Home › Privacy
Privacy
How MKMesse UG (haftungsbeschränkt) processes personal data on this website, under the GDPR, the German Federal Data Protection Act (BDSG) and the German Telecommunications Digital Services Data Protection Act (TDDDG).
We have not appointed a data protection officer, as the statutory thresholds of § 38 BDSG do not apply. Ferdinand Franz is the contact for all data protection matters.
We process personal data only where a legal basis permits it, where you have consented, or where processing is necessary to provide a functioning website and our services. Personal data means any information relating to an identified or identifiable natural person under Art. 4 (1) GDPR.
Where we rely on your consent, it is voluntary and can be withdrawn at any time with effect for the future.
This website is hosted by Netlify, Inc., 512 2nd Street, Suite 200, San Francisco, CA 94107, USA. Netlify processes the data described in section 4 on our behalf in order to deliver the website and its serverless functions.
Legal basis: Art. 6 (1) (f) GDPR, our legitimate interest in secure and reliable hosting. A data processing agreement under Art. 28 GDPR is in place with Netlify. Transfers to the United States are addressed in section 20.
When you access this website, the hosting infrastructure automatically records information transmitted by your browser:
This data is required to deliver the website, to ensure stability and security, and to detect and trace attacks. It is not merged with other data sources and is not used to identify individual visitors.
Legal basis: Art. 6 (1) (f) GDPR. Retention: log data is deleted or anonymised after 30 days at the latest, unless a specific security incident requires longer retention as evidence.
We use services of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, in particular Cloudflare Turnstile (section 9). Where Cloudflare services are used, connection data including your IP address is processed in order to distinguish human visitors from automated requests and to protect our infrastructure.
Legal basis: Art. 6 (1) (f) GDPR, our legitimate interest in protecting this website against misuse and automated attacks. A data processing agreement under Art. 28 GDPR is in place.
This website uses TLS encryption for all connections. You can recognise an encrypted connection by the padlock symbol in your browser's address bar. Data you transmit through this website cannot be read by third parties in transit.
We use Cookiebot, a service of Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark, to obtain and document consent for cookies and comparable technologies.
When you first access the website, Cookiebot stores a cookie containing your consent decision, together with a randomly generated consent ID, your anonymised IP address, the date and time of consent, the consent status per category, and technical information about the browser used. This record allows us to demonstrate consent as required by Art. 7 (1) GDPR.
Legal basis: § 25 (2) no. 2 TDDDG, as storage is strictly necessary to provide a service you have expressly requested, in conjunction with Art. 6 (1) (c) GDPR, our legal obligation to document consent. Retention: consent records are stored for twelve months, after which you will be asked again.
You can withdraw or change your decision at any time using the "Cookie settings" link in the footer of every page.
Cookies are small text files stored on your device. We distinguish two categories:
A current and automatically updated list of all cookies used on this website, including provider, purpose and retention period, is shown in section 21 of this policy.
You can also configure your browser to refuse cookies or to alert you when cookies are set. Disabling strictly necessary cookies may impair the functioning of this website.
All forms on this website are protected by Cloudflare Turnstile, a service of Cloudflare, Inc. Turnstile analyses technical characteristics of the browser and the request in order to establish whether a submission originates from a human being. Your IP address, browser and device information and interaction signals are transmitted to Cloudflare for this purpose. Turnstile does not use tracking cookies and does not profile visitors across websites.
Legal basis: Art. 6 (1) (f) GDPR, our legitimate interest in protecting our forms against automated misuse and spam, and § 25 (2) no. 2 TDDDG, as the technology is strictly necessary to provide the requested form service.
This website uses the typefaces Newsreader, Inter and IBM Plex Mono. These fonts are currently retrieved from servers of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When a page is loaded, your browser establishes a connection to Google servers, which allows Google to receive your IP address and information about the page requested.
Legal basis: Art. 6 (1) (f) GDPR, our legitimate interest in a consistent and fast presentation of our website. We are in the process of hosting these fonts locally on our own infrastructure; once this change is completed, no connection to Google servers will be established and this section will be updated accordingly.
