BK-Event

Event management tool of the Blue Knights European Conference

Privacy Policy

Privacy Policy

This Privacy Policy explains how BK-Event, the event-management application of the Blue Knights European Conference (BKEC), collects, uses, and protects personal data of its users, in accordance with the General Data Protection Regulation (GDPR / EU 2016/679) and the German Federal Data Protection Act (BDSG).

BK-Event is operated on a voluntary, non-commercial basis to organise the BKEC event. It is not a public website – it is used by registered members of the Blue Knights community to register for the event and, for organisers, to manage that registration.

2. Data Controller

The controller responsible for data processing within the meaning of the GDPR is:

Karl-Michael („Karlo“) Kühnke
Berliner Ring 5
D-49456 Bakum, Germany
Email: webmaster@blue-knights.eu
Phone: +49 4446 9897786

3. What Data We Process

Depending on how you use BK-Event, the following categories of personal data are processed:

CategoryExamples
Account dataName, email address, password (stored as a salted hash, never in plain text), assigned role (e.g. participant, staff, event manager, webmaster)
Registration dataArrival/departure dates, accommodation and roommate preferences, dietary requirements, emergency contact details, and any other information you voluntarily provide as part of your event registration
Consent flagsWhether you have given GDPR consent for event-related data processing and, separately, whether you consent to photos being taken of you during the event ("photo consent")
Accommodation & logistics dataRoom and bed assignments derived from your registration, used to plan and coordinate accommodation for the event
Audit log dataA record of who changed which piece of registration or account data, and when, kept for accountability and security purposes
Session dataA signed, encrypted login token (JWT) stored in a cookie in your browser so you stay logged in; this token is technically necessary and is not used for tracking or advertising
Technical/server dataStandard web server log data (such as IP address, date/time, and requested page), generated automatically by our hosting infrastructure for security and stability purposes

We do not knowingly collect any special category data (Art. 9 GDPR, e.g. health data) beyond what you may voluntarily disclose in free-text fields such as dietary requirements, which is processed solely to accommodate your needs at the event.

4. Legal Basis

  • Contract / registration processing (Art. 6 (1)(b) GDPR): processing your account and registration data is necessary to register you for the event and to organise your participation.
  • Consent (Art. 6 (1)(a) GDPR): where we ask for it explicitly – for example the photo-consent flag – processing is based on your consent, which you may withdraw at any time with effect for the future.
  • Legitimate interest (Art. 6 (1)(f) GDPR): audit logging and technical server logs are kept in our legitimate interest to keep the system secure, traceable, and free of misuse.

5. Cookies & Session

BK-Event uses a single, strictly necessary session cookie to keep you signed in. We do not use analytics, tracking, or advertising cookies of any kind, and we do not share data with advertising networks.

6. Hosting & Processors

We keep the number of processors involved as small as possible, and all of them process data within the European Union / European Economic Area:

  • Application hosting: BK-Event runs on a virtual server (VPS) located in Karlsruhe, Germany.
  • Transactional email: System emails (such as registration confirmations) are sent via Amazon Web Services (Amazon SES), using the AWS "eu-north-1" region (Stockholm, Sweden), under an AWS account held by the Blue Knights European Conference.

Because both processing locations are within the EU/EEA, no transfer of personal data to a "third country" outside the EU/EEA takes place.

7. Who Can See Your Data

Your registration data is visible to BKEC event organisers, according to their role in the system (staff, event manager, or webmaster), strictly for the purpose of planning and running the event – for example to coordinate accommodation or catering. Data is not sold, rented, or passed on to any third party for marketing or any other unrelated purpose.

8. Retention & Backups

Your account and registration data is retained for as long as it is needed for the purpose it was collected for – in practice, for the duration of the relevant BKEC event and a reasonable period afterward for organisational and accounting purposes – after which it is deleted or anonymised, unless a longer retention period is required by law.

To protect against data loss, BK-Event's database is backed up automatically. Backups are encrypted (GPG) and retained as follows: local backups for 30 days, daily cloud backups for 30 days, and monthly cloud backups for 365 days. Backups older than these periods are automatically deleted.

9. Your Rights

Under the GDPR, you have the right to:

  • request access to the personal data we hold about you (Art. 15 GDPR);
  • request correction of inaccurate data (Art. 16 GDPR);
  • request erasure of your data (Art. 17 GDPR), where applicable;
  • request restriction of processing (Art. 18 GDPR);
  • receive your data in a portable format (Art. 20 GDPR);
  • object to processing based on legitimate interest (Art. 21 GDPR);
  • withdraw any consent you have given, at any time, with effect for the future (Art. 7 (3) GDPR); and
  • lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).

To exercise any of these rights, please contact us using the details below.

10. Data Protection Contact

For any questions or requests regarding data protection, please contact:

Karl-Michael („Karlo“) Kühnke
Berliner Ring 5
D-49456 Bakum, Germany
Email: webmaster@blue-knights.eu
Phone: +49 4446 9897786 · Mobile: +49 174 9267072

A separate, formally appointed Data Protection Officer has not been designated, as this is a small, non-commercial community project that does not meet the thresholds under Art. 37 GDPR / § 38 BDSG that would require one. Karlo personally acts as the point of contact for all data protection matters.

11. Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for the controller named above is:

Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5, 30159 Hannover (postal address: Postfach 221, 30002 Hannover)
Germany
Phone: +49 511 120-4500
Email: poststelle@lfd.niedersachsen.de
Website: www.lfd.niedersachsen.de

12. Changes to This Policy

We may update this Privacy Policy from time to time, for example when BK-Event's features or processors change. The current version always applies; please check back occasionally if you have concerns.

See also: Legal Notice