Data Protection APP
Data Protection APP
Controller within the meaning of data protection laws, particularly the EU General Data Protection Regulation (GDPR), is:
Gerhard Frank
Your rights as affected persons
You can exercise the following rights at any time under the contact details of our data protection officer:
- Information about your data stored with us and its processing (Art. 15 GDPR),
- Correction of incorrect personal data (Art. 16 GDPR),
- Deletion of your data stored with us (Art. 17 GDPR),
- Restriction of data processing, insofar as we may not delete your data due to legal obligations (Art. 18 GDPR),
- Objecting to the processing of your data with us (Art. 21 GDPR), and
- Data portability, provided you have consented to data processing or have concluded a contract with us (Art. 20 GDPR).
If you have granted us consent, you can revoke it at any time with effect for the future.
You can lodge a complaint with a supervisory authority at any time, for example with the competent supervisory authority of the federal state of your residence or with the authority responsible for us as the responsible entity.
A list of supervisory authorities (for the non-public sector) with addresses can be found at: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html.
Collection of general information when visiting our website
Type and purpose of processing:
If you access our website, i.e., if you do not register or otherwise transmit information, general information is automatically collected. This information (server log files) includes, for example, the type of web browser, the operating system used, the domain name of your internet service provider, your IP address, and similar data.
They are processed particularly for the following purposes:
- Ensuring a smooth connection build-up of the website,
- Ensuring a smooth use of our website,
- Evaluation of system security and stability, and
- For further administrative purposes.
We do not use your data to draw conclusions about your person. Information of this kind is statistically evaluated by us if necessary to optimize our internet presence and the underlying technology.
Legal basis:
The processing is carried out in accordance with Art. 6 (1) (f) GDPR based on our legitimate interest in improving the stability and functionality of our website.
Recipients:
Recipients of the data may be technical service providers who act as processors for the operation and maintenance of our website.
Storage duration:
The data will be deleted as soon as they are no longer required for the purpose of collection. This is generally the case for the data that serve the provision of the website when the respective session has ended.
Provision required or necessary:
The provision of the aforementioned personal data is neither legally nor contractually required. However, without the IP address, the service and functionality of our website cannot be guaranteed. In addition, certain services and features may not be available or may be restricted. For this reason, an objection is excluded.
Cookies
Type and purpose of processing:
Like many other websites, we also use so-called “cookies”. Cookies are small text files that are stored on your end device (laptop, tablet, smartphone, etc.) when you visit our website.
This allows us to obtain certain data such as your IP address, the browser used, and the operating system.
Cookies cannot be used to launch applications or transfer viruses to a computer. Based on the information contained in cookies, we can facilitate your navigation and enable the correct display of our websites.
In no case will the data we collect be passed on to third parties or linked to personal data without your consent.
Of course, you can generally view our website without cookies. Internet browsers are usually set to accept cookies. In general, you can deactivate the use of cookies at any time via the settings of your browser. Please use the help functions of your internet browser to find out how to change these settings. Please note that individual functions of our website may not work if you have disabled the use of cookies.
Storage duration and cookies used:
If you allow us to use cookies through your browser settings or consent, the following cookies may be used on our websites:
If these cookies may also affect personal data, we will inform you about this in the following sections.
You can delete individual cookies or the entire cookie stock via your browser settings. Additionally, you will receive information and instructions on how these cookies can be deleted or blocked in advance. Depending on your browser provider, you can find the necessary information under the following links:
- Mozilla Firefox: https://support.mozilla.org/de/kb/cookies-loeschen-daten-von-websites-entfernen
- Internet Explorer: https://support.microsoft.com/de-de/help/17442/windows-internet-explorer-delete-manage-cookies
- Google Chrome: https://support.google.com/accounts/answer/61416?hl=de
- Opera: http://www.opera.com/de/help
- Safari: https://support.apple.com/kb/PH17191?locale=de_DE&viewlocale=de_DE
Registration on our website
Type and purpose of processing:
When registering for the use of our personalized services, some personal data is collected, such as name, address, contact, and communication data (e.g., telephone number and email address). If you are registered with us, you can access content and services that we only offer to registered users. Registered users also have the option to change or delete the data provided at registration at any time if needed. Of course, we will also provide you with information about the personal data we have stored about you at any time.
