Privacy Policy
1. Introduction and scope
In this Privacy Policy, “WeAreDevelopers”, “we”, “us” and “our” refer to WeAreDevelopers GmbH and its affiliated companies listed in Section 2. This policy explains how we collect, use, share and protect personal data when you:
- visit our websites, including wearedevelopers.com, its subdomains, and other websites we operate that link to this policy (the “Websites”);
- create an account and use our online services and features (the “Platform”);
- register for, attend, speak at, sponsor or exhibit at our events, conferences, summits, side events and other activities we organise (the “Events”); or
- otherwise interact with us, for example by contacting our teams, participating in surveys, promotions or competitions, or engaging with us on social media.
Our services and features evolve continuously. This policy therefore describes our processing by purpose and data category rather than by individual feature. New or changed features are covered by this policy as long as the purposes described here remain the same; where a specific feature or activity involves additional processing, we inform you at the point of collection. If we start processing personal data for materially new purposes, we will update this policy and inform you where required.
We process personal data in accordance with the EU General Data Protection Regulation (“GDPR”) and the Austrian Data Protection Act. In addition, the national law of the country in which the responsible WeAreDevelopers company is established or in which an Event takes place may apply to specific activities. Sections 15 and 16 contain additional information for users in the United States and India.
2. Who is responsible for your personal data
WeAreDevelopers GmbH, Schottenfeldgasse 23, 1070 Vienna, Austria, operates the Websites, the Platform and our central systems (such as CRM, marketing and event systems) and is the controller for the associated processing, unless stated otherwise below. The company identified as the organiser of an Event (in the relevant registration, ticket or contract) is the controller for the processing connected with that Event:
| Company | Registered office | Controller for |
|---|---|---|
| WeAreDevelopers GmbH | Schottenfeldgasse 23, 1070 Vienna, Austria | Websites, Platform, central systems, marketing and CRM; Events it organises |
| WeAreDevelopers Germany GmbH | Wattstrasse 11, 13355 Berlin, Germany | Events organised in Germany |
| WeAreDevelopers Inc. | 8 The Green, STE R, Dover, DE 19901, USA | Events organised in the United States |
For Events in other countries, the organiser identified in the registration is responsible. Other affiliated companies may perform internal support functions on behalf of the responsible company; in that case they act on its instructions and not as controllers.
Where WeAreDevelopers GmbH and another WeAreDevelopers company jointly determine the purposes and essential means of processing for a specific service or Event, they act as joint controllers under Art. 26 GDPR. In that case, WeAreDevelopers GmbH coordinates privacy information and the handling of data subject requests as the central contact point; you may nevertheless exercise your rights against each company involved.
We have appointed a data protection officer, who can be reached at privacy@wearedevelopers.com.
3. What personal data we collect
We collect personal data that you provide to us, data generated when you use our services, and limited data from third parties. Depending on how you use our services, this may include:
- Identity and contact data, such as name, email address, phone number, postal address, country, job title, company, profile photo.
- Professional and profile data, such as CV, work experience, education, skills, portfolio links, social media profiles, salary expectations and preferences, application documents, professional interests, content interests.
- Content you publish or present, such as talks, sessions, recordings, articles, comments and other material you upload to or publish on the Platform or present at our Events, together with the profile information displayed with it.
- Event data, such as registration and ticket details, ticket type, dietary or accessibility requirements you choose to share, session attendance, badge scans, networking activity, questions submitted in Q&A, entry logs at access-controlled areas.
- Payment and billing data, such as billing address, VAT number and payment method details (processed by our payment providers; we do not store full payment card numbers).
- Communications, such as emails, chat messages (including support chats), survey responses, form submissions, and feedback.
- Usage, device and log data, such as IP address, browser and device information, operating system, language settings, pages visited, referring URLs, approximate location derived from IP, interactions with our emails (opens/clicks), error and diagnostic data.
- Audio-visual data, such as photographs and video or audio recordings made at our in-person or virtual Events (see Section 7.5) and recordings of sessions you present.
