Privacy Policy

Privacy Policy for drone-days.de

As of September 23, 2026

  1. Person in Charge

The entity responsible for processing personal data on this website is:

b.r.m. IT & Aerospace GmbH
Hanna-Kunath-Straße 31
28199 Bremen
Germany

Phone: +49 421 34 14 94
Email: brm@brm.de

Managing Directors: Markus Rossol and Harald Rossol

  1. Data Protection Officer

Our Data Protection Officer is:

Thorsten Brendel
ViCoTec IT Security & Data Protection GmbH & Co. KG

Phone: +49 441 24 92 65 20
Email: datenschutz@brm.de

  1. General Information

Personal data is information that relates to an identified or identifiable individual. This includes, for example, name, email address, phone number, IP address, and information regarding event registration.

We process personal data only if there is a legal basis for doing so. In particular, the following legal bases may apply:

  • Art. 6(1)(a) of the GDPR: You have given your consent.
  • Art. 6(1)(b) of the GDPR: Processing is necessary for the performance of a contract or for the implementation of precontractual measures.
  • Art. 6(1)(c) of the GDPR: We must comply with a legal obligation.
  • Art. 6(1)(f) of the GDPR: The processing is necessary for the purposes of a legitimate interest pursued by the controller, and there are no overriding interests of the data subject that would prevent such processing.

When we store information on your device or retrieve it from your device, we also comply with Section 25 of the TDDDG. For cookies and similar technologies that are not strictly necessary, we obtain your consent in advance.

We retain personal data only for as long as is necessary for the respective purpose. This does not affect statutory retention requirements or the retention of data for the purpose of asserting, exercising, or defending legal claims.

To the best of our current knowledge, no decisions with legal or similarly significant effects within the meaning of Article 22 of the GDPR are made solely by automated means.

  1. Hosting

Following technical monitoring, the website will be hosted on the infrastructure of:

Hetzner Online GmbH
Industriestraße 25
91710 Gunzenhausen
Germany

Provided. The server location detected during the scan is in Germany.

When you visit the website, the web server processes the following information in particular:

  • IP address,
  • Date and time of access,
  • page or file accessed,
  • Referrer URL,
  • Browser type and browser version,
  • Operating system,
  • the amount of data transferred, as well as
  • HTTP status code.

The purpose of this processing is to ensure the secure, stable, and technically error-free operation of the website. The legal basis is Article 6(1)(f) of the GDPR. Our legitimate interest lies in the secure and uninterrupted operation of our website.

To the extent that Hetzner processes personal data on our behalf, this is done on the basis of a data processing agreement pursuant to Article 28 of the GDPR.

Server logs are stored for a maximum of eleven days. After that, they are deleted unless a security incident or other legitimate reason requires them to be retained for a longer period.

  1. Transport encryption

This website uses TLS encryption.

  1. Cookies and Similar Technologies

Cookies are small files or data records that are stored on your device. Similar technologies include, for example, your browser's local storage and session storage.

We distinguish between the following categories:

6.1 Essential Technologies

These technologies are necessary to provide the website and the features you request. This includes, in particular, storing your privacy settings and technically necessary store or session functions.

Data is stored or retrieved in accordance with Section 25(2)(2) of the TDDDG. Depending on the purpose, we base the subsequent processing of personal data on Article 6(1)(b), (c), or (f) of the GDPR.

6.2 Statistics and Marketing

Statistics and marketing technologies help us measure visits, referral sources, and the effectiveness of our advertising. They are activated only after you give your consent.

The legal basis is Section 25(1) of the TDDDG and Article 6(1)(a) of the GDPR.

6.3 Functional External Services

Certain external services may be used for translations or other convenience features. Unless their use is absolutely necessary, they will not be loaded until you give your consent.

The legal basis is Section 25(1) of the TDDDG and Article 6(1)(a) of the GDPR.

You can revoke or change your consent at any time through the permanently accessible privacy settings. The revocation takes effect going forward.

  1. Borlabs Cookie

We use Borlabs Cookie to query, implement, and document your preferences regarding cookies and similar technologies.

The provider is:

Borlabs GmbH
Hamburger Straße 11
22083 Hamburg
Germany

Borlabs Cookie may process the following data in particular:

  • Consent status,
  • Selected services and categories,
  • Time of selection,
  • Version of the consent settings and
  • Technical identifiers.

