Privacy Policy

Contents

1. General Information

2. Controller

3. Data Protection Contact

4. Technical Implementation, Processing and Hosting

5. Provision of the Website and Server Log Files

6. User Account and Authentication in Indico

7. Submission, Review and Selection of Abstracts

8. Personal Data of Co-authors

9. Publication of Accepted Contributions and Programme Information

10. Conference Registration

11. Email Communication and System Notifications

12. Cookies and Technically Necessary Storage on End Devices

13. External Links

14. Recipients, Processors and Technical Service Providers

15. Transfers to Third Countries

16. No Automated Decision-making or Profiling

17. Rights of Data Subjects

18. Right to Lodge a Complaint with a Supervisory Authority

19. Status and Amendments to this Privacy Policy

1. General Information

This Privacy Policy explains which personal data HFES Europe processes when the HFES Conference Platform is used, the purposes for which the data are processed, the legal bases for the processing, who receives access to the data and how long the data are retained.

The platform is based on the open-source software Indico and is used in particular to provide a restricted conference area, manage user accounts and conference registrations, and support the submission, review, selection, programme planning and publication of scientific contributions. Technical implementation is carried out by Technische Universität Chemnitz, Chair of Ergonomics and Innovation, on behalf of HFES Europe.

2. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Human Factors and Ergonomics Society (HFES) – Europe Chapter
Contact via:
Secretary Europe Chapter of the HFES
Mr Niels Brandenburger
DLR
Institute for Transportation Systems
Germany
Email: secretary@hfes-europe.org

3. Data Protection Contact

For data protection enquiries, HFES Europe can currently be contacted at:

Mr Niels Brandenburger
Secretary Europe Chapter of the HFES
DLR
Institute for Transportation Systems
Germany
Email: secretary@hfes-europe.org

4. Technical Implementation, Processing and Hosting

HFES Europe has commissioned Technische Universität Chemnitz to host and technically configure the Indico platform and to provide organisational and technical support for the abstract submission, review and selection process. Technische Universität Chemnitz processes the personal data required for these purposes as a processor within the meaning of Article 28 GDPR, on behalf of and in accordance with the documented instructions of HFES Europe.

HFES Europe, as controller, determines the purposes and essential means of the processing, in particular the personal data collected in connection with the conference, the abstract submission and review process, and the publication of programme information.

The server infrastructure is provided by the University Computer Centre (URZ) of Technische Universität Chemnitz. Installation, configuration and administration of the Indico platform are carried out by authorised staff of Technische Universität Chemnitz, Chair of Ergonomics and Innovation.

As Indico is operated on self-hosted infrastructure, the mere use of the open-source software does not result in personal data stored on the platform being transferred to CERN or the Indico development team.

Data Backups and Recovery

For backup purposes, fully encrypted backup copies are created using a Bareos backup server operated by the URZ. The backups are used solely for recovery in the event of technical faults or data loss and are retained for up to 180 days. Data that have meanwhile been deleted or anonymised in the production system may therefore remain in backup copies until the end of this retention period.

5. Provision of the Website and Server Log Files

When the platform is accessed, technically necessary access data are processed. These may include, in particular, the IP address, date and time, requested resource and HTTP status code, amount of data transferred, browser and operating-system information, referrer URL and, for logged-in users, where applicable, a user identifier in application-related logs. The data are not combined to create advertising or usage profiles.

The legal basis is Article 6(1)(f) GDPR. The legitimate interest lies in providing a functional and secure platform, analysing errors, and preventing misuse and security incidents. Server log files are normally deleted or anonymised after one month unless, exceptionally, they are required for a longer period to investigate a specific security incident. The right to object under Article 21 GDPR is explained in Section 17.

6. User Account and Authentication in Indico

A personal Indico user account is required to access the restricted conference area. In particular, first name, family name, institutional affiliation, email address, authentication data and technical account and login information are processed when the account is created. First name, family name, institutional affiliation and email address are required for full use of the conference platform and its associated functions. Additional profile information may be provided voluntarily where applicable. Passwords are not stored in plain text.

The legal basis for creating and using the user account and for the associated processing of registration, authentication and account data is Article 6(1)(b) GDPR. A user relationship exists between HFES Europe and registered users, and the processing of these data is necessary to perform that relationship. Personalised access cannot be provided without this processing and the processing is therefore objectively necessary for performance of the user relationship. Where personal data are additionally processed for IT security, prevention of misuse, or the management of access and permission arrangements, and such processing is not already covered by Article 6(1)(b) GDPR, the legal basis is Article 6(1)(f) GDPR. The legitimate interest in this respect lies in the secure and proper operation of the platform.

Account data are retained for as long as the account is required for use of the platform. Once the purpose no longer applies, personal account data are deleted or, where complete deletion is not technically possible because necessary links to event data must be retained, anonymised. The retention periods set out below apply to event-related data.

7. Submission, Review and Selection of Abstracts

A personal Indico user account is required to submit an abstract. The first name, family name and institutional affiliation stored in the user account are transferred to the abstract submission as the submitter’s author details and linked to the relevant contribution. In addition, the data processed include, in particular, the link to the user account, the title and content of the abstract, the preferred presentation format, where applicable an indication that a full paper may be submitted at a later stage, and any further academic or organisational information requested as part of the Call for Abstracts.

During the review and selection process, status information, assessments, comments and the information required for programme planning are also processed. Information relating to co-authors is described in Section 8.

The legal basis for processing the submitter’s personal data as part of the abstract procedure is Article 6(1)(a) GDPR. Before the abstract is submitted, explicit consent is obtained and recorded through a separate mandatory consent field in the submission form. The consent covers administration of the submission, the scientific review and selection process, programme planning and the associated communication.

As part of the abstract submission, a preference may be stated for the intended presentation format. This preference is taken into account during the review and selection process and in programme planning. Depending on the review outcome and the available programme slots, the final allocation to a presentation format may differ from the stated preference.

An abstract submission may be withdrawn by notifying the organising team during the review, selection and programme-planning process. Withdrawal of a submission for organisational purposes does not automatically constitute withdrawal of consent under data protection law. For programme information that has already been published, the provisions of Section 9 also apply.

Irrespective of any organisational withdrawal, consent given under Article 6(1)(a) GDPR may be withdrawn at any time with effect for the future. Withdrawal of consent may mean that the relevant submission can no longer be processed, reviewed or considered in the selection and programme-planning process. The lawfulness of processing carried out before consent was withdrawn remains unaffected. Further processing based on consent will cease following withdrawal unless another legal basis applies to a separate processing purpose. Section 4 also applies to backup copies already created.

Submissions that are not accepted or are withdrawn for organisational reasons, together with the associated personal data, are deleted or anonymised no later than twelve months after the end of the relevant conference, unless another legal basis permits or requires longer retention. In the event that consent is withdrawn, the provisions on withdrawal set out above apply.

For accepted contributions and their publication, the provisions of Section 9 also apply.

8. Personal Data of Co-authors

When an abstract is submitted, the first name, family name and institutional affiliation of co-authors are provided as author details and linked to the relevant contribution. These details are generally provided by the submitter. If a co-author already has an Indico user account, the existing person record may instead be linked to the contribution.

The submitter is required to inform the co-authors they have listed about the submission of the contribution and the associated processing of their personal data, and to make this Privacy Policy available to them. The submission form contains a separate authorship confirmation for this purpose. By submitting the abstract, the submitter confirms that the listed co-authors have been informed of the submission, their identification as authors, the intended processing and, where applicable, publication of their author details, and that they have agreed to the submission of the contribution.

As the submitter’s consent does not also constitute consent on behalf of the co-authors, their personal data are processed on the basis of Article 6(1)(f) GDPR. HFES Europe has a legitimate interest in accurately recording and attributing authorship, conducting the scientific review and selection process and, where a contribution is accepted, attributing and publishing it in the scientific conference programme and conference documentation.

It should also be taken into account that naming individuals in connection with a scientific contribution generally serves the interests of the authors concerned in proper academic attribution. The information obligations under Article 14 GDPR remain unaffected.

The retention period depends on the status of the associated contribution. Section 7 applies to contributions that are not accepted or are withdrawn; Section 9 applies to accepted contributions.

9. Publication of Accepted Contributions and Programme Information

For accepted contributions, the contribution title, first and family names of authors and co-authors, where applicable their institutional affiliation, and allocation to programme items may be published on the conference website, in the timetable, in the conference programme and, where applicable, in the conference proceedings or comparable conference materials. Publication may also take place through official HFES Europe channels.

This programme information may be published regardless of whether a poster or full paper is additionally submitted for publication.

For the personal data of the submitter, where the submitter is named as an author of the accepted contribution, the legal basis for publishing and making this programme information permanently available is Article 6(1)(b) GDPR. Publication and permanent documentation of the accepted scientific contribution in the conference programme and conference documentation form part of the performance of the user and participation relationship associated with the submission and conference participation. Section 8 additionally applies to the processing and publication of co-author details; such processing is based on Article 6(1)(f) GDPR. Naming the authors generally also serves the interests of the authors concerned in proper academic attribution.

Following acceptance of a contribution, and depending on the assigned presentation format, authors may voluntarily submit a poster or full paper for publication. These files are not collected through the Indico abstract submission process but are voluntarily sent by email to the organising team. A full paper may be included in the publicly and freely accessible conference proceedings. A voluntarily submitted poster may likewise be made publicly and freely accessible through the channels provided for the conference.

Before sending the file, authors are informed that the voluntarily submitted file is intended to be made publicly available. Where author details contained in published posters and full papers relate to the submitter, they are processed for scientific publication and documentation purposes on the basis of Article 6(1)(b) GDPR. Section 8 additionally applies to co-authors; their author details are processed on the basis of Article 6(1)(f) GDPR. Publication of the scientific work itself is also governed by the publication and copyright terms applicable to the relevant publication format.

A contribution withdrawn for organisational reasons before publication of the conference programme will generally not be included in subsequent publication. Once publication has taken place, changes, withdrawals, retractions or notices relating to a contribution are additionally governed by the scientific and publishing rules applicable to the relevant publication format. The data protection rights of the individuals concerned remain unaffected.

The published scientific programme and the information it contains about accepted contributions are generally retained permanently beyond the end of the conference as scientific conference documentation and as a conference archive. The same applies to published conference proceedings and posters voluntarily provided for publication, unless the applicable publication and withdrawal rules provide for a subsequent change. Copies already downloaded or stored by third parties cannot always be fully recalled or removed from circulation.

Where co-author details are processed on the basis of Article 6(1)(f) GDPR, the individuals concerned have the right under Article 21 GDPR to object to the processing on grounds relating to their particular situation. The other rights of data subjects are described in Section 17.

Contact details, account data and internal processing data that are not required for scientific documentation are subject to the separate retention and deletion periods specified for those data.

10. Conference Registration

Registration via the Indico platform is required to attend the conference. The data processed include, in particular, first name, family name, institutional affiliation, academic degree or title and the link between the registration and the user account. Further information is collected only to the extent required for the specific organisation of the conference. Payment processing via Indico is not envisaged.

The legal basis is Article 6(1)(b) GDPR. The processing is necessary for registration and for organising and conducting conference participation. Mandatory information is required for registration; additional information that is not necessary is provided on a voluntary basis.

Registration data are required only for organising, conducting and following up the conference and are deleted or anonymised no later than twelve months after the end of the relevant conference, unless a statutory retention obligation or another legal basis permits or requires longer retention. Registration data are not published.

11. Email Communication and System Notifications

Indico sends automated emails, in particular in connection with account and registration administration, abstract submissions and review status, as well as organisational information. The data processed comprise the email address and, depending on the process, the name and the event and usage data required for the message. Emails are sent through the email infrastructure of Technische Universität Chemnitz; no external newsletter, marketing or transactional email service is used.

If you contact HFES Europe by email in connection with the conference, reply to a system notification, or voluntarily submit a poster or full paper for publication, the contact details, content and any attachments you provide are processed for the purpose of handling the relevant matter. For general organisational communication relating to the user account, registration and conference participation, the legal basis is generally Article 6(1)(b) GDPR; abstract-related communication is covered by the consent described in Section 7. Section 9 applies to the publication of author details in posters and full papers.

Data stored in Indico are subject to the respective retention periods set out in Sections 6, 7 and 10. Direct email correspondence and unpublished attachments are retained only for as long as necessary to handle, conduct and document the relevant matter. Section 9 applies to published posters and full papers. Technical SMTP/mail-server logs are retained in accordance with the requirements of the TU email infrastructure only for as long as necessary for delivery, troubleshooting and IT security.

Where technical SMTP/mail-server logs are processed for troubleshooting and IT security, and such processing is not already covered by the legal basis applicable to the underlying communication, the processing is based on Article 6(1)(f) GDPR. The legitimate interest lies in the secure and reliable operation of the email infrastructure.