- Optional sensitive data, such as accessibility or dietary information you choose to share for an Event, which may reveal health or religious information. We request such data only where necessary and process it based on your explicit consent (Art. 9(2)(a) GDPR).
- Data from third parties, such as publicly available business information (for example from your company website or professional networks) used for marketing, sales and partnership outreach; profile data from a login provider if you sign in with a third-party account; attendee data provided by your employer or a colleague who books a ticket for you or registers you to an Event on your behalf.
You are not obliged to provide personal data, but without certain data we cannot provide the relevant service (for example, we cannot issue an event ticket without a name and email address). Please do not include sensitive personal data in free-text fields unless it is requested and necessary for the relevant service.
4. Purposes and legal bases
We process personal data for the following purposes and on the following legal bases:
| Purpose | Examples | Legal basis (GDPR) |
|---|---|---|
| Providing our services | Accounts and Platform features, issuing event tickets, event admission, our event app | Art. 6(1)(b) – contract |
| Payment and billing | Processing payments, invoicing, fraud prevention | Art. 6(1)(b) – contract; Art. 6(1)(c) – legal obligation; Art. 6(1)(f) – legitimate interest (fraud prevention) |
| Event operations and safety | Access control, capacity management, security, incident handling, code of conduct enforcement | Art. 6(1)(b) – contract; Art. 6(1)(f) – legitimate interest |
| Connecting you with companies at your initiative | Product or partner offers you request, session registrations, workshop registrations, job applications, raffles, networking requests | Art. 6(1)(b) – contract or steps at your request; Art. 6(1)(a) – consent where required |
| Badge scanning by sponsors and exhibitors at Events | A sponsor scans your badge and receives your registration profile (Section 7.3) | Art. 6(1)(a) – consent (given by allowing the scan) |
| Optional accessibility and dietary information | Considering accessibility needs, catering at Events | Art. 6(1)(a) and Art. 9(2)(a) – explicit consent |
| Marketing communications | Newsletters, product updates, event announcements, special offers | Art. 6(1)(a) – consent; for existing customers, Art. 6(1)(f) in line with applicable electronic-marketing rules (own similar services, with opt-out) |
| B2B sales and partnerships | Contacting business representatives about sponsorship, recruiting or partnership offerings; CRM management | Art. 6(1)(f) – legitimate interest in B2B marketing |
| Personalisation and recommendations | Suggesting and ranking content, events, jobs or companies based on your profile, preferences and interactions (Section 12) | Art. 6(1)(b) – contract (integral features); Art. 6(1)(f) – legitimate interest; Art. 6(1)(a) – consent where required |
| Analytics and improvement | Understanding how the Websites and Platform are used, improving content and services | Art. 6(1)(a) – consent (cookie-based tools); Art. 6(1)(f) – legitimate interest (aggregated or server-side measurement) |
| Advertising and retargeting | Showing our ads to previous visitors on advertising and social media platforms | Art. 6(1)(a) – consent via our consent manager |
| Content, community and media | Publishing content you submit, upload or present, speaker profiles, event recordings and event coverage | Art. 6(1)(b) – contract (speakers, publishing users); Art. 6(1)(a)/(f) for community features and event coverage |
| Legal compliance | Tax and accounting retention, responding to lawful requests by authorities, exercising or defending legal claims | Art. 6(1)(c) – legal obligation; Art. 6(1)(f) – legitimate interest |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You can object to processing based on legitimate interests at any time (see Section 11).
5. Cookies and tracking technologies
We use cookies and similar technologies (pixels, local storage, SDKs) on our Websites, grouped into the categories shown in our consent manager (currently: necessary services, for example for login, forms, support chat and consent storage; statistics services that help us understand how our Websites are used; marketing services for conversion measurement and retargeting on the internet and social media platforms; and social sharing and embedded media).
Only strictly necessary services run by default. Everything else is loaded only with your consent, which we collect and manage through our consent management platform, TRUENDO (Truendo Technologies GmbH, Vienna, Austria). The consent manager (“Manage Cookies” in the footer of our Websites) contains the current list of all cookies and similar tracking technologies used on our Websites, including their purposes, providers and storage durations, and is where you can adjust or withdraw your consent at any time. Cookies and the identifiers they contain (such as cookie IDs and IP addresses) can constitute personal data.