According to the technical report, the following first-party cookies, in particular, are used:

Name

Purpose

Duration

borlabs-cookie

Saving Your Privacy Preferences

about two months

borlabs-cookie-gcs

Implementation or Documentation of the Google Consent Status

about two months

This information must be stored so that the website can remember your selection and does not ask you to confirm it every time you visit a page. End-device processing is carried out in accordance with § 25(2)(2) of the TDDDG. We base the recording of your selection on Article 6(1)(c) of the GDPR in conjunction with Article 7(1) of the GDPR. Technical operation is additionally based on Article 6(1)(f) of the GDPR.

The selection will be deleted when the configured time limit expires, when you reset the settings, or when you delete the relevant browser data. The report specifies a duration of one month and 30 days for both Borlabs cookies.

  1. WordPress and Elementor

We use WordPress as our content management system and Elementor to design and publish the website.

Elementor can create entries in the browser's session storage and local storage. During technical monitoring, the entry "elementor" was detected both in session storage and, on a permanent basis, in local storage.

This storage serves the technical display and processing of website content. To the extent that the entries are required exclusively for a website function you have requested, access to your device is permitted under Section 25(2)(2) of the TDDDG. We base the associated data processing on Article 6(1)(f) of the GDPR. Our legitimate interest lies in ensuring the technically stable and consistent presentation of the website.

Retention Period: The session storage entry is generally deleted at the end of the browser session. The local storage entry remains until it is technically overwritten or deleted by you via your browser settings.

  1. WooCommerce

We use WooCommerce to handle the technical aspects of event registrations, orders, and the associated participant management.

The software provider is:

Automattic Inc.
60 29th Street #343
San Francisco, CA 94110
USA

WooCommerce runs on our WordPress installation. Simply using the software does not automatically mean that login data is transferred to Automattic in the U.S. However, such a transfer may occur if external WooCommerce services, extensions, or telemetry features are enabled.

In particular, when you register, we process the following:

  • First and last name,
  • Companies,
  • Address,
  • job title,
  • Phone number,
  • Email address,
  • booked participation or services,
  • Billing and payment information,
  • Information about exhibition or visibility packages,
  • Approvals or acknowledgments, as well as
  • Technical order and log data.

This data processing is used to handle registration, invoicing, payment allocation, participant management, communication, and event organization.

The legal basis is Article 6(1)(b) of the GDPR. Retention required by law is carried out in accordance with Article 6(1)(c) of the GDPR. We base our IT security measures and measures to defend against legal claims on Article 6(1)(f) of the GDPR.

We retain contract and billing data in accordance with the statutory retention periods. We delete other registration data once it is no longer needed for the conduct and follow-up of the event. Unless otherwise required by law, the retention period is 3 months.

  1. Event Registration and Ticket Orders

To register for a paid event, we require the information marked as required fields on the form. Without this information, we cannot process your registration or enter into a participation agreement.

We use the data specifically for:

  • Execution and implementation of the participation agreement,
  • Confirmation of registration,
  • Invoicing and payment allocation,
  • Communication regarding the event,
  • Participant and Access Management,
  • Security organization,
  • Handling inquiries as well as
  • Enforcement or defense of legal claims.

The legal basis is Article 6(1)(b) of the GDPR. Retention requirements under tax and commercial law are based on Article 6(1)(c) of the GDPR. Access and security arrangements, as well as the defense of legal claims, may be based on Article 6(1)(f) of the GDPR. Our legitimate interest lies in ensuring the safe conduct of events and safeguarding our legal positions.

Recipients may include:

  • internal staff members responsible for this,
  • Hosting and IT service providers,
  • Accounting and Tax Consulting,
  • Credit institutions,
  • Event and security service providers,
  • Venue operators, as well as
  • Government agencies, courts, and legal counsel, as necessary.
  1. Expression of Interest in Exhibition and Visibility Packages

If you request information about an exhibition or visibility package on the registration form, we will process your contact information to fulfill this request.

The legal basis is Article 6(1)(b) of the GDPR if the processing is related to contract negotiations initiated by you. Any use beyond this for general advertising purposes will only take place if there is a separate legal basis.

We will delete the data once the request has been fully processed and provided that there are no legal retention requirements or legal claims that would prevent us from doing so.

  1. Sourcebuster.js

We use Sourcebuster.js to determine which source visitors used to reach our website. For example, the service can distinguish whether a page view came from a search engine, an advertising campaign, a link from another website, or a direct visit.

According to the monitoring report, Sourcebuster.js runs as a first-party technology on our domain. This means that the data is initially stored via drone-days.de. The scan does not identify a separate external Sourcebuster domain as the data recipient. Nevertheless, usage and origin data may be processed and linked to an order or registration.

