Privacy Guide

privacy guide

Evolutio — the DjangoCon Europe 2027 organizers — is responsible for the website 2027.djangocon.eu, DjangoCon Europe 2027 official website. The privacy and security of the personal data of our attendees, speakers, sponsors, and volunteers – participants – are very important to us. DjangoCon Europe 2027 organizers are committed to observing the principles of data protection to the best of their ability, in compliance with the (EU) Regulation 2016/679 of the European Parliament and Council of 27th of April 2016, concerning the protection of natural persons with regard to the processing of personal data and the free movement of such data, which revokes Directive 95/46/EC (General Data Protection Regulation), and other additional legislation.

Please read the following text to learn how the DjangoCon Europe 2027 organizers will use your personal data. Should any doubts or questions arise, email us at 2027@djangocon.eu.

who we are

Evolutio, the organizers of DjangoCon Europe 2027, operate the official conference website, registration system, and communication channels for the event held at SoWi University Innsbruck. We are committed to protecting participants' personal data in line with the EU General Data Protection Regulation (GDPR).

why we process your data

The specific purpose for which we process personal data is to organize and run the DjangoCon Europe 2027 conference: registration and ticketing, speaker and session management, sponsor logistics, volunteer coordination, on-site safety (including Code of Conduct handling), and post-event communication and reporting.

We process personal data based on: your consent (for example, opting into the mailing list, or being photographed); performance of a contract (processing your ticket purchase or your sponsorship agreement); and, in limited cases such as safety incidents, our legitimate interest in running a safe event, balanced against your rights. We do not sell personal data, and we do not share it with third parties beyond what is described in what we collect and why we process your data without your consent.

what we collect, by participant type

  • Attendees: name, email address, and payment details (processed by our payment provider; we do not store full card numbers). Optional: dietary requirements, accessibility needs, T-shirt size.
  • Speakers: the above, plus talk title, abstract, bio, and profile photo, used for program selection and the published schedule. If you accept, your talk may be recorded and published, and your slides may be shared publicly after the conference — you will be asked to confirm this separately.
  • Sponsors: the minimum information necessary to fulfil the sponsorship contract (billing and logistics contacts).
  • Volunteers: name, email, and any information you choose to share about your availability or preferences.
  • Code of Conduct reports: if you file or are named in a report, we collect what's needed to investigate it — see the dedicated section below.

code of conduct reports — special handling

Information collected during a Code of Conduct investigation is treated as more sensitive than general registration data. It is visible only to the CARE team (and, where a case is escalated, to a small number of designated organizers). It is not shared with sponsors, speakers' employers, or the wider organizing team. Where DjangoCon Europe's affiliation with the Django Software Foundation requires coordination with the DSF's own conduct process, relevant details may be shared with the DSF conduct committee under the same confidentiality expectations — we will tell you if this applies to your report. Anonymized, aggregated summaries (counts and categories, no identifying details) may be published in a post-conference transparency report.

photography, filming, and live streaming

Sessions, and some social events, will be photographed and filmed, and some sessions may be live-streamed or later published on YouTube. If you do not want to appear in photographs or recordings, you may request an opt-out badge marker at registration; photographers and the recording team will be briefed to respect it, though we cannot guarantee exclusion from wide crowd shots at a public venue.

data retention

  • General registration and ticketing data: retained for as long as the organizing entity's tax and accounting obligations require, and no longer, after which it is deleted or anonymized.
  • Speaker and sponsor data needed for the published program or sponsorship record: retained indefinitely as part of the historical conference record, unless you request removal (see Your Rights).
  • Code of Conduct report records: retained in restricted CARE-only storage for long enough to identify repeat-offender patterns across editions, then deleted, except where retention is required by law.
  • Photographs and recordings: retained per the above unless a specific opt-out or takedown request is honored.

If you want to know the exact retention period that applies to your data, write to 2027@djangocon.eu and we will tell you.

cookies and analytics

The conference website uses cookies for essential site functionality and for analytics (Google Analytics or an equivalent). You can control non-essential cookies via the cookie banner on first visit. If you accept, we also record when a visitor follows a link to our ticket shop, so we can tell which pages lead people to tickets; we only ever see that a link was followed, never whether a purchase was made. If you decline, nothing is measured at all. External links from our site (sponsors, venues, social media) are governed by their own privacy policies, not this one.

your rights

Under GDPR, you may access, rectify, erase, restrict, or object to the processing of your personal data at any time by writing to conduct@djangocon.eu. We will respond within one month, as required by law. You also have the right to lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde), Barichgasse 40–42, 1030 Vienna, Austria — dsb@dsb.gv.at — or with your own country's supervisory authority if you are based elsewhere in the EU.

data security

We take reasonable technical and organizational measures to protect personal data, including restricting access to Code of Conduct records to the CARE team and limiting payment processing to PCI-compliant third-party providers. In the event of a data breach affecting your personal data, we will notify the Austrian Data Protection Authority within 72 hours as required by GDPR, and notify affected individuals directly where the breach poses a high risk to their rights.

contact

For any privacy question or to exercise your rights: conduct@djangocon.eu