Privacy Policy
adventics GmbH (hereinafter: „adventics” or „we”) attaches great importance to the protection of your personal data. In the following, we would like to inform you about the processing of your personal data on our websites and platforms in accordance with Art. 13 GDPR.
B. Contact details of our Data Protection Officer
C. Processing of personal data on the Scan2Lead website
D. Processing of personal data via the Scan2Lead web shop
E. Processing of Personal Data of Business Partners
F. Processiong of personal data via the plattform (portal, app, shop)
G. Promotional contact of visitors by e-mail after a trade fari visit
A. Controller
The controller responsible for the processing of your personal data is
adventics GmbH
Münchener Str. 23A
85540 Haar b. Munich, Germany
Phone: +49 89 4444 33 100
Email: info@adventics.de
B. Contact details of our Data Protection Officer
datenschutz süd GmbH
Wörthstraße 15
97082 Würzburg
Phone: +49 931 30 49 76 – 0
Email: office@datenschutz-sued.de
C. Processing of personal data on the Scan2Lead website
I. Usage Data
When you visit our Scan2Lead website, so-called usage data is temporarily stored as a log on our web server for statistical purposes in order to improve the quality of our website. This data set consists of
- the IP address of the requesting computer, shortened in such a way that a personal reference can no longer be established,
- the host name,
- the date and time of the request,
- the time zone difference to Greenwich Mean Time (GMT),
- the specific pages of our website that you access,
- the access status/ HTTP status code (file transferred, file not found),
- the amount of data transferred in each case,
- the website from which the request originates (referrer),
- the specific pages of our website that you access,
- the browser, in terms of type, version and language setting,
- the operating system in terms of type and version,
- the activated Java scripts for: screen resolution, colour depth, size of the browser window, installed browser plugins.
The log data mentioned is stored in anonymised form only. The legal basis for processing usage data is Art. 6 (1) (f) GDPR. The processing is carried out in our legitimate interest in providing the content of our website and ensuring a device- and browser-optimised presentation. The log data is deleted at regular intervals, at the latest by the end of the following calendar month.
II. SSL / TLS Encryption
For security reasons and to protect the transmission of confidential content, such as orders or enquiries that you send to us as the site operator, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the browser address line changes from „http://” to „https://” and by the lock symbol in your browser line. When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
III. Hosting
We use Timme Hosting GmbH & Co. KG, Marie-Curie-Straße 5, 21337 Lüneburg, to host our website. We have carefully selected this external service provider and entered into a data processing agreement in accordance with Article 28 of the GDPR.
IV. Consent Management Platform
On our website we use the consent management platform Borlabs. The processing associated with the use of Borlabs and the logging of the settings you make is carried out on the basis of Art. 6 (1) (f) GDPR. Our legitimate interest is to display our content in accordance with your preferences and to be able to demonstrate the consent you have granted. The settings you have made, the consent granted thereby and parts of your usage data are stored in a cookie. This means that it is retained for subsequent page requests and your consent can continue to be traced. Your cookie decision, i.e. the consent granted or refused, is stored for a period of 60 days; after that we ask for your selection again.
No information about visitors is transmitted to Borlabs via the Borlabs cookie.
V. Cookies
We use cookies on our websites. Cookies are small text files that can be stored and read on your device. A distinction is made between session cookies, which are deleted as soon as you close your browser, and permanent cookies, which are stored beyond the individual session. Cookies can contain data that make it possible to recognise the device used. In some cases, however, cookies only contain information on certain settings that cannot be related to a person.
For the display and functionality of our website, we use both necessary session cookies and permanent cookies. The processing is carried out on the basis of Art. 6 (1) (f) GDPR, Section 25 (2) TDDDG. Our interest is to enable the display of our website. You can object to the processing at any time. To do so, please send an e-mail to datenschutz@adventics.de. You can set your browser to inform you about the placement of cookies. You can also delete cookies at any time via the corresponding browser setting and prevent the setting of new cookies. In this case, our website may not be displayed optimally and some functions may no longer be technically available.
We also use tracking cookies on our website in order to track your user behaviour and subsequently send you targeted advertising. The processing is carried out on the basis of your consent pursuant to Art. 6 (1) (a) GDPR, Section 25 (1) TDDDG, provided that you have previously given your consent to tracking via our cookie banner. You can withdraw any consent you have given to the use of a tracking cookie at any time with effect for the future, without this affecting the lawfulness of the processing carried out to date. To withdraw, please send an e-mail to datenschutz@adventics.de
We use the following tracking cookies on our website:
Google Analytics / Google Tag Manager
To design our websites in line with requirements, we use the web analytics tool „Google Analytics”. Google Analytics creates usage profiles on the basis of pseudonyms. For this purpose, permanent cookies are stored on your device and read by us. In this way, we are able to recognise and count returning visitors. To control Google Analytics, we use Google Tag Manager, an auxiliary service that itself processes personal data (IP address) only for technically necessary purposes.
As part of the Google Analytics / Google Tag Manager service, Google Ireland Limited supports us as a processor pursuant to Art. 28 GDPR. The data processing may also take place through Google outside the EU or the EEA (in particular in the USA). With regard to Google, an adequate level of data protection is ensured on the basis of the adequacy decision (EU-U.S. Data Privacy Framework). In addition, Google undertakes to conclude standard contractual clauses with further sub-processors.
Zoho Forms
For the provision of our online forms we use Zoho Forms, a service of Zoho Corporation B.V., Beneluxlaan 4B, 3527 HT Utrecht, Netherlands.
