Privacy Policy – Ticket Shop
ADITUS GmbH (Straße der Nationen 5, 30539 Hannover) acts as the ticket seller and contractual partner
of the buyer for the events presented on this platform.
ADITUS GmbH is responsible for ticket sales, invoicing and payment processing.
The organisation of the event, event-related communications by the organiser and the organiser's own
event purposes are the responsibility of the respective event organiser.
BREKO Servicegesellschaft mbH (hereinafter "BREKO") remains responsible for these areas.
By ordering a ticket, customers also enter into a contractual relationship with the
event organiser.
Below we inform you about the processing of data by ADITUS GmbH
in this ticket shop. As the controller responsible for ticket sales, you can reach
our Data Protection Officer at
datenschutz@aditus.de.
The privacy policy of the event organiser BREKO
can be found at:
https://fiberdays.de/en/data-protection/
1. General Information and Principles of Data Processing
Here you will find information about how we handle your personal data when you visit our ticket shop. In order to provide the functions and services of the ticket shop, it is necessary for us to collect certain personal data about you. Below we explain the nature and scope of the respective data processing, its purpose, the corresponding legal basis and the respective retention period.
Personal data, as defined in Art. 4(1) GDPR, means any information relating to an identified or identifiable natural person. This includes, for example, information such as your first and last name, your address, your telephone number, your email address and your IP address.
Data that cannot be linked to your person, for example as a result of anonymisation, does not constitute personal data. Any processing of personal data is carried out only on the basis of a legal permission or your consent in accordance with the provisions of the GDPR. Processing includes in particular the collection, storage, retrieval, consultation, use, transmission, erasure or destruction of personal data pursuant to Art. 4(2) GDPR.
Personal data will be deleted as soon as the respective processing purpose ceases to apply and no statutory retention obligations remain. If deletion is not possible due to statutory retention periods, the processing of the data concerned will be restricted.
This privacy policy applies exclusively to this ticket shop. It does not apply to other websites to which we refer by means of hyperlinks. Insofar as this ticket shop contains links to third-party websites, we have no influence over their content, privacy practices or compliance with applicable data protection regulations. The respective operators are solely responsible for the processing of personal data by these third-party providers. Information about how your personal data is handled can be found in the privacy policies of the respective providers.
2. Controller
The controller responsible for the processing of personal data on this website is:
ADITUS GmbH
Straße der Nationen 5
30539 Hannover
Germany
Email: info@aditus.de
Data Protection Officer: datenschutz@aditus.de
3. Provision and Use of the Website / Server Log Files
a) Nature and Scope of Data Processing
When you use this website without otherwise transmitting data to us (e.g. through registration or a ticket order), we collect technically necessary data that is automatically transmitted to our servers and stored in so-called server log files.
The following data may be processed in particular:
- IP address
- Date and time of the request
- Name and URL of the retrieved file
- Referrer URL (the previously visited website)
- Access status / HTTP status code
- Browser type and browser version
- Language and version of the browser software
- Operating system
b) Purpose and Legal Basis
The processing of this data is technically necessary in order to provide you with our website and to ensure its proper functioning. In addition, the data serves to ensure IT security, error analysis, system stability and the detection and prevention of abusive access and attacks on our systems.
The legal basis for the processing is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and functional provision of our ticket shop.
c) Retention Period
The server log files are deleted as soon as they are no longer required for the purposes stated above and no statutory retention obligations prevent their deletion. Storage beyond this period only takes place insofar as this is required by law or is necessary for the investigation of specific security incidents.
4. Use of Cookies
a) Nature, Scope and Purpose of Data Processing
Cookies are small text files that are stored on your device when you visit our website. They serve to technically enable the use of our website, to make it more user-friendly and to provide certain functions of the ticket shop.
We use only technically necessary cookies that are required for the operation of the ticket shop, the execution of the ordering process, the storage of your cookie settings and for security functions.
Temporary Cookies (Session Cookies)
Session cookies are automatically deleted when you close your browser. They serve to recognise your browser during a session and to provide certain functions of the ticket shop, for example during the ordering process.
Persistent Cookies
Persistent cookies remain stored on your device for a defined period of time and allow, for example, your cookie settings or security-related preferences to be recognised on a subsequent visit. The respective retention period depends on the cookie used.