In particular, the following can be processed:

  • Origin or source of the visit,
  • Referrer URL,
  • Campaign parameters,
  • page accessed,
  • Date of the visit,
  • Meeting information and
  • Technical identifiers.

The monitoring process identified the following storage instances in particular:

Name

Type

determined duration

sbjs_current

First-party cookie

Meeting

sbjs_current_add

First-party cookie

Meeting

sbjs_first

First-party cookie

Meeting

sbjs_first_add

First-party cookie

Meeting

sbjs_migrations

First-party cookie

Meeting

sbjs_session

First-party cookie

30 minutes

sbjs_udata

First-party cookie

Meeting

We will not activate Sourcebuster.js until we have received your consent. The legal basis for this is Section 25(1) of the TDDDG and Article 6(1)(a) of the GDPR. You may revoke your consent at any time via the privacy settings.

This scan did not detect any direct transfers to third countries by Sourcebuster.js. To the extent that the collected information is shared with Google Ads or other providers, the notices regarding the respective service also apply.

  1. Google Ads and Conversion Tracking

We use Google Ads conversion tracking. The provider is:

Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland

This service helps us track whether people take specific actions on our website after seeing a Google ad—such as visiting an event page or completing a registration.

In particular, the following data may be processed:

  • IP address,
  • Browser and device information,
  • pages viewed,
  • Ad interactions,
  • Time of a conversion,
  • Referrer information,
  • Campaign parameters, as well as
  • Cookies or other pseudonymous identifiers.

The monitoring identified the following storage instances in particular:

Name

Location

Purpose

determined duration

IDE

doubleclick.net

Advertising and Conversion Tracking

about one year and 25 days

_gcl_au

drone-days.de

Measuring Ad Conversions

about three months

_gcl_ls

Local Storage on drone-days.de

Storage of Conversion Information

until deleted by the user or the application

The service will be activated only after you give your consent. The legal basis for this is Section 25(1) of the TDDDG and Article 6(1)(a) of the GDPR. You may revoke your consent at any time via the privacy settings.

Google may also process data in the United States and other countries. For certified U.S. recipients, data transfers may be based on the European Commission’s adequacy decision regarding the EU-U.S. Data Privacy Framework. In addition, Google may use standard contractual clauses.

We cannot rule out the possibility that authorities in third countries may access data within the scope of their legal authority. By opting out of Google Ads, you can prevent such data transfers.

Google may determine the retention period for individual data items according to its own guidelines. Our own first-party identifiers will no longer be used for Google Ads when a page is reloaded, either after the period mentioned above has elapsed or upon revocation.

  1. Weglot

We use Weglot to provide foreign-language versions of the website.

The provider is:

Weglot SAS
138 rue Pierre Joigneaux
92270 Bois-Colombes
France

When using the service, the following data, in particular, may be processed:

  • IP address,
  • the page accessed and its content,
  • Selected language,
  • Browser and device information, as well as
  • Date and time of the call.

Weglot is based in France and is therefore located within the European Economic Area. The service was detected when the homepage was accessed. The monitoring system identifies it as an external service that was loaded without prior consent.

Until a technical review confirms that Weglot is loaded solely based on an explicitly selected language and does not process any additional data, we will not activate Weglot until we have received your consent.

The legal basis for this is Section 25(1) of the TDDDG and Article 6(1)(a) of the GDPR. You may withdraw your consent at any time via the privacy settings.

To the extent that Weglot acts as a data processor, we enter into a contract in accordance with Article 28 of the GDPR. Weglot may engage subcontractors. Transfers to third countries by such subcontractors are safeguarded by an adequacy decision, standard contractual clauses, or other appropriate safeguards.

The data will be deleted as soon as it is no longer needed for the translation function, provided that no legal obligations prevent this.

  1. Contact via Email and Phone

When you contact us by email or phone, we process the following information in particular:

  • Name,
  • Contact information,
  • Content of your message,
  • The date and time of the communication, as well as
  • contract-related information, if applicable.

If your inquiry relates to a contract or the initiation of a contract, the legal basis is Article 6(1)(b) of the GDPR. In other cases, we base the processing on Article 6(1)(f) of the GDPR. Our legitimate interest lies in the proper handling of your inquiry.

We will delete the data once the request has been fully processed and there are no legal retention requirements or legitimate reasons for further storage. Business correspondence may be subject to legal retention requirements.