When you fill in and submit a form on our website, the data you enter (e.g. name, e-mail address, telephone number and other form details) is processed and transmitted to Zoho. In addition, technical data such as IP address, browser type, operating system and the date and time of the request may be processed insofar as this is necessary for the provision and security of the service.
Your data is processed for the purpose of handling your enquiry or carrying out pre-contractual measures pursuant to Art. 6 (1) (b) GDPR, or on the basis of our legitimate interest in the efficient and secure provision of online forms pursuant to Art. 6 (1) (f) GDPR. Insofar as consent is required for the use of Zoho Forms (e.g. when using cookies or comparable technologies), the processing is carried out on the basis of Art. 6 (1) (a) GDPR. Insofar as personal data is transferred to third countries, this is done on the basis of appropriate safeguards pursuant to Art. 46 GDPR, in particular by concluding standard contractual clauses (SCCs), where required. Further information on data processing by Zoho can be found at https://www.zoho.com/privacy.html.
VI. Contact
1. Contact via the form
You have the option of contacting us via our web form. For this we need your form of address, your surname, first name, e-mail address, the company as well as your subject and your message. The legal basis for processing this personal data is Art. 6 (1) (f) GDPR, as we have a legitimate interest in answering your enquiry as simply, promptly and appropriately as possible. Without the provision of your data, we are unfortunately unable to process your enquiry. You have the right to object to the processing pursuant to Art. 21 GDPR. However, your enquiry can then no longer be answered.
Enquiries that you send us as part of a general enquiry about the services and products we offer are processed on the basis of Art. 6 para. 1 sentence 1 lit. b) GDPR.
In addition, you can decide for yourself whether you would like to provide us with further information. This information is provided voluntarily and is not mandatory for contacting us. We process your voluntary information on the basis of your consent in accordance with Art. 6 para. 1 sentence 1 lit. a) GDPR. You can revoke your consent to data processing at any time at datenschutz@adventics.de.
Your personal data will be deleted 12 months after your enquiry has been answered. Statutory retention periods remain unaffected. We do not transfer your personal data to third parties.
2. Contact via chat
You can contact us via the chat window in the bottom right-hand corner of the landing page and all subpages of our website. Use is voluntary. We use two services for this with different tasks.
a) Zoho SalesIQ (live chat and visitor recognition)
For the live chat with our staff and for the recognition of visitors, we use Zoho SalesIQ, a service of Zoho Corporation B.V., Beneluxlaan 4B, 3527 HT Utrecht, Netherlands. The data you enter in the chat (e.g. name, e-mail address, chat content) as well as technical data such as IP address, browser type, operating system, pages visited and access time are processed. Cookies are set in the process. The processing is carried out on the basis of your consent pursuant to Art. 6 (1) (a) GDPR, Section 25 (1) TDDDG, provided that you have previously given this consent via our consent banner. SalesIQ is only loaded after your consent. You can withdraw your consent at any time with effect for the future.
b) Zetabot (automated chatbot)
For the automated initial answering of your enquiries, we use the AI-supported chatbot „Zetabot”. The messages you enter and any data provided voluntarily (e.g. name, e-mail address) as well as the date and time and your IP address are processed. The processing is carried out on the basis of our legitimate interest pursuant to Art. 6 (1) (f) GDPR in answering your enquiry as simply, promptly and appropriately as possible; in the case of pre-contractual enquiries, additionally Art. 6 (1) (b) GDPR. We process additional voluntary information on the basis of your consent pursuant to Art. 6 (1) (a) GDPR.
Common provisions
You can object to the processing or withdraw your consent at any time at datenschutz@adventics.de; afterwards we can no longer process your enquiry via the chat. Chat histories are stored for a period of 12 months and then deleted. In the provision and evaluation of the chat, we are supported by the instruction-bound processors Zoho Corporation B.V. (SalesIQ) and Event Power House as the provider of the chatbot „Zetabot”. A data processing agreement pursuant to Art. 28 GDPR has been concluded with both.
VII. Embedded YouTube Videos
On subpages of our website we embed YouTube videos that are not stored on our servers. In order to ensure that accessing these subpages does not result in content being loaded from YouTube, a locally stored preview image of the video is displayed. As a result, the third-party provider receives no information about you. Only with your consent via our consent banner is content from e.g. YouTube loaded. In this context, YouTube receives information about you, including your IP address, which is technically necessary to retrieve the content. We generally have no influence on the further processing by YouTube.
The embedding is carried out on the basis of your consent, provided that you have given your consent via our consent banner. Please note that embedding videos results in your data being processed outside the EU or the EEA.
D. Processing of personal data via the Scan2Lead web shop
VIII. Order form
We offer you the option of ordering Scan2Lead licences for future events via our web shop. We have already created your customer account in our web shop on the basis of the personal data available to us from the existing business relationship or business initiation, and it is administered by us. Should your data change at any time, we ask you to inform us accordingly.
Your personal data is automatically entered into the input mask from the Scan2Lead system and processed by us for the purpose of handling your order. When you place an order via our website, we process, in the web shop, company, name, surname, address, country, e-mail address and telephone number. The data processing is carried out in response to your order and, pursuant to Art. 6 (1) (b) GDPR, is necessary for the stated purposes for the proper handling of your order and for the mutual fulfilment of obligations arising from the purchase contract.
In addition, you can decide for yourself whether you wish to provide us with further information. This information is provided voluntarily and is not mandatory for the order. We process your voluntary information on the basis of your consent pursuant to Art. 6 (1) (a) GDPR. You can withdraw your consent to the data processing at any time at datenschutz@adventics.de.
The personal data collected by us for the processing of your order is stored until the expiry of the statutory retention period and then deleted, unless we are obliged to store it for a longer period due to tax and commercial law (among others) retention and documentation obligations (e.g. under the German Commercial Code (HGB), the German Criminal Code (StGB) or the German Fiscal Code (AO)).
Your personal data is only passed on to third parties involved in the processing of the contract, such as the credit institution commissioned with payment matters. In cases where your personal data is passed on to third parties, the scope of the transmitted data is limited to the necessary minimum.
IX. Payment options
Depending on the payment method you have chosen, we also process personal data in the context of the processing and reversal of payments. The legal basis for processing this personal data is Art. 6 (1) (b) GDPR, as it is necessary for the fulfilment of our service contract.
1. Purchase on account / advance payment
In the case of payment on account or by advance payment, we process the data required for payment processing relating to your order, including the name of the account holder, the IBAN and the BIC as well as further details of your bank, on the basis of Art. 6 (1) (b) GDPR, as these are necessary for the fulfilment of our service contract, in particular for invoicing. Access to the purchased products and the processing of the data required for payment processing only takes place after receipt of payment has been recorded.
2. Credit card
In the case of payment by credit card, in addition to the data required for payment processing relating to your order, we also process data on your credit card provider, where applicable the issuing credit institution, the card number, the name of the cardholder, the expiry date and the card verification number on the basis of Art. 6 (1) (b) GDPR. The data processing is necessary in order to be able to carry out the payment on the one hand and, on the other hand, to carry out a renewed charge when a subscription is renewed. We transmit this data to the following independently responsible payment service providers for payment processing:
- PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg,
- Stripe Payment Europe Limited (SPEL), Grand Canal Street Lower, Grand Canal Dock, Dublin D02 H210, Ireland.
3. Purchase on final invoice
If you have chosen the payment method „purchase on final invoice”, the data stored by you is processed by the respective trade fair at which you exhibited. Your data is processed on the legal basis of Art. 6 (1) (b) GDPR between you and the trade fair as the organiser.
E. Processing of personal data of business partners
We process your professional contact data, in particular e-mail address and telephone number, in order to enter into pre-contractual measures or to perform an already existing contract between adventics and you, on the basis of Art. 6 (1) (b) GDPR.
In the event that a contract is concluded between adventics and your company as a legal entity, we process the aforementioned personal data as your contact person on the legal basis of Art. 6 (1) (f) GDPR. Our legitimate interest is to contact you as the contact person and to be able to perform the contract with the legal entity.
We treat your personal data confidentially, of course, and do not transfer it to third parties. adventics stores the personal data you provide for the duration of the business relationship with you and until the expiry of the applicable limitation periods, as well as any resulting claims and statutory retention obligations.
For the processing of your personal data, we use the following strictly instruction-bound external service providers. We have concluded a data processing agreement with them:
- Zoho Corporation B.V., Beneluxlaan 4B, 3527 HT Utrecht, Netherlands (CRM system)
- Zendesk GmbH, Neue Schönhauser Str. 3-5, 10178 Berlin, Germany (support system)
- Anthropic PBC, 548 Market Street, San Francisco, CA 94104, USA (AI-supported analyses)
- AC PM LLC (Postmark), 1 North Dearborn Street, Chicago, IL 60602, USA (sending of system e-mails)
F. Processing of personal data via the platform (portal, app, shop)
X. Usage data
When you use our platform, so-called usage data is temporarily stored as a log on our web server for statistical purposes in order to improve the quality of our website. This data set consists of:
- the IP address of the requesting computer, shortened in such a way that a personal reference can no longer be established,
- the date and time of the request,
- the time zone difference to Greenwich Mean Time (GMT),
- the content of the request (specific page),
- the access status/ HTTP status code (file transferred, file not found),
- the amount of data transferred in each case,
- the website from which the request originates (referrer),
- the specific pages of our website that you access,
- the browser, in terms of type, version and language setting,
- the operating system in terms of type and version,
- the activated Java scripts for: screen resolution, colour depth, size of the browser window, installed browser plugins.
The log data mentioned is stored in anonymised form only. The legal basis for processing usage data is Art. 6 (1) (f) GDPR. The processing is carried out in our legitimate interest in providing the content of our website and ensuring a device- and browser-optimised presentation. The log data is deleted at regular intervals, at the latest by the end of the following calendar month.
XI. SSL / TLS encryption
For security reasons and to protect the transmission of confidential content, such as orders or enquiries that you send to us as the site operator, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the browser address line changes from „http://” to „https://” and by the lock symbol in your browser line. When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties. When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
XII. Processing of visitor data
The personal data of visitors processed within the scope of Scan2Lead is stored, via the web application and the app, in a data centre of Microsoft Azure in the EU (service provider Microsoft Corporation) as well as in the Firestore database service of Google Ireland Limited in the multi-region ‚eur3′, whose data centres are located exclusively in the EU. We have carefully selected these external service providers and concluded data processing agreements pursuant to Art. 28 GDPR. In processing the visitor data, adventics acts as a processor of the respective exhibitor, who as controller holds the right to issue instructions. Vis-à-vis the aforementioned service providers, adventics ensures via the data processing agreements that processing is carried out exclusively in accordance with documented instructions and under continuous control.
