Imprint
Note: This is a courtesy translation. The German version is legally binding.
The party responsible for this website, in accordance with Article 4(7) of the GDPR and Section 5(1) of the DDG, is:
MRMCD e.V.
c/o Chaos Computer Club Darmstadt e.V.
Wilhelminenstraße 17
64283 Darmstadt
E-Mail: grenzenlos@mrmcd.net
Telefon: +49 6151 / 52 000 88 (only for problems with mrmcd.net e-mail traffic)
The MRMCD association is registered in the register of associations at the Darmstadt Local Court under number VR83480.
It is represented by the board of directors: Oliver Knapp, Felix Breidenstein, and Ian Bierlich.
VAT ID: DE312569598
Privacy Policy
Purposes and Legal Bases for the Processing of Personal Data Under the GDPR
In accordance with its mission, the nonprofit organization MRMCD e.V. organizes noncommercial professional events. To this end, MRMCD e.V. may collect and store data from participants and other individuals interested in these professional events.
Rights of Data Subjects
All individuals whose personal data is processed by MRMCD e.V. have the following rights:
- Right to be informed whether and which personal data concerning the individual is being processed (Art. 15 GDPR)
- Right to rectification of inaccurate data (Art. 16 GDPR)
- Right to restriction of processing or erasure of personal data (Arts. 17–18 GDPR)
- Right to receive personal data concerning the individual in a structured, commonly used, and machine-readable format (right to data portability, Art. 20 GDPR)
- The right to object to data processing on grounds relating to your particular situation (Art. 21 GDPR)
- The right to file a complaint with the competent supervisory authority
Lawfulness of Processing
MRMCD e.V. processes personal data as defined by the GDPR that is provided to the association in connection with the use of its services or participation in its events. The storage and processing of personal data therefore takes place in accordance with Article 6(1)(a) of the GDPR (consent to data processing by data subjects). It is possible to withdraw consent at any time with future effect. The lawfulness of data processing carried out on the basis of consent up until the time of withdrawal remains unaffected by such withdrawal.
Furthermore, the processing and storage of personal data in connection with event registration by participants and interested parties is carried out in accordance with Article 6(1)(b) (performance of a contract).
For data subject to statutory retention requirements, storage and processing are also carried out in accordance with Article 6(1)(c) (legal obligation to retain data).
Furthermore, the association reserves the right to store and process personal data in accordance with Article 6(1)(f), provided that such storage is necessary to safeguard the legitimate interests of the association or a third party, e.g., in the context of a potential legal dispute. Processing and storage pursuant to Article 6(1)(f) of the GDPR will not take place if the interests or fundamental rights and freedoms of the data subject, which require the protection of personal data, prevail.
Processed Data
In order to carry out the respective event, we process the following categories of personal data in particular, provided they have been transmitted to us:
- Master data such as name, address, and contact information
- Contract or customer data related to the advance purchase of products, such as order number, order items, and payment information
- Data you have provided in connection with presentation submissions, such as title, description, and notes
Recipients of the Data
Your personal data will be disclosed—only to the extent necessary—to the following categories of recipients:
- Volunteers involved in putting together a diverse and annually changing program of events for decision-making purposes,
- External service providers (e.g., the bank that manages our account for remittances, hosting providers with a data processing agreement),
- Public authorities, to the extent that we are legally required to do so.
Retention Period
The association operates in accordance with the principle of data minimization as set forth in Article 5(1)(c) of the GDPR. Personal data is stored only for as long as necessary for the stated purposes or as required by statutory retention obligations. We therefore regularly delete or anonymize data content once it is no longer necessary. In doing so, we comply with statutory archiving requirements.
Profiling
No automated decision-making, including profiling, takes place in accordance with Article 22 of the GDPR.