Skip to content

Data protection

1. Controller and data protection officer

 

The controller responsible for processing personal data on our websites and in connection with our events is:

MUNICH FABRIC START Exhibitions GmbH
Thomas-Wimmer-Ring 17, 80539 Munich, Germany
Phone: +49 (0)89 4522470
Email: visitor@munichfabricstart.com
Authorised managing directors: see Legal notice

This privacy policy applies to the following websites: www.munichfabricstart.com and its subdomains (e.g. guest.munichfabricstart.com), as well as to our trade shows and other events (together “MFS services”).

You can reach our data protection officer at:

 

Mayolove GmbH
Freibadstraße 15
81543 München
E-Mail: carla.hartung@mayolove.com 

 

2. General information on data processing

 

Legal bases. We only process personal data where there is a legal basis for doing so. The following in particular apply:

  • consent (Art. 6(1)(a) GDPR), which can be withdrawn at any time with effect for the future
  • contract or pre-contractual measures, e.g. buying a ticket or registering (Art. 6(1)(b) GDPR)
  • legal obligation, e.g. retention for tax purposes (Art. 6(1)(c) GDPR)
  • legitimate interest (Art. 6(1)(f) GDPR); we state the specific interest for each processing activity
  • storing and accessing information on your device: consent under Section 25(1) TDDDG (German Telecommunications Digital Services Data Protection Act), unless strictly necessary (Section 25(2) no. 2 TDDDG)

 

Storage period. We delete data as soon as the purpose no longer applies or you withdraw your consent. Exception: statutory retention periods, for example under commercial and tax law (up to 10 years), require longer storage. In that case we restrict processing until the period expires.

 

Recipients. We use service providers who process data on our behalf and with whom we have concluded contracts under Art. 28 GDPR. These cover hosting, email and newsletter delivery, consent management, ticketing and registration, payment processing, and the maintenance and development of the websites. Other recipients (e.g. exhibitors) are named in the relevant sections.

 

Transfers to third countries. Data is only processed outside the EU/EEA if there is an adequacy decision or appropriate safeguards are in place. For the USA, the adequacy decision on the EU-US Data Privacy Framework applies (Art. 45 GDPR), provided the recipient is certified. Otherwise we use the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).

 

Obligation to provide data, no automated decision-making. You are not legally obliged to provide us with data. Without the information marked as mandatory, however, we cannot, for example, issue a ticket. There is no automated decision-making or profiling within the meaning of Art. 22 GDPR.

 

3. Providing the websites

 

Hosting. Our websites are hosted by HostPress GmbH, Bahnhofstraße 34, 66571 Eppelborn, Germany (server location: Germany). The provider processes the data generated when the websites are accessed on our behalf (Art. 28 GDPR).

 

Server log files. Each time you access our websites, your browser automatically transmits the following data:

  • IP address
  • date and time of the request
  • page or file accessed and amount of data transferred
  • referrer URL (previously visited page)
  • browser type and version, operating system

We need this data to deliver the websites, ensure their stability and security, and fend off attacks. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR). The log files are deleted after 7 days. They are only kept longer if a security incident needs to be investigated. The data is not combined with other data sources.

 

TLS encryption. We use TLS encryption to protect data in transit. You can recognise an encrypted connection by “https://” and the padlock symbol in the address bar.

 

4. Cookies and consent management

 

We use cookies and similar technologies (e.g. local storage, pixels). We use technically necessary cookies without consent because the websites would not work otherwise, e.g. for login, the shopping cart or storing your cookie choice (Section 25(2) no. 2 TDDDG, Art. 6(1)(f) GDPR). We only use all other cookies and services (statistics, marketing, external media) with your consent (Section 25(1) TDDDG, Art. 6(1)(a) GDPR).

We manage your consent with the consent tool CookieYes (CookieYes Limited, 3 Warren Yard, Warren Park, Wolverton Mill, Milton Keynes MK12 5NW, United Kingdom). There is an adequacy decision of the European Commission for the United Kingdom (Art. 45 GDPR). We store your choice, the date and time, and a pseudonymous ID so that we can prove your consent (Art. 6(1)(c) in conjunction with Art. 7(1) GDPR). Your choice is stored for 12 months.

You can change or withdraw your consent at any time via “Cookie settings” in the footer. You will also find an overview of all cookies used there, with provider, purpose and storage period.

 

5. Contact, registration and ticketing

 

Contact. If you contact us via a contact form, email or phone, we process your details to handle your enquiry and any follow-up questions. The legal basis is Art. 6(1)(b) GDPR if the enquiry relates to a contract, otherwise our legitimate interest in responding (Art. 6(1)(f) GDPR). We delete the data once the enquiry has been fully dealt with and no retention period applies.

 

Registration and tickets. For visiting the trade show, a user profile or buying a ticket, we process:

  • name, title, language
  • company, position, industry, country and address
  • email address and, where applicable, phone number
  • information on interests and product groups
  • ticket and invoice data

The legal basis is the performance of a contract (Art. 6(1)(b) GDPR). We retain invoice data due to legal obligations (Art. 6(1)(c) GDPR). Registration is restricted to persons of legal age.

Registration and ticketing are handled by VIMA as our processor. Payments in the shop are processed by PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg; alternatively, you can pay by invoice. We do not receive complete payment data, and it is never passed on to exhibitors.

We store your user profile until you delete it.

