RISE OF AI
Privacy Policy
Privacy Policy
A personal note from us
Rise of AI is a family business. We care about the people who visit our website, attend our events, subscribe to our newsletter, or contact us about working together.
Protecting personal data is part of that responsibility. This Privacy Policy explains, in straightforward language, what information we collect, why we need it, which service providers support us, and what rights you have.
If you have any questions, please contact us. You will reach a real person, and we will be happy to help.
1. Who is responsible for your data?
The controller responsible for processing personal data is:
AI for Humans GmbH
Taunusstraße 66
12309 Berlin
Germany
Represented by its Managing Director:
Fabian J. G. Westerheide
Email: contact@riseof.ai
Registered with the Local Court of Berlin-Charlottenburg under HRB 189962.
VAT identification number: DE314217474.
We have not appointed a formal data protection officer. Privacy enquiries may be sent directly to contact@riseof.ai.
2. What this Privacy Policy covers
This Privacy Policy applies when you:
visit the Rise of AI website;
purchase, receive, or transfer a ticket;
register for or attend a Rise of AI event;
apply as a speaker, partner, guest, or participant;
subscribe to our newsletter or event updates;
contact us by email or through an online form;
take part in networking or other event formats; or
otherwise interact with Rise of AI.
Additional privacy information may be provided where a particular activity or service requires it.
3. Why we process personal data
We process personal data only when we have a legitimate purpose and a valid legal basis.
Depending on the situation, we process data because:
it is necessary to perform a contract or take steps before entering into a contract under Article 6(1)(b) GDPR;
we must comply with a legal obligation under Article 6(1)(c) GDPR;
you have given us your consent under Article 6(1)(a) GDPR;
it is necessary for our legitimate interests or those of a third party under Article 6(1)(f) GDPR; or
another legal basis applies in a specific situation.
Where we rely on legitimate interests, we consider the interests, rights, and reasonable expectations of the people concerned.
Where processing is based on consent, you may withdraw that consent at any time with effect for the future.
4. Visiting our website
When you visit our website, our systems and technical service providers may automatically process information such as:
your IP address;
the date and time of access;
the pages and files requested;
the website from which you reached us;
browser and device information;
operating-system information;
language settings; and
technical error and security information.
We use this information to provide the website, maintain its security, identify technical problems, and prevent misuse.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure, stable, and efficient operation of our website.
Technical log data is deleted or anonymised when it is no longer required for these purposes, unless longer storage is necessary to investigate a security incident or comply with a legal obligation.
5. Hosting and website operation
We use technical service providers to host, maintain, and securely deliver our website.
These providers may process IP addresses, browser and device information, access times, requested pages, and technical security data on our behalf.
Where a service provider acts as our processor, it is contractually required to process personal data only in accordance with our instructions and applicable data-protection law.
6. Cookies and similar technologies
Our website may use cookies and similar technologies.
Some cookies are technically necessary for the website to work, remember privacy settings, provide security, or deliver a service expressly requested by you. These technologies may be used without consent where permitted by law.
Optional technologies are activated only where the required consent has been obtained.
The legal bases may include:
Section 25(2) TDDDG and Article 6(1)(f) GDPR for strictly necessary technologies; and
Section 25(1) TDDDG and Article 6(1)(a) GDPR for optional technologies.
You can accept or reject optional technologies through our cookie banner. You can withdraw or change your consent at any time through the cookie settings available on our website.
Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
We currently do not use Google Analytics, Meta Pixel, LinkedIn Insight Tag, or comparable advertising-tracking services. If this changes, we will update this Privacy Policy and the relevant cookie settings before activating such services.
7. YouTube videos
We upload videos to YouTube and may embed them on our website.
YouTube is a service provided by Google. When you activate an embedded YouTube video, YouTube may receive information including:
your IP address;
browser and device information;
the page on which the video is embedded;
information about your interaction with the video; and
cookies or other identifiers used by YouTube.
If you are logged into a Google or YouTube account, YouTube may associate your interaction with that account. We do not receive your Google or YouTube password or login credentials.
Where required, embedded YouTube content is loaded only after you have given your consent. The legal basis for the associated processing is Article 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.
You may withdraw your consent through the cookie settings on our website.
YouTube or Google may process data outside the European Economic Area. Google is responsible for its own processing under its privacy terms. Where we are responsible for a transfer, we rely on a legally recognised transfer mechanism.
8. Contacting us
When you contact us by email, we process the information you provide, such as:
your name;
email address;
organisation and professional role;
contact details;
the content of your enquiry; and
any documents or other information you choose to send us.
We use this information to respond to your enquiry and manage the resulting communication.
The legal basis is Article 6(1)(b) GDPR where the communication relates to a contract or potential contract. In other cases, the legal basis is Article 6(1)(f) GDPR. Our legitimate interest is responding to enquiries and maintaining professional relationships.
We retain correspondence for as long as necessary to deal with the enquiry and any resulting relationship. Legal retention requirements may require longer storage.
9. Forms and applications through Fillout
We use Fillout for online forms, including speaker applications, partnership enquiries, registrations, surveys, and similar submissions.
Depending on the relevant form, we may collect:
your name and contact details;
organisation and professional role;
LinkedIn profile or other professional profiles;
biography and professional background;
proposed speaking topics;
partnership interests;
event preferences;
answers to application questions;
files, photographs, presentations, or links submitted by you; and
technical information relating to the form submission.
We process this information to review the submission, communicate with you, select speakers or participants, discuss a possible partnership, and plan our events.
The legal basis is Article 6(1)(b) GDPR where the submission relates to a potential agreement or participation. Otherwise, processing is based on Article 6(1)(f) GDPR or, where expressly requested, your consent under Article 6(1)(a) GDPR.
Submitting a form does not guarantee an invitation, speaking engagement, partnership, ticket, or other contractual relationship.
Fillout processes data on our behalf as a service provider. Data may be processed outside the European Economic Area. Where required, the transfer is protected by an adequacy decision, the European Commission’s Standard Contractual Clauses, or another legally recognised safeguard.
10. Newsletters and mailings through Brevo
We use Brevo to manage email lists and send newsletters, invitations, event information, and other Rise of AI communications.
When you subscribe to our newsletter or request updates, we may process:
your email address;
first and last name;
organisation and professional role;
subscription source;
communication preferences;
date and time of registration;
confirmation and consent information; and
information about newsletter delivery and interaction, where legally permitted.
The legal basis for newsletters is your consent under Article 6(1)(a) GDPR. We may use a double opt-in process to confirm that the email address belongs to you.
You may unsubscribe at any time by using the unsubscribe link included in each newsletter or by emailing contact@riseof.ai.
Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
Where performance measurement is enabled, information about delivery, email openings, and link interactions is processed only where legally permitted and, where required, with your consent.
We retain evidence of registration, consent, and withdrawal where necessary to demonstrate compliance with legal obligations.
Transactional emails required to manage a booking, application, or contractual relationship may be sent independently of a newsletter subscription.
11. Ticket purchases through Eventbrite
We use Eventbrite to sell and manage tickets.
When you purchase or receive a ticket, Eventbrite processes your information under its own privacy terms and provides us with the information required to manage the booking and event.
Depending on the booking, this may include:
your name;
email address;
organisation and professional role;
billing address;
VAT or invoice information;
ticket category;
booking and order number;
payment status;
answers to registration questions;
dietary or accessibility requirements;
LinkedIn profile;
consent and communication preferences; and
attendance status.
We do not normally receive complete credit-card or bank-account details. Payment information is processed by Eventbrite and its payment providers.
We use the information provided through Eventbrite to:
process and administer your booking;
issue tickets and invoices;
manage guest lists and admission;
create name badges;
communicate important event information;
provide the services included with your ticket;
process ticket transfers; and
comply with accounting and tax requirements.
The legal basis is Article 6(1)(b) GDPR. Information required for accounting, tax, or other legal obligations is processed under Article 6(1)(c) GDPR.
Eventbrite may act partly as our processor and partly as an independent controller for its own services. Eventbrite may process data outside the European Economic Area using legally recognised transfer mechanisms.
