Privacy policy
This policy explains what personal data Ertl-Yang GmbH collects through this website and our summit registration and partnership forms, why we process it, and the rights you have over it under the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
Introduction
We take the protection of your personal data seriously and process it in accordance with the GDPR, the BDSG and other applicable data protection law. "Personal data" means any information relating to an identified or identifiable natural person.
This policy explains what data we collect when you visit this website or use our forms, the purposes and legal basis for processing it, who we share it with, how long we keep it, and the rights available to you.
Controller
Ertl-Yang GmbH
Director: Jing Ertl-Yang
Französische Straße 20, 10117 Berlin, Germany
Phone: +49 (0) 30 43973757
Email: info@ertl-yang.com
Data Protection Officer:
Ertl-Yang GmbH
Mr. Philipp Bauer, LL.M.
Französische Straße 20, 10117 Berlin, Germany
Phone: +49 (0) 30 43973757
Email: pbauer@ertl-yang.com
Personal data collection
We collect the following categories of personal data through this website:
Cookies
We use Google Analytics with IP anonymisation enabled to understand how visitors use this website. You may reject cookies through your browser settings or Google's opt-out tool. The website remains accessible without cookies, though certain functions such as ticket purchasing may not be available.
Social media links
This website links to our profiles on Facebook, X (Twitter), Instagram and LinkedIn. Visiting those platforms involves data processing by their respective operators under their own privacy policies, which we do not control.
Third party processors
We share personal data with the following categories of recipients, only as necessary to operate the website and our summits:
Place of data processing
Where personal data is transferred to service providers located outside the European Economic Area (EEA), in particular in the United States, such transfers are carried out in compliance with Chapter V GDPR. Since the European Commission's adequacy decision of 10 July 2023, the EU-U.S. Data Privacy Framework (DPF) provides an appropriate level of protection for transfers to U.S. organisations that are self-certified under the Framework. Google LLC, provider of Google Analytics, is certified under the EU-U.S. Data Privacy Framework. Where a recipient is not, or is no longer, certified under the DPF — including Formspree, Inc. — we rely on the European Commission's Standard Contractual Clauses (SCCs) as the transfer mechanism, supplemented where necessary by additional technical and organisational safeguards.
Deletion of personal data
We delete personal data once it is no longer required for the purpose it was collected for: six months after consent is withdrawn, twelve months after a contract is settled, or six months after our legitimate interest in processing it ceases.
Where a statutory retention obligation applies, data is kept for the relevant period instead — six years under the German Commercial Code (HGB), ten years under the German Tax Code (AO), or up to thirty years where necessary to establish, exercise or defend legal claims.
Your rights
Subject to the conditions set out in the GDPR, you have the right to:
Automated decision-making
We do not use automated decision-making, including profiling, within the meaning of Article 22 GDPR.
Data breach notification
In the event of a personal data breach, we assess the risk to the rights and freedoms of the individuals concerned without undue delay. Where the breach is likely to result in a risk to those rights and freedoms, we notify the competent supervisory authority within 72 hours of becoming aware of it, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk to affected individuals, we also notify those individuals without undue delay, in accordance with Article 34 GDPR.