top of page
Privacy Policy
Privacy Policy
Last updated: 8 August 2026
This Privacy Policy explains how the German-Indian Forum gemeinnützige UG (haftungsbeschränkt) collects, uses, discloses and protects personal data in connection with the German-Indian Business Forum website, events, registrations, invitations and related programmes.
1. Data Controller
The controller responsible for processing your personal data is:
German-Indian Forum gemeinnützige UG (haftungsbeschränkt)
Germeringer Str. 13
82152 Planegg
Germany
Managing Director: Siddharth Mudgal
Email: events@german-indian-forum.de
Website: www.german-indian-forum.de
Data-protection enquiries and requests may be sent to the email address above.
2. Scope of This Policy
This Privacy Policy applies when you:
-
Visit our website;
-
Contact us by email or through a website form;
-
Register or apply for an event;
-
Accept or request an invitation;
-
Purchase a ticket or participation package;
-
Apply for a startup, investor or matchmaking programme;
-
Subscribe to marketing communications;
-
Participate in an event;
-
Appear in official event photography or recordings; or
-
Otherwise interact with the German-Indian Business Forum.
3. Personal Data We Collect
Depending on your interaction with us, we may process the following categories of personal data:
Identification and Contact Information
-
Name and preferred form of address;
-
Professional email address;
-
Telephone number;
-
Country of residence or representation;
-
LinkedIn profile or professional website; and
-
Official identification details where required for security verification.
We generally do not retain copies of official identification unless this is necessary and legally permissible.
Professional Information
-
Job title and designation;
-
Organisation or institution;
-
Professional sector;
-
Government or diplomatic position;
-
Professional biography;
-
Areas of expertise and interest; and
-
Speaker, partner, investor or startup profile.
Registration and Participation Information
-
Event selections;
-
Invitation source or reference code;
-
Registration and attendance status;
-
Programme preferences;
-
Matchmaking interests;
-
Topic-table selections;
-
Meeting requests;
-
Access requirements; and
-
Communications relating to participation.
Startup and Investment Information
-
Company profile and website;
-
Funding stage;
-
Pitch deck;
-
Commercial traction;
-
Investment requirements;
-
Investor thesis;
-
Investment range;
-
Technology interests; and
-
Corporate pilot, procurement or partnership interests.
Information submitted in pitch decks may contain confidential business information. Applicants should provide only information appropriate for review by the organiser and relevant programme reviewers.
Payment and Billing Information
-
Billing name and address;
-
Organisation details;
-
Tax or VAT information;
-
Ticket and payment status; and
-
Transaction references.
Complete payment-card details are generally processed by the relevant payment provider and are not stored directly by us.
Dietary and Accessibility Information
Where voluntarily provided, dietary, allergy or accessibility information may reveal health-related data.
We process this information only to make appropriate event arrangements and, where required, on the basis of your explicit consent under Article 9(2)(a) GDPR.
Technical Information
When you use our website, certain information may be processed automatically, including:
-
IP address;
-
Browser and device type;
-
Operating system;
-
Date and time of access;
-
Referring page;
-
Pages visited;
-
Cookie identifiers; and
-
Technical log and security information.
Photographs and Recordings
Official photography, video and audio recording may take place during our events. This may include general event imagery, stage recordings, interviews and photographs of speakers or participants.
4. Sources of Personal Data
We generally collect personal data directly from you.
We may also receive professional or invitation-related information from:
-
Event partners;
-
Diplomatic missions;
-
Government institutions;
-
Speakers and hosts;
-
Your organisation or executive office;
-
Start2 Group, Plug and Play or other programme partners;
-
Individuals who nominate or invite you; and
-
Publicly available professional sources, such as company websites or LinkedIn.
Where information is obtained from another source, we will provide the information required under Article 14 GDPR where applicable.
5. Purposes and Legal Bases
Website Operation and Security
We process technical and log information to operate the website, ensure system security, prevent abuse and diagnose technical problems.
Legal basis: Article 6(1)(f) GDPR—our legitimate interest in providing a secure and functional website.
Enquiries and Communications
We process contact information and correspondence to respond to enquiries, partnership requests and other communications.
Legal basis: Article 6(1)(b) GDPR where the communication concerns a possible or existing agreement; otherwise Article 6(1)(f) GDPR.