Where we use session replay or heatmap technology as part of our statistics services, it runs only with your consent, records interactions such as mouse movement, clicks and scrolling (with text you type into input fields masked), and is listed with its provider in the consent manager.
We operate server-side tagging on our own subdomain. This allows us to control and filter what data reaches third-party tools before it leaves our infrastructure.
6. Accounts and online services
Accounts and profiles: when you create an account, we process your registration and profile data to operate your account, personalise your experience and provide the features you use. If you sign in via a third-party login provider, we receive the profile data you authorise that provider to share (typically name, email address, profile picture).
Content you publish: you may be able to publish content on the Platform, such as talks, session recordings, articles or comments. Content you publish, together with your name and profile information, is visible to other users or the public, depending on the feature and your settings. The publication of recordings of sessions you present is governed by the terms you accept when you present or upload them.
Features that connect you with companies: some of our features are designed to connect you with companies, for example applying to a job, requesting information about a product or service, registering for a partner offer or workshop, or entering a promotion run together with a partner. Where you use such a feature, we share the data necessary for that purpose with the respective company, which processes it as an independent controller under its own privacy policy. We tell you at the point of use which company will receive your data. If you are a company representative, your name and business contact details may be visible to the users you interact with.
Surveys, promotions and competitions: if you participate, we process your entry to run the activity, notify winners and comply with legal obligations. Specific conditions are provided with the respective activity.
7. Events
7.1 Registration and ticketing
When you register for an Event, we process your registration data to issue your ticket, manage attendance and provide the Event. If your ticket was purchased by your employer or a colleague, we receive your data from them. Ticketing and payments are handled by service providers acting on our behalf (Section 8); we do not store full payment card numbers.
7.2 Event app and networking
We provide an official event app as part of our Platform, operated by us on our own domains. If you activate networking features, your profile (name, job title, company and any details you add) is visible to other participants, and you can exchange messages and meeting requests. You control your visibility in the app settings.
7.3 Badge scanning and sharing your data with sponsors and exhibitors
Sponsors and exhibitors at our Events may use lead-capture tools to scan attendee badges. When you allow a sponsor or exhibitor to scan your badge (at a booth, at a session where scanning is enabled, or by presenting your badge), you consent to us transferring your registration profile data (such as name, email address, job title, company, country) to that sponsor or exhibitor.
Ordinary event entry or attendance alone is never treated as consent to sponsor marketing. Presenting your badge for scanning is always voluntary, and the scanning interface or on-site information identifies the sponsor receiving your data.
The sponsor or exhibitor receives this data as an independent controller and processes it under its own privacy policy, typically to follow up with you about its products and services. You can withdraw consent for future transfers at any time; withdrawal does not affect data already transferred, but you can exercise your rights (including objection to marketing) directly with the respective sponsor or with us. You can also request a list of the sponsors that scanned your badge.
7.4 Speakers and call for papers
If you submit a session proposal, we process your submission through our call-for-papers and speaker management tools. If you speak at an Event, we process your speaker profile, publish it on our Websites, the Platform and our marketing channels, and record your session (video and audio). Recordings and speaker materials may be published and promoted on the Platform, our Websites and our channels on third-party platforms.
7.5 Photography and filming at Events
Our Events are public, documented events. We (and photographers and film crews engaged by us) take photographs and video recordings at our Events for documentation and for the marketing of WeAreDevelopers, our services and future events, across our own and third-party channels. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in documenting and promoting our Events. In addition, the image-rights law of the country in which an Event takes place may apply.
We instruct our teams to focus on the overall event experience, crowds, stages and public areas rather than portraying individuals prominently without context. If you do not want to appear in specific material, contact our on-site team or privacy@wearedevelopers.com and we will take reasonable steps to avoid or remove footage in which you are prominently and identifiably depicted. Sponsors and other attendees may also take photos; we are not the controller for their recordings.
