top of page

Privacy Policy

HIVE FESTIVAL 2027 – PRIVACY POLICY

Legal Notice

This English version of the Privacy Policy is provided for convenience only. In the event of any discrepancy between the German and the English version, the German version shall prevail and shall be the sole legally binding version.

As of: 21 July 2026

1 Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and the other applicable data protection provisions, in particular the German Federal Data Protection Act (BDSG) and the German Telecommunications-Telemedia Data Protection Act (TDDDG), is:

On Point Productions GmbH
Storkower Straße 121
10407 Berlin
Germany

Email: info@hive-festival.de
Website: www.hive-festival.de

No data protection officer has been appointed, as the controller has assessed that the statutory requirements for a mandatory appointment under Article 37 GDPR in conjunction with Section 38 BDSG are currently not met. This assessment is reviewed on an ongoing basis, in particular with regard to the scope of automated processing of personal data in connection with ticket sales, the festival app and the cashless system. Data protection inquiries by visitors, ticket holders and other data subjects should be addressed to the email address stated above.

2 General Information
This Privacy Policy informs you about the scope and purposes for which the controller processes personal data in connection with HIVE Festival 2027, taking place from 17 to 21 June 2027 in Ferropolis, Ferropolisstraße 1, 06773 Gräfenhainichen. It covers both the processing carried out in connection with the operation of the website www.hive-festival.de and the processing carried out in connection with ticket sales, the festival app, the cashless system, event photography and other festival-related services.

Personal data means any information relating to an identified or identifiable natural person. Processing takes place exclusively on one of the legal bases set out in Article 6(1) GDPR, in particular for the performance of a contract or the taking of pre-contractual steps, for compliance with a legal obligation, for the purposes of the legitimate interests pursued by the controller or a third party, or on the basis of freely given consent. The applicable legal basis is specified in the respective chapter below for each processing activity.

Unless expressly stated otherwise, the provision of personal data is neither required by law nor by contract. In certain cases, however, such as the purchase of a personalised ticket or the use of the cashless system, it is necessary for the conclusion or performance of the respective contract; without such data, the relevant service cannot be provided.

3 Hosting
The website www.hive-festival.de is operated and hosted on the Wix.com Ltd. platform. In the course of hosting, Wix processes personal data on our behalf as a processor within the meaning of Article 28 GDPR, in particular data generated when the website is accessed and used, including server log files, IP addresses and the information submitted through forms and order processes.

A data processing agreement pursuant to Article 28 GDPR is in place with Wix. As Wix may maintain server locations outside the European Union and the European Economic Area, reference is made to Chapter 15 on international data transfers. The use of the hosting provider is based on the controller's legitimate interest in a secure, stable and performant provision of the website pursuant to Article 6(1)(f) GDPR.

4 Website Visits
When the website is accessed, the hosting provider automatically collects information in so-called server log files, which the browser of the accessing device automatically transmits. This includes, in particular, the IP address of the requesting device, the date and time of access, the page accessed, the amount of data transferred, the browser type and version used, the operating system used, and the previously visited page (referrer URL).

This data is processed to ensure a smooth connection, to ensure convenient use of the website, to evaluate system security and stability, and for administrative purposes. The legal basis is Article 6(1)(f) GDPR. Server log files are stored for security reasons for a maximum period of seven days and are then deleted or anonymised, unless a statutory retention obligation applies or a specific reason for further evaluation exists, for example in the event of a security-related incident.

5 Cookies
Cookies and comparable technologies, in particular local storage and pixels, are used when visiting the website. Cookies are small text files that are stored on the user's device and contain certain information.

Technically necessary cookies, without which the website or individual functions thereof cannot be operated properly, are set without consent as permitted by law.

For all other cookies and comparable technologies, in particular for analytics and marketing purposes, freely given, informed and granular consent is obtained via a cookie consent banner before such technologies are used. Consent may be withdrawn at any time with effect for the future via the cookie or privacy settings accessible through the banner or the footer of the website.

The consent management tool logs the consents given and refused in order to demonstrate compliance with legal requirements.

