Privacy Statement
Last update: October 2026
1. Graphics Programming Conference
Stichting Graphics Programming Conference is a Dutch foundation, registered with the Dutch Chamber of Commerce (KVK) under number 97310972. It organises the Graphics Programming Conference. Our address is Molenstraat 41a, 4844 AM Terheijden, The Netherlands. We store our data on servers in the European Economic Area (“EEA”).
2. General
This privacy statement (“Privacy Statement”) explains when and how Stichting Graphics Programming Conference (also referred to as “us”, “our” and “we”) collects, uses, protects and discloses your personal data. It applies when you visit our website, graphicsprogrammingconference.com, and its subdomains (“Website”). It also applies when you buy a ticket for or attend our conference, submit or give a talk, email us, or work with us as a sponsor.
We are the controller of the personal data described in this Privacy Statement.
We may change this Privacy Statement from time to time. If we make substantial changes, we will announce them on the Website. We recommend that you check this page periodically for changes.
3. Which personal data do we process?
Below we explain, for each situation, which personal data we process, why we process it, on what legal basis and how long we keep it.
3.1 Visitors to our Website
We do not set cookies on our main website, and it has no accounts, forms or newsletter signup. The Weeztix ticket shop embedded on our home page and tickets page is loaded from Weeztix and may set its own cookies (see section 3.2). The submission system is described in section 3.3.
A. Hosting. The Website, our analytics, the submission system and our file storage run on servers rented from Hetzner Online GmbH in Germany. To deliver the Website and keep it secure and working, our web server receives the data below. It may record this data in access logs, which we use to fix technical problems and to investigate abuse. We keep these logs for at most 90 days. Our processing basis is our legitimate interest in running a secure and working Website.
- IP address
- Date and time of the request
- The page or file requested
- The referring page
- Browser information
B. Statistics. To understand how the Website is used, we run our own installation of Plausible Analytics on our own server. Plausible does not use cookies and does not store your IP address or browser information. It uses them only to count unique visitors with a code that changes every day. As a result, the statistics cannot identify you. Because the statistics cannot identify you, we keep them indefinitely. Our processing basis is our legitimate interest in improving the Website. Your interests are safeguarded because the data collected is limited and cannot identify you. Plausible records:
- The pages you visit and the page that referred you
- Location data at country level, and where available region and city level
- Device type, browser and operating system
- Campaign tags in the link you followed (for example
utm_source)
C. Campaign tags. If you arrive through a link that contains campaign tags (utm_ parameters), the Website keeps these tags in your browser’s session storage until you close the tab. If you then open the ticket shop, the tags are passed on to it. Within the Website no identifier is stored. If you buy a ticket, Weeztix records the tags with your order, so that we can see which campaigns lead to ticket sales. Our processing basis is our legitimate interest in measuring the effectiveness of our promotion.
D. Venue map. The venue page shows a map. To display it, your browser loads the map software from unpkg.com, which is delivered through Cloudflare, and the map images from the OpenStreetMap Foundation in the United Kingdom. These parties receive your IP address and browser information when you open the venue page. Cloudflare is based in the United States and is certified under the EU-U.S. Data Privacy Framework. The United Kingdom is covered by an EU adequacy decision. See the privacy policies of Cloudflare and the OpenStreetMap Foundation. Our processing basis is our legitimate interest in showing visitors where the venue is.
E. Links to other websites. Talk recordings are published on YouTube, and the Website links to them. When you follow such a link, Google’s privacy policy applies.
3.2 Ticket buyers and attendees
A. Buying a ticket. Our ticket shop is provided by Weeztix and is loaded from Weeztix’s servers. Weeztix processes the data below on our behalf. For payment handling, its own cookies and its own services, Weeztix’s privacy policy applies. We do not receive your full payment card details.
To sell you a ticket, send it to you and invoice you, we process the data below. Our processing basis is the performance of our agreement with you. For invoices and payment records, it is also our legal obligation. You need to provide this data to buy a ticket; without it we cannot issue or invoice one.
- First and last name
- E-mail address
- Country
- Company (optional)
- VAT details, if your company buys the ticket
- Payment information
B. At the conference. We also ask for the data below, for the purposes listed. Our processing basis is our legitimate interest in running a safe event and in understanding our audience. Your interests are safeguarded because we use statistics only in aggregated form.
- Date of birth, to check the age of attendees
- Phone number, so we can reach you in an emergency during the conference
- Gender and city, to compile statistics about our audience
C. Updates. If you tick “Keep me updated about this and future events”, we use your name and e-mail address to inform you about this and future conferences. Our processing basis is your consent. You can withdraw it at any time by following the instructions in each e-mail or by contacting us.
