Privacy notice

Privacy

Privacy notice for the Smart Hub

We process personal data about you in the Smart Hub of the Online Print Summit. Below we explain what data this is, how it is processed and what rights you have.

How this relates to the website privacy notice

This notice covers the Smart Hub at opsprod.pulse.place. A separate privacy notice applies to the website online-print-summit.com. The two run on different systems.

Personal data is any information relating to an identified or identifiable natural person, as defined in Art. 4 (1) GDPR.

1. Controllers within the meaning of the GDPR

This privacy notice covers the processing of personal data in the Smart Hub by the joint controllers:

Verband Druck und Medien Beratung GmbH

Einsteinring 1a
85609 Aschheim
Germany

zipcon consulting GmbH

Am Buchenhain 4
45239 Essen
Germany

(hereinafter: OPS)

The controllers have concluded an arrangement on joint processing pursuant to Art. 26 GDPR. We will make the essence of that arrangement available to you on request.

You can send data protection requests, for example about erasure or the withdrawal of consent, to privacy-policy@online-print-summit.com.

2. The Smart Hub and the platform provider

The Smart Hub is the digital home of the Online Print Summit. It holds the programme, the speakers, the partners and your attendee profile, and it is where you book tickets and register for sessions. No app is offered for the Online Print Summit 2027.

The Smart Hub is operated technically by run.events GmbH, Mainzer Straße 186, 55411 Bingen am Rhein, Germany. run.events processes the data exclusively on our behalf and on our instructions, on the basis of a data processing agreement pursuant to Art. 28 GDPR dated 9 July 2026. In addition, the run.events privacy notice applies to the processing that run.events carries out under its own responsibility.

According to the contractual assurances given by run.events, the servers on which the data is processed are located within the European Economic Area. Processing outside the EEA only takes place with our express consent, and we have not given such consent.

3. When you visit the Smart Hub

You can open the Smart Hub without disclosing your identity. When you access it, your device automatically transmits data for technical reasons. The following data is stored separately from other data:

  • date, time and duration of your visit
  • IP address
  • the page you accessed
  • your browser and operating system
  • the action carried out
  • whether the access was successful
  • information retrieved, including downloads

This data is stored in log files and deleted after [OPEN: retention period can only be obtained from run.events, it is not visible in the backend]. Longer storage only takes place in individual cases, for example where misuse or fraud is suspected.

The legal basis is Art. 6 (1) sentence 1 (f) GDPR. We have a legitimate interest in being able to offer you the Smart Hub in a technically sound, secure and optimised way.

4. Ticket booking and payment

To attend the Online Print Summit you book a ticket in the Smart Hub. Our event is reserved for a professional audience and is aimed exclusively at companies and their employees.

The following details are mandatory:

  • first name and surname
  • email address
  • name of the organisation
  • street address, town, postal code and country
  • tax type and tax number

Optionally you can provide a second address line, a region and a free text for the invoice, such as a purchase order number.

We need these details in order to identify you as a trade visitor, to grant you access to the event, to issue your ticket and to respond to your enquiries. The legal basis is Art. 6 (1) (b) GDPR, as the processing is necessary for the performance of the contract.

If you book a member ticket, you also state the partner association your company belongs to. This is used to verify your eligibility for the price.

Payment is made by credit card. The payment is processed by Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, which run.events engages as a sub-processor. The payment details you enter are transmitted directly to Stripe. We do not receive complete credit card details.

We retain ticket and accounting data for ten years due to statutory retention obligations.

5. Your profile in the Smart Hub

A profile is created for you in the Smart Hub when you book a ticket. You use this profile to manage your tickets, to register for sessions and to connect with other attendees.

You may optionally add further details, such as a short bio, a profile picture or your interests.

By default your profile is not visible to other attendees. In that case your details can only be seen by the administrators of the event, that is by us as the organizers.

You can set your profile to public yourself. Your first name, surname, short bio, company and job title are then visible to other attendees, and you can appear in search results, speaker lists and matchmaking suggestions. Even then your full profile remains hidden until you accept a contact request. Your email address and your postal address are not visible to other attendees.

You can withdraw that visibility at any time by setting your profile back to not public or by deleting individual optional details.