Browser Settings Configuration
You can restrict or prevent the storage of cookies at any time via your browser settings. Please note that this may mean that certain functions of our ticket shop may not be available or may only be available to a limited extent.
5. Cookie Policy
a) List of Cookies
The cookies listed in the following table are technically necessary
so that you can use our ticket shop, purchase tickets and save your cookie settings.
These cookies serve to provide basic functions and the security of the ticket shop.
Cookie Name |
Category |
Description |
Validity Period |
Country of Data Processing |
Source |
|
cookies_and_content |
Necessary |
Storing cookie settings |
1 year |
Germany |
https://messe-tickets.de |
b) Legal Basis
The processing of personal data using technically necessary cookies is carried out
on the basis of Art. 6(1)(f) GDPR.
Our legitimate interest lies in the secure, functional and user-friendly
provision of our ticket shop.
c) Retention Period
The retention period of the individual cookies is set out in the table above.
After the respective retention period has expired, the cookies are automatically deleted.
Storage beyond this period only takes place insofar as this is required by law.
d) Browser Settings Configuration
Most web browsers are preconfigured to accept cookies automatically.
However, you can configure your browser so that only certain cookies or no cookies at all are stored.
We point out that this may mean that not all functions of our ticket shop
can be used without restriction.
6. Data Collection for the Performance of Pre-Contractual Measures and for Contract Fulfilment
a) Nature and Scope of Data Processing
In the course of initiating, performing and processing ticket orders, we collect and process personal data about you. This includes in particular information such as first and last name, address, email address, telephone number and other information that you provide in the course of the order or the use of our ticket shop. This may include, in particular, order, invoice, ticket and payment information. Insofar as this is necessary for the performance of the event, the data required for this purpose will be transmitted to the respective event organiser.
b) Purpose and Legal Basis of Data Processing
The processing of your personal data is carried out exclusively for the performance of pre-contractual measures and for the fulfilment of the contract concluded with you.
The legal basis for this is Art. 6(1)(b) GDPR. Insofar as consent is required for individual processing operations, the processing is additionally based on Art. 6(1)(a) GDPR.
c) Retention Period
The data is stored for as long as this is necessary for the performance of the contract and the fulfilment of the obligations associated with it. In addition, statutory retention obligations may apply, in particular under the German Commercial Code (HGB) or the German Fiscal Code (AO).
After the respective retention periods have expired, the data concerned will be deleted, unless there are further legal grounds for continued storage.
6a. Social Login
a) Description and Scope of Data Processing
In our ticket shop, we offer you the option of logging in via existing user accounts with third-party providers (Social Login).
The following providers are available:
- Google – Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
- Apple – Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland
- Facebook – Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland
- LinkedIn – LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland
When you log in via one of these services, you will be redirected to the login page of the respective provider. There you enter your credentials directly with the respective provider. We never have access to your password at any time.
After successful login, the following data in particular may be transmitted to us:
- First and last name
- Email address
- Unique user ID of the respective provider
The specific data transmitted depends on the information you have shared with the respective provider.
We use this data exclusively for the creation and management of your customer account and for the allocation and processing of your ticket orders.
b) Purpose and Legal Basis
The processing of data collected via Social Login is carried out for the purpose of authentication, the provision of your customer account and the processing of your ticket orders.
The legal basis is Art. 6(1)(b) GDPR (contract fulfilment or performance of pre-contractual measures).
Insofar as the use of a Social Login provider requires additional consent or approval from the respective provider, the processing is additionally based on Art. 6(1)(a) GDPR.
You can unlink your Social Login account at any time in your customer account or contact us at datenschutz@aditus.de.
c) Disclosure to Third Parties
By using Social Login, the respective provider receives the information that you are using our ticket shop. What data the providers process beyond this and whether data is processed outside the European Union can be found in the privacy policies of the respective providers.
- Google: Google Privacy Policy
- Apple: Apple Privacy Policy
- Facebook: Facebook Privacy Policy
- LinkedIn: LinkedIn Privacy Policy
d) Retention Period
The data collected in the course of Social Login is stored for as long as your customer account exists.
After deletion of your customer account, the data will be deleted, unless statutory retention obligations prevent this.
6b. Google reCAPTCHA
a) Description and Scope of Data Processing
On our website we use the service "Google reCAPTCHA" provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google reCAPTCHA is used to determine whether inputs on our website are made by a natural person or are abusively generated by automated programs (so-called bots).
