DATA PROTECTION DECLARATION
This text version is a translation of the original German text which is the only legally binding version.
ICA Institutional Capital Associates GmbH (ICA) attaches great importance to the responsible handling of personal data. We would like users to know when certain data is collected and used by ICA. ICA operates a website under the domain www.ic-icf.com. The activities of ICA are announced and archived on this website. It is also possible to register for ICA events via this website. We only process personal data to the necessary extent. The basis on which different data is processed depends on the purpose for which the data is required.
1. WHO IS RESPONSIBLE FOR DATA PROCESSING AND WHO CAN I CONTACT?
ICA is responsible for processing your data in line with Article 4(7) GDPR. You can find our contact details below:
ICA Institutional Capital Associates GmbH,
represented by is managing director Mr. Hans-Peter Dohr
Setzbergstrasse 8
83624 Otterfing
Germany
Tel.: +49 89 125 01 80 30
E-Mail: hp.dohr@ic-ica.com
2. WHAT IS THE LEGAL BASIS FOR US TO PROCESS YOUR PERSONAL DATA?
ICA processes personal data in accordance with the European General Data Protection Regulation (GDPR), the German Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG) and, where applicable, the German Telecommunications Digital Services Data Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, TDDDG).
Where ICA obtains the consent of the data subject for the processing of personal data, Article 6(1)(a) GDPR serves as the legal basis. Any consent granted may be withdrawn at any time with effect for the future. The withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
Where processing is necessary for the performance of a contract to which the data subject is party, Article 6(1)(b) GDPR serves as the legal basis. This also applies to processing operations that are necessary in order to take steps prior to entering into a contract.
Where processing is necessary for compliance with a legal obligation to which ICA is subject, Article 6(1)(c) GDPR serves as the legal basis in conjunction with the relevant statutory provisions.
In rare cases, where processing is necessary in order to protect the vital interests of the data subject or of another natural person, Article 6(1)(d) GDPR serves as the legal basis.
Where necessary, ICA also processes personal data for the purposes of its own legitimate interests or the legitimate interests of third parties, unless such interests are overridden by the interests or fundamental rights and freedoms of the data subject. Such legitimate interests may include the establishment, exercise or defence of legal claims, ensuring IT security and IT operations, public relations activities, and the prevention of criminal offences. In such cases, Article 6(1)(f) GDPR serves as the legal basis.
3. WHAT PERSONAL DATA IS PROCESSED IN CONNECTION WITH THE USE OF OUR WEBSITE AND OUR ONLINE SERVICES?
3.1 Provision of the website and server log files
Each time our website is accessed, our web server automatically processes certain technical data transmitted by the user’s browser. This may include, in particular:
- the IP address of the accessing device;
- the date and time of access;
- the page or file requested;
- the amount of data transferred;
- the browser type and version;
- the operating system used;
- the referrer URL, where applicable;
- the requesting provider;
- the HTTP status code.
This data is processed in order to provide the website technically, ensure system security and stability, detect and prevent misuse, and optimise the technical operation of the website.
The legal basis for this processing is Article 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and reliable operation of our website and IT systems.
The log file data is not combined with other personal data of the user and is not used by ICA to draw conclusions about the identity of individual website visitors. The data is deleted as soon as it is no longer required for the purposes for which it was collected. In the case of server log files, this is usually after 30 days, unless longer storage is required in individual cases for security reasons, for example to investigate misuse or attacks on our IT systems.
3.2 Cookies and similar technologies
Our website uses cookies and similar technologies. Cookies are small text files that are stored on the user’s device by the browser. Some cookies are technically necessary in order to provide the website and its functions.
Technically necessary cookies may be used, for example, to enable the secure operation of the website, maintain a session, store technical preferences, prevent misuse, or ensure the proper functioning of online forms.
The legal basis for the use of technically necessary cookies and similar technologies is Section 25(2) of the German Telecommunications Digital Services Data Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, TDDDG). To the extent that personal data is processed in this context, the legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in providing a technically functional, secure and user-friendly website.
Where cookies or similar technologies are used that are not strictly necessary for the operation of the website, such technologies will only be used on the basis of the user’s consent, where such consent is legally required. The legal basis in such cases is Section 25(1) TDDDG and Article 6(1)(a) GDPR. Any consent granted may be withdrawn at any time with effect for the future.
Users can also configure their browser settings so that cookies are blocked, deleted or only permitted in individual cases. However, if technically necessary cookies are disabled, some functions of the website may not be available or may only be available to a limited extent.
3.3 Use of Google reCAPTCHA
To protect our website and our online forms from misuse, spam and automated submissions, we use Google reCAPTCHA. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
reCAPTCHA is used to verify whether a form submission is made by a human user or by an automated program. For this purpose, technical information and usage data may be processed, including, in particular, the IP address, browser and device information, referrer URL, date and time of access, interaction data with our website, and other information required for security and abuse prevention.
