate with active users of these networks or to provide information about us.
We would like to point out that user data may be processed outside the European Union in this context. This may result in risks for users, as the enforcement of user rights could, for example, become more difficult.
Furthermore, user data within social networks is generally processed for market research and advertising purposes. For example, usage profiles may be created based on user behavior and resulting interests. These profiles may then be used to display advertisements within and outside the networks that are presumed to correspond to users’ interests. For this reason, cookies are generally stored on users’ computers, in which usage behavior and interests are recorded. In addition, data may also be stored in usage profiles independently of the devices used by users (especially if users are members of the respective platforms and are logged in there).
For a detailed description of the respective processing methods and objection options (opt-out), we refer to the privacy policies and information provided by the operators of the respective networks.
We also point out that requests for information and the exercise of data subject rights can be handled most effectively by the providers themselves. Only the providers have access to user data and can take appropriate measures and provide information directly. If you still require assistance, you can contact us.
- Types of data processed: Contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. text-based or image-based messages and posts, as well as related information such as authorship details or creation dates). Usage data (e.g. page views and time spent on the website, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Communication; feedback (e.g. collecting feedback via online forms). Public relations.
- Retention and deletion: Deletion in accordance with the information provided in the section “General Information on Data Storage and Deletion”.
- Legal bases: Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR).
Changes and Updates
We ask you to regularly review the content of our Privacy Policy. We will update the Privacy Policy as soon as changes to our data processing activities make this necessary. We will inform you as soon as the changes require your cooperation (e.g. consent) or any other individual notification.
If we provide addresses and contact information of companies and organizations in this Privacy Policy, please note that these addresses may change over time, and we ask you to verify the information before contacting them.
Definitions of Terms
This section provides an overview of the terminology used in this Privacy Policy. Where terms are legally defined, the respective legal definitions apply. The explanations below are primarily intended to aid understanding.
- Employees: Employees are individuals who are in an employment relationship, whether as staff members, employees, or in similar positions. An employment relationship is a legal relationship between an employer and an employee established through an employment contract or agreement. It includes the employer’s obligation to pay remuneration while the employee performs their work. The employment relationship includes various stages, including the establishment stage, during which the employment contract is concluded, the performance stage, during which the employee carries out their work, and the termination stage, when the employment relationship ends, whether through dismissal, a termination agreement, or otherwise. Employee data refers to all information relating to these individuals and arising in the context of their employment. This includes aspects such as personal identification data, identification numbers, salary and bank details, working hours, holiday entitlements, health data, and performance evaluations.
- Master Data: Master data comprises essential information required for the identification and management of contractual partners, user accounts, profiles, and similar assignments. This data may include personal and demographic information such as names, contact details (addresses, telephone numbers, email addresses), dates of birth, and specific identifiers (user IDs). Master data forms the basis for all formal interactions between individuals and services, organizations, or systems by enabling clear identification and communication.
- Content Data: Content data includes information generated during the creation, editing, and publication of content of all kinds. This category of data may include texts, images, videos, audio files, and other multimedia content published on various platforms and media. Content data is not limited to the actual content itself but also includes metadata that provides information about the content, such as tags, descriptions, author information, and publication dates.
- Contact Data: Contact data refers to essential information that enables communication with individuals or organizations. This includes, among other things, telephone numbers, postal addresses, and email addresses, as well as communication channels such as social media handles and instant messaging identifiers.
- Meta, Communication, and Process Data: Meta, communication, and process data are categories containing information about how data is processed, transmitted, and managed. Metadata, also known as “data about data”, includes information describing the context, origin, and structure of other data. It may include details such as file size, creation date, document author, and revision history. Communication data records the exchange of information between users through various channels, such as email correspondence, call logs, social media messages, and chat histories, including the persons involved, timestamps, and transmission methods. Process data describes processes and procedures within systems or organizations, including workflow documentation, records of transactions and activities, and audit logs used to track and verify operations.
- Usage Data: Usage data refers to information that records how users interact with digital products, services, or platforms. This data includes a wide range of information showing how users use applications, which functions they prefer, how long they remain on certain pages, and which paths they take while navigating through an application. Usage data may also include frequency of use, timestamps of activities, IP addresses, device information, and location data. It is particularly valuable for analyzing user behavior, optimizing user experiences, personalizing content, and improving products or services. Furthermore, usage data plays an important role in identifying trends, preferences, and potential problem areas within digital services.
- Personal Data: “Personal data” means any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”). A natural person is considered identifiable if they can be identified directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier (e.g. a cookie), or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
- Log Data: Log data refers to information about events or activities recorded in a system or network. This data typically includes information such as timestamps, IP addresses, user actions, error messages, and other details relating to the use or operation of a system. Log data is often used to analyze system issues, monitor security, or generate performance reports.
- Data Controller: A data controller is the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of processing personal data.
- Processing: “Processing” means any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and covers virtually any handling of data, including collection, analysis, storage, transmission, or deletion.
Created using the free Datenschutz-Generator.de tool by Dr. Thomas Schwenke