Details of the specific cookies used, their purpose, providers, storage period and category can be found in the cookie overview available in the cookie banner.

6 Ticket Sales
Ticket sales for HIVE Festival 2027 are carried out via the technical ticketing service provider Ticket.io. During the ordering process, first and last name, date of birth, email address, billing address, telephone number (where applicable) and the payment data required for the selected payment method are processed.

All festival tickets and designated add-on passes are issued in personalised form. The data of the ticket holder is permanently linked to the ticket and is used at admission to verify the holder's identity against an official photo ID.

Where a ticket is officially transferred to another person, the data of the new ticket holder is processed accordingly.

Where a ticket is submitted through the official refund system, the required order, ticket and payout information is processed in order to manage the resale and refund.

Payment data is transmitted only to the selected payment service provider. The controller does not store complete payment card details.

To prevent fraud, multiple use of access media and unauthorised resale, ticket, order and admission data may be automatically cross-checked.
 

7 Festival App

Where ticket holders use the festival app, personal data is processed in connection with registration and use, in particular the data provided when creating an account, ticket and admission-related information, data on cashless balances and, where separate authorisation has been granted for this purpose, location data for displaying the site map and personalised content.

The legal basis for account management and the core functions of the app, including displaying the ticket, programme and cashless balance, is Article 6(1)(b) GDPR.

For functions going beyond contract performance, in particular push notifications with programme information, promotional content or the collection of location data, separate consent is obtained prior to first use. Consent may be withdrawn at any time in the app settings.

Safety-related push notifications, such as evacuation notices, weather warnings or urgent programme changes, may be sent independently of marketing consent where necessary to protect visitors and ensure the safe operation of the festival.

Where the festival app relies on third-party technical services, such as mapping or push notification services, the provisions described in Chapters 13 and 14 also apply.
 

8 Contact Forms

The website provides several contact options, including a general contact form, a dedicated awareness contact form and a contact option for artists and management.

When using one of these forms, the data entered, including your name, email address, message and any voluntarily provided information, is processed solely for handling and responding to your enquiry.

Where the enquiry relates to the initiation or performance of a contract, processing is based on Article 6(1)(b) GDPR. In all other cases, processing is based on the controller's legitimate interest in efficiently handling enquiries.

The awareness contact form may contain sensitive information, including reports relating to discrimination, assaults or health-related matters. Such information is processed only where it is voluntarily provided by the data subject and only where legally permitted under Article 9 GDPR. Access to these enquiries is restricted to the awareness team and, where necessary, festival management.
 

9 Newsletter

Visitors may subscribe to the HIVE Festival newsletter by providing their email address and, optionally, their name.

Subscription uses the double opt-in procedure. After registration, a confirmation email is sent containing a confirmation link. The newsletter is only activated after this link has been confirmed.

The legal basis for newsletter distribution is the user's consent pursuant to Article 6(1)(a) GDPR.

The time of subscription, confirmation and the IP address used are stored in order to document the proper subscription process where legally required.

Consent may be withdrawn at any time by clicking the unsubscribe link contained in every newsletter or by contacting the organiser directly. Following withdrawal, the relevant personal data will be deleted unless statutory retention obligations apply.

Newsletter delivery may be carried out by a specialised service provider acting on behalf of the controller under a data processing agreement pursuant to Article 28 GDPR.
 

10 Applications

The website allows applications for the volunteer programme as well as applications from vendors and catering partners.

For volunteer applications, personal data such as name, contact details, date of birth, preferred areas of work and any additional voluntarily submitted information is processed.

For vendor applications, contact details of the business or responsible contact person, business information and application documents are processed.

Processing is based on Article 6(1)(b) GDPR where necessary for the initiation of a contractual relationship and otherwise on the controller's legitimate interest in conducting an orderly application and selection process.

Application documents relating to unsuccessful applications are deleted after completion of the selection process unless consent has been given for longer storage for future editions of the festival.
 

11 Cashless Payment

The event is operated wholly or partly as a cashless festival.