Legal basis:
The processing of the data entered during registration is based on the user’s consent (Art. 6 para 1 lit. a GDPR).
If the registration serves to fulfill a contract to which the data subject is a party or to carry out pre-contractual measures, the additional legal basis for the processing of the data is Art. 6 para 1 lit. b GDPR.
Recipients:
Recipients of the data may be technical service providers who act as processors for the operation and maintenance of our website.
Storage duration:
Data is only processed in this context as long as the corresponding consent is in place. After that, they will be deleted unless there are statutory retention obligations preventing this. For contact in this context, please use the contact details provided at the end of this privacy policy.
Provision required or necessary:
The provision of your personal data is voluntary, solely based on your consent. Without providing your personal data, we cannot grant you access to the content and services we offer.
Provision of paid services
Type and purpose of processing:
To provide paid services, we request additional data, such as payment details, in order to execute your order.
Legal basis:
The processing of the data necessary for the conclusion of the contract is based on Art. 6 para 1 lit. b GDPR.
Recipients:
Recipients of the data may be processors.
Storage duration:
We store this data in our systems until the statutory retention periods have expired. These generally amount to 6 or 10 years for proper accounting and tax purposes.
Provision required or necessary:
The provision of your personal data is voluntary. Without providing your personal data, we cannot grant you access to the content and services we offer.
Comment function
Type and purpose of processing:
When users leave comments on our website, in addition to this information, the time of their creation and the username previously selected by the website visitor are stored. This serves our security, as we can be held accountable for unlawful content on our website even if it was created by users.
Legal basis:
The processing of the data entered as a comment is based on a legitimate interest (Art. 6 para 1 lit. f GDPR).
By providing the comment function, we want to enable you to have a straightforward interaction. Your statements will be stored for the purpose of processing the request as well as for possible follow-up questions.
Recipients:
Recipients of the data may be processors.
Storage duration:
The data will be deleted as soon as they are no longer required for the purpose of collection. This is generally the case when the communication with the user is completed, and the company can infer from the circumstances that the matter has been conclusively clarified.
Provision required or necessary:
The provision of your personal data is voluntary. However, without providing your personal data, we cannot grant you access to our comment function.
Newsletter
Type and purpose of processing:
Your data will only be used to deliver the subscribed newsletter via email. The provision of your name is for the purpose of addressing you personally in the newsletter and potentially identifying you if you wish to exercise your rights as an affected person.
To receive the newsletter, providing your email address is sufficient. When registering for our newsletter, the data you provide will only be used for this purpose. Subscribers may also be informed about circumstances via email that are relevant to the service or the registration (e.g., changes to the newsletter offer or technical details).
For a valid registration, we need a valid email address. To verify that a registration has indeed been made by the owner of an email address, we use the “double opt-in” procedure. To do this, we log the order of the newsletter, the sending of a confirmation email, and the receipt of the requested response. No further data will be collected. The data will only be used for sending the newsletter and will not be passed on to third parties.
Legal basis:
Based on your expressly granted consent (Art. 6 para 1 lit. a GDPR), we regularly send you our newsletter or comparable information via email to the email address you provided.
You can revoke your consent to the storage of your personal data and its use for newsletter dispatch at any time with effect for the future. Each newsletter contains a corresponding link in this regard. In addition, you can unsubscribe directly on this website at any time or inform us of your revocation using the contact option provided at the end of this privacy notice.
Recipients:
Recipients of the data may be processors.
Storage duration:
The data will only be processed as long as the corresponding consent is in place. After that, they will be deleted.
Provision required or necessary:
The provision of your personal data is voluntary, solely based on your consent. Without existing consent, we cannot send you our newsletter.
Contact form
Type and purpose of processing:
The data you enter will be stored for the purpose of individual communication with you. For this, providing a valid email address and your name is required. This serves to assign the request and respond to it. Providing further data is optional.
Legal basis:
The processing of the data entered in the contact form is based on a legitimate interest (Art. 6 para 1 lit. f GDPR).
By providing the contact form, we want to enable you to have easy contact. Your statements will be stored for the purpose of processing the request and for possible follow-up questions.