The legal basis for creating and maintaining the profile is Art. 6 (1) (b) GDPR. Visibility to other attendees is based on your consent pursuant to Art. 6 (1) (a) GDPR, as it only comes about when you enable it yourself. You can withdraw that consent at any time.

6. Networking and matchmaking

The Smart Hub offers a function that suggests other attendees who might be of interest to you. You only appear in these suggestions if you have set your profile to public, see section 5.

For this function, details from your profile are analysed, such as your company, your job title and your interests. The analysis is supported by artificial intelligence. Mistral AI SAS, France, is engaged for this as a sub-processor of run.events. The processing takes place within the European Union.

The suggestions are recommendations only. There is no automated decision in an individual case producing legal effects or similarly significantly affecting you within the meaning of Art. 22 GDPR.

The legal basis is your consent pursuant to Art. 6 (1) (a) GDPR, which you give when you make your profile public. You can withdraw it at any time by setting your profile back to not public.

7. Registering for sessions

Registration through the Smart Hub is required for the C-Level Classrooms, the Executive Briefings and the pre-event programme, as places are limited. We process which formats you have registered for. This is used to plan the rooms and the catering. The legal basis is Art. 6 (1) (b) GDPR.

8. Check-in on site

Your ticket contains a QR code. It is scanned at check-in in order to verify your entitlement to attend and to issue your badge.

Only your entitlement to attend is verified. There is no record of who checked in when, and attendance at individual sessions is not recorded.

Your badge being scanned by partners: partner companies can scan your badge at their stands. Details from your profile are then transmitted to the partner company, in particular your name, email address and company. This only happens if you agree to it at the moment of scanning. The legal basis is your consent pursuant to Art. 6 (1) (a) GDPR. The partner company is itself responsible for any further use of that data.

9. Speaker and partner areas

Anyone contributing to the programme as a speaker creates a profile in the Smart Hub and submits details of their session there. Name, job title, company, short bio and photo are published on the speaker page of the Online Print Summit. The legal basis is Art. 6 (1) (b) GDPR within the scope of taking part in the programme.

Partner companies are given access to a partner area. There we process the contact details of the named contact persons in order to administer the partnership, Art. 6 (1) (b) GDPR.

10. Emails from the system

In connection with your booking you receive emails from the Smart Hub, such as your booking confirmation, your invoice, your payment confirmation and your ticket. These emails are part of performing the contract, Art. 6 (1) (b) GDPR. You cannot object to them, as they are necessary in order to perform the contract.

These emails are sent using Mailjet SAS, France, a company of the Sinch group. The recipient name, the email address and the content of the message are processed.

Our newsletter is separate from this. It is sent via HubSpot and requires your consent. Further details are set out in the privacy notice for the website.

11. Cookies in the Smart Hub

The Smart Hub sets cookies that are technically necessary for its operation, in particular to keep you signed in and to store your settings. No consent is required for such cookies pursuant to section 25 (2) TDDDG.

12. Recipients of your data

We engage service providers who process your data exclusively on our behalf and on our instructions, that is processors pursuant to Art. 28 GDPR:

  • run.events GmbH, Bingen am Rhein, Germany, for operating the Smart Hub

run.events in turn engages its own sub-processors. According to the list dated 26 June 2026 these are:

  • Microsoft Corporation, USA with data residency in the EU: cloud infrastructure and hosting of the platform, processes platform, account and event data
  • Mistral AI SAS, France: artificial intelligence features, processes content entered into such features
  • Stripe, Inc. and Stripe Payments Europe Ltd., USA and Ireland: payment processing, processes payment and transaction data
  • Mailjet SAS, France, a company of the Sinch group: delivery of transactional and notification emails, processes recipient name, email address and content
  • Bitmovin GmbH, Austria: processing and delivery of session videos. Sessions at OPS 2027 are recorded and made available as video.

run.events makes the current version of that list available on request. run.events informs us in advance of intended changes, and we can object within 14 days.

In addition, your registration data is passed to the two organizers so that they can plan and deliver the event.

Your first name, surname, job title and company appear on attendee lists which are made available to other attendees on request. This serves the purpose of networking and is based on Art. 6 (1) (b) GDPR.

13. Use of the data by the platform provider

Under the agreement concluded with run.events, the provider may also use the data beyond delivering the service for purposes directly related to improving its platform. These include test running, analytics and customer satisfaction surveys among users. run.events carries out a legitimate interest assessment for this and bases the processing on Art. 6 (1) (f) GDPR under its own responsibility.