Event Applications and Registrations
We process registration and professional information to:
-
Review applications;
-
Verify eligibility and invitations;
-
Manage registrations;
-
Issue confirmations and tickets;
-
Coordinate programme participation;
-
Communicate essential event information; and
-
Administer attendance.
Legal basis: Article 6(1)(b) GDPR and, where applicable, Article 6(1)(f) GDPR.
Invitation-Only Events and Security
For invitation-only, diplomatic or security-controlled events, we may process information to:
-
Verify invitations and identities;
-
Coordinate protocol requirements;
-
Prepare authorised guest lists;
-
Manage venue access; and
-
Protect participants, public officials and event personnel.
Legal basis: Article 6(1)(f) GDPR and, where applicable, Article 6(1)(c) GDPR.
Our legitimate interests include maintaining event security, protocol standards and the integrity of restricted-access programmes.
Payments and Accounting
We process billing and transaction information to collect participation fees, issue invoices, administer refunds and comply with accounting and tax requirements.
Legal basis: Articles 6(1)(b) and 6(1)(c) GDPR.
Matchmaking and Curated Introductions
We use professional profiles, interests and participation objectives to identify potentially relevant meetings, topic tables and introductions.
Legal basis: Article 6(1)(b) GDPR where matchmaking forms part of the requested programme and Article 6(1)(f) GDPR for relevant professional networking.
Direct contact information is not shared for independent marketing without an appropriate legal basis.
Guest Lists and Professional Profiles
Your name, designation, organisation and professional profile may appear in restricted guest materials, speaker pages or event communications where this is necessary for programme delivery or where you have consented.
Legal basis: Article 6(1)(b), Article 6(1)(f) or Article 6(1)(a) GDPR, depending on the context.
Public promotional use of a participant profile will be based on consent where required.
Marketing Communications
Where you opt in, we may send information about:
-
Current and future events;
-
Programme announcements;
-
Partnership opportunities;
-
Business and innovation initiatives; and
-
Related activities of the German-Indian Forum.
Legal basis: Article 6(1)(a) GDPR.
Consent is optional and may be withdrawn at any time through the unsubscribe link or by emailing events@german-indian-forum.de.
Withdrawing consent does not affect processing carried out before the withdrawal.
Photography and Event Documentation
We may use general event imagery to document and report on our programmes and communicate the work of the German-Indian Forum.
Legal basis: Article 6(1)(f) GDPR where our legitimate interests and the circumstances permit such processing.
Identifiable portraits, interviews, testimonials and dedicated promotional profiles will be based on consent where required.
Participants may contact the event team if they have concerns about appearing in event imagery.
Legal Claims and Compliance
We may process information where necessary to comply with legal obligations, respond to authorities or establish, exercise or defend legal claims.
Legal basis: Articles 6(1)(c) and 6(1)(f) GDPR.
6. Registration Through Luma
We use Luma to administer registrations, guest approvals, invitations, event communications and, where applicable, ticket payments.
When you register through Luma, Luma processes information under its own terms and privacy policy and provides relevant registration information to us as the event host.
Where tickets are purchased through Luma, relevant payment information may be processed by Luma’s payment provider, including Stripe.
Further information is available in Luma’s Privacy Policy.
7. Website Hosting Through Wix
Our website is built or hosted using services provided by Wix.
Wix may process technical information required to deliver the website, maintain security, store website content and provide associated functionality.
Depending on how the website is configured, Wix services may also support forms, databases, email communications, analytics or cookies.
Further information is available in Wix’s Privacy Policy.
8. Payment Providers
Payments may be processed by third-party payment providers such as Stripe, PayPal or a provider integrated with Luma or Wix.
The payment provider processes payment credentials under its own privacy information. We generally receive transaction status, payment reference, billing details and the amount paid, but not complete card credentials.
Before publication, retain only the payment providers actually used by GIBF.
9. Cookies and Similar Technologies
Our website may use cookies and similar technologies that are:
-
Strictly necessary for website operation and security;
-
Used to remember preferences;
-
Used to understand website performance; or
-
Used for analytics or marketing.
Strictly necessary technologies may be used without consent where legally permitted.
Non-essential analytics and marketing technologies will be activated only after the required consent has been obtained through the website’s cookie-consent mechanism.