12. Ticket transfers
If a ticket is transferred to another person, we process:
the booking or order number;
the name of the current ticket holder;
the name of the new ticket holder; and
the new ticket holder’s email address.
We use this information to update the booking, guest list, communication details, and name badge.
The legal basis is Article 6(1)(b) GDPR.
The person requesting the transfer must ensure that they are entitled to provide the new ticket holder’s information and that the new ticket holder has been informed about the transfer.
13. Participant management through Airtable
We use Airtable as our internal database for event, contact, and participant management.
Depending on your relationship with Rise of AI, Airtable may contain:
your name and contact information;
organisation and position;
ticket or invitation category;
booking or application details;
attendance status;
speaker or partner information;
professional profile or LinkedIn link;
communication history;
invoice or payment status;
dietary or accessibility requirements;
networking and publication preferences; and
internal organisational notes required to manage the event.
We use this information to organise events, manage invitations and guest lists, coordinate speakers and partners, communicate with participants, prepare admission and name badges, and maintain relevant professional relationships.
The legal basis is Article 6(1)(b) GDPR where the processing is required for a contract, booking, application, or participation.
In other cases, processing is based on Article 6(1)(f) GDPR. Our legitimate interests include efficient event organisation, maintaining accurate business records, avoiding duplicate communication, and managing our professional network.
Access to Airtable is restricted to authorised team members and service providers who require the information for their work.
Airtable may process data outside the European Economic Area. Where required, transfers are protected by an adequacy decision, the European Commission’s Standard Contractual Clauses, or another legally recognised safeguard.
14. Dietary and accessibility information
You may voluntarily provide information about allergies, dietary requirements, disabilities, health conditions, or accessibility needs.
Some of this information may constitute health data or otherwise reveal sensitive information.
We use this information only to support your safe and accessible participation in the event. Where required, processing is based on your explicit consent under Article 9(2)(a) GDPR.
Providing this information is voluntary. However, without it, we may not be able to make the requested arrangements.
Access is limited to people who require the information, such as responsible Rise of AI team members, the venue, or catering providers.
The information is not used for advertising or unrelated profiling.
15. Networking and attendee information
Rise of AI is designed to create trusted professional connections.
Where networking formats are offered, we will explain which information may be visible to other authorised participants. This may include:
your name;
organisation and professional role;
profile photograph;
biography;
professional interests; and
LinkedIn profile.
We do not make your contact details or professional profile publicly available solely because you purchased a ticket.
Participation in optional networking formats and the publication of profile information is based on your choice and, where required, your consent.
Please do not provide information that you do not want authorised participants to see.
16. Photography, video, and audio recordings
Photography, video recording, and audio recording may take place during Rise of AI events.
Recordings may show individual guests or groups of people and may be used for:
event documentation;
editorial reporting;
livestreams and recordings of sessions;
the Rise of AI website;
YouTube;
newsletters and mailings;
press and public relations;
social-media communication; and
communication about current and future Rise of AI events.
Depending on the situation, processing may be based on our legitimate interests under Article 6(1)(f) GDPR, consent under Article 6(1)(a) GDPR, contractual arrangements, or applicable rules concerning images and recordings.
Our legitimate interests include documenting the event and communicating the work and community of Rise of AI.
We respect situations in which an individual’s interests override these purposes. If you do not wish to appear in recordings, please inform the event team. We will make reasonable efforts to accommodate your request.
Separate consent may be requested for interviews, testimonials, staged portraits, or other recordings in which an individual is the primary subject.
17. Speakers, partners, and professional contacts
If you act as a speaker, partner, sponsor, supplier, journalist, community representative, or other professional contact, we may process:
your professional contact information;
organisation and role;
biography and profile photograph;
contractual and billing information;
communication history;
presentation materials;
travel or organisational information; and
publicly available professional information.
We process this data to prepare and perform agreements, organise the event, communicate with you, and maintain our professional network.
The legal bases are Article 6(1)(b) GDPR and Article 6(1)(f) GDPR.