The cashless system uses a payment medium, such as a festival wristband with an integrated chip or a corresponding function within the festival app.

The system processes transaction data including top-ups, purchases, payment times, points of sale and current account balances.

Where the payment medium is personalised, it is linked to the ticket information described in Chapter 6.

Processing is based on Article 6(1)(b) GDPR for the provision of the cashless service and Article 6(1)(f) GDPR for fraud prevention and the secure operation of payment transactions.

Unused balances may be refunded in accordance with the published cashless terms. Refund information is processed solely for completing the refund and retained only for the applicable statutory retention periods.

Where the cashless system is operated by an external technical service provider, a data processing agreement pursuant to Article 28 GDPR is in place. The provider may not process the data for its own purposes.
 

12 Event Photography and Media Production

During HIVE Festival, photographs, film and audio recordings are created by the organiser and commissioned photographers, camera crews and media professionals for documentation, editorial reporting, public relations and the promotion of future editions of the festival, including the official aftermovie.

Overview images of the event, the audience and the stages, as well as recordings in which individual persons appear only as part of the overall event, may be published where legally permitted.

For targeted portraits, interviews or other recordings in which a specific individual is clearly the main subject, separate consent is obtained before publication unless another legal basis applies.

No recordings are made in areas of the festival that are expressly designated as no-photo zones.

Drone recordings are carried out exclusively by appropriately licensed service providers in compliance with applicable aviation regulations.

Visitors who do not wish an individually identifiable recording of themselves to be made or who request the deletion of such a recording may contact the organiser using the contact details provided in Chapter 21.

Private photographs and videos taken by visitors for personal, non-commercial purposes are not covered by this Privacy Policy.

 

13 Social Media and Embedded Content

The controller maintains official profiles on Instagram and TikTok in order to provide information about the festival and to communicate with visitors.

When visiting these profiles, personal data may also be processed by the respective platform operators, who may act as independent or joint controllers under the GDPR. Details regarding the processing of personal data can be found in the privacy policies of the respective providers.

The website may also embed third-party content, including Google Maps for displaying the event location, YouTube videos, Spotify audio and SoundCloud content.

Where embedded content is protected by a two-click solution, data is only transmitted to the respective provider after the user has actively activated the content. Otherwise, embedded content is only loaded after the necessary consent has been provided through the cookie consent banner.

When embedded content is loaded, the user's IP address may be transmitted to the relevant provider, which may also place cookies or analyse user behaviour.

The legal basis for this processing is the user's consent pursuant to Article 6(1)(a) GDPR.

14 Analytics and Marketing Services

To improve the website and evaluate the effectiveness of advertising campaigns, the controller uses Google Analytics and the Meta Pixel.

These services are activated only after the user has provided consent through the cookie consent banner.

Google Analytics creates pseudonymous usage statistics, including information about pages visited, approximate location, device information and access times in order to analyse website usage.

The Meta Pixel allows the controller to measure the effectiveness of advertising campaigns on Meta platforms and to build audiences for future advertising.

The legal basis for the use of these services is Article 6(1)(a) GDPR in conjunction with Section 25 TDDDG.

Neither Google Analytics nor the Meta Pixel is loaded without prior consent.

Consent may be withdrawn at any time through the cookie settings.

Where required, data processing agreements or corresponding contractual arrangements are in place with Google Ireland Limited and Meta Platforms Ireland Limited.

As both providers maintain group companies in the United States, international data transfers may occur as described in Chapter 15.

15 International Data Transfers

Where personal data is transferred to recipients outside the European Union or the European Economic Area, including service providers such as Wix, Google, YouTube, Meta, Spotify and TikTok, such transfers take place only where the requirements of Articles 44 et seq. GDPR are fulfilled.

Where an adequacy decision of the European Commission exists, such as the EU–U.S. Data Privacy Framework, transfers are based on Article 45 GDPR.

Where no adequacy decision applies, transfers are based on the European Commission's Standard Contractual Clauses together with any additional technical and organisational safeguards required to ensure an adequate level of data protection.

A copy of the relevant safeguards may be requested using the contact details provided in Chapter 21.

