Privacy
Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Niels BrüggerVogelsangstr. 101A
70197 Stuttgart
Email: hello@daifestival.dance
General information
Protecting your personal data matters to us. We process personal data exclusively within the bounds of the GDPR and the German Federal Data Protection Act (BDSG). In this policy we inform you about the nature, scope and purpose of the processing of personal data on this website.
Personal data is any data by which you can be personally identified. You can generally use this website without providing personal data; data is only provided if you contact us via a form or subscribe to the newsletter, for example.
Your rights
You have the right at any time to:
- information about the data stored about you (Art. 15 GDPR),
- rectification of inaccurate data (Art. 16 GDPR),
- erasure of your data (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- object to processing (Art. 21 GDPR).
If you have consented to processing, you may withdraw that consent at any time with effect for the future (Art. 7 (3) GDPR). An informal message to the email address above is sufficient.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg.
Legal bases
We process personal data on the basis of Art. 6 (1) GDPR — depending on the case, based on your consent (lit. a), to handle a contract or enquiry (lit. b), or on the basis of our legitimate interest in a secure, functional website with effective reach (lit. f).
Hosting
This website is hosted by an external service provider: Netlify, Inc., 101 2nd Street, San Francisco, CA 94105, USA. On our behalf, the provider processes technical data required to operate the website (see server log files). The basis is Art. 6 (1) lit. f GDPR (legitimate interest in reliable provision). A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place with the provider.
Personal data may be transferred to the USA in this context. Netlify, Inc. is certified under the EU-US Data Privacy Framework (DPF); the transfer is therefore based on the European Commission’s adequacy decision pursuant to Art. 45 (3) GDPR.
Open — Confirm the DPA with Netlify: Netlify’s Data Processing Agreement applies automatically by reference in its Terms of Use (copy: netlify.com/pdf/netlify-dpa.pdf — download and file it). Then remove this note; the text above is already accurate.
Server log files
When the website is accessed, information transmitted by your browser and technically required is automatically recorded: page accessed, date and time, volume of data transferred, referrer URL, browser type and version, operating system and the (where applicable, truncated) IP address. This data serves technical delivery, stability and security and is not merged with other data sources. The legal basis is Art. 6 (1) lit. f GDPR. It is stored only for as long as necessary for these purposes.
SSL/TLS encryption
For security reasons, this website uses SSL/TLS encryption. You can recognise an encrypted connection by the “https://” in your browser’s address bar.
Contacting us (partner/contact form & email)
If you contact us via the contact/partner form or by email, we process the data you provide (e.g. name, email address and your message) in order to handle your enquiry. The legal basis is Art. 6 (1) lit. b GDPR (handling an enquiry with a view to a possible contract) or lit. f GDPR (legitimate interest in responding). We store your details until your enquiry has been fully dealt with and no statutory retention obligations apply.
Newsletter
If you subscribe to our newsletter, we use your email address to send you information about D.AI (programme, dates, updates). Subscription uses the double opt-in procedure: after signing up you receive a confirmation email; the subscription only takes effect once you click the link it contains. This is how we make sure the subscription really comes from you.
The legal basis is your consent pursuant to Art. 6 (1) lit. a GDPR. You can unsubscribe at any time (withdrawal of consent), e.g. via the unsubscribe link at the end of every newsletter email or by sending us a message. We store your subscription data (time of sign-up and confirmation, IP address) as proof of consent for as long as the newsletter subscription exists.
Open — We use Brevo (Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin, Germany) to send our newsletter. Your email address is transferred to Brevo for this purpose; a data processing agreement pursuant to Art. 28 GDPR is in place. The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time via the unsubscribe link in every email.
Ticket purchase (ticket shop, payment, admission)
You can buy festival tickets via the “Tickets” page and the ticket shop embedded there. In doing so, we process: order data (email address, order number, booked tickets, price, payment method and payment status, time of order, language), attendee data (name of the person using the ticket; confirmation of the minimum age for the NIGHT programme), invoice data if an invoice is requested (name/company, address, VAT ID if applicable), voluntary information (newsletter consent), technical data when accessing the shop (IP address, time, pages accessed, browser) and admission data (time and place of the ticket code scan).
Purposes and legal bases: processing the ticket purchase, ticket delivery, admission control and customer service on the basis of the contract (Art. 6(1)(b) GDPR); invoicing and retention to fulfil legal obligations (Art. 6(1)(c) GDPR, Section 147 AO, Section 257 HGB); age verification for the NIGHT programme to comply with youth protection law (Art. 6(1)(c) GDPR); newsletter only with your consent (Art. 6(1)(a) GDPR, revocable at any time); operation, security and abuse prevention of the shop on the basis of our legitimate interest (Art. 6(1)(f) GDPR).
Providing your email address and the attendee name is required for the ticket purchase; without this information, no ticket can be issued. All other information is voluntary.
Ticket system: the ticket shop is operated using the pretix software. The servers are located in the European Union.
Open — Enter the hosting variant. While the shop runs on pretix Hosted: “The provider is rami.io GmbH, Berthold-Mogel-Straße 1, 69126 Heidelberg, Germany, as a processor under a data processing agreement pursuant to Art. 28 GDPR.” After the move to tickets.daifestival.dance: “The software runs on servers of Hetzner Online GmbH, Gunzenhausen, Germany (data centre in Germany); the technical service provider is LEVER GbR, Stuttgart, as a processor under a data processing agreement.”
Payment service provider: for payments by card, Apple Pay, Google Pay or SEPA direct debit, the payment is processed by Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland. Stripe receives the data required for the payment (amount, payment instrument, email address, order number) and is an independent controller in this respect. Stripe’s privacy policy: https://stripe.com/en-de/privacy. Data is transferred to third countries only insofar as the payment service provider requires this for the payment; adequacy decisions or standard contractual clauses are in place.
Open — If PayPal is activated as a payment method, add: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg; https://www.paypal.com/en/legalhub/privacy-full.
Other recipients: admission staff and security see the name and ticket category when scanning. Tax advisors and accounting receive invoice and revenue data.
Retention period: order and invoice data are stored for the duration of the statutory retention periods (up to ten years). Attendee and admission data are deleted no later than six months after the festival unless a retention obligation exists. Server logs of the shop are deleted after 14 days.
Open — Confirm deletion periods: attendee and admission data six months after the festival, server logs 14 days. Both values must match the actual configuration of the ticket system.
Photo, film and audio recordings: recordings are made at the festival for documentation and public relations (Art. 6(1)(f) GDPR, Sections 22, 23 KUG). Areas where recordings are made are marked. Anyone who does not wish to be recorded can contact the staff; for individual recordings we obtain consent.
Reach measurement / web analytics
We use Plausible Analytics, a privacy-friendly web analytics service by Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia. Plausible works without cookies, builds no personal profiles and processes data within the EU; IP addresses are not stored permanently. The legal basis is our legitimate interest in a website with effective reach (Art. 6 (1) lit. f GDPR).
Cookies
This website does not set any cookies — neither for marketing or tracking purposes nor technically necessary ones. Comparable techniques such as local storage are not used either; a cookie banner is therefore not required. Should a service set cookies in future, this policy will be updated and, where required, your consent will be obtained.
Fonts
This website uses only the system fonts on your device or locally hosted fonts. No connection to third-party servers (e.g. Google Fonts) is made; your IP address is not transmitted to external providers.
Validity and changes
This privacy policy reflects the status stated above. Further development of the website or changes to legal or regulatory requirements may make an amendment necessary. The current version is available on this page at any time.