This information covers the website, guest ticket purchases and festival visits. Service details are updated whenever the technical setup changes.
1. Controller
Kazel Eventagentur Owner: Kemal Kazel Wilfried-Diekmann-Straße 20b, 44536 Lünen, Deutschland Email: info@kazelexpo.com
No data protection officer is currently appointed. Privacy requests may be sent directly to the email address above.
2. Principles and legal bases
Personal data is information relating to an identified or identifiable person. We process it only for specified, explicit and legitimate purposes and only to the extent required for operating the website, communicating, performing contracts, ensuring event safety or providing services you choose voluntarily.
Depending on the activity, we rely on consent under Art. 6(1)(a) GDPR, contract performance or pre-contract steps under Art. 6(1)(b), a legal obligation under Art. 6(1)(c), or legitimate interests under Art. 6(1)(f). Section 25 TDDDG additionally applies when information is stored on or read from your device.
We do not make solely automated decisions producing legal or similarly significant effects, including profiling within Art. 22 GDPR. Data required for a contract or legal obligation must be provided; other information is voluntary.
3. Hosting and server logs
This website is currently delivered through OpenAI Sites on Cloudflare infrastructure. If the hosting provider changes, this notice will be updated with the provider and the specific technical processing then used.
When pages are requested, IP address, date and time, requested address and file, volume transferred, response status, referrer, browser type and version, operating system, security and error data may be processed. This is necessary to deliver content, keep the service stable and secure, and investigate attacks or faults.
Server logs are generally deleted or anonymised after 7–14 days. Logs connected with a specific security incident may be retained until investigation and the establishment, exercise or defence of claims are complete.
4. Contact, exhibitor and sponsorship enquiries
If you contact us by email, form or WhatsApp, we process your contact details, message, time of communication and required metadata. Exhibitor, catering or sponsorship enquiries may also include company, role, preferred event and proposal details.
Contractual and pre-contractual requests rely on Art. 6(1)(b) GDPR; general communication and organised handling of business enquiries rely on Art. 6(1)(f). When you choose WhatsApp, that service’s own privacy terms also apply.
Information is deleted when the enquiry is complete unless retention, evidence or limitation periods apply. Non-contractual enquiries are normally reviewed and deleted within two years; business correspondence may be kept for six years and accounting documents for eight years.
5. Ticket shop and guest checkout
For ticket selection, ordering, administration and admission we process name, address where genuinely required, email, invoice data, language, event and day, category and quantity, order number, payment status and ticket, barcode or QR identifier.
Tickets are ordered as a guest without registration or an account. First name, last name and a confirmed email address are required. Billing-address data is collected only where the payment method, invoice or law genuinely requires it. A phone number and delivery address are not mandatory for digital tickets.
Data is used for pre-contract steps, the contract, ticket delivery, support, misuse prevention and admission checks. Ticket and QR identifiers are electronically checked and redeemed at entry. They are not used for advertising without a separate legal basis.
6. Payments and fraud prevention
Payments may be handled through Stripe and PayPal. Stripe may provide cards, Klarna, Apple Pay and Google Pay. The methods actually available in checkout are decisive.
Depending on the method, providers receive name, billing and contact data, amount, currency, order reference, device and transaction data, and information required for authorisation and fraud prevention. Full card or bank credentials are usually collected directly by the provider and are not stored by Kazel Expo.
Relevant providers include Stripe Payments Europe, Limited or the affiliated Stripe entity responsible for the chosen method, and PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg. Providers may process some data as independent controllers; their privacy notices also apply to the payment method you select.
7. PDF and wallet tickets
After a successful purchase, tickets are provided as PDF and, where technically available, as Apple Wallet and Google Wallet passes. Order reference, event and ticket data, QR or barcode, and the email needed for delivery are processed for this purpose.
If an external technical service is used, this policy identifies the provider, its role, data location, processing arrangements, subprocessors and relevant deletion periods.
9. Consent management and essential storage
On first visit you can choose essential functions, statistics, marketing and external media. Optional categories are not preselected, and rejecting is as easy as accepting. The choice, time and policy version are stored locally so the website can remember it.