12. Cookies and Technically Necessary Storage on End Devices

The platform uses technically necessary first-party cookies. In particular, Indico sets the indico_session session cookie to manage the user session, maintain login status and enable the use of restricted functions. Technical security mechanisms, in particular CSRF protection mechanisms, are also used to protect against abusive requests. Cookies for advertising, tracking, profiling or audience-measurement purposes are not envisaged.

The storage of, or access to, technically necessary information on the end device is based on Section 25(2) no. 2 TDDDG, insofar as this provision applies to the provision of the service. Where personal data are processed to manage the user session, maintain login status and enable the use of restricted functions, the legal basis is Article 6(1)(b) GDPR. Where personal data are processed as part of technical security mechanisms for IT security and the prevention of misuse, and such processing is not already covered by Article 6(1)(b) GDPR, the legal basis is Article 6(1)(f) GDPR; the legitimate interest in this respect lies in the secure and functional operation of the platform. Technically necessary cookies can be deleted or blocked in the browser, which may impair restricted functions.

Current Cookie Overview

Cookie

Provider

Purpose

Retention Period

indico_session

HFES Europe / technical provision by Technische Universität Chemnitz

Management of the user session and login status

31 days of inactivity

13. External Links

The conference website may contain ordinary hyperlinks to external services. A link to Google Maps may be provided for the conference venue. Google Maps is not embedded; merely accessing the conference platform therefore does not load any maps, scripts or frames from Google. Only when the link is actively clicked does the browser establish a connection to the relevant external provider, which is responsible for the subsequent processing of data.

Links from LinkedIn, the HFES Europe website or other external sites to the Indico conference page do not constitute an integration of those services into the conference platform. Any referrer URL transmitted may form part of the technical access data described in Section 5.

14. Recipients, Processors and Technical Service Providers

Personal data are made available only to persons who require them for the relevant task. These may include, in particular, authorised members of the organising team and the scientific programme committee, reviewers, and technically authorised administrators.

Technische Universität Chemnitz processes personal data on behalf of HFES Europe for hosting, technical configuration and administration of the platform, as well as for the agreed organisational support of the abstract process. The University Computer Centre provides the technical infrastructure within Technische Universität Chemnitz. Use of the self-hosted open-source software Indico does not make CERN or the Indico development team processors. No external payment service providers, newsletter providers, web analytics services or tracking services are currently used.

Where programme information, posters or full papers are published, the information concerned is accessible to the public.

15. Transfers to Third Countries

Under the current arrangements, no transfer of personal data to recipients outside the European Union or the European Economic Area is envisaged for the technical operation of the conference platform. If members of a programme or review committee outside the EEA are to be granted access to personal data, it will be assessed before access is enabled whether and on what basis a transfer to a third country is permissible under Articles 44 et seq. GDPR, and whether access can be limited to what is necessary.

16. No Automated Decision-making or Profiling

No solely automated decision-making within the meaning of Article 22 GDPR takes place. In particular, abstracts are not accepted or rejected solely by automated means. No profiling is carried out for advertising, marketing or behavioural-analysis purposes.

17. Rights of Data Subjects

Subject to the applicable statutory requirements, data subjects have, in particular, the following rights:

·         Right of access under Article 15 GDPR;

·         Right to rectification under Article 16 GDPR;

·         Right to erasure under Article 17 GDPR;

·         Right to restriction of processing under Article 18 GDPR;

·         Right to notification under Article 19 GDPR;

·         Where applicable, right to data portability under Article 20 GDPR;

·         Right to object under Article 21 GDPR where processing is based on Article 6(1)(f) GDPR. The objection may be based on grounds relating to the particular situation of the data subject;

·         Right to withdraw consent: Consent given under Article 6(1)(a) GDPR may be withdrawn at any time with effect for the future. The lawfulness of processing carried out before consent was withdrawn remains unaffected.

To exercise these rights, data subjects may contact HFES Europe or the data protection contact specified in Section 3.

18. Right to Lodge a Complaint with a Supervisory Authority

Under Article 77 GDPR, data subjects have the right to lodge a complaint with a data protection supervisory authority if they consider that their personal data are being processed unlawfully. A complaint may, in particular, be lodged with the supervisory authority for the place of habitual residence, place of work or place of the alleged infringement.

Competent data protection supervisory authority:
Autoriteit Persoonsgegevens
Postbus 93374
2509 AJ Den Haag
Netherlands

19. Status and Amendments to this Privacy Policy

This Privacy Policy is current as at 1 September 2026. It will be updated if the technical functions of the platform, the data collected, the services used, organisational responsibilities or the applicable legal framework change.