The purpose of this processing is to protect our website, our online forms and our IT systems against spam, automated attacks and other forms of misuse.
The legal basis for the use of reCAPTCHA is Article 6(1)(f) GDPR. Our legitimate interest lies in protecting our website and our online forms from misuse, spam and automated attacks. To the extent that consent is required for the use of reCAPTCHA, the processing is carried out on the basis of Article 6(1)(a) GDPR and Section 25(1) TDDDG. Any consent granted may be withdrawn at any time with effect for the future.
According to Google, reCAPTCHA customers act as controllers for the data processed through reCAPTCHA, while Google processes such data as a processor in accordance with the applicable Google Cloud terms and data processing terms. Google states that reCAPTCHA data is processed for the purpose of providing and maintaining the service and ensuring security, threat detection and abuse prevention.
3.4 Contact by email or contact form
Users may contact ICA by email or, where available, via online contact forms. In this context, we process the personal data transmitted by the user. This may include, in particular, the user’s name, email address, organisation, telephone number, the content of the message and any other information voluntarily provided by the user.
The data is processed for the purpose of handling the enquiry, communicating with the user and, where applicable, initiating or performing a contractual relationship.
The legal basis for processing is Article 6(1)(f) GDPR. Our legitimate interest lies in responding to enquiries and maintaining business communication. Where the enquiry relates to the conclusion or performance of a contract, Article 6(1)(b) GDPR also serves as the legal basis.
The data will be deleted once the enquiry has been fully processed and no statutory retention obligations or legitimate interests require further storage.
3.5 Registration on the website and registration for events
Users may register on our website or register themselves and, where applicable, other participants for ICA events. In this context, we process the personal data required for registration, event organisation and participant management. This may include, in particular:
- institution or organisation;
- salutation;
- first name and surname;
- role or job title;
- department;
- email address;
- telephone number;
- billing and payment information, where applicable;
- information relating to the selected event;
- information on participation in specific programme elements;
- information on dietary requirements or accessibility needs, where voluntarily provided.
Mandatory information is processed in order to identify the contracting party, process the registration or order, issue confirmations and invoices, organise the event, prepare name badges and participant lists, provide access to the event, and contact participants in connection with the event.
The legal basis for this processing is Article 6(1)(b) GDPR, insofar as the processing is necessary for registration, ticket purchase, event participation or the performance of related contractual obligations. Where processing is required to comply with statutory obligations, in particular tax or commercial law retention obligations, Article 6(1)(c) GDPR serves as the legal basis. Where we process data for event organisation, participant communication, statistical evaluation or the invitation to similar future professional events, Article 6(1)(f) GDPR may also serve as the legal basis. Our legitimate interest lies in the professional organisation, administration and further development of our events.
3.6 Participant lists, name badges and event materials
For the purpose of organising and conducting our events, ICA may prepare name badges, check-in lists, participant lists and other event-related materials. These may include the names, organisations and, where applicable, roles or affiliations of participants.
Participant lists may be used internally for event organisation and, where appropriate, made available to registered participants, speakers, sponsors, event partners or co-organising institutions, provided this is necessary or appropriate for the professional networking character of the event and the interests of the participants do not override this.
The legal basis for this processing is Article 6(1)(b) GDPR where it is necessary for the performance of the event contract. In other cases, the legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in enabling professional networking, participant management and the proper organisation of our events.
3.7 Photography and filming at events
During ICA events, photographs and video recordings may be taken by ICA or by service providers commissioned by ICA. These recordings may show participants, speakers, sponsors, event partners and other persons present at the event.
We process such recordings for the purposes of documenting the event, reporting on the event, making selected event impressions available to registered participants, and for public relations and marketing activities relating to this and future ICA events. This may include publication on our website, in printed event materials, in newsletters and on social media channels, in particular LinkedIn.
The legal basis for this processing is Article 6(1)(f) GDPR. Our legitimate interest lies in documenting our professional events, informing participants and interested professional audiences about our events, and presenting our event formats and activities to the market.
Selected recordings may be made available to registered participants, speakers, sponsors and event partners, for example via a password-protected gallery or download link. Where recordings are published on social media platforms or other online channels, they may be accessible worldwide and further processing by platform providers or third parties cannot be excluded.
If you do not wish to be photographed or filmed, please inform the photographer or our event team at the venue. You may object to the processing of recordings showing you at any time on grounds relating to your particular situation pursuant to Article 21 GDPR. We will take such objections into account and will, where appropriate, refrain from producing, using or further publishing such recordings.
For close-up portraits, interviews, testimonials or other recordings in which an individual person is the main subject and which are intended for promotional use, we may ask for separate consent.
3.8 Payment processing
Where payments are made in connection with registrations, ticket purchases or other services, we process the data required for payment and invoicing. This may include, in particular, billing address, invoice details, payment amount, payment method and, where applicable, bank or payment transaction data.
The data is processed for the purpose of processing the payment, issuing invoices, fulfilling contractual obligations and complying with statutory accounting and tax obligations.
The legal basis is Article 6(1)(b) GDPR, insofar as the processing is necessary for the performance of a contract. Where processing is required to comply with statutory retention or accounting obligations, Article 6(1)(c) GDPR serves as the legal basis.
4. DISCLOSURE OF PERSONAL DATA TO THIRD PARTIES AND SERVICE PROVIDERS
ICA will only disclose personal data to third parties where this is legally permitted, where it is necessary for the purposes described in this data protection declaration, where the data subject has given consent, or where ICA is legally obliged to do so.
In particular, personal data may be disclosed to the following categories of recipients, where applicable:
- IT, hosting and website service providers;
- providers of online forms, security tools and anti-spam solutions, including Google reCAPTCHA;
- email, communication and office service providers;
- payment service providers and banks;
- tax advisors, auditors, legal advisors and other professional advisors;
- event venues, event service providers and technical service providers;
- photographers, videographers and providers of event galleries or media platforms;
- co-organising institutions, event partners and sponsors, where this is necessary or appropriate for the organisation and implementation of the relevant event;
- public authorities, courts or other public bodies, where ICA is legally obliged to disclose data or where disclosure is necessary for the establishment, exercise or defence of legal claims.
Where ICA uses external service providers that process personal data on behalf of ICA, such service providers are generally engaged as processors within the meaning of Article 28 GDPR and are contractually bound to process personal data only in accordance with ICA’s instructions and applicable data protection law.
Where data is disclosed to independent controllers, such recipients are responsible for their own data processing activities. This may apply, for example, to certain payment service providers, public authorities, professional advisors, social media platforms or event partners, depending on the specific processing activity.
Personal data of participants registered for events may be disclosed to the relevant co-organising institutions, event partners, sponsors, venues or service providers where this is necessary for the organisation, implementation, documentation or follow-up of the event. Co-organising institutions and event partners are usually specified in the description of the relevant event.
ICA does not sell personal data to third parties.
5. TRANSFERS OF PERSONAL DATA TO THIRD COUNTRIES
In connection with the use of our website, online services, communication tools, event services and external service providers, personal data may be transferred to countries outside the European Union or the European Economic Area, so-called third countries, or may be accessed from such countries.
Such transfers may occur, in particular, where service providers, affiliated companies or sub-processors used by our service providers are located outside the European Union or the European Economic Area. This may apply, for example, in connection with IT, hosting, security, communication, office, event, payment, analytics, media, social media or cloud services.
Where personal data is transferred to a third country for which the European Commission has issued an adequacy decision within the meaning of Article 45 GDPR, the transfer is based on that adequacy decision.
Where personal data is transferred to the United States, the transfer may be based on the EU-US Data Privacy Framework, provided that the relevant US recipient is certified under this framework.
Where no adequacy decision exists or where the recipient is not covered by an adequacy decision, ICA will only transfer personal data to third countries if appropriate safeguards within the meaning of Article 46 GDPR are in place, in particular the European Commission’s Standard Contractual Clauses, or if another legal basis for the transfer exists under Articles 44 et seq. GDPR.
Despite such safeguards, it cannot be completely excluded that authorities in third countries may access personal data in accordance with the laws applicable in those countries and that data subjects may not have the same legal remedies as within the European Union or the European Economic Area.
Further information on specific third-country transfers may be provided in the descriptions of individual services in this data protection declaration.
6. WHAT DATA PROTECTION RIGHTS DO I HAVE?
You have the following rights with regard to the personal data concerning you:
- the right of access in accordance with Article 15 GDPR;
- the right to rectification in accordance with Article 16 GDPR;
- the right to erasure in accordance with Article 17 GDPR;
- the right to restriction of processing in accordance with Article 18 GDPR;
- the right to data portability in accordance with Article 20 GDPR;
- the right to object in accordance with Article 21 GDPR.
Where processing is based on your consent, you may withdraw your consent at any time with effect for the future. The withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
With regard to the right of access and the right to erasure, the restrictions pursuant to Sections 34 and 35 of the German Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG) may apply.
You may assert the above rights by contacting ICA using the contact details stated in Section 1 of this data protection declaration.
You also have the right to lodge a complaint with a data protection supervisory authority pursuant to Article 77 GDPR. The supervisory authority responsible for ICA is generally:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany
Phone: +49 (0) 981 180093-0
Email: poststelle@lda.bayern.de
You may also contact ICA at any time if you have any questions or complaints regarding the processing of your personal data.
7. AMENDMENTS TO THE DATA PROTECTION DECLARATION
ICA reserves the right to modify this data protection declaration so that it always adheres to current legal requirements. We recommend that you read our data protection declaration regularly in order to stay up to date regarding the protection of the personal data that we collect.
This text version is a translation of the original German text which is the only legally binding version.