Privacy Statement
1. An Overview of Data Protection
2. Hosting
3. General Information and Mandatory Information
4. Data Collection on this Website
5. Hosted ConfTool Installations
6. Changes to this Privacy Statement
Scope of this statement
This privacy statement applies to the website www.conftool.net and to our publicly accessible demo installations. It does not apply to the ConfTool installations that we operate on behalf of conference organizers – for those, see Hosted ConfTool Installations below.
1. An Overview of Data Protection
General
The following gives a simple overview of what happens to your personal data when you visit our website. Personal data is any data with which you could be personally identified. Detailed information on the subject of data protection can be found in the sections below.
Data Collection on our Website
Who is responsible for the data collection on this website?
The data collected on this website is processed by the website operator, ConfTool GmbH. Our contact details can be found in the section Party Responsible for this Website.
How do we collect your data?
Some data is collected when you provide it to us – for example the data you enter when you register for one of our ConfTool demo installations, or when you contact us by e-mail.
Other data is collected automatically by our IT systems when you visit the website. This is primarily technical data such as the browser and operating system you are using or the time at which you accessed the page.
What do we use your data for?
The data is used to provide the website reliably and securely, to investigate technical faults and security-related incidents, and to process the requests you send us. We do not carry out any web analytics, user tracking or profiling, and we do not use your data for advertising purposes.
What rights do you have regarding your data?
You have the right to receive information about your stored data, its origin, its recipients and the purpose of its collection free of charge at any time. You also have the right to request that this data be corrected, deleted or its processing restricted, and – under certain conditions – the right to object to processing and the right to data portability. You may contact us at any time using the address given below, and you may lodge a complaint with the competent supervisory authority.
2. Hosting
This website runs on servers operated by ConfTool GmbH. The servers are located in the data centre park in Falkenstein/Vogtland, Germany, operated by:
Hetzner Online GmbH
Industriestr. 25
91710 Gunzenhausen
Germany
Hetzner Online GmbH provides the data centre infrastructure and acts as a processor on our behalf within the meaning of Art. 28 GDPR; a corresponding data processing agreement has been concluded. No personal data relating to this website is transferred to countries outside the European Economic Area.
3. General Information and Mandatory Information
Data Protection
We take the protection of your personal data very seriously. We treat your personal data as confidential and in accordance with the statutory data protection regulations and this privacy statement.
Please note that data transmitted via the internet (for example in e-mail communication) may be subject to security breaches. Complete protection of your data against access by third parties is not possible.
Party Responsible for this Website
The party responsible for processing data on this website is:
ConfTool GmbH
Hochrad 58
22605 Hamburg
Germany
Telephone: +49 40 2022 7297
E-mail: info@conftool.net
The responsible party is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data.
Legal Bases for Processing
Where we process personal data, we do so on the following legal bases:
- Art. 6 (1) (a) GDPR – your consent, for example when you register for a demo installation.
- Art. 6 (1) (b) GDPR – performance of a contract or pre-contractual measures, for example when you enquire about our services.
- Art. 6 (1) (f) GDPR – our legitimate interest in providing this website reliably and securely, for example when processing server log files.
Storage Duration
Unless a more specific storage period is stated in this privacy statement, your personal data will remain with us until the purpose for the data processing no longer applies. If you assert a justified request for deletion or revoke your consent to data processing, your data will be deleted, unless we have other legally permissible reasons for storing your personal data – such as statutory retention periods under tax or commercial law. In the latter case, the data will be deleted once these reasons cease to apply.
Revocation of Your Consent to the Processing of Your Data
Many data processing operations are only possible with your express consent. You may revoke your consent at any time with effect for the future. An informal e-mail making this request is sufficient. The lawfulness of the data processing carried out before we receive your request remains unaffected.
Right to Object to the Collection of Data (Art. 21 GDPR)
If data is processed on the basis of Art. 6 (1) (f) GDPR, you have the right to object to the processing of your personal data at any time on grounds relating to your particular situation. The respective legal basis on which any processing is based can be found in this privacy statement. If you object, we will no longer process the personal data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
We do not process personal data for direct marketing purposes.
Right to Lodge a Complaint with a Supervisory Authority
In the event of infringements of the GDPR, data subjects are entitled to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or place of the alleged infringement. This right is without prejudice to any other administrative or judicial remedy.
The supervisory authority responsible for us is the Hamburg Commissioner for Data Protection and Freedom of Information. A list of all German supervisory authorities is available from the Federal Commissioner for Data Protection and Freedom of Information (BfDI).
Right to Data Portability
You have the right to have data that we process automatically on the basis of your consent or in performance of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done to the extent that it is technically feasible.
Information, Correction, Deletion and Restriction
Within the framework of the applicable statutory provisions, you have the right to obtain information free of charge at any time about your stored personal data, its origin, its recipients and the purpose of the data processing, and, where applicable, the right to have this data corrected or deleted. You also have the right to request that the processing of your personal data be restricted in accordance with Art. 18 GDPR – for example if you contest the accuracy of the data, or if the processing is unlawful but you oppose deletion. You may contact us at any time at the address given above.