XIII. Processing of exhibitor data
The personal data of exhibitors provided and processed within the scope of Scan2Lead is stored, via the web application and the app, in the CRM system Zoho used by adventics, on the legal basis of Art. 6 (1) (f) GDPR. Our legitimate interest is to contact you as the exhibitor’s contact person and to be able to perform the contract with the legal entity.
For the processing of your personal data, we use the strictly instruction-bound external service provider Zoho Corporation B.V., Beneluxlaan 4B, 3527 HT Utrecht, Netherlands. We have concluded a data processing agreement with this provider.
XIV. Registration
In order to be able to use the Scan2Lead applications, you need access and must register accordingly. For registration we require the following information from you:
- e-mail,
- form of address,
- first name,
- surname,
- individual password and its confirmation.
The data is collected on the basis of Art. 6 (1) (b) GDPR and thus on the basis of our contractual obligation arising from the service contract between you as the user and adventics as the service provider. The information is stored in our database and serves, among other things, for your login. The personal data you provide here is stored for the period for which you need it to use the web application. Deletion takes place as soon as your personal data is no longer required for the described processing purposes and no legitimate interests or other (statutory) grounds for retention prevent deletion.
XV. Login via third-party providers (single sign-on)
You can register and log in to our platform by using an existing account with one of the providers listed below („single sign-on”). The use of these login procedures is voluntary; alternatively, registration with an e-mail address and password is available to you.
If you choose an SSO procedure, you will first be redirected to the respective provider, who verifies your identity on the basis of the access data stored there. The provider then transmits the data required to create the account to us – as a rule your name, your e-mail address and a unique user identifier. The login itself takes place at the provider under its own responsibility and data protection provisions.
The following providers are available:
Sign in with Apple – Apple Distribution International Limited, Hollyhill Industrial Estate, Hollyhill, Cork, Ireland (for the EEA); Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA. Name, e-mail address and a user identifier are transmitted. If you select the „Hide e-mail address” option, we receive an anonymised forwarding address from Apple instead of your real address. Privacy: https://www.apple.com/legal/privacy/
Sign in with Microsoft – Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland; Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA. Name, e-mail address, a user identifier and, where applicable, further profile data are transmitted. Privacy: https://privacy.microsoft.com/privacystatement
LinkedIn – LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland; LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA. Name, e-mail address, profile picture, where applicable brief professional details and a user identifier are transmitted. Privacy: https://www.linkedin.com/legal/privacy-policy
Sign in with Google – Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Name, e-mail address, profile picture and a Google account identifier are transmitted. Privacy: https://policies.google.com/privacy
Which data the respective provider transmits to us depends on your data protection settings there. We have no influence on the processing by the provider itself.
The purpose of the processing is the creation and administration of your user account as well as your authentication each time you log in.
The legal basis is Art. 6 (1) (b) GDPR, as the processing serves to provide the login procedure actively chosen by you and thus to fulfil the user agreement.
Data transfer to third countries: The providers named belong to corporate groups headquartered in the USA and may process data there. Insofar as a provider is certified under the EU-US Data Privacy Framework, the transfer is based on the adequacy decision of the EU Commission (Art. 45 GDPR); otherwise standard contractual clauses pursuant to Art. 46 GDPR apply. The respective provider is independently responsible for the data transmitted in the course of the login; please refer to the privacy policies linked above for details.
XVI. Login and use
Every opening and login in Scan2Lead is logged by adventics with a user ID and a time stamp and stored for a period of 180 days. This data is collected on the basis of our legitimate interest pursuant to Art. 6 (1) (f) GDPR. The purpose of the data collection and our legitimate interest lies in ensuring the security of the service. This data is used, for example, to detect and, where applicable, prevent disproportionately frequent access such as is typical in the form of a DDoS attack.
You can object to the data processing in accordance with the provisions of Art. 21 GDPR at datenschutz@adventics.de. You will then no longer be able to use the web application. The personal data named here is not passed on to third parties.
XVII. Sending of system e-mails
Within the scope of the platform, we send system e-mails, in particular portal notifications, licence e-mails and so-called pickup e-mails with which captured leads or documents are provided. In this context, the recipient’s e-mail address, the dispatch metadata and the respective message content are processed. The legal basis is Art. 6 (1) (b) GDPR, insofar as the dispatch serves to fulfil our contractual service.
For dispatch we use the service provider Postmark (AC PM LLC, part of the ActiveCampaign group, Chicago, USA) as a processor pursuant to Art. 28 GDPR. The dispatch data is processed on servers in the USA. The transfer is based on the standard contractual clauses of the EU Commission pursuant to Art. 46 GDPR; a transfer impact assessment has been carried out.
XVIII. Push notifications
Our app can send you push notifications. We distinguish between functional or service-related notifications and promotional notifications. Different legal bases and objection options apply to each.
1. Functional and service-related push notifications
We use push notifications to provide you with operational and service-related information about the Scan2Lead app. This includes in particular notices about the expiry of licences or reminders to return a rented device, as well as other security-relevant and technical messages.
For this purpose we process the push token of your device required for delivery, a device- or app-related identifier and information about the operating system used. The legal basis is Art. 6 (1) (b) GDPR, insofar as the notification serves to provide the app functions you use, otherwise our legitimate interest in a functional, secure and reliable operation of the application pursuant to Art. 6 (1) (f) GDPR. Insofar as information on your device is accessed for delivery, this is done because such access is strictly necessary for the function you have expressly requested (Section 25 (2) no. 2 TDDDG). You can deactivate the receipt of push notifications at any time via the system settings of your device and in the notification settings of the app. Please note that certain functional notices will then no longer be displayed to you.
2. Promotional push notifications
In addition, we inform you via push notifications about our own similar products and services, for example about the Scan2Lead bonus time, the annual subscription Scan2Lead 365 and comparable offers. We send these notifications to you as an existing customer. We received your contact data in connection with the booking or use of Scan2Lead and use it to inform you about our own similar services. For this we process your push token, a device- or app-related identifier and, where applicable, information on whether and how you reacted to a notification, in order to display relevant notices to you.
The legal basis is our legitimate interest in direct advertising for our own similar products pursuant to Art. 6 (1) (f) GDPR in conjunction with Section 7 (3) UWG. You can object to the use of your data for promotional push notifications at any time, without incurring any costs other than the transmission costs according to the basic tariffs. We draw your attention to this right of objection as early as at the point of collection of your data. You can declare the objection via the notification settings of the app or via the system settings of your device.
3. Recipients and transfer to third countries
For the technical delivery of the notifications we use the push services of the operating system providers, the Apple Push Notification service (APNs) of Apple Inc. or Firebase Cloud Messaging (FCM) of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, as processors pursuant to Art. 28 GDPR. In this context, a transfer of data, in particular of the push token, to a third country, namely the USA, may take place. Insofar as a provider is certified under the EU-US Data Privacy Framework, the transfer is based on the adequacy decision of the EU Commission (Art. 45 GDPR); otherwise standard contractual clauses pursuant to Art. 46 GDPR apply.
4. Storage period and purpose limitation
We store the push token for as long as the app is installed on your device and, in the case of promotional notifications, as long as you have not objected to receiving them. If you object, deactivate the notifications or uninstall the app, the token is deleted or blocked for the respective purpose. The data collected for delivery is not used for purposes other than those stated here without a separate legal basis. You can manage functional and promotional notifications separately from one another in the notification settings of the app.
XIX. Lead capture
Scan2Lead requires various permissions for certain functions, such as taking images of business cards or visitor badges. This generally gives rise to the data processing operations of lead capture.
With the help of Scan2Lead, visitors are scanned by the exhibitor via their business cards or their visitor badge. In this context, in particular the e-mail address, telephone number (business), address (business), language, gender and nationality are captured and processed by the exhibitor. The legal basis for this data processing is Art. 6 (1) (b) GDPR.
Insofar as you as a visitor are a contact person of a legal entity that is carrying out pre-contractual measures with the exhibitor, the data processing is based on the legal basis of Art. 6 (1) (f) GDPR. The exhibitor’s legitimate interest is to communicate with the exhibitor’s contact person in order to be able to conclude a contract with the legal entity.
The storage period of the personal data is 60 days from the end of the respective event. The personal data named here is not passed on to third parties.
If the exhibitor commissions adventics to retain the visitor and lead data beyond this period, for example within the scope of the annual subscription Scan2Lead 365, the data remains stored for the duration of this commission and is used for inviting visitors, comparative statistics and continuous product improvement. The exhibitor can end the commission at any time and request deletion of the data; termination is part of the cancellation of the respective contract.
XX. Upload and provision of data
Via Scan2Lead you can upload various types of data and attach them to your user profile. In principle, you can upload documents, questionnaires, photos or notes. We provide this function to you as a service within the scope of the use of Scan2Lead. The data processing is also based on the legal basis of Art. 6 (1) (b) GDPR, in order to fulfil our contractual obligation arising from the service contract between you as the user and adventics as the service provider.
XXI. Connection to customer systems or download of leads
You can download your leads from the „visitor data” area and/or transfer them to your own system. We would like to point out that forwarded or downloaded data is no longer subject to the access restriction within the web application.
For the transfer to your own systems, you can also use integration platforms such as Make (Make.com, Celonis group). In this case, the transfer is carried out at your instigation and via your own account with the integration platform; from the point of transfer, you are responsible for the further processing.
XXII. AI-supported functions
For internal analyses, for example for the evaluation of usage and support data for the purpose of quality assurance and product improvement, we use AI models of the provider Anthropic (Anthropic PBC, 548 Market Street, San Francisco, CA 94104, USA), which we integrate via a programming interface. In this context, the content belonging to the respective analysis is transmitted to Anthropic for processing; as far as possible, this is done without direct identification features. Anthropic acts as our processor pursuant to Art. 28 GDPR; the transmitted content is not used to train the AI models. Standard contractual clauses pursuant to Art. 46 GDPR have been agreed. The legal basis for the processing is our legitimate interest in the analysis and improvement of our services pursuant to Art. 6 (1) (f) GDPR.
XXIII. Support services
1. Support by telephone
You have the option of contacting us by telephone with questions or for assistance. For this we process your telephone number.
The legal basis for processing this personal data is Art. 6 (1) (f) GDPR, as we have a legitimate interest in answering your enquiry as simply, promptly and appropriately as possible. Without the provision of your telephone number, we are unfortunately unable to process your enquiry. You have the right to object to the processing pursuant to Art. 21 GDPR. However, your enquiry can then no longer be answered.
Support enquiries that you submit to us regarding the Scan2Lead services we offer are processed on the basis of Art. 6 (1) (b) GDPR.
In addition, you can decide for yourself whether you wish to provide us with further information. This information is provided voluntarily and is not mandatory for making contact. We process your voluntary information on the basis of your consent pursuant to Art. 6 (1) (a) GDPR. You can withdraw your consent to the data processing at any time at datenschutz@adventics.de.