10. Analytics and Advertising Technologies
Retain this section only for services that are currently active.
Subject to consent, we may use services such as:
-
Google Analytics;
-
Google Ads conversion measurement;
-
Meta Pixel;
-
LinkedIn Insight Tag; or
-
Wix Analytics.
These services may process information about your device, website activity, interactions and cookie identifiers.
The exact services, providers, purposes, storage periods and available withdrawal mechanisms must be identified in the website’s cookie settings.
Legal basis: Article 6(1)(a) GDPR and applicable telecommunications and cookie rules.
11. Social Media and External Links
Our website may link to social-media platforms and other third-party websites.
A standard external link does not normally transmit information to the destination provider until you click it. Embedded feeds, videos, maps or social-media plugins may process information earlier and should therefore be activated only in accordance with applicable consent requirements.
The respective provider is responsible for its independent processing after you access its service.
12. Recipients of Personal Data
Where necessary, personal data may be disclosed to:
-
Website, hosting and IT providers;
-
Registration and event-management platforms;
-
Payment and accounting providers;
-
Venues and security personnel;
-
Event-production and accreditation providers;
-
Programme and matchmaking partners;
-
Government or diplomatic protocol teams;
-
Professional advisers;
-
Authorities where legally required; and
-
Other participants where necessary for an agreed introduction.
Recipients receive only the information reasonably required for their function.
Programme partners may not use participant data for their independent marketing unless the participant has consented or another legal basis applies.
13. International Data Transfers
Some service providers may process data outside the European Economic Area.
Where personal data is transferred to a country without an applicable European Commission adequacy decision, we use legally recognised safeguards where required, such as the European Commission’s Standard Contractual Clauses, together with supplementary measures where appropriate.
Information about relevant safeguards may be requested by contacting us.
14. Retention
We retain personal data only for as long as necessary for the relevant purpose or applicable legal obligations.
The following criteria generally apply:
-
Enquiries are retained until the matter is resolved and for a reasonable follow-up period;
-
Registration and attendance information is retained for event administration and legitimate documentation requirements;
-
Billing and transaction records are retained for applicable commercial and tax-law periods;
-
Unsuccessful application information is deleted or anonymised after a reasonable period following the event;
-
Security and access lists are deleted when no longer required for security, incident management or legal claims;
-
Dietary and accessibility information is deleted after the event unless continued retention is legally necessary;
-
Marketing information is retained until consent is withdrawn or the information is no longer required; and
-
A limited suppression record may be retained to ensure that an opt-out continues to be respected.
Information required for legal claims may be retained until the relevant limitation period expires.
15. Automated Decision-Making
We do not make decisions producing legal or similarly significant effects based solely on automated processing.
Event applications and invitation decisions may be supported by registration criteria, but material decisions are subject to human review.
16. Your Rights
Subject to the conditions of applicable law, you may have the right to:
-
Obtain information about the processing of your personal data;
-
Access your personal data;
-
Correct inaccurate or incomplete information;
-
Request deletion;
-
Restrict processing;
-
Receive data in a portable format;
-
Object to processing based on legitimate interests;
-
Object at any time to direct marketing;
-
Withdraw consent at any time; and
-
Lodge a complaint with a supervisory authority.
To exercise your rights, contact events@german-indian-forum.de.
We may request information necessary to verify your identity before responding.
17. Right to Object
Where processing is based on Article 6(1)(f) GDPR, you may object on grounds relating to your particular situation.
You may object to the processing of personal data for direct-marketing purposes at any time. If you object to direct marketing, your data will no longer be used for that purpose.
18. Supervisory Authority
You have the right to lodge a complaint with a competent data-protection authority.
The supervisory authority responsible for private-sector organisations in Bavaria is:
Bayerisches Landesamt für Datenschutzaufsicht — BayLDA
Promenade 18
91522 Ansbach
Germany
Website: www.lda.bayern.de
19. Data Security
We use appropriate technical and organisational measures designed to protect personal data against unauthorised access, alteration, loss, destruction and unlawful disclosure.
No internet transmission or storage system can be guaranteed to be completely secure.
20. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in law, technology, service providers or our processing activities.
The current version will be published on this website with its effective date.
bottom of page