TLS Encryption
This site uses TLS encryption for security reasons and to protect the transmission of confidential content, such as the enquiries you send to us. You can recognise an encrypted connection by the fact that the address line of your browser starts with "https://" and by the lock icon in your browser bar. When TLS encryption is active, the data you transfer to us cannot be read by third parties.
4. Data Collection on this Website
Cookies
Our website uses cookies. Cookies are small text files that are stored on your device by your browser; they do not harm your device and contain no viruses.
We only use technically necessary cookies that are required to provide the website and the functions you have requested – in particular session cookies, which are automatically deleted when you close your browser. We do not use any cookies for analytics, tracking or advertising purposes.
The storage of technically necessary cookies takes place on the basis of Section 25 (2) of the German Telecommunications Digital Services Data Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, TDDDG); no consent is required for these. The associated processing of personal data is based on Art. 6 (1) (f) GDPR, our legitimate interest in the technically error-free and optimised provision of our services.
You can configure your browser to inform you about the use of cookies, to accept cookies only in individual cases, to generally refuse them, or to delete cookies automatically when closing your browser. Disabling cookies may limit the functionality of this website.
No External Content, Local Fonts
We do not embed any content from third-party servers on this website – no external fonts, no maps, no videos and no social media plug-ins. In particular, all web fonts used are stored on our own servers and delivered directly from there. When you call up a page, no connection is established to the servers of any external provider, and no data – in particular no IP address – is transmitted to them.
Server Log Files
The website provider automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. This is:
- browser type and browser version
- operating system used
- referrer URL
- host name of the accessing computer
- time of the server request
- IP address
This data is not combined with data from other sources. The log files are evaluated exclusively in the event of security-related incidents and technical faults. No analysis of user behaviour takes place.
The processing is based on Art. 6 (1) (f) GDPR. We have a legitimate interest in the technically error-free presentation and the security of our website.
The log files are retained for three months and are then deleted, unless they are required for the further investigation of a security incident. This retention period results from the security requirements we are subject to as a payment-related service provider: the PCI DSS requires audit logs to be retained and to be kept immediately available for analysis for at least three months.
Registration for our Demo Installations
You can register on our website in order to access our ConfTool demo installations. The data you enter will only be used for the purpose of using the respective demo installation. The mandatory information requested during registration must be provided in full; otherwise we cannot accept your registration.
This processing is based on your consent pursuant to Art. 6 (1) (a) GDPR. You may revoke your consent at any time with effect for the future; an informal e-mail is sufficient. The lawfulness of the processing carried out before we receive your request remains unaffected.
Our demo installations are reset at the end of each calendar year; the data entered there, including your registration data, is deleted in the process. Statutory retention periods remain unaffected.
Contacting Us by E-mail or Telephone
If you contact us by e-mail or telephone, your enquiry and all personal data resulting from it will be stored and processed by us for the purpose of handling your request. We do not pass this data on without your consent.
This data is processed on the basis of Art. 6 (1) (b) GDPR where your enquiry is related to the performance of a contract or to pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of enquiries addressed to us (Art. 6 (1) (f) GDPR).
The data you send to us will remain with us until you request its deletion or the purpose for storing the data no longer applies. Mandatory statutory provisions – in particular retention periods – remain unaffected.
Transfer of Data to Third Parties
We transmit personal data to third parties only to the extent required to fulfil the terms of a contract with you – for example to the bank or payment service provider entrusted with processing your payment. Your data will not be transferred for any other purpose unless you have given your express consent. Your data will not be disclosed to third parties for advertising purposes.
5. Hosted ConfTool Installations
In addition to this website, we operate individual ConfTool installations on behalf of conference organizers. For the personal data processed in those installations – for example the data of authors, reviewers and participants – the respective conference organizer is the controller within the meaning of Art. 4 (7) GDPR. They decide on the purposes and means of the processing, and they provide their own privacy statement within their installation.
In these cases, ConfTool GmbH acts solely as a processor pursuant to Art. 28 GDPR and processes the data exclusively on the documented instructions of the respective organizers, on the basis of data processing agreements pursuant to Art. 28 GDPR. All customer installations are also operated on servers in Germany.
If you are an author, reviewer or participant of a conference and wish to exercise your rights regarding your data, please contact the organizers of that conference directly. You can find their contact details via the link "Contact and Legal Notice" of the corresponding installation. Please note that installations, including all data they contain, are deleted in accordance with the contracts with the respective organizers, usually a few months after the event.
6. Changes to this Privacy Statement
We may update this privacy statement if required, for example to reflect changes in our services or in the applicable legal situation. The current version is always available on this page.
This statement was last updated on 19 Aug 2026.