Topic: General information regarding the General Data Protection Regulation (GDPR)

(A German version of this article is available.)

Please note: As a software provider, we cannot give any legal advice regarding the General Data Protection Regulation. The following is intended as a short overview only. All statements are hints without guarantee - for detailed information, please consult legal counsel.

In Short

We comply with the requirements of the GDPR on our website and in our event management system ConfTool Pro. The use of the system and of the data is under the responsibility of the event organizers.

Regarding the use of ConfTool Pro, the GDPR therefore addresses mainly you as the organizers of the event: as organizer, you are the responsible operator of the system (the controller). ConfTool GmbH acts as data processor for the purposes of GDPR Article 28.

What We Do

  • We make sure that all personal data is transmitted only encrypted.
  • We use two-factor authentication for administrative access. This is also available to you as the organizer in the security settings, and we recommend it for all users with access to personal data.
  • Every event has its own installation with a separate database and separate user accounts; user data is not referenced between events. This follows the principle of data separation.
  • All customer installations are hosted in Germany (Hetzner data centre, Falkenstein). We have concluded a data processing agreement with our hosting provider.
  • Our website and ConfTool Pro use only technical cookies, and all fonts are hosted locally on our own servers - no data is transferred to third-party providers when you use our pages.
  • Server log files are kept for 12 weeks and then deleted.
  • We delete all data of your event from our servers after the end of your event, once you as the organizer have confirmed the deletion.
  • Our local devices such as PCs, laptops and backup media use encrypted hard drives for all data.
  • Our servers are scanned monthly by HackerGuardian for security vulnerabilities, in accordance with PCI DSS requirements.
  • We maintain corresponding security, privacy and backup concepts, and we gladly provide the corresponding documents on request.

What You Should Do

Required Settings in ConfTool

  • Publish a privacy statement.
    Every operator of a website or web-based system that processes personal data has to publish an easily comprehensible privacy statement. We recommend publishing it on your own website. Tools such as this privacy statement generator can help you.
    You can enable the link to your privacy statement in ConfTool at:
    Overview => Settings => Main Setup
    There you also find a pre-formulated privacy statement, which we provide without guarantee, as we cannot give legal advice (see attached picture no. 1).
  • Ask your users for their consent.
    Organizers have to ask their users whether they agree to the storing and processing of their data. You find the corresponding function in ConfTool Pro at:
    Overview => Settings => Main Setup
    We recommend enabling it (it is enabled in new installations by default) and adapting the wording to your requirements (see attached picture no. 2).
  • Ask existing users as well.
    If you already have many users in the database and want to make sure that they all see and confirm the data privacy agreement the next time they log in, please go to:
    Overview => Settings => Settings for User Registration => Main Settings for User Registration
    ... and set the option "Text Mandatory Fields at Login" to "Always..." (see attached picture no. 3).

In Your Organization

  • If you want to transfer user data from one event to the next, please consider this during the registration process, as you need the users' permission for it as well. Transferring data from one event to the next may otherwise conflict with the principles of purpose limitation and data minimization.
  • All organizations that store and process personal data must maintain a record of processing activities documenting all processes that involve personal data, including the affected and responsible persons. This record is not public and serves internal quality control.
  • We recommend concluding a data processing agreement (processor agreement under GDPR Article 28) with all service providers who come into contact with personal data on your behalf. It confirms that the provider processes the data in accordance with the instructions of the controller. Such an agreement is advisable with ConfTool GmbH as well as with other service providers such as accountants and e-mail providers. We usually send a corresponding agreement together with our offer - if you have not received it, please send us an e-mail and we will provide it.
  • Please minimize the data recorded in ConfTool to the information you actually need. Recording dates of birth, religious affiliations or passport numbers in particular will lead to significantly increased data protection requirements for you.
  • Make sure that you store all data securely, so that third parties cannot access the data on your devices. Limit access to all workstations with passwords and use encryption for all mobile devices (laptops, flash drives etc.). Do not send personal data unencrypted.
  • Please delete personal data that is no longer required, and make sure that third parties cannot access the information (e.g. by shredding old printouts).
  • Check whether you need to appoint a data protection officer. Under GDPR Article 37 this is mandatory for public authorities and where your core activities involve large-scale regular and systematic monitoring, or large-scale processing of special categories of data. In Germany, section 38 of the Federal Data Protection Act (BDSG) additionally requires an officer as soon as at least 20 persons are constantly involved in the automated processing of personal data (this threshold was raised from 10 to 20 in November 2019). Other countries have their own rules, so please check the requirements that apply to you.

Organizers outside the EU: Additional or different rules may apply to you - for example the UK GDPR, the revised Swiss Federal Act on Data Protection (in force since September 2023), or data protection laws of individual US states. The measures described above are a good starting point in any case, but please check the requirements of your own jurisdiction.