Your personal data will be deleted 12 months after your enquiry has been answered. Statutory retention periods remain unaffected. We do not transfer your personal data to third parties.
2. Support via live chat
You can also contact us via our live chat, which you will find in the bottom right-hand corner of the landing page and all subpages of our website. Use of the live chat is voluntary. To answer your enquiries, the date and time, your name and your e-mail address are collected and stored for the course of the chat. The processing is carried out on the basis of our legitimate interest pursuant to Art. 6 (1) (f) GDPR. The legitimate interest lies in answering your enquiry via our live chat as simply, promptly and appropriately as possible. You have the right to object to the processing at any time at datenschutz@adventics.de. Afterwards, we can no longer process your enquiry via our live chat.
In addition, you can decide for yourself whether you wish to provide us with further information. This information is provided voluntarily and is not mandatory for making contact via our live chat. We process your voluntary information on the basis of your consent. You can withdraw your consent to the data processing at any time at datenschutz@adventics.de.
For the use and operation of the chat function, technically necessary cookies are used. The processing is carried out on the basis of Art. 6 (1) (f) GDPR. Our interest is to enable recognition of your internet browser in order to distinguish individual users of the chat function of our website. The information generated by the cookies about your use of our website is transmitted to a server of the chat service provider and stored there. Chat histories are stored for a period of 12 months. After that, all data is deleted.
We use the service provider Zendesk (Zendesk GmbH, Neue Schönhauser Str. 3-5, 10178 Berlin) for the provision of our live chat. For the initial answering of enquiries, an AI-supported chat assistant from Zendesk is used, which automatically evaluates your chat inputs in order to suggest suitable answers and help articles. You can request forwarding to an employee at any time. We have carefully selected this external service provider and concluded a data processing agreement pursuant to Art. 28 GDPR.
XXIV. Cookies
On our portal and shop pages we use exclusively technically necessary session cookies. Cookies are small text files that can be stored and read on your device. A distinction is made between session cookies, which are deleted as soon as you close your browser, and permanent cookies, which are stored beyond the individual session. Cookies can contain data that make it possible to recognise the device used. In some cases, however, cookies only contain information on certain settings that cannot be related to a person.
Our websites are operated on the basis of the web framework ASP.NET Core. To ensure the basic functionality and security of the application, the following session cookies are set:
- .AspNetCore.Session: stores an anonymous session identifier via which your entries and settings during a visit are assigned to the respective session. The cookie is deleted when the browser is closed.
- .AspNetCore.Antiforgery.: serves to protect against cross-site request forgery attacks (CSRF) and thus the security of data transmitted via forms. The cookie is deleted when the browser is closed.
- .AspNet.Consent: stores your decision on the use of technically non-necessary cookies (consent or refusal). These cookies are technically necessary to ensure the operation and security of our websites; without them, the desired functions could not be provided. They contain no personal profiles and are not used for analysis or marketing purposes.
1. Tracking cookies
On our website we also use tracking cookies in order to detect and rectify technical errors and to improve the stability, functionality and user-friendliness of our website. Use for advertising purposes, for the display of personalised advertising or for other marketing purposes is not carried out by us. The processing is carried out on the basis of your consent pursuant to Art. 6 (1) (a) GDPR, Section 25 (1) TDDDG, provided that you have previously given your consent to tracking via our cookie banner. You can withdraw any consent you have given at any time with effect for the future, without this affecting the lawfulness of the processing carried out up to the withdrawal.
We use the following tracking cookie on our website:
a) Microsoft Clarity
For technical troubleshooting and for the needs-based improvement of our website, we use the web analytics tool „Microsoft Clarity”. Microsoft Clarity enables a usage analysis on the basis of a pseudonymous user ID and thus on the basis of pseudonymous data. In this context, we process in particular usage data (e.g. pages visited, access times), movement data (e.g. mouse and scroll movements), location data (information on the approximate geographical position of a device) and meta/communication data (e.g. device information, IP address) in pseudonymised form. We have made the corresponding settings so that data collection at and by Microsoft alone already takes place in a pseudonymised manner, in particular in the form of IP masking (pseudonymisation of the IP address).
We use Microsoft Clarity exclusively for technical purposes, namely for the detection and analysis of errors and display problems, to ensure technical stability and to improve the usability of our website. The creation of user profiles for marketing purposes, interest- or behaviour-based profiling, remarketing, conversion measurement or cross-device tracking does not take place.
As part of the Microsoft Clarity service, Microsoft Corporation supports us as a processor pursuant to Art. 28 GDPR. The data processing may also take place through Microsoft outside the EU or the EEA (in particular in the USA). With regard to Microsoft, an adequate level of data protection is ensured on the basis of the adequacy decision (EU-U.S. Data Privacy Framework). In addition, Microsoft undertakes to conclude standard contractual clauses with further sub-processors.
Affected by this data processing are all users of our website who have consented to the corresponding use via our cookie consent service. The data processing is therefore carried out solely on the basis of your consent pursuant to Art. 6 (1) (a) GDPR.
XXV. Map display (OpenStreetMap)
To display the location plan of our ServiceDesk in the portal, we embed map material from OpenStreetMap, a service of the OpenStreetMap Foundation, St John’s Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom. When loading the map sections, your IP address is transmitted to the servers of the OpenStreetMap Foundation for technical reasons; no further personal data is transmitted. The processing is carried out on the basis of our legitimate interest in a functional display of directions pursuant to Art. 6 (1) (f) GDPR. For the United Kingdom, an adequacy decision of the EU Commission exists.