In addition, under its terms of use run.events may use aggregated analyses, from which no individual person and no individual customer can be identified, in order to develop and market the platform.

You can object to this processing. Please contact privacy-policy@online-print-summit.com or run.events directly at info@runevents.eu. Further details are set out in the run.events privacy notice.

14. Transfers to third countries

The data is stored on servers within the European Economic Area. Two of the companies engaged are, however, established in the USA, so access from a third country cannot be ruled out:

  • Microsoft Corporation, USA. The data is held in the EU. Microsoft is certified under the EU-U.S. Data Privacy Framework, so any transfer is based on the adequacy decision of the European Commission pursuant to Art. 45 GDPR.
  • Stripe, Inc., USA. The contracting party for payment processing in Europe is Stripe Payments Europe Ltd. in Ireland. Stripe, Inc. is certified under the EU-U.S. Data Privacy Framework.

You can check the current certification status at dataprivacyframework.gov. Where a recipient is not covered by an adequacy decision, we base the transfer on the EU standard contractual clauses pursuant to Art. 46 GDPR.

15. Retention periods

  • Ticket and accounting data: ten years, due to statutory retention obligations
  • Your profile in the Smart Hub: you can delete optional details or your entire account at any time. After the account has been deleted, the associated data is removed within 24 hours. Unused accounts are deleted regularly, and you are informed beforehand.
  • Log files:
  • Consents and objections: up to three years after they were last used, in order to meet our obligations of proof

16. Photos and videos during the event

We take photos and videos during the event in which attendees may be visible. We use this material to report on the event and to promote future events. The grant of rights is governed by our terms and conditions.

The legal basis is our legitimate interest in documenting and promoting the event pursuant to Art. 6 (1) (f) GDPR. You can object to the use of recordings in which you are identifiable. An email to privacy-policy@online-print-summit.com is sufficient.

17. External content and forms

On the Service and Information page we embed an interactive map from Google Maps, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The map is only loaded after you have agreed to it. No data is transmitted to Google before that.

Once loaded, Google collects device-related information, log data including your IP address and location-related information. A transfer to the USA may take place in this context. The legal basis is your consent pursuant to Art. 6 (1) (a) GDPR and section 25 (1) TDDDG. You can withdraw it at any time with effect for the future.

The form for partner enquiries is processed through an endpoint on zipcon.de. We use the data entered there exclusively to deal with your enquiry, Art. 6 (1) (a) and (b) GDPR. The recipient of the form data is zipcon consulting GmbH only. It is not passed on to any other party.

18. Your rights

You have the right:

  • to withdraw a consent you have given at any time, pursuant to Art. 7 (3) GDPR
  • to request information about the data we process about you, pursuant to Art. 15 GDPR
  • to request the rectification of inaccurate data or the completion of your data, pursuant to Art. 16 GDPR
  • to request the erasure of your data, pursuant to Art. 17 GDPR, unless statutory retention obligations prevent this
  • to request the restriction of processing, pursuant to Art. 18 GDPR
  • to receive your data in a structured, commonly used and machine-readable format, pursuant to Art. 20 GDPR
  • to object to processing based on Art. 6 (1) (f) GDPR, pursuant to Art. 21 GDPR
  • to lodge a complaint with a supervisory authority, pursuant to Art. 77 GDPR

As we are joint controllers, you can exercise your rights against either of us. The quickest route is privacy-policy@online-print-summit.com.

19. Right to object pursuant to Art. 21 GDPR

You have the right to object at any time, on grounds relating to your particular situation, to the processing of data concerning you where that processing is based on Art. 6 (1) (f) GDPR. This also applies to profiling based on that provision.

If you object, we will no longer process your data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, or the processing serves to establish, exercise or defend legal claims.

Where your objection concerns direct marketing, we will stop the processing immediately. In that case you do not need to state a particular situation.

20. Data security

All data you transmit is encrypted using the TLS standard. You can recognise a secure connection by the https in your browser's address bar and by the padlock symbol.

We also use appropriate technical and organisational measures to protect your data against accidental or intentional manipulation, loss, destruction or unauthorised access by third parties. Our measures are continuously improved in line with technological developments.

21. Currency and changes

This privacy notice is dated 02.09.2026 .