  1. Payment processing via invoice and bank transfer

When payment is made by invoice or bank transfer, we process the following information in particular:

  • Account holder's name,
  • Account information, to the extent that it appears on the bank statement,
  • Payment amount,
  • Posting date,
  • Purpose of use, as well as
  • Invoice or transaction number.

The processing is necessary for the performance of the participation agreement. The legal basis is Article 6(1)(b) of the GDPR. Records required under commercial and tax law are retained in accordance with Article 6(1)(c) of the GDPR.

Recipients may include our bank, accounting department, and tax advisor. We store payment and billing data in accordance with the statutory retention periods.

  1. Recipients of Personal Data

Depending on the specific processing activity, the following recipients or categories of recipients may receive data:

  • internal staff members responsible for this,
  • Hetzner, or rather the hosting provider actually used,
  • IT, maintenance, and security service providers,
  • Borlabs,
  • Weglot,
  • Google and its affiliates, with your consent,
  • Banks,
  • Accounting and Tax Consulting,
  • Event and security service providers,
  • Venue operators,
  • Government agencies and courts, as well as
  • Legal advice.

We engage service providers to process data on our behalf in accordance with Article 28 of the GDPR. Other recipients receive data only if there is a separate legal basis for doing so.

  1. Transfers to Third Countries

Data may be processed outside the European Union or the European Economic Area by Google Ads and, potentially, by subcontractors of other services.

For recipients in countries for which the European Commission has issued an adequacy decision, we base the transfer on Article 45 of the GDPR. For appropriately certified U.S. companies, this includes the EU-U.S. Data Privacy Framework.

If there is no adequacy decision, we will, in particular, use standard contractual clauses pursuant to Article 46(2)(c) of the GDPR and assess any necessary additional safeguards.

  1. Withdrawal of Consent

You may revoke your consent at any time, effective for the future. To do so, use the privacy settings on the website, which are always available, or contact us.

The withdrawal does not affect the lawfulness of the processing that took place prior to the withdrawal.

  1. Right to Object

If we process your data pursuant to Article 6(1)(e) or (f) of the GDPR, you may object at any time on grounds relating to your particular situation.

We will not process the data further unless we can demonstrate compelling legitimate grounds for doing so that override your interests, rights, and freedoms. Furthermore, further processing remains possible to the extent that it serves to assert, exercise, or defend legal claims.

If we process personal data for direct marketing purposes, you may object at any time without having to provide a specific reason. We will then no longer use the data for this purpose.

  1. Your Privacy Rights

You have the following rights in accordance with the applicable legal requirements:

  • Information pursuant to Article 15 of the GDPR,
  • Rectification pursuant to Article 16 of the GDPR,
  • Erasure pursuant to Article 17 of the GDPR,
  • Restriction of processing pursuant to Article 18 of the GDPR,
  • Data portability under Article 20 of the GDPR,
  • Objection under Article 21 of the GDPR,
  • Withdrawal of consent pursuant to Article 7(3) of the GDPR, as well as
  • Filing a complaint with a supervisory authority pursuant to Article 77 of the GDPR.

To exercise your rights, you may contact the data controller or the data protection officer.

  1. Right to File a Complaint

You have the right to file a complaint with a data protection supervisory authority. In particular, you may contact the authority in your place of habitual residence, your place of work, or the location of the alleged violation.

The following supervisory authority has jurisdiction over the data controller in particular:

The State Commissioner for Data Protection and Freedom of Information of the Free Hanseatic City of Bremen
Arndtstraße 1
27570 Bremerhaven
Germany

  1. Obligation to Provide Data

You do not need to actively provide us with any data simply by visiting the website. However, technical access data is collected automatically.

To register for the event, we require the information marked as required fields. Without this information, we cannot enter into a participation agreement or process your registration.

Consent to marketing, statistical, or translation services is voluntary and is not a requirement for event registration.

  1. Sources of Personal Data

Generally, we collect your data directly from you, for example, when you register, place an order, or contact us.

With your consent, we may also use Sourcebuster.js and Google Ads to obtain additional information about which campaign, search engine, ad, or referring website led you to our site. This information comes from your browser, campaign parameters, and, where applicable, from Google.

  1. Automated Decisions

We do not use fully automated decision-making, including profiling as defined in Article 22 of the GDPR, that produces legal effects concerning you or similarly significantly affects you.

Attributing a website visit to an advertising campaign is used solely to measure reach and effectiveness.

  1. Current Status and Changes

We will update this Privacy Policy if there are changes to our data processing practices, the services we use, or legal requirements.

The most current version is available on this website.