XXVI. Monitoring (Sentry)
On our website we use the services of Sentry, an analytics service of Functional Software, Inc., 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA.
Sentry supports us with error monitoring of the application and helps to detect, analyse and rectify errors. We use the Sentry analytics service in order to design our services in line with requirements and to ensure error-free operation.
Die Speicherung und Verarbeitung von Daten erfolgt auf Grundlage von § 25 Abs.2 Nr. 2 TDDDG i.V.m Art. 6 Abs. 1 S. 1 lit. f) DSGVO auf eigenen Servern. Außerhalb dieser Verarbeitung erfolgt keine Übermittlung der Daten an Dritte.
Further information on the terms of use and data protection can be found at: https://sentry.io/terms/ and https://sentry.io/privacy/.
You can object to the processing at any time. To do so, please send an e-mail to: datenschutz@adventics.de.
You can also delete cookies at any time via the corresponding device settings and prevent the setting of new cookies. In this case, our website may not be displayed optimally and some functions may no longer be technically available.
G. Promotional contact of visitors by e-mail after a trade fair visit
If, as a trade fair visitor at a mass event of the exhibitor, you are interested in the exhibitor’s products/services, you have the option of being contacted by the exhibitor for promotional purposes by e-mail. The processing of your surname, first name and your e-mail address is carried out on the legal basis of your consent pursuant to Art. 6 (1) (a) GDPR.
The subscription to the e-mails is voluntary for you. The provision of your data for this purpose is neither required by law nor by contract, nor is it necessary for the conclusion of a contract. In the event of non-provision, your data is not passed on and you will not receive any e-mails.
The data is not passed on to third parties.
After granting your consent, you can withdraw it at any time with effect for the future. To do so, please send an e-mail to the exhibitor’s known address. By withdrawing, you unsubscribe from the newsletter and your contact data collected for this purpose is deleted immediately.
With regard to the promotional contact by adventics on behalf of the exhibitor, adventics acts as a processor. A data processing agreement pursuant to Art. 28 GDPR has been concluded with the exhibitors.
H. Social media channels
When you visit our social media pages, the data concerning you is processed. In the following, we would therefore like to inform you in accordance with Art. 13 of the General Data Protection Regulation (GDPR) about how we handle your data and about the rights arising from this.
adventics GmbH operates the following social media pages:
- LinkedIn: https://www.linkedin.com/company/17996961/
- X: https://x.com/scan2lead
- YouTube Scan2Lead: https://www.youtube.com/user/Scan2Lead
- YouTube Adventics: https://www.youtube.com/@adventics/videos
- Instagram: https://www.instagram.com/scan2lead/
- Facebook: https://www.facebook.com/people/Scan2Lead-Smart-LeadTracking-for-exhibitors/100064187736762/
- Xing: https://www.xing.com/pages/adventicsgmbh
XXVII. Data processing by adventics
1. Public relations
The data you provide on our social media pages, such as user names, comments, videos, images, likes, public messages, etc., is published by the social media platform and is never processed by us for other purposes. We merely reserve the right to delete content should this be necessary. Where applicable, we share your content on our page, if this is a function of the social media platform, and communicate with you via the social media platform.
If you submit an enquiry to us on the social media platform, we may, depending on the content, also refer you to other, secure communication channels that guarantee confidentiality. For example, you always have the option of sending us your enquiries to the address or e-mail address named. The choice of the appropriate communication channel is your own responsibility. The legal basis for the aforementioned processing of your data is Art. 6 (1) (f) GDPR. The data processing is carried out in our legitimate interest in conducting public relations for our company and being able to communicate with you.
2. Data processing in joint controllership
For some of the processing activities, we are jointly responsible together with the respective operator of the social media platform. We have accordingly concluded the required agreement pursuant to Art. 26 GDPR, provided that the operator of the social media platform enables this.
LinkedIn
https://www.linkedin.com/static?key=privacy_policy
https://legal.linkedin.com/pages-joint-controller-addendum
The essential elements of the joint controllership can be found in the following section.
3. Statistics (insights)
The social media platforms used regularly create statistics (insights) on the basis of usage data that contain information about your interaction with our social media page. We cannot influence or prevent the production and provision of these statistics.
We process the aforementioned information (statistics) pursuant to Art. 6 (1) (f) GDPR in our legitimate interest in validating the handling of our social media pages and improving our content in a target-group-oriented manner.
4. Target-group-oriented advertising
We also use the described social media platforms to display targeted advertising.
For this we use target-group definitions provided to us by the social media operator. In doing so, we use only anonymous target-group definitions – i.e. we define characteristics for example on the basis of general demographic information, behaviour, interests and connections. The operator of the social media platform uses these to display advertisements to its users accordingly. The legal basis for this is the consent that the operator of the social media platform has obtained from its users.
If you wish to withdraw this consent, please use the withdrawal options provided by the operator of the social media platform, as the social media platform operator is responsible for this processing.
We or the operator of the social media platform also use publicly available data for the target-group definition. The legal basis for this processing is then Art. 6 (1) (f) GDPR. Our legitimate interest here is to make the most suitable target-group definition possible. We never use sensitive categories of personal data named in Art. 9 and 10 GDPR (e.g. political opinions, sexual orientation) for the target-group definition.
We also use information about the visiting of or interaction with other websites (so-called remarketing) for the target-group definition. For this we also use, among other things, cookies. In these cases, however, we obtain the consent of the users in advance on the respective other pages via a consent banner and provide information about the data processing at that point. You can withdraw this consent at any time by calling up the consent banner of the respective website again.