If you contact us to request a quote, the processing of the data entered in the contact form is for the purpose of carrying out pre-contractual measures (Art. 6 para 1 lit. b GDPR).
Recipients:
Recipients of the data may be processors.
Storage duration:
Data will be deleted no later than 6 months after processing the request.
If a contractual relationship is established, we are subject to statutory retention periods under the Commercial Code (HGB) and will delete your data after these periods have expired.
Provision required or necessary:
The provision of your personal data is voluntary. However, we can only process your inquiry if you provide us with your name, email address, and the reason for the inquiry.
Use of Google Analytics
Type and purpose of processing:
This website uses Google Analytics, a web analytics service of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA (hereinafter: “Google”). Google Analytics uses so-called “cookies”, i.e., text files that are stored on your computer and enable an analysis of your use of the website. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there. Due to the activation of IP anonymization on these websites, your IP address will be truncated by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area beforehand. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there. On behalf of the operator of this website, Google will use this information to evaluate your website usage, compile reports on website activities, and provide other services related to website usage and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other data from Google.
The purposes of data processing lie in the evaluation of the use of the website and in the compilation of reports on activities on the website. Based on the use of the website and the internet, further related services should then be provided.
Legal basis:
The processing of the data is based on the consent of the user (Art. 6 para 1 lit. a GDPR).
Recipients:
The recipient of the data is Google as the processor. We have concluded the corresponding processing agreement with Google for this.
Storage duration:
The deletion of the data occurs as soon as they are no longer required for our recording purposes.
Third country transfer:
Google processes your data in the USA and has subjected itself to the EU-US Privacy Shield https://www.privacyshield.gov/EU-US-Framework.
Provision required or necessary:
The provision of your personal data is voluntary, solely based on your consent. If you prevent access, this may lead to functional restrictions on the website.
Revocation of consent:
You can prevent the storage of cookies by adjusting your browser software accordingly; however, we point out that in this case you may not be able to use all features of this website fully. Additionally, you can prevent the collection of data generated by the cookie and related to your usage of the website (including your IP address) to Google as well as the processing of this data by Google by downloading and installing the browser plugin available at the following link: Browser Add On to deactivate Google Analytics.
Additionally or as an alternative to the browser add-on, you can prevent tracking by Google Analytics on our pages by clicking this link. An opt-out cookie will be installed on your device as a result. This will prevent collection by Google Analytics for this website and for this browser for the future, as long as the cookie remains installed in your browser.
Profiling:
With the help of the tracking tool Google Analytics, the behavior of website visitors can be assessed and interests analyzed. For this, we create a pseudonymous user profile.
Use of script libraries (Google Webfonts)
Type and purpose of processing:
To correctly and graphically present our content in a cross-browser manner, we use “Google Web Fonts” from Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; hereinafter “Google”) for the presentation of fonts on this website.
The privacy policy of the library operator Google can be found here: https://www.google.com/policies/privacy/
Legal basis:
The legal basis for the integration of Google Webfonts and the associated data transfer to Google is your consent (Art. 6 para 1 lit. a GDPR).
Recipients:
The call for script libraries or font libraries automatically establishes a connection to the operator of the library. It is theoretically possible – currently, however, unclear if and possibly for what purposes – that the operator in this case Google collects data.
Storage duration:
We do not collect personal data through the integration of Google Webfonts.
Further information on Google Web Fonts can be found at https://developers.google.com/fonts/faq and in Google’s privacy policy: https://www.google.com/policies/privacy/.
Third country transfer:
Google processes your data in the USA and has subjected itself to the EU-US Privacy Shield https://www.privacyshield.gov/EU-US-Framework.
Provision required or necessary:
The provision of personal data is neither legally nor contractually required. However, the correct presentation of the content may not be possible without standard fonts.
Revocation of consent:
For the presentation of content, the programming language JavaScript is regularly used. Therefore, you can object to data processing by deactivating JavaScript execution in your browser or installing a JavaScript blocker. Please note that this may cause functional restrictions on the website.