Where appropriate, speaker names, biographies, photographs, organisations, and programme information may be published as part of the event programme and event communication.
18. Who receives personal data?
Within AI for Humans GmbH, personal data is available only to people who require it for their work.
Depending on the relevant activity, we may share data with:
Airtable for database and participant management;
Eventbrite for ticketing and booking administration;
Brevo for newsletters, mailings, and email-list management;
Fillout for forms and applications;
YouTube or Google when embedded videos are activated;
website hosting and technical service providers;
venues, caterers, security, and accreditation providers;
photographers, videographers, and production teams;
accounting, legal, and other professional advisers;
public authorities where disclosure is legally required; and
other recipients where you have expressly agreed to the disclosure.
Service providers acting on our behalf are contractually required to process personal data only in accordance with our instructions and applicable data-protection law.
We do not sell personal data.
We do not provide attendee lists to partners or sponsors for their own advertising unless the person concerned has expressly agreed or another clear legal basis applies.
19. International data transfers
Some of our service providers may process data outside the European Union or European Economic Area, particularly in the United States.
Where the European Commission has issued an adequacy decision, data may be transferred on that basis. This may include providers participating in the EU–US Data Privacy Framework.
Where no adequacy decision applies, we use appropriate safeguards where required. These may include the European Commission’s Standard Contractual Clauses and additional technical or organisational measures.
Information about the relevant safeguards may be requested from us.
20. How long we keep personal data
We keep personal data only for as long as it is required for the relevant purpose.
The retention period depends on the type of information and may include:
website and security data: until it is no longer needed for operation or security;
enquiries: until the enquiry and any resulting relationship have been concluded;
speaker and partnership applications: for the selection and planning process and a reasonable follow-up period;
ticket and event data: for the organisation and follow-up of the event;
newsletter information: until consent is withdrawn or the subscription is otherwise ended;
dietary and accessibility information: until it is no longer required for the event and related follow-up;
contractual and accounting information: for the applicable statutory retention period; and
legal documentation: for as long as it may be required to establish, exercise, or defend legal claims.
Data may be retained for longer where required by law, necessary in connection with a dispute, or requested by a competent authority.
Where information is stored in more than one system, deletion may take place at different times in accordance with the respective purpose and retention obligation.
21. Your rights
Subject to the applicable legal requirements, you have the right to:
request information about the personal data we process about you;
request correction of inaccurate or incomplete information;
request deletion of your personal data;
request restriction of processing;
receive data you provided in a structured, commonly used, and machine-readable format;
object to processing based on legitimate interests;
object at any time to processing for direct marketing;
withdraw consent at any time with effect for the future; and
lodge a complaint with a data-protection supervisory authority.
If processing is based on legitimate interests, you may object for reasons arising from your particular situation. We will stop the processing unless we can demonstrate compelling legitimate grounds or require the information to establish, exercise, or defend legal claims.
To exercise your rights, email contact@riseof.ai. We may need to verify your identity before responding.
22. Right to complain
You may lodge a complaint with any competent data-protection supervisory authority.
The supervisory authority responsible for our registered office is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin
Germany
Email: mailbox@datenschutz-berlin.de
You are welcome to contact us first so that we can try to resolve the matter directly.
23. Data security
We use appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, disclosure, or access.
These measures are reviewed and adjusted where appropriate. However, no internet transmission or electronic storage system can guarantee absolute security.
Please avoid sending particularly sensitive information through ordinary, unencrypted email unless this is necessary.
24. Automated decision-making
We do not use personal data to make decisions based solely on automated processing that produce legal effects or similarly significant consequences for individuals.
Applications and participation decisions may be supported by structured information stored in our systems, but the final decision is made by a person.
25. Changes to this Privacy Policy
We may update this Privacy Policy when our website, events, service providers, or legal requirements change.
The current version will be published on this website. Where a change materially affects an existing service or consent, we will provide additional information where required.
26. Contact
Questions about privacy or the use of your personal data are always welcome.
AI for Humans GmbH
Taunusstraße 66
12309 Berlin
Germany
Email: contact@riseof.ai
Version: 15 September 2026