Privacy Policy
What we collect, why, on what legal basis, and for how long.
Written to be read rather than to be survived. If anything here is unclear, ask us and we will explain it in plain language.
1. Who we are
World Digital Forum is operated by the company identified below, which is the controller of the personal data described in this policy for the purposes of the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
Site operator & data controller
- Legal name
- UAB
- Company number
- 234290861
- Registered address
- Kolbenova 2, 190 00 Prague 9, Czech Republic
- Contact email
- awatef.keltai@worlddigitalforum2025berlin.com
- Website
- worlddigitalforum2025berlin.com
This policy covers the website at worlddigitalforum2025berlin.com, our newsletter, and enquiries sent to us through the contact form or by email. Write to awatef.keltai@worlddigitalforum2025berlin.com about anything in it.
2. Data Protection Officer
We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR. All privacy requests are handled directly by the contact below.
In practice this means there is one route for every privacy question, request or complaint: awatef.keltai@worlddigitalforum2025berlin.com. Requests are answered within one month of receipt, as required by Article 12(3) GDPR. If a request is unusually complex we may extend that by up to two further months, and we will tell you within the first month if that happens, and why.
3. What we collect, and why
3.1 Newsletter subscription
When you subscribe we collect your email address and the topic and frequency preferences you select. We ask for nothing else — no name, no employer, no job title. We use this solely to send you the newsletter you asked for.
Alongside it we store the evidence that you asked: the date and time of your request in UTC, the IP address the request came from, the browser user-agent string, the exact wording of the consent statement displayed to you, its version identifier, and the date and time you confirmed by clicking the link in our confirmation email. This is explained further in section 5.
3.2 Confirmation, preference and unsubscribe links
We generate random single-use or long-lived codes so that you can confirm a subscription, change your preferences, or unsubscribe without creating an account or giving us a password. We store only a cryptographic hash of each code, never the code itself, so that a copy of our database does not let anyone act on your subscription.
3.3 Contact form and email enquiries
The contact form collects your name, email address, an optional organisation, the subject you select and your message, together with the time of submission and the IP address it was sent from. We use this to answer you and to handle any follow-up. Sending us an enquiry never adds you to the newsletter.
3.4 Server logs
Our web server records ordinary technical information about each request: IP address, timestamp, the page requested, HTTP status code, referrer and user-agent. We use it to keep the site available, to diagnose faults, and to detect and block abuse such as automated form submissions.
3.5 What we deliberately do not collect
- We do not run analytics, and we do not profile visitors.
- We do not buy, rent or append data about you from third parties.
- We do not use advertising networks, retargeting or social-media pixels.
- We do not ask for special-category data, and please do not send it to us.
4. Legal bases for each purpose
| Purpose | Data | Legal basis |
|---|---|---|
| Sending the newsletter you asked for | Email address, preferences | Consent — Article 6(1)(a) GDPR, and Article 6(1)(a) of the ePrivacy Directive as implemented locally |
| Proving that consent was validly given | Consent record: timestamp, IP, user-agent, consent text and version | Legal obligation — Article 6(1)(c) with Article 7(1) GDPR |
| Honouring an unsubscribe permanently | Suppression record | Legal obligation — Article 6(1)(c) with Article 21(3) GDPR |
| Answering your enquiry | Contact form fields | Legitimate interests — Article 6(1)(f), namely responding to someone who contacted us; or pre-contractual steps under Article 6(1)(b) where your enquiry concerns taking part in an event |
| Keeping the site secure and available | Server logs, rate-limiting records | Legitimate interests — Article 6(1)(f), namely network and information security |
| Strictly necessary cookies | Session and notice cookies | Exempt from consent under Article 5(3) of the ePrivacy Directive; processed under Article 6(1)(f) GDPR |
Where we rely on legitimate interests we have considered your rights and freedoms and concluded that the processing is limited, expected, and does not override them. You can object at any time under Article 21 — see section 12.
5. Our record of your consent
Article 7(1) GDPR requires us to be able to demonstrate that you consented. We therefore keep, for every subscription, a record containing:
- the email address that was entered;
- the date and time of the request, in UTC, in ISO 8601 format;
- the IP address from which the request was made;
- the browser user-agent string sent with the request;
- the full text of the consent statement that was displayed, stored verbatim;
- the version identifier of that consent statement (currently 2026-09-07.v1); and
- the date and time at which you confirmed the subscription from the link in our confirmation email.
We store consent wording in a way that lets us reproduce, years later, the exact sentence you were shown — not merely the sentence we happen to display today. If you ask us what you agreed to, that is what we will send you.
We operate double opt-in. A subscription that is never confirmed is never mailed, and pending records that are not confirmed are deleted.