This website offers four forms: a request for proposal, a request for a Commercial Risk Review, a request for a conversation with an adviser, and a partner application.
Data processed: depending on the form, we process the name of your organisation, details of the event or company concerned, estimated attendance and accommodation figures, dates, services required, your name, role, business email address, telephone number, any message you write, any documents you upload, and technical metadata used to prevent misuse (see sections 9 and 12).
Purposes: to assess your enquiry, to respond to it, and to take steps at your request prior to entering into a contract.
Legal basis: Art. 6 (1) (b) GDPR for pre-contractual measures and Art. 6 (1) (a) GDPR on the basis of the consent you give when submitting the form. Where an enquiry concerns an existing or prospective business relationship with a company, Art. 6 (1) (f) GDPR also applies.
Retention: enquiries are retained for 24 months from the last contact, unless they lead to a contractual relationship, in which case statutory retention periods of up to ten years under commercial and tax law apply. You may request deletion at any time, subject to those statutory periods.
To distinguish genuine business enquiries from automated or irrelevant submissions, each form submission receives an internal quality indicator. This indicator is calculated from information you provide yourself, such as the type of email address, the scale of the event and the services requested, together with technical characteristics of the submission.
This assessment supports our internal prioritisation only. It does not produce any automated decision with legal effect or similarly significant effect within the meaning of Art. 22 GDPR. Every enquiry is reviewed by a person.
Legal basis: Art. 6 (1) (f) GDPR, our legitimate interest in efficient handling of enquiries and in protection against misuse.
Forms allow you to attach documents such as a request for proposal, an event brief or a company profile. Files are checked for type and size, stored separately from the public website and made accessible only to the members of our team handling your enquiry. Please do not upload special categories of personal data within the meaning of Art. 9 GDPR.
Legal basis: Art. 6 (1) (b) and Art. 6 (1) (a) GDPR. Documents are retained together with the corresponding enquiry (section 11).
Notifications generated by our forms are delivered using Resend, a service of Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA. The content of the enquiry, including your contact details, is transmitted to Resend for the sole purpose of delivering it to our own mailbox.
Legal basis: Art. 6 (1) (b) and Art. 6 (1) (f) GDPR. A data processing agreement under Art. 28 GDPR is in place. Transfers to the United States are addressed in section 20.
On our "Speak with an expert" page we offer scheduling through Calendly, a service of Calendly LLC, 271 17th St NW, Atlanta, GA 30363, USA. The scheduling interface is only loaded after you have given consent through our consent banner. If you do not consent, no connection to Calendly is established and you can arrange an appointment by email instead.
If you book an appointment, Calendly processes the name, email address and appointment details you enter, together with your time zone and technical connection data.
Legal basis: Art. 6 (1) (a) GDPR and § 25 (1) TDDDG. Withdrawal of consent is possible at any time through the "Cookie settings" link in the footer, with effect for the future.
If you contact us by email or telephone, we process the data you provide in order to handle your request. This includes correspondence conducted through our business email and office systems.
Legal basis: Art. 6 (1) (b) GDPR where your request relates to a contract or pre-contractual measures, otherwise Art. 6 (1) (f) GDPR. Business correspondence is retained in accordance with statutory commercial and tax retention periods.
The services described in sections 17.1 to 17.7 are only loaded after you have given consent for the corresponding category through our consent banner. Without consent, no connection to the providers is established and no data is transmitted. You can withdraw your consent at any time through the "Cookie settings" link in the footer, with effect for the future.
Legal basis for all services in this section: § 25 (1) TDDDG in conjunction with Art. 6 (1) (a) GDPR.
We use Google Tag Manager, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Tag Manager is an administration tool that allows us to manage other tags on this website. It does not itself create user profiles or set cookies, but it loads the services listed below and processes your IP address in doing so.