D. Sponsors. We do not share attendee data with sponsors. We only tell sponsors how many people attend.
E. Retention. We keep invoices and payment records for 7 years, as Dutch tax law requires. We do not keep copies of ticket data outside Weeztix. We keep the other ticket data in our Weeztix account for 2 years after the conference.
3.3 Speakers and reviewers
A. Submissions. Talk proposals are handled in our own submission system at submissions.graphicsprogrammingconference.com. To review and schedule proposals and organise the conference, we process the data below. Our processing basis is the performance of our agreement with you as a submitter, speaker or reviewer.
- Name
- E-mail address
- Title and affiliation
- Phone number (optional)
- Photo
- Your proposals, slides and other material you upload
- Comments and reviews on submissions
Organisers can see this data. Assigned reviewers can see the submissions and comments, and a submission’s authors can see the comments on it. Name, e-mail address and affiliation are needed to take part; without them we cannot review or schedule your proposal.
The submission system uses a cookie to keep you logged in. It records actions taken in the system, and which e-mails it sent you, so that changes can be traced and abuse investigated. Our processing basis for this log is our legitimate interest in keeping the system secure. It sends e-mails through Scaleway. Uploaded files are stored with Hetzner in Germany.
B. Travel. If we arrange your hotel, a visa invitation letter or travel reimbursement, we process the data needed for that. This can include passport details and bank account details. Passport and bank details are stored encrypted. Passport details and visa letters are deleted 6 months after the last conference you spoke at. Bank details are deleted once your reimbursement claims are settled. If we book your hotel, we share your name and stay dates with the hotel. Our processing basis is the performance of our agreement with you.
C. Publication and recordings. If your talk is accepted, we publish your name, title, affiliation and photo together with the talk’s title and description on the Website and in our archive, and the slides if you choose to share them. We record talks and publish the recordings on YouTube. Our processing basis is the performance of our agreement with you as a speaker. If you cannot be recorded, tell us before the conference and we will not publish a recording of your talk.
D. Retention. We keep your account data until you delete your account. You can do so at any time in the submission system. Deleting your account removes your photo, contact details and travel data, and detaches your name from your submissions, comments and reviews, which are kept in anonymised form. To prevent abuse, we keep a keyed hash of your e-mail address for 24 months, or longer if the account was banned; it cannot be read back to your address. The system’s action log is kept with your name removed. Talks that have already been published remain part of the conference’s public archive, with your name, title and affiliation as published at the time. Our processing basis for keeping the archive is our legitimate interest in maintaining a historical record of the conference. If you want a recording or a published entry removed, contact us and we will consider your request.
3.4 Photos at the conference
We take photos at the conference. We do not publish photos of individual attendees publicly. We do publish photos of the conference that may show attendees, and we share photos of speakers on stage with those speakers. Our processing basis is our legitimate interest in documenting and promoting the conference. If you do not want to be photographed, please tell us at the conference. If you are in a photo and want it removed, or want yourself blurred out, contact us and we will do so.
3.5 When you contact us
A. Questions and requests. When you email us, we process the data below to respond to your question or request. We keep it for 2 years after we last had contact with you. Our processing basis is our legitimate interest in responding to questions and requests.
- Name
- E-mail address
- Organisation
- Content of any communications you have with us
Our mailboxes are hosted by mailbox.org. Outgoing e-mail may be sent through Scaleway.
B. Code of conduct reports. Reports to complaints@graphicsprogrammingconference.com can be read only by the conference organisers. A report may contain sensitive information about you or others. We use it only to handle the report and to keep our events safe, and we process any sensitive information in it only to the extent needed for that and to establish or defend legal claims. We keep reports for 2 years after the report has been handled, or longer if this is needed to prevent a repeat incident or to deal with a legal claim. Our processing basis is our legitimate interest in providing a safe event.
3.6 Sponsors and partners
If you are the contact person for a sponsor or partner, we process the data below to arrange and fulfil the sponsorship. We keep it for 2 years after we last had contact with you. We keep contracts and invoices for 7 years, as Dutch tax law requires. Our processing basis is the performance of our agreement with your organisation and our legitimate interest in maintaining the relationship.
- Name
- E-mail address
- Phone number
- Organisation and function
- Content of communications you have with us
4. Sharing your personal data
4.1 Our data processors
Some parties help us run the conference and the Website. These processors process personal data on our behalf, and we agree with them that they may only use it to provide their service to us. Their own privacy policies describe how they handle data:
- Hetzner hosts our servers and file storage in Germany.
- Weeztix runs our ticket shop.
- mailbox.org hosts our mailboxes.
- Scaleway sends e-mail on our behalf.