6. How long we keep it
| Category | Retention period | Why |
|---|---|---|
| Newsletter subscription and consent record | For as long as you remain subscribed, and 3 years after you unsubscribe | To prove the lawfulness of consent under Article 7(1) GDPR and to honour your unsubscribe request |
| Unsubscribe / suppression record | Retained indefinitely while we operate the mailing list | To ensure we never contact you again after you opt out |
| Contact form enquiry | 24 months from the last message in the exchange | To handle your enquiry and any follow-up |
| Web server access logs | 14 days | Security, abuse prevention and diagnostics |
At the end of a retention period the data is deleted. The one deliberate exception is the suppression record described above: keeping a minimal record of an address that asked not to be contacted is the only way to guarantee we never contact it again, and erasing it would defeat your own request.
7. Who else sees your data
We do not sell, rent, or share personal data for anyone else’s marketing. Your address is never passed to sponsors, partners, exhibitors or speakers. The only third parties involved are service providers acting as processors on our documented instructions under an Article 28 contract:
- Our hosting provider, which operates the servers on which this site and its database run, and therefore has technical access to the data stored there.
- Our email delivery provider, which transmits the newsletter and the confirmation, preference and unsubscribe emails on our behalf.
We describe these providers by their role rather than by name because the identity of a provider can change; if you would like to know who currently holds those roles, ask us at awatef.keltai@worlddigitalforum2025berlin.com and we will tell you.
We may also disclose personal data where we are legally required to do so, for example in response to a valid order from a competent authority, or where it is necessary to establish, exercise or defend legal claims.
8. Transfers outside the EEA
We do not routinely transfer personal data outside the European Economic Area. Where a service provider processes data outside the EEA, we rely on the European Commission's standard contractual clauses or an adequacy decision.
You may ask us for a copy of the safeguards that apply to any particular transfer by emailing awatef.keltai@worlddigitalforum2025berlin.com.
9. Cookies and tracking
We do not use analytics, advertising, profiling or social-media cookies. We do not embed third-party trackers, and no fonts, scripts or images are loaded from another company's servers. The only cookies set are the strictly necessary ones listed below, which do not require consent under Article 5(3) of the ePrivacy Directive.
Every cookie this site sets is listed, with its purpose and lifetime, in our Cookie Policy.
10. Security
We apply measures appropriate to the risk, as Article 32 requires. In practice that means: the site is served over HTTPS; access tokens are generated from a cryptographic random source and stored only as hashes; database queries are parameterised; every form submission is checked against a per-session token to prevent cross-site request forgery; submissions are rate-limited by IP address; we collect the minimum data we need and no more; and the database file is stored outside the public web root so it cannot be requested over the web.
No system is perfectly secure. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the supervisory authority within 72 hours as required by Article 33, and we will tell you directly where Article 34 requires it.
11. Automated decision-making and profiling
We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR. Nothing about you is scored, ranked, or decided by a machine.
12. Your rights
You have the following rights in relation to your personal data. To exercise any of them, email awatef.keltai@worlddigitalforum2025berlin.com. We do not charge, and we do not require you to use a particular form of words.
| Right | Article | What it means |
|---|---|---|
| Access | Article 15 | Obtain confirmation of whether we process your data and receive a copy of it. |
| Rectification | Article 16 | Have inaccurate data corrected and incomplete data completed. |
| Erasure | Article 17 | Have your data deleted where one of the grounds in the GDPR applies. |
| Restriction | Article 18 | Ask us to limit how we use your data while a dispute is resolved. |
| Portability | Article 20 | Receive the data you gave us in a structured, machine-readable format. |
| Objection | Article 21 | Object to processing based on our legitimate interests, and to direct marketing at any time. |
| Withdraw consent | Article 7(3) | Withdraw your consent at any time, without affecting processing carried out before withdrawal. |
| Complain | Article 77 | Lodge a complaint with a supervisory authority, including the one where you live or work. |
Two of these are worth spelling out. Withdrawing consent to the newsletter needs no email at all: the unsubscribe link in every message we send takes one click, works without a login, and takes effect immediately. And your right to object to direct marketing under Article 21(2) is absolute — there is no balancing test and we will always comply.
We may ask you for information that helps us confirm you are the person the data relates to, but only where we have reasonable doubts about your identity, and we will not use that information for anything else.
13. Complaints
If you think we have handled your personal data unlawfully, please tell us first at awatef.keltai@worlddigitalforum2025berlin.com — most problems are quickest to fix directly.
You also have the right under Article 77 GDPR to lodge a complaint with a supervisory authority. Because our place of establishment is in Lithuania, the lead authority for us is the Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate), L. Sapiegos g. 17, LT-10312 Vilnius, Lithuania, email ada@ada.lt, website vdai.lrv.lt. You may equally complain to the supervisory authority of the EU or EEA country where you live, where you work, or where the alleged infringement took place. Exercising this right does not affect any other remedy available to you.
14. Children
Our events and our newsletter are aimed at professionals and are not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, tell us and we will delete it.
15. Changes to this policy
We update this policy when what we do changes. The date below is the date of the current version. If we make a change that materially affects how we use data you have already given us, we will tell subscribers by email before it takes effect, and where the change requires fresh consent we will ask for it rather than assume it.
Last updated: 7 September 2026. Consent wording version in force: 2026-09-07.v1.