For this purpose, reCAPTCHA analyses the behaviour of website visitors based on various characteristics. This analysis begins automatically as soon as the corresponding function is called.
In the course of the verification, the following data in particular may be processed:
- IP address
- Date and time of the page visit
- Browser and device information
- Time spent on the website
- Mouse movements and interactions
- Other information used by Google to detect automated access
The data collected in this process is transmitted to Google and analysed.
b) Purpose and Legal Basis
The processing is carried out to detect and prevent abusive automated access to our systems and to protect our ticket shop from spam, fraud attempts and other attacks.
The legal basis for the processing is Art. 6(1)(f) GDPR. Our legitimate interest lies in ensuring the security, integrity and availability of our systems.
c) Recipients and Third-Country Transfers
The collected data is transmitted to Google Ireland Limited. A transfer to Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, cannot be excluded.
Google LLC is certified under the EU-U.S. Data Privacy Framework, so that an adequate level of data protection exists for corresponding data transfers.
d) Retention Period
The data processed in connection with Google reCAPTCHA is only stored for as long as this is necessary for the stated purposes. Further processing and retention periods are governed by Google's privacy policy.
Further information about Google reCAPTCHA can be found at Google reCAPTCHA .
Further information about data processing by Google can be found in the Google Privacy Policy .
6c. Microsoft Entra ID (Authentication Service)
a) Description and Scope of Data Processing
For authentication and account management in this ticket shop, we use Microsoft Entra ID (formerly Azure Active Directory) as an identity provider. The service is provided by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland.
In the course of authentication and account management, the following personal data in particular may be processed:
- Basic personal data (e.g. first and last name)
- Contact information (e.g. email address)
- Authentication and login data (e.g. login time, session information, login attempts and security-related log data)
- Technical log and usage data (e.g. IP address, browser type or device information)
b) Purpose and Legal Basis
The processing is carried out for the secure authentication of users, for the management of user accounts and for the provision of functions such as single sign-on (SSO) and multi-factor authentication (MFA).
The processing is carried out for the performance of pre-contractual measures and for the fulfilment of existing contractual relationships on the basis of Art. 6(1)(b) GDPR.
Insofar as the processing serves to ensure IT security, prevent misuse and protect our systems, it is additionally based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and reliable provision of our ticket shop.
c) Recipients and Third-Country Transfers
The data is transmitted to Microsoft Ireland Operations Limited in the course of providing the service. Processing by Microsoft Corporation, One Microsoft Way, Redmond, Washington 98052, USA, as well as by sub-processors engaged by Microsoft cannot be excluded.
Insofar as personal data is transferred to third countries, such transfers are made on the basis of appropriate safeguards pursuant to Art. 44 et seq. GDPR. These include in particular the standard contractual clauses recognised by the European Commission.
In addition, Microsoft Corporation is certified under the EU-U.S. Data Privacy Framework.
Microsoft holds a C5 attestation from the German Federal Office for Information Security (BSI) for relevant cloud services. Further information can be found at Cloud Computing Compliance Criteria Catalogue (C5) .
d) Retention Period
The data processed in the course of authentication is deleted or anonymised as soon as it is no longer required for the respective purposes and no statutory retention obligations prevent this.
Log and diagnostic data is regularly deleted or anonymised as soon as it is no longer needed for security, support or verification purposes.
Further information about data processing by Microsoft can be found at the Microsoft Trust Center .
6d. Payment Service Provider
a) Description and Scope of Data Processing
For the processing of payments in connection with ticket purchases, we use the payment service provider Saferpay of Worldline Payment Services (Germany) GmbH. The service provider accepts payments via the payment methods offered in the ticket shop and carries out the payment processing.
The payment options provided in the ticket shop are available for payment, in particular credit card (Visa, Mastercard) and WERO.
The data you enter during the payment process is processed exclusively for the purpose of payment processing and is transmitted to the respective payment service provider for this purpose.
For fraud prevention, risk analysis and compliance with statutory requirements, additional security and verification measures may be carried out in the course of payment processing.
Saferpay (Worldline)
Payment processing for credit card payments and WERO is carried out via the Saferpay Payment Page of Worldline Payment Services (Germany) GmbH, Langenhorner Chaussee 92–94, 22415 Hamburg, Germany.