We run Plausible Analytics, Nextcloud (at storage.graphicsprogrammingconference.com) and our submission system ourselves on our Hetzner servers. The makers of this software do not receive your data.
4.2 Sharing your personal data with third parties
We only share your personal data with third parties if this is:
- described in this Privacy Statement and we have a legitimate basis for this;
- reasonably necessary or appropriate to comply with our legal obligations;
- necessary to comply with legal requests from authorities;
- necessary to respond to any claims;
- necessary to protect the rights, property or safety of us, our attendees, our speakers or the public;
- necessary to protect ourselves and others from fraudulent, offensive, inappropriate or unlawful use of our services.
We will inform you immediately if a government agency makes a request relating to your personal data, unless we are prohibited from doing so by law.
Our Website also contains links to websites of other parties. If you provide your personal data on these third-party pages, the privacy statement of these third parties applies. We are not responsible for the content of the privacy statement of these third parties and the way in which these parties process your personal data. We encourage you to review their privacy statement before providing any personal information to them.
5. Protection of your personal data
We have taken appropriate technical and organisational security measures to protect your personal data. These measures include:
- Our servers are physically and digitally secured so that people cannot view your personal data without our consent.
- We ensure that data is sent encrypted between your browser and our servers.
- Vulnerabilities in the Website and the submission system are addressed as soon as possible.
- Physical and electronic measures are designed to prevent unauthorised access, loss or misuse of personal data as much as possible.
We would like to emphasise that the internet is never fully secure. Be careful what you share via the internet. If in doubt, contact us first.
6. Your rights
6.1 Rights
You have certain rights regarding your personal data. The rights mentioned below are not absolute rights. We will always consider the interests involved to see if we can reasonably meet your request. If this is reasonably not possible (for example, because it would be at the unreasonable expense of the privacy (rights) of others), we may refuse your request. If we refuse a request, we will tell you why.
A. Right to access and transfer data
You have the right to request which personal data we process about you. You can also ask us:
- what (types of) personal data we process about you;
- on what basis we process your personal data and for what reasons;
- which parties and what type of parties we share your personal data with;
- how long we store your personal data;
- where the personal data comes from, and;
- whether we use automated decision-making.
You may also request a copy of your personal data processed by us. If you want additional copies, we may charge a reasonable fee for them.
B. Right to rectification
When personal data processed by us is incorrect or incomplete, you may request us to adjust or supplement your personal data. If we approve your request, we will, insofar as this is reasonably possible, inform the parties to whom we provide data.
C. Right to erasure of data
You can request us to delete personal data when you no longer want us to process certain personal data.
If we have accidentally processed data unlawfully or a specific law prescribes that we must delete data, we will delete the data. If the data is necessary for the settlement of a legal procedure or a (legal) dispute, we will only delete the personal data after the procedure or dispute has ended.
If we approve your request, we will, as far as is reasonably possible, inform the parties to whom we provide data.
D. Restriction of processing
If you believe that we are not processing the correct personal data about you, or if you believe that we are processing your personal data unlawfully or no longer need it, you can request us to restrict the processing of that personal data. For example, during the time that we need to assess your request, or if there is no lawful basis (anymore) but you still have an interest in us not deleting the personal data yet. If we restrict the processing of your personal data at your request, we may still use that data for the settlement of legal proceedings or a (legal) dispute.
E. Right to object
Where we process your personal data on the basis of our legitimate interest, you can object to this processing on grounds relating to your particular situation. We will then stop, unless we have compelling legitimate grounds that outweigh your interests, or need the data for a legal claim.
F. Automated individual decision-making
We do not make decisions based solely on automated processing.
G. Withdrawal of consent
Where we process your personal data based on your consent, you may withdraw your consent at any time by contacting us. Our contact details are described below. Withdrawing your consent does not affect processing that took place before you withdrew it.
6.2 Exercising your rights
Requests can be sent to: contact@graphicsprogrammingconference.com.
Before responding to your request, we will verify that it concerns your personal data. We usually do so by replying to the e-mail address that the data belongs to.
We aim to deal with your request or complaint within one month. If we are not able to do so, we will notify you of the reasons for the delay and when our reply is expected to be provided. This can never be longer than 3 months after receipt of your request or complaint.
6.3 Dutch Data Protection Authority / Autoriteit Persoonsgegevens
Please contact us if you have any complaints about our processing. If we cannot come to an agreement with you, you also have the right to file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). Contact details can be found here: autoriteitpersoonsgegevens.nl.
7. Contact details
Stichting Graphics Programming Conference
Molenstraat 41a
4844 AM Terheijden
The Netherlands
For questions, concerns or comments about this Privacy Statement, please contact us by e-mail at: contact@graphicsprogrammingconference.com.
