Skip to main content
Back to the link page

Legal

Privacy Policy

Translation notice: This English text is a convenience translation of the German original. In the event of any discrepancy or ambiguity, the German version is authoritative.

Controller

The controller responsible for this website, events and related enquiries is:
Sept & Royal Events GbR
Vimbucher Straße 60
77815 Bühl
Germany
Email: kontakt@zdc.events
Telephone: +49 176 21410091

No data protection officer has been appointed.

Website, hosting and server logs

This website is operated on servers administered by us. We use Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, as our hosting and infrastructure service provider and processor.

When you access the website, technical access data may be processed, including in particular your IP address, the date and time of the request, the URL accessed, the HTTP status code, user agent and referrer, where transmitted. This data is required to deliver the website, secure its operation and analyse technical errors.

Technical access and security logs are generally retained for up to 90 days. They are retained for longer only where this is necessary in an individual case to investigate or defend against a specific security incident.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and stable operation of the website.

Website analytics with Umami

We use an internally operated Umami system at umami.veryun.cool to measure use of our website, identify technical anomalies and improve its content. The data processed may include, in particular, pages accessed, timestamps, referrers, device type, browser, operating system, screen size, an approximate location based on the IP address, and clicks on elements marked accordingly. We use this data internally only for audience measurement, error analysis and improvement of the website.

Under its current configuration, Umami does not set cookies on this website. The tracking script may, however, read local browser storage, in particular to respect an opt-out set through umami.disabled.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure, stable and user-friendly operation of the website. Where information is stored on or read from your device for analytics or recognition purposes, Section 25 TDDDG also applies.

We do not use externally loaded fonts or embedded social-media posts. External platforms are linked only.

Contact and equipment rental

If you contact us by email or submit an equipment-rental enquiry, we process the information you provide in order to handle your enquiry. This may include your name, contact details, event date, location, requested equipment and the content of your message.

Emails are processed through an email system operated by us. Forms on this website – including the equipment-rental form and enquiry forms created through the page editor – merely open a pre-populated email using mailto:; this website does not store the form data on the server.

The legal basis is Article 6(1)(b) GDPR where the enquiry concerns pre-contractual or contractual matters, and Article 6(1)(f) GDPR for other communications. Enquiries are deleted when they are no longer required, unless statutory retention obligations apply.

Ticket sales through external providers

Ticket links on this website lead to external ticket providers. This website does not embed an external ticket shop and does not load content from the destination provider before you deliberately open a ticket link. The server initiates the redirect based on the selected published date.

Only after the click and redirect does your browser connect to the relevant ticket provider. Technically necessary connection data, such as your IP address, time, browser and device information, is then transmitted to the destination provider. The redirect is configured so that the ZDC page is not transmitted as the referrer. The provider may use cookies or comparable storage mechanisms for the shopping cart, ordering process, login or payment. The privacy notice and cookie settings of the provider identified on the destination page apply.

Ticket ordering, checkout and payment take place entirely with the external provider. This website does not receive or store order, payment or customer data in that process. The destination provider processes the information required for sale, billing and admission under the privacy and contractual relationship identified on its website. This may include, in particular, name, email address, billing information, ticket type, order and payment status, and check-in and admission data.

Where we process data ourselves to perform the event contract, the legal basis is Article 6(1)(b) GDPR; Article 6(1)(c) GDPR applies to statutory retention and record-keeping obligations. The legal bases stated by the ticket provider apply to any processing for which that provider is independently responsible.

Payment service providers

The payment service providers available for an online ticket purchase are identified in the relevant external ticket shop. The privacy notices linked there apply to those providers. For card payments at the venue, we use PayPal POS/Zettle. PayPal services are provided in particular by PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. Payment service providers process the data required to handle payments, such as the payment amount, transaction data, payment status and, depending on the payment method, further payment information.