We use Google Analytics 4 (Google Ireland Limited) to understand how this website is used. Analytics processes information about your visit, including pages viewed, time on site, approximate location, device and browser characteristics, and a randomly generated identifier stored in a cookie. IP anonymisation is enabled, so your IP address is truncated within the EU before any transfer.
We use this information to improve our content and structure. Retention of user and event data is set to 14 months.
We use Microsoft Clarity, a service of Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Clarity records how pages of this website are used, including clicks, scrolling and mouse movement, and aggregates this into heatmaps and session recordings. The purpose is to identify usability problems, for example forms that are abandoned at a particular step.
Clarity masks text entered into form fields by default, so the content of your enquiries is not recorded. Clarity is loaded only after you have given consent for statistics; without consent no connection to Microsoft is established.
We use the Universal Event Tracking tag of Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, together with Bing Webmaster Tools. The UET tag records whether visitors reached our website through a Microsoft search or advertisement and which actions they subsequently take, in order to measure the effectiveness of our search presence.
We use the Meta Pixel of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland. The pixel records visits to this website and actions taken on it, allowing us to measure the effect of campaigns and to address visitors again on Meta platforms. Where personal data is transmitted to Meta, we and Meta act as joint controllers under Art. 26 GDPR for the collection and transmission stage; the joint controller arrangement is available from Meta.
We use the Insight Tag of LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. It records visits to this website in order to provide aggregated statistics about our visitors and to measure and address campaigns on LinkedIn. LinkedIn does not share personal data with us; we receive aggregated reports only.
Where we embed maps from Google Maps (Google Ireland Limited), your IP address and information about the page requested are transmitted to Google when the map is loaded. Maps are only loaded after consent; until then a placeholder is displayed.
For business correspondence, document handling and internal collaboration we use Microsoft 365 (Microsoft Ireland Operations Limited). Where you contact us by email, the content of that correspondence is processed within this environment. A data processing agreement under Art. 28 GDPR is in place with Microsoft.
Legal basis for section 17.7: Art. 6 (1) (b) GDPR where the correspondence relates to a contract or pre-contractual measures, otherwise Art. 6 (1) (f) GDPR, our legitimate interest in efficient business communication.
Where this website links to external platforms, these are plain hyperlinks. No content is embedded and no data is transmitted to those platforms until you actively follow the link.
MKM Insights may contain links to the public LinkedIn profiles of authors and contributors. These links are provided solely to allow visitors to learn more about the respective author and their professional background.
No connection to LinkedIn is established simply by visiting our website. A connection to LinkedIn is only made if you actively click on a LinkedIn link. From that point onwards, the privacy policy and terms of LinkedIn apply.
For more information, please refer to LinkedIn's privacy policy: https://www.linkedin.com/legal/privacy-policy
Personal data is disclosed only where necessary. Recipients may include:
We do not sell personal data and do not disclose it for third-party advertising purposes.
Some of the providers named above are established in the United States. Where personal data is transferred there, the transfer is safeguarded either by the provider's certification under the EU-US Data Privacy Framework pursuant to the European Commission's adequacy decision of 10 July 2023, or by the European Commission's Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR, together with supplementary technical and organisational measures.
Despite these safeguards, it cannot be excluded that authorities in third countries may access such data. You can request a copy of the relevant safeguards from us at any time.
The following overview is generated automatically by our consent management platform and reflects the cookies actually present on this website.
Unless a longer period is stated above, we retain personal data only as long as necessary for the purpose concerned:
You have the following rights in relation to personal data concerning you:
To exercise any of these rights, a message to datenschutz@mkmesse.de is sufficient. We may ask for information to verify your identity.
If we process personal data on the basis of Art. 6 (1) (f) GDPR, you have the right to object at any time on grounds relating to your particular situation. If you object, we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or unless the processing serves to establish, exercise or defend legal claims.
You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. The authority competent for us is:
We review this policy regularly and update it where our processing changes or where legal requirements make it necessary. The current version always applies and is available on this page.
Version: 1.0 · Last updated: August 2026