7.6 Access control, safety and security
We process badge and entry data for access control and capacity management, and we may process incident-related data to enforce our Code of Conduct and protect the safety of participants and staff (Art. 6(1)(f) GDPR). Venue operators may operate their own security systems, including CCTV, as independent controllers under their own privacy policies; we do not operate such systems ourselves without notice.
7.7 Other event formats and activities
Our Events include changing formats and activities, such as workshops, hackathons, competitions, community and side events, meetups and partner activations. The principles in this Section 7 apply to all of them. Where a specific format or activity involves additional data processing beyond what is described here (for example a competition with its own conditions, or an activity run together with a partner who receives your data), we inform you at the point of registration or participation.
8. Recipients: marketing, processors and independent controllers
Marketing by us: we send newsletters, messages, and marketing emails based on your consent, or, where permitted by law, to existing customers for our own similar products and services with an opt-out. Every marketing email contains an unsubscribe link; we measure opens and clicks to improve our campaigns, and you can object to this measurement by unsubscribing. For business representatives (for example potential sponsors, partners or employers), we process business contact data in our CRM and may contact you about our B2B offerings based on our legitimate interest in direct marketing and, for electronic communications, in accordance with applicable electronic-marketing rules; you can object at any time.
We share personal data only with the following categories of recipients, in each case limited to what is necessary:
- The WeAreDevelopers companies listed in Section 2.
- Processors acting on our documented instructions under Art. 28 GDPR data processing agreements, in the categories: hosting and cloud infrastructure; CRM, marketing, email delivery and communications; customer support; consent management; ticketing and payment processing; event services such as call-for-papers tools, badge printing and access control; analytics and IT tooling. The tracking and advertising services active on our Websites are always listed in our consent manager (Section 5); information about other specific providers is available on request via privacy@wearedevelopers.com.
- Independent controllers where the service requires it: companies you connect with through our features (Section 6); sponsors and exhibitors who scan your badge (Section 7.3); partners of specific activities where announced; advertising and social media platforms (for consent-based advertising, Section 5); venue operators for safety purposes.
- Potential or actual acquirers, investors and their advisers in connection with a corporate transaction (such as a financing, merger, acquisition or reorganisation), under confidentiality obligations and in accordance with applicable law.
- Professional advisers, auditors, insurers, and authorities or courts where legally required.
We do not sell personal data. Our processors may use your data only on our instructions and not for their own purposes. Transfers to independent controllers happen only as described in this policy and, where required, with your consent.
9. International data transfers
Some of our service providers and affiliated companies are located outside the European Economic Area, in particular in the United States. Where we transfer personal data to the US, we rely on the EU-U.S. Data Privacy Framework where the recipient is certified under it, and otherwise on the European Commission’s Standard Contractual Clauses (Art. 46(2)(c) GDPR), supplemented where necessary by additional safeguards. For other third countries, we rely on adequacy decisions or Standard Contractual Clauses. You can request information about the safeguards applicable to a specific transfer via privacy@wearedevelopers.com.
10. How long we keep your data
We keep personal data only as long as necessary for the purpose it was collected for, and thereafter as required by statutory retention obligations or for the establishment, exercise or defence of legal claims. The following standard periods and criteria apply, unless a specific legal obligation, an ongoing legal dispute or another legitimate need requires otherwise:
| Data category | Retention period | Reason |
|---|---|---|
| Account and profile data | Life of the account, plus 30 days after deletion | Contract performance; grace period for accidental deletion |
| Event registration and attendance data | Generally 7 years after the end of the year of the Event | Contract, follow-up, defence of legal claims (general limitation period), re-invitation |
| Badge-scan transfers to sponsors | Transfer log kept for the same period as the event data | Accountability; the sponsor’s own retention is governed by its policy |
| CRM / B2B business contact data | Generally 5 years after the last active contact | Legitimate interest in business relationships; aligned with the general limitation period |
| Marketing consents and opt-outs | Until withdrawal; proof of consent or opt-out kept for 5 years thereafter | Accountability (Art. 5(2) GDPR); suppression lists |
| Applications and requests you send to companies via our features | Transmitted to the company; our copy generally deleted 3 years after conclusion of the process | The receiving company is the controller; claim periods under anti-discrimination law |
| Invoices, accounting and tax records | 7 years (Austria, §132 BAO); up to 10 years (Germany, §147 AO); as required by applicable US law | Legal obligation |
| Support and other correspondence | Generally 7 years after resolution | Legitimate interest in service quality; general limitation period |
| Server and security logs | Up to 90 days, longer only for specific security incidents | Security, fraud prevention |
| Cookie and tracking data | As shown per service in our consent manager | Consent-based; managed in the consent manager |
| Talk recordings, published content and event photography | Published content retained as part of our media archive; removal on justified request (Sections 6 and 7.5) | Legitimate interest / speaker and publishing terms |
When retention ends, we delete or anonymise the data. Backup copies are deleted in the ordinary backup cycle and are isolated from active use until deletion.
11. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy (Art. 15);
- rectification of inaccurate or incomplete data (Art. 16);
- erasure (Art. 17) and restriction of processing (Art. 18), under the conditions set out there;
- data portability (Art. 20);
- Right to object (Art. 21): you can object to processing based on legitimate interests, and you can object at any time to direct marketing - if you object to direct marketing, we will stop it;
- withdraw any consent at any time with effect for the future (Art. 7(3)), for example via the cookie manager, unsubscribe links or by contacting us; and
- lodge a complaint with a supervisory authority, in particular the Austrian Data Protection Authority (dsb.gv.at), the supervisory authority of your place of residence, or - for Events in Germany - the competent German state authority.
To exercise your rights, contact privacy@wearedevelopers.com. WeAreDevelopers GmbH handles all requests for all companies listed in Section 2. We respond within one month and may ask you to verify your identity. Exercising your rights is free of charge.
12. Automated decision-making, profiling and AI
We use automated systems, which may include machine-learning and AI models, for two main purposes. First, to make our services relevant: search, recommendations and personalisation may combine your profile data, preferences you choose and interaction signals (such as views, clicks, saves and searches) to rank and suggest content, events, jobs, companies or other opportunities. Second, for advertising: we build audience segments for our own marketing campaigns based on consent or legitimate interest as described in Section 4. We also use automated systems to detect spam, fraud and abuse.
These systems affect the relevance and ordering of what you see. We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. Where external AI providers process personal data on our behalf, they act as processors under contract, and we do not permit them to use your personal data to train their general-purpose models unless we have specifically disclosed this and have a lawful basis. You can object to profiling based on legitimate interests and withdraw any consent at any time (Section 11).
13. Security
We apply appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls and role-based permissions, logging, vendor due diligence and data processing agreements, and staff confidentiality obligations. No system is perfectly secure; we maintain incident response processes and will notify you and the competent authority of personal data breaches where legally required.
14. Minors
Our services are directed at professionals and are not intended for persons under 18. Where a specific service or Event permits participation by younger persons (for example accompanied minors or student offers), we state the applicable conditions and provide the relevant information at the point of registration. Otherwise, we do not knowingly collect personal data from persons under 18; if we become aware of such data, we will delete it.
15. Additional information for US residents
If you are a resident of a US state whose privacy law applies to you and grants you rights such as access, correction, deletion or opting out of targeted advertising, you can exercise these rights via privacy@wearedevelopers.com and manage advertising cookies via the “Manage Cookies” link on our Websites.
16. Additional information for users in India
For users in India, we process digital personal data in line with the Indian Digital Personal Data Protection Act, 2023 and its rules as they enter into force. Where we rely on consent, you may withdraw it at any time. For grievances relating to your personal data, contact privacy@wearedevelopers.com ; we will designate further contact points and mechanisms as required under this framework.
17. Changes to this Privacy Policy
We review this Privacy Policy regularly and update it when our processing, our services or the law change. The current version, including its “Last updated” date, is always available on our Websites. For material changes affecting you (for example new purposes), we will inform you appropriately, for example by email or a notice on the Websites.
18. Contact
WeAreDevelopers GmbH
Schottenfeldgasse 23, 1070 Vienna, Austria
*Last updated: July 31, 2026*
Legal Documents