When paying by credit card, your card details (card number, expiry date and security code) are entered directly on the secure payment page of Worldline and processed there. ADITUS GmbH never has access to your complete credit card data at any time.
When paying by WERO, you will be redirected to your bank for authorisation. The payment is processed via SEPA Instant Payments.
The transmission of your payment data is based on Art. 6(1)(b) GDPR and only insofar as this is necessary for payment processing.
Further information about data processing by Worldline can be found at: Worldline Privacy Notice .
Further information about data processing in connection with WERO can be found at: WERO Privacy Notice .
b) Purpose and Legal Basis of Data Processing
The processing of payment data is carried out for the performance of the ordering and payment process and for the fulfilment of the contract concluded with you.
The legal basis for this is Art. 6(1)(b) GDPR. Insofar as statutory obligations must be fulfilled, the processing is additionally based on Art. 6(1)(c) GDPR.
c) Recipients and Categories of Recipients
Personal data is only transmitted to those entities that are necessary for payment processing, as well as in the context of statutory obligations or permissible commissioned processing.
d) Retention Period
The data is stored for as long as this is necessary for the performance of payment processing and the fulfilment of statutory or contractual obligations.
In addition, commercial and tax law retention obligations may apply. After the respective retention periods have expired, the data will be deleted, unless there are further legal grounds for storage.
e) Option to Amend
Until you submit your order, you can change the data you have entered at any time or cancel the ordering process. Likewise, you can select or change the desired payment method before completing the order.
7. Data Transmission
We only disclose your personal data if there is a legal basis for doing so or you have consented to the disclosure.
Personal data is disclosed in particular in the following cases:
a) You have given your express consent to the disclosure of your data pursuant to Art. 6(1)(a) GDPR.
b) The disclosure is necessary pursuant to Art. 6(1)(b) GDPR for the fulfilment of a contract with you or for the performance of pre-contractual measures.
c) The disclosure is made on the basis of a legal obligation pursuant to Art. 6(1)(c) GDPR.
d) We are legally obliged to transmit data to authorities or public bodies, for example to tax authorities, supervisory authorities or law enforcement authorities.
e) The disclosure is made pursuant to Art. 6(1)(f) GDPR to safeguard the legitimate interests of our company or to establish, exercise or defend legal claims, provided that your interests worthy of protection do not prevail.
f) We use external service providers (processors) pursuant to Art. 28 GDPR for the processing of personal data. These service providers have been carefully selected, contractually bound and process personal data exclusively in accordance with our instructions.
We use processors in particular in the following areas:
- IT and hosting services
- Authentication and identity services
- Payment processing
- Marketing
- Analytics and statistics services
Insofar as personal data is transferred to recipients in countries outside the European Union (EU) or the European Economic Area (EEA), we ensure that an adequate level of data protection is guaranteed.
A transfer only takes place if the requirements of Art. 44 et seq. GDPR are met, in particular on the basis of an adequacy decision by the European Commission or other appropriate safeguards, such as standard contractual clauses.
8. Your Rights
With regard to your personal data, you have the following rights vis-à-vis ADITUS GmbH:
- Right of Access (Art. 15 GDPR): You have the right to obtain information about whether and which personal data we process about you.
- Right to Rectification (Art. 16 GDPR): You have the right to request the rectification of inaccurate or the completion of incomplete personal data.
- Right to Erasure (Art. 17 GDPR): You have the right to request the erasure of your personal data, provided the statutory requirements are met.
- Right to Restriction of Processing (Art. 18 GDPR): You have the right to request the restriction of the processing of your personal data, provided the statutory requirements are met.
- Right to Data Portability (Art. 20 GDPR): You have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format or – where technically feasible – to have it transferred to another controller.
- Right to Object (Art. 21 GDPR): You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data where such processing is based on a legitimate interest. In addition, you may object at any time to the processing of your personal data for direct marketing purposes.
- Right to Withdraw Consent (Art. 7(3) GDPR): Where the processing of your personal data is based on consent, you may withdraw such consent at any time with effect for the future. The lawfulness of the processing carried out prior to the withdrawal remains unaffected.
- Right to Lodge a Complaint (Art. 77 GDPR): You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates data protection regulations.
The contact details of the data protection supervisory authorities of the German federal states can be found at: Data Protection Supervisory Authorities of the Federal States .
Information about the European data protection supervisory authorities can be found at: European Data Protection Supervisory Authorities .