Storage may be used without consent only where it is required solely for transmitting a message or providing a digital service you expressly request. This can include security, language, cart, checkout and consent settings. Optional tracking and embedded maps stay blocked until the relevant consent.
You may reopen Cookie settings in the footer at any time to change or withdraw the choice for the future. Withdrawal does not affect processing lawfully carried out before it.
10. Google Analytics, Meta Pixel and TikTok Pixel
With consent, Google Analytics 4 may measure reach, while Meta Pixel and TikTok Pixel may measure campaigns and conversions. Device, browser, usage, event, campaign and approximate location data may be processed and linked with information held by the platforms.
Google services are provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Meta services by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; and TikTok services in the EEA generally by TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland. The provider information and configuration actually in use when a service is activated are authoritative.
Transfers to affiliates or providers outside the EEA, especially the United States, may occur. They will be based on a lawful mechanism such as an adequacy decision or standard contractual clauses plus supplementary measures.
These services load only when the relevant service is configured and you have first consented to the matching category. The settings, events and retention periods used are reflected in this policy. GA4 event retention is kept as short as reasonably possible.
11. Google Maps and external links
Maps on festival pages use a two-click design and are embedded only after consent to external media. Loading may transmit IP address, device and browser information, language and possibly location data to Google. The venue address and direct directions link remain available without consent.
Selecting Plan route deliberately leaves our website and opens Google Maps. Google’s privacy rules then apply. Social icons in the footer are simple links; they do not load social plugins or platform cookies on our website.
12. Events, admission, photography, filming and safety
Ticket and QR identifiers are processed for entry checks. Photo and film teams create overview, group, stage and audience images for current reporting, press, social media, promotion of future events and long-term documentation in the company archive.
General event images may rely on legitimate interests in information, public relations and documentation. Express consent is normally obtained for targeted portraits, interviews and advertising close-ups, especially of children. Individuals can speak to the team on site or contact us by email; each case is assessed against the image, publication and competing interests.
Commissioned photographers and videographers receive only what is necessary and are contractually bound. Material is transferred to Kazel Expo and may remain in the long-term archive; unnecessary working files and rejected selections are deleted.
CCTV may operate only in marked security-relevant areas for danger prevention and evidence. Footage is normally deleted within 48–72 hours unless a specific incident requires longer preservation for authorities or legal claims.
13. Recipients, processors and international transfers
Recipients may include hosting and IT providers, ticket and communication systems, payment providers, tax advisers, delivery and support services, commissioned media and security teams, and public authorities where required for performance, safety or law.
Exhibitors or sponsors do not automatically receive visitor contact details. A transfer, for example after a voluntary badge scan or for an optional attendee list, occurs only following transparent information and separate consent. No public attendee list is currently active.
Providers acting only on our instructions are bound by data-processing agreements. Transfers outside the EEA occur only under Arts. 44 et seq. GDPR. Copies of relevant safeguards may be requested to the extent provided by law.
14. Retention
We do not retain all ticket data for a blanket ten-year period. Accounting records and the necessary order and invoice data are generally kept for eight years; commercial or business correspondence generally for six. Statutory periods often begin at the end of the relevant calendar year.
Operational ticket and entry data is deleted after the event and resolution of open cases, or reduced to what is required for evidence and accounting. Contact enquiries, unconfirmed newsletter signups, server logs and CCTV follow the shorter periods stated above.
Exceptionally, data may be retained longer where required by law, authority order, a security incident, or the establishment, exercise or defence of legal claims. It is deleted or anonymised afterwards.
15. Your rights
Send requests to info@kazelexpo.com. We may request reasonable proof of identity to prevent unauthorised disclosure.
This policy is updated when law, providers or actual processing change. The version published on this page applies to the current visit.
- Access under Art. 15 GDPR
- Correction under Art. 16 GDPR
- Erasure under Art. 17 and restriction under Art. 18 GDPR
- Data portability under Art. 20 GDPR
- Objection to legitimate-interest processing under Art. 21 GDPR
- Withdrawal of consent for the future under Art. 7(3) GDPR
- Complaint to a supervisory authority, in particular the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia
If translations differ, the German version prevails unless mandatory consumer law provides otherwise.