Use of Google Maps
Type and purpose of processing:
On this website, we utilize the service of Google Maps. Google Maps is operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter “Google”). This allows us to show you interactive maps directly on the website and enables you the convenient use of the map feature.
Further information about data processing by Google can be obtained from Google’s privacy notices. There you can also change your personal privacy settings in the privacy center.
Detailed instructions on managing your data in connection with Google products can be found here.
Legal basis:
The legal basis for the integration of Google Maps and the associated data transfer to Google is your consent (Art. 6 para 1 lit. a GDPR).
Recipients:
By visiting the website, Google receives information that you have accessed the corresponding subpage of our website. This occurs regardless of whether Google provides a user account through which you are logged in, or whether no user account exists. If you are logged into Google, your data will be directly assigned to your account.
If you do not want the assignment to your profile at Google, you have to log out before activating the button. Google stores your data as usage profiles and uses them for purposes of advertising, market research, and/or needs-based design of its website. Such an evaluation occurs, especially (even for users who are not logged in) for the purpose of providing needs-based advertising and informing other users of the social network about your activities on our website. You have the right to object to the formation of these user profiles, wherein you must address Google to exercise this right.
Storage duration:
We do not collect personal data through the integration of Google Maps.
Third country transfer:
Google processes your data in the USA and has subjected itself to the EU-US Privacy Shield https://www.privacyshield.gov/EU-US-Framework.
Revocation of consent:
If you do not want Google to collect, process, or use data about you through our internet presence, you can disable JavaScript in your browser settings. In this case, however, you may not be able to fully utilize our website or may only do so to a limited extent.
Provision required or necessary:
The provision of your personal data is voluntary, solely based on your consent. If you prevent access, this may lead to functional restrictions on the website.
Embedded YouTube Videos
Type and purpose of processing:
On some of our web pages, we embed YouTube videos. The operator of the corresponding plugins is YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA (hereinafter “YouTube”). When you visit a page with the YouTube plugin, a connection is established to YouTube servers. In this process, YouTube is informed of which pages you visit. If you are logged into your YouTube account, YouTube can link your browsing behavior to you personally. You can prevent this by logging out of your YouTube account beforehand.
If a YouTube video is started, the provider uses cookies that collect information about user behavior.
Further information about the purpose and extent of data collection and its processing by YouTube can be found in the provider’s privacy notices. There you will also find further information about your rights and settings options to protect your privacy (https://policies.google.com/privacy). Google processes your data in the USA and has subjected itself to the EU-US Privacy Shield https://www.privacyshield.gov/EU-US-Framework
Legal basis:
The legal basis for the integration of YouTube and the related data transfer to Google is your consent (Art. 6 para 1 lit. a GDPR).
Recipients:
Calling YouTube automatically establishes a connection to Google.
Storage duration and revocation of consent:
Those who have disabled cookie storage for the Google ad program will not have to reckon with such cookies when viewing YouTube videos. However, YouTube also stores non-personal usage information in other cookies. If you wish to prevent this, you must block the storage of cookies in your browser.
Further information on data protection at “YouTube” can be found in the provider’s privacy policy at: https://www.google.de/intl/de/policies/privacy/
Third country transfer:
Google processes your data in the USA and has subjected itself to the EU-US Privacy Shield https://www.privacyshield.gov/EU-US-Framework.
Provision required or necessary:
The provision of your personal data is voluntary, solely based on your consent. If you prevent access, this may lead to functional restrictions on the website.
SSL encryption
To protect the security of your data during transmission, we use encryption procedures that correspond to the current state of technology (e.g., SSL) over HTTPS.
Engaged processors
The following organizations, companies, or individuals have been commissioned by the operator of this website to process data:
Change of our privacy policy
We reserve the right to adapt this privacy policy to ensure that it always complies with current legal requirements or to implement changes to our services in the privacy policy, e.g., with the introduction of new services. The new privacy policy applies for your renewed visit.
Questions to the Data Protection Officer
If you have questions about data protection, please send us an email or contact the person responsible for data protection in our organization directly:
Responsible for data protection: Gerhard Frank, ims media gmbh +43 650 88 99 1 99, office@my-bookings.org
The privacy policy was created with the help of activeMind AG, the experts for external data protection officers (Version #2019-04-10).