Last updated: 23 July 2026
1. Controller
The controller responsible for the processing of personal data on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Stichting ASD Trustee Engweg 65 3972 JD Driebergen, The Netherlands Chamber of Commerce (KvK) no.: 30274037
Email: fg@asd-international.org Represented by: Ron Henkes
For data protection enquiries, please contact Jakob Tewes at admin@asd-international.org.
We have not appointed a Data Protection Officer. We are not required to do so under Article 37 GDPR, as we have no employees, do not carry out large-scale monitoring, and do not process special categories of personal data on a large scale. All data protection enquiries should be addressed to Jakob Tewes at admin@asd-international.org.
2. Scope and applicable law
This policy applies to the website https://www.asd-international.org, including the member and community area and the conference registration forms operated under this domain, and to the file exchange we provide to conference participants and members.
Processing is governed by the GDPR and, as national implementing law, by the Dutch Uitvoeringswet AVG (UAVG). The storage of information on, and access to information already stored in, your terminal equipment is governed by Article 11.7a of the Dutch Telecommunicatiewet.
3. Legal bases
Depending on the processing operation, we rely on:
- Article 6(1)(a) GDPR – consent, which you may withdraw at any time with effect for the future;
- Article 6(1)(b) GDPR – performance of a contract or membership relationship, or steps taken at your request prior to entering into one;
- Article 6(1)(c) GDPR – compliance with a legal obligation;
- Article 6(1)(f) GDPR – our legitimate interests, in particular the secure, stable and functional operation of this website.
4. Hosting and server log files
This website is hosted by:
ALL-INKL.COM – Neue Medien Münnich, Inh. René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany
All servers are located in Germany. All-INKL acts as our processor. A data processing agreement pursuant to Article 28 GDPR is in place.
When you access this website, the server automatically records data transmitted by your browser in log files:
- the page or file requested,
- date and time of the request,
- volume of data transferred,
- HTTP status code,
- referring URL,
- browser type and version, operating system,
- the requesting IP address in anonymised form.
IP addresses are anonymised before storage; we are therefore unable to identify individual visitors from log files. Log data is stored for 14 days and is deleted thereafter. The processing serves to ensure the operation, security and stability of the website and is based on Article 6(1)(f) GDPR.
5. Transport encryption
This website uses TLS encryption (HTTPS) on all pages. You can recognise an encrypted connection by the padlock symbol in your browser’s address bar.
6. Cookies and local storage
The publicly accessible pages of this website do not set cookies and do not store or read any other information on your device beyond what is strictly necessary to deliver the pages.
Cookies and local storage are used only in the member and community area, which we operate on our own server. These are strictly necessary for the functionality you have requested — maintaining your login session, security tokens against cross-site request forgery, and your interface preferences. Under Article 11.7a(3) Telecommunicatiewet, no consent is required for storage that is strictly necessary to provide a service you have expressly requested. The associated processing of personal data is based on Article 6(1)(b) GDPR.
Session cookies are deleted when you close your browser or when you log out. Persistent login cookies remain valid for the period configured by our login and security components and are removed when you log out. You can delete these cookies at any time through your browser.
You can configure your browser to block or delete cookies. If you block cookies for this domain, you will not be able to log in to the member area.
7. Contact and conference registration
Registration forms for our conferences and events, and any contact forms, are operated on our own server using self-hosted form software. Form data is not transmitted to any third-party form provider.
Data processed: the fields marked as mandatory in the respective form (typically name, email address, organisation, and event-specific details) as well as any optional information you choose to provide. Data is stored in the database of this website and used exclusively to process your registration, to communicate with you about the event, and to fulfil related obligations.
Legal basis: Article 6(1)(b) GDPR for registration and participation; Article 6(1)(f) GDPR for general enquiries, in our legitimate interest in responding to them.
Retention: registration data is retained for the duration of the event and afterwards for as long as necessary to settle the event, and for the periods required by statutory retention obligations where financial records are concerned. Enquiries not leading to a contractual relationship are deleted once the matter is concluded, unless statutory retention obligations apply.
8. Member area and member directory
Access to the member area requires an account. We process the account data you provide and the data generated by your use of the area (login timestamps, content you post in the community area).
The member directory displays only the information you have actively chosen to make visible in your profile settings. You control which fields are published and can change or withdraw this at any time in your profile. Publication of profile data in the directory is based on your consent under Article 6(1)(a) GDPR; withdrawal takes effect for the future and does not affect the lawfulness of prior publication.
Content you post in the community area is visible to other logged-in members. Do not post personal data of third parties there without a legal basis for doing so.
Account data is deleted when your membership ends, unless statutory retention obligations require otherwise.
9. Member communication and member letters
For communication with members and registered participants we use FluentCRM, a self-hosted application running on our own server at our hosting provider. Your email address and communication data are not transmitted to any external service.
We send member letters — regular information for our members and participants. Where several types of member letter are offered, you can choose which ones you wish to receive and change your selection at any time. We do not use a double opt-in procedure. Legal basis: Article 6(1)(b) GDPR, as part of the membership relationship; where you opt into an optional category of member letter, Article 6(1)(a) GDPR.
We record whether emails are delivered and whether the links they contain are clicked, in order to assess and improve our member communication. If you object to this, please contact us.
You can unsubscribe at any time using the link at the end of every email or by contacting us. Following unsubscription we retain your address on a suppression list for the sole purpose of preventing further mailings, unless you request full deletion.
10. Sending of emails
Outgoing emails from this website are sent via the SMTP servers of our hosting provider ALL-INKL.COM using self-hosted mail configuration software. No external email delivery service is used. Transport takes place over encrypted connections where the receiving server supports this. We cannot guarantee end-to-end encryption of email content; for confidential matters please contact us to agree an alternative channel.
11. File exchange (Nextcloud)
For the exchange of documents with members, conference participants and applicants we operate a Nextcloud instance hosted by:
wolkesicher.de – MEHRTENS.IT, Inh. Eduard Mehrtens, Am Hagen 15, 28790 Schwanewede, Germany
The provider acts as our processor; a data processing agreement pursuant to Article 28 GDPR is in place. Servers are located in Germany.
Nextcloud is not accessible from the public website. Share links are issued only to persons who have registered for a conference or who are members or applicants. When you open a share link, the Nextcloud server processes the technical connection data described in section 4 and records access to the shared resource. The processing serves the provision of documents to registered participants and is based on Article 6(1)(b) GDPR.
Shared files and the associated access logs are deleted once the purpose of the exchange has been fulfilled, at the latest one year after the end of the respective event.
12. Links to social media
Our website contains plain hyperlinks to our profiles on social media platforms. These are simple links; no plugins, buttons or embedded content of the platform operators are integrated. No data is transmitted to the platform operators when you visit our website. Data is only transmitted once you click a link and leave our site, at which point the privacy policy of the respective platform applies.
13. Recipients of personal data
We do not sell personal data and do not disclose it to third parties for their own purposes. Personal data is accessible to:
- ALL-INKL.COM – Neue Medien Münnich (hosting and email, processor, Germany);
- MEHRTENS.IT – Inh. Eduard Mehrtens (Nextcloud hosting, processor, Germany);
- members of our board and authorised volunteers, to the extent required for their tasks;
- public authorities, where we are legally obliged to disclose.
14. Transfers to third countries
We do not transfer personal data outside the European Economic Area. All processors we engage are located within the EEA (Germany).
15. Retention
We retain personal data only for as long as necessary for the purposes described above, or for as long as statutory retention obligations require. Specific periods are stated in the relevant sections. Where no period is stated, data is deleted once the purpose for which it was collected ceases to apply.
16. Your rights
Under the GDPR you have the right to:
- obtain confirmation as to whether we process personal data concerning you, and access to that data (Article 15);
- have inaccurate data corrected (Article 16);
- have your data erased (Article 17);
- have processing restricted (Article 18);
- receive your data in a structured, commonly used, machine-readable format and to have it transmitted to another controller (Article 20);
- object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(f) GDPR, and to object at any time to processing for direct marketing purposes (Article 21);
- withdraw consent at any time with effect for the future (Article 7(3)).
To exercise these rights, contact us using the details in section 1.
You also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement (Article 77 GDPR). The authority competent for us is:
Autoriteit Persoonsgegevens Postbus 93374, 2509 AJ Den Haag, The Netherlands https://www.autoriteitpersoonsgegevens.nl
17. No automated decision-making
We do not use automated decision-making, including profiling, within the meaning of Article 22 GDPR.
18. Obligation to provide data
You are not legally or contractually obliged to provide personal data. However, without the data marked as mandatory in our forms we cannot process your conference registration or maintain a membership account.
19. Changes to this policy
We may amend this policy to reflect changes in our processing activities or in legal requirements. The version published on this page at the time of your visit applies.