The legal basis is Article 6(1)(b) GDPR for payment processing and Article 6(1)(c) GDPR for statutory accounting and record-keeping obligations. The payment service providers generally act as independent controllers. Data may also be processed outside the EU/EEA; details and safeguards are set out in the privacy notice of the provider in use. For PayPal, the PayPal privacy notice applies.

Payment, billing and accounting data is retained in accordance with statutory requirements, in particular commercial and tax-law obligations, generally for up to 10 years.

Photography and video recordings at events

Photographs and video recordings may be made at events. The focus is on crowd, atmosphere, artist, stage and DJ recordings for the documentation, public relations, promotion and follow-up reporting of our events. Recordings may be published on this website, Instagram, TikTok and WhatsApp.

The legal basis for general crowd, atmosphere and event recordings is Article 6(1)(f) GDPR. Our legitimate interest is the public relations work and documentation of our events. We use specifically targeted, identifiable individual or portrait recordings, in particular for promotional materials, only with consent under Article 6(1)(a) GDPR or following a clear agreement.

Recipients may include commissioned photographers and videographers, our internal organizational systems, website hosting providers and the respective platform providers, in particular Meta Platforms for Instagram/WhatsApp and TikTok. When recordings are published on social media, processing in third countries, particularly the United States, cannot be ruled out; the respective platform’s privacy notice applies to any further processing.

Where possible, we display clearly visible notices at the venue to indicate that event recordings are being made. If you do not wish to be included in recordings, please speak to the team, photographer or awareness team at the venue. You can request the removal of recordings already published by emailing kontakt@zdc.events. The amount of raw footage retained is reduced once it is no longer needed for selection, editing and follow-up reporting; published posts generally remain available for as long as they are required for documentation and public relations, or unless legitimate objections require otherwise.

Video surveillance at the entrance

At certain events, particularly at the Hangar, the entrance or property area may be under video surveillance. The purpose is to protect parked aircraft and other objects, deter and investigate specific cases of property damage, and preserve evidence of specific incidents.

Surveillance is spatially limited to the area required. No audio is recorded, and the recordings are not used for marketing or social media. Under the current concept, the venue is not subject to general video surveillance.

The legal basis is Article 6(1)(f) GDPR. Recordings are generally deleted after 48 to 72 hours. They are retained for longer only in the event of a specific incident, where evidence must be preserved, or where disclosure to the police or public authorities is required. Separate information is provided at the venue before you enter the monitored area.

Social media and external links

This website contains links to Instagram, TikTok, WhatsApp and ticket shops. You leave this website only when you click one of these links. The respective providers process personal data under their own responsibility and in accordance with their privacy terms.

We operate the WhatsApp group as a community channel. When you join, WhatsApp or Meta processes personal data, in particular your telephone number, profile information and communication content, in accordance with WhatsApp’s terms.

Awareness cases, venue bans and lost property

If you contact us about an awareness-related incident, a complaint or lost property, we process the information required to handle the matter. Depending on the case, this may include your name, contact details, message content, time, persons involved and internal notes.

We do not store photographs or copies of identity documents for venue bans. Where necessary, we document in particular the person’s name, date of birth, reason, date, duration and an internal justification. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is safety, traceability and the enforcement of our right to control access to the premises.

Internal organization

We use systems administered by us for internal organization. Necessary documents such as event planning, contracts, invoices, ticketing and accounting records, photo and video material, and equipment-rental enquiries may be processed in these systems.

We do not retain copies of identity documents or proof of age as part of our standard process. Only authorized persons have access to internal documents. Data is deleted when it is no longer required for its respective purpose, unless statutory retention obligations apply.

Your rights

Subject to the conditions of the GDPR, you have the right of access, rectification, erasure, restriction of processing and data portability, as well as the right to object to processing based on legitimate interests. Where processing is based on consent, you may withdraw that consent at any time with effect for the future.

To exercise your rights, please contact kontakt@zdc.events.

Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority. In particular, the supervisory authority responsible for our registered office is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg): baden-wuerttemberg.datenschutz.de.

Version

July 2026

Imprint (DE) Privacy Policy Terms & Conditions