XXVIII. Data processing by the operator of the social media platform
The operator of the social media platform uses web tracking methods. The web tracking may also take place regardless of whether you are logged in or registered with the social media platform.
We would therefore like to point out that it cannot be ruled out that the operator of the social media platform uses and evaluates your profile and behavioural data for its own purposes. We have no influence on the processing of your data by the operator of the social media platform. Please bear this in mind when using the social media platform.
Further information on data processing by the operator of the social media platform, configuration options for protecting your privacy and further objection options can be found in the operator’s privacy policy.
XXIX. Storage period
We delete your personal data when it is no longer required for the aforementioned processing purposes and no statutory retention obligations prevent deletion.
I. Your rights in the processing of your data
In the processing of your personal data, the GDPR grants you the following rights:
XXX. Right of access (Art. 15 GDPR)
You have the right to request confirmation as to whether personal data concerning you is being processed; if this is the case, you have a right to information about this personal data and to the information listed in detail in Art. 15 GDPR.
XXXI. Right to rectification and erasure (Art. 16 and 17 GDPR)
You have the right to demand the immediate rectification of incorrect personal data concerning you and, where applicable, the completion of incomplete personal data. You also have the right to demand that personal data concerning you be erased without delay, provided that one of the grounds listed in detail in Art. 17 GDPR applies, e.g. if the data is no longer required for the purposes pursued.
XXXII. Right to restriction of processing (Art. 18 GDPR)
You have the right to demand the restriction of processing if one of the conditions listed in Art. 18 GDPR is met, e.g. if you have lodged an objection pursuant to Art. 21 GDPR against the processing or for the duration of any examination as to whether our legitimate interests outweigh your interests as a data subject.
XXXIII. Right to data portability (Art. 20 GDPR)
In certain cases listed in detail in Art. 20 GDPR, you have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format or to demand the transmission of this data to a third party.
XXXIV. Right to object (Art. 21 GDPR)
Where data is collected on the basis of Art. 6 (1) (f) GDPR (data processing to safeguard legitimate interests), you have the right to object at any time to the processing on grounds relating to your particular situation. We will then no longer process the personal data, unless there are demonstrably compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.
XXXV. Right of withdrawal (Art. 7 (3) GDPR)
Insofar as the data processing is based on your consent, you can withdraw this consent at any time, without this affecting the lawfulness of the data processing up to the point of withdrawal.
XXXVI. Right to lodge a complaint with the supervisory authority
Pursuant to Art. 77 GDPR, you also have the right to lodge a complaint with the supervisory authority if you are of the opinion that the processing of the data concerning you violates data protection provisions. The right to complain can be asserted in particular with the supervisory authority in the member state of your place of residence, your place of work or the place of the alleged infringement.
J. Data protection FAQs
Scan2Lead is used to capture the visitor’s business card or visitor pass. Accordingly, the following personal visitor data, in particular, is processed:
- Title,
- First and last name of the contact person,
- Company,
- Department,
- Salutation,
- Email,
- Phone number and cell phone number,
- Address,
- Language
- Responses from the visitor survey
- Time of the scan
- Exhibiting company that recorded the contact
Details can be found on the registration page for the respective event.
Your personal data as a customer (exhibitor), as well as the scanned visitor leads, are stored in a Microsoft Azure cloud in a European data center and in the Firestore database service provided by Google Ireland Limited in the “eur3” multi-region, whose data centers are located exclusively in the EU (Belgium and the Netherlands, with backup in Finland). Data processing agreements pursuant to Article 28 of the GDPR have been concluded with both service providers.
Only you, as the exhibitor (data controller), and adventics (as the data processor) have access to personal data in Scan2Lead.
The protection of your personal data is subject to the highest security standards. Our data center is certified to ISO/IEC 27001. It also meets BSI Availability Class VK 2.
Personal data in Scan2Lead is never disclosed to third parties.
Personal data is transferred to third parties only if the data subject has given consent. At partner trade shows, visitors consent – upon registering with the organizer – to having their data transferred to the exhibitors whose badges they have scanned. Exhibitors do not transfer lead data to the organizer; at most, the organizer receives aggregated, non-personal statistics.
Leads generated via Scan2Lead are stored for a period of 60 days after the end of the trade show to allow exhibitors to download the leads within this timeframe.
If the exhibitor instructs adventics to retain visitor and lead data beyond this period—for example, as part of the Scan2Lead 365 annual subscription – the data will remain stored for the duration of this instruction. This retention is intended for cross-event use, particularly for comparative statistics and the reuse of questionnaires. The exhibitor may terminate the agreement at any time and request deletion; such termination is part of the termination of the respective contract.
We have made the technical and organizational measures (TOMs) we implement as part of Scan2Lead available to you via the following LINK.
A list of the subprocessors we use as part of Scan2Lead can be found in Appendix 2 of our Data Processing Agreement: Download
Scan2Lead, of course, complies with the requirements of the General Data Protection Regulation.
Yes, a data processing agreement pursuant to Article 28 of the GDPR must be entered into between the following parties for the use of Scan2Lead:
Exhibitors and adventics GmbH
Trade Show Organizers and adventics GmbH
Please download our Data Processing Agreement pursuant to Article 28 of the GDPR at the following link: Download
datenschutz süd GmbH
Wörthstraße 15
97082 Würzburg
Phone: +49-9313049760
Email: datenschutz@adventics.de