16 Recipients of Personal Data

Within the organiser's organisation, access to personal data is limited to those persons and departments that require the information in order to perform their respective duties, including ticketing, admission, security, awareness services, cashless operations and public relations.

Where necessary for the purposes described in this Privacy Policy, personal data may be shared with the following categories of recipients:

  • Ticket.io for ticket sales, personalisation, re-personalisation and the refund system.

  • Payment service providers for payment processing.

  • Wix for website hosting.

  • Providers of embedded content and analytics services described in Chapters 13 and 14.

  • The technical operator of the cashless payment system.

  • Security service providers responsible for admission and event security.

  • Competent authorities where disclosure is required by law.

Where service providers act as processors within the meaning of Article 28 GDPR, appropriate data processing agreements are in place.

Personal data is disclosed to public authorities only where legally required or where permitted to safeguard legitimate safety interests.

17 Data Retention

Personal data is processed and stored only for as long as necessary to fulfil the respective processing purpose or where statutory retention obligations apply.

Ticket and order data is generally retained for the applicable commercial and tax retention periods, which are usually ten years after the end of the relevant calendar year.

Data relating to ticket personalisation and admission is retained only where necessary for complaint handling, fraud prevention or compliance with statutory obligations.

Cashless transaction data is retained for the applicable statutory retention periods. Remaining balances are deleted after they have been used, refunded or have expired in accordance with the published refund policy.

Application data is deleted after completion of the selection process unless consent has been given for longer retention.

Newsletter data is stored until consent is withdrawn.

Cookies and similar technologies are retained for the storage periods specified in the cookie settings.

Photographs, video and audio recordings used for reporting or promotional purposes are retained for as long as they continue to serve those purposes unless a valid request for deletion is granted in accordance with Chapter 12.

 

18 Rights of Data Subjects

Under the GDPR, data subjects have the following rights:

  • The right of access to personal data processed concerning them (Article 15 GDPR).

  • The right to rectification of inaccurate or incomplete personal data (Article 16 GDPR).

  • The right to erasure ("right to be forgotten") under Article 17 GDPR.

  • The right to restriction of processing (Article 18 GDPR).

  • The right to data portability (Article 20 GDPR).

  • The right to object to processing based on Article 6(1)(f) GDPR, in particular where personal data is processed for direct marketing purposes (Article 21 GDPR).

Where processing is based on consent, consent may be withdrawn at any time with effect for the future pursuant to Article 7(3) GDPR. The withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

To exercise these rights, an informal request sent to the contact details provided in Chapter 21 is sufficient.

Before responding to a request, the controller may verify the identity of the requesting person in an appropriate and proportionate manner in order to prevent unauthorised disclosure of personal data.

Without prejudice to any other administrative or judicial remedy, every data subject has the right to lodge a complaint with a competent data protection supervisory authority pursuant to Article 77 GDPR.

In particular, complaints may be submitted to the Berlin Commissioner for Data Protection and Freedom of Information or to the supervisory authority responsible for the data subject's habitual residence or place of work.

19 Data Security

The controller implements appropriate technical and organisational measures pursuant to Article 32 GDPR in order to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.

These measures include, in particular:

  • Encryption of data transmissions using current transport encryption standards.

  • Role-based access controls within the organisation and its service providers.

  • Regular review and updating of technical systems.

  • Contractual obligations requiring processors to maintain appropriate levels of data protection.

These measures are continuously reviewed and adapted to reflect technological developments and the specific risks associated with the processing activities, particularly in connection with the cashless payment system and the festival app.

20 Amendments

This Privacy Policy may be updated where necessary to reflect changes in applicable legislation or changes to the services and processing activities described herein, including new or modified website features, festival app functions or cashless services.

The version of the Privacy Policy published on the website at the time of visiting the website or using the relevant service shall apply.

21 Contact

If you have any questions regarding this Privacy Policy or wish to exercise any of your rights described above, please contact:

On Point Productions GmbH

Storkower Straße 121

10407 Berlin

Germany

Email: info@hive-festival.de

bottom of page