§1
Introduction
We take the protection of your personal data seriously and process it in accordance with the GDPR, the BDSG and other applicable data protection law. "Personal data" means any information relating to an identified or identifiable natural person.
This policy explains what data we collect when you visit this website or use our forms, the purposes and legal basis for processing it, who we share it with, how long we keep it, and the rights available to you.
§2
Controller
Ertl-Yang GmbH
Director: Jing Ertl-Yang
Französische Straße 20, 10117 Berlin, Germany
Phone: +49 (0) 30 43973757
Email: info@ertl-yang.com
Data Protection Officer:
Ertl-Yang GmbH
Mr. Philipp Bauer, LL.M.
Französische Straße 20, 10117 Berlin, Germany
Phone: +49 (0) 30 43973757
Email: pbauer@ertl-yang.com
§3
Personal data collection
We collect the following categories of personal data through this website:
Automatic logfile data. IP address, date and time of access, GMT offset, HTTP status, data transfer volume, referrer source, browser type and operating system. This data is saved anonymously in logfiles for security and technical operation.
Registration form. When you submit our "Register your interest" form, we collect full name, business email address, company name, professional role/title, preferred summit selection, and any additional information you choose to provide in the free-text note field.
Newsletter subscription. Email address (required) and name where you purchase a ticket. Subscriptions use a double opt-in mechanism with a 24-hour confirmation window.
Speaker data. Name, photograph, position and biography, for speakers appearing on our programme.
Direct marketing. Business email addresses of companies and individuals sourced from publicly available data, processed on the basis of our legitimate interest.
§4
Cookies
We use Google Analytics with IP anonymisation enabled to understand how visitors use this website. You may reject cookies through your browser settings or Google's opt-out tool. The website remains accessible without cookies, though certain functions such as ticket purchasing may not be available.
§5
Social media links
This website links to our profiles on Facebook, X (Twitter), Instagram and LinkedIn. Visiting those platforms involves data processing by their respective operators under their own privacy policies, which we do not control.
§6
Third party processors
We share personal data with the following categories of recipients, only as necessary to operate the website and our summits:
Technical service providers supporting our website and IT infrastructure.
Summit partner collaborators involved in organising a specific event.
Bookkeepers, lawyers and tax consultants bound by professional confidentiality.
Google LLC (USA) provider of Google Analytics.
Social platforms Meta, X and LinkedIn, in connection with our social media presence.
Formspree, Inc. (San Francisco, California, USA) — form-submission processing service used to transmit registration form data to our summit team. Formspree processes this data on our behalf as a data processor under Article 28 GDPR, pursuant to a data processing agreement between Ertl-Yang GmbH and Formspree, Inc.
§7
Place of data processing
Where personal data is transferred to service providers located outside the European Economic Area (EEA), in particular in the United States, such transfers are carried out in compliance with Chapter V GDPR. Since the European Commission's adequacy decision of 10 July 2023, the EU-U.S. Data Privacy Framework (DPF) provides an appropriate level of protection for transfers to U.S. organisations that are self-certified under the Framework. Google LLC, provider of Google Analytics, is certified under the EU-U.S. Data Privacy Framework. Where a recipient is not, or is no longer, certified under the DPF — including Formspree, Inc. — we rely on the European Commission's Standard Contractual Clauses (SCCs) as the transfer mechanism, supplemented where necessary by additional technical and organisational safeguards.
§8
Deletion of personal data
We delete personal data once it is no longer required for the purpose it was collected for: six months after consent is withdrawn, twelve months after a contract is settled, or six months after our legitimate interest in processing it ceases.
Where a statutory retention obligation applies, data is kept for the relevant period instead — six years under the German Commercial Code (HGB), ten years under the German Tax Code (AO), or up to thirty years where necessary to establish, exercise or defend legal claims.
§9
Your rights
Subject to the conditions set out in the GDPR, you have the right to:
9.1access the personal data we hold about you
9.2request rectification of inaccurate data
9.3request erasure of your data
9.4request restriction of processing
9.5object to processing based on our legitimate interest
9.6withdraw consent at any time, with effect for the future
9.7receive your data in a structured, portable format
9.8lodge a complaint with a data protection supervisory authority
§10
Automated decision-making
We do not use automated decision-making, including profiling, within the meaning of Article 22 GDPR.
§11
Data breach notification
In the event of a personal data breach, we assess the risk to the rights and freedoms of the individuals concerned without undue delay. Where the breach is likely to result in a risk to those rights and freedoms, we notify the competent supervisory authority within 72 hours of becoming aware of it, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk to affected individuals, we also notify those individuals without undue delay, in accordance with Article 34 GDPR.