 

6. Visiting the trade show: admission, lead scanning and exhibitors

 

Admission control. At the entrance, we or our service providers scan your ticket or name badge. This allows us to check your admission rights and record visitor numbers. The legal bases are the performance of a contract (Art. 6(1)(b) GDPR) and our legitimate interest in security and access control (Art. 6(1)(f) GDPR).

 

Lead scanning by exhibitors. Exhibitors can scan your name badge at their stand, but only if you show it to them voluntarily. With the scan, they receive your name, company, position, email address, country and interests from your registration, like a digital business card. The legal basis is the consent you give by allowing the scan (Art. 6(1)(a) GDPR). Bank and payment data are never transmitted. Once the data has been transmitted, the exhibitor is responsible for it and may contact you in connection with the trade show. Please address any objections to the exhibitor.

 

Disclosure to partners. We only pass your data on to affiliated companies or other trade show organisers if you have expressly consented to this when registering. Beyond that, we only disclose data if we are legally obliged to do so.

 

Photos and videos. At our events, we take photos and videos for coverage on our websites and social media channels. The legal basis is our legitimate interest in documenting the event (Art. 6(1)(f) GDPR). Notices at the entrance point this out. If you do not wish to be photographed or filmed, please speak to our photography team.

 

7. Newsletter

 

With your consent (Art. 6(1)(a) GDPR), we regularly send you information about our events, exhibitors and partners. We use the double opt-in procedure: the newsletter only starts once you have clicked the link in our confirmation email. As proof, we store the time and IP address of your sign-up and confirmation (Art. 6(1)(c) GDPR).

The newsletter is sent via Brevo (Sendinblue SAS, 106 boulevard Haussmann, 75008 Paris, France) as our processor. We also use Brevo to send emails relating to forms and orders.

You can unsubscribe from the newsletter at any time: via the unsubscribe link in every email, in your user profile, or by sending a message to visitor@munichfabricstart.com. We will then remove your address from the mailing list. To prevent you from being contacted again, we may keep it on a blocklist (Art. 6(1)(f) GDPR). Data in your user profile is not affected.

 

8. Web analytics and marketing

We only use the following services if you have given your consent in the consent tool (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). You can withdraw your consent at any time via the cookie settings.

 

Google Analytics 4

The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics evaluates how visitors use our websites, e.g. pages viewed, time spent, device type and approximate location. We use this to create statistics that help us improve our services. Google Analytics 4 does not store IP addresses for users in the EU. Google Signals and the link to Google Ads are disabled.

Data may be transferred to Google LLC in the USA. Google LLC is certified under the EU-US Data Privacy Framework. The data is deleted after 14 months. More: Google’s privacy policy.

 

Meta Pixel

The provider is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. With the Meta Pixel, we measure how effective our ads on Facebook and Instagram are (conversion tracking). We can also show visitors to our websites relevant ads there (Custom Audiences). If you are logged in to Facebook or Instagram, Meta can link your visit to your account.

We are jointly responsible with Meta for collecting the data and transmitting it to Meta (Art. 26 GDPR), on the basis of the joint controller agreement. Meta is solely responsible for any further processing. Data may be transferred to Meta Platforms, Inc. in the USA, which is certified under the EU-US Data Privacy Framework. We have no influence on how long Meta stores the data. More: Meta’s privacy policy.

 

LinkedIn Insight Tag

The provider is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. With the LinkedIn Insight Tag, we measure how effective our ads on LinkedIn are (conversion tracking) and can show visitors to our websites relevant ads there (retargeting). We only receive aggregated reports, no information about individual people. If you are logged in to LinkedIn, LinkedIn can link your visit to your account. Data may be transferred to LinkedIn Corporation in the USA, which is certified under the EU-US Data Privacy Framework. LinkedIn deletes the data after 180 days at the latest. More: LinkedIn’s privacy policy.

 

9. Fonts

 

Our fonts are hosted locally on our server. No connection to Google or other font providers is made when a page loads.

 

10. Social media presence

 

On our websites, we link to our profiles on Instagram, Facebook, LinkedIn and YouTube. These are simple links without embedded plugins. Data is only transferred when you click a link and open the platform. The privacy policy of the respective platform then applies.

For our company pages on Facebook and Instagram, we are jointly responsible with Meta Platforms Ireland Limited to the extent that Meta provides us with statistics (Insights) (Art. 26 GDPR). The same applies to LinkedIn (LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland). You can exercise your rights with us or directly with the respective provider.

We show recent posts from our Instagram and LinkedIn profiles on our websites. We retrieve them on our server and store the images there; your browser does not connect to Instagram or LinkedIn in the process.

 

11. Your rights

 

You have the following rights with regard to your personal data:

  • access (Art. 15 GDPR)
  • rectification (Art. 16 GDPR)
  • erasure (Art. 17 GDPR)
  • restriction of processing (Art. 18 GDPR)
  • data portability (Art. 20 GDPR)
  • withdrawal of consent with effect for the future (Art. 7(3) GDPR)

 

Right to object (Art. 21 GDPR). If we process data on the basis of our legitimate interest (Art. 6(1)(f) GDPR), you can object at any time on grounds relating to your particular situation. You can object to processing for direct marketing purposes at any time without giving reasons.

To exercise your rights, an informal message to visitor@munichfabricstart.com or to our data protection officer (section 1) is sufficient.

 

12. Right to lodge a complaint, changes, last updated

 

Right to lodge a complaint. You can lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.

 

Changes. We update this privacy policy when our services or the legal situation change. The version published here applies.

Last updated: October 2026