Privacy Policy
Preamble
With this privacy policy, we would like to inform you about the types of your personal data (hereinafter also referred to as “data”) we process, for what purposes and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the course of providing our services and, in particular, on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as “Online Offering”).
The terms used are not gender-specific.
Controller
DB Travels – David Brachnak
Böhringer Steige 17
78628 Rottweil
Germany
Email: info@db-travels.com
Phone: +49 176 30356752
Legal Notice (Impressum): https://db-travels.com/imprint-2/
Overview of Processing Activities
The following overview summarises the types of data processed and the purposes of their processing, and refers to the data subjects concerned.
Types of Data Processed
- Master data
- Payment data
- Location data
- Contact data
- Content data
- Contract data
- Usage data
- Meta, communication and process data
- Log data
Categories of Data Subjects
- Service recipients and clients
- Prospective customers
- Communication partners
- Users
- Business and contractual partners
Purposes of Processing
- Provision of contractual services and fulfilment of contractual obligations
- Communication
- Security measures
- Reach measurement
- Tracking
- Office and organisational procedures
- Audience building
- Affiliate tracking
- Organisational and administrative procedures
- Feedback
- Marketing
- Profiles with user-related information
- Provision of our online offering and user-friendliness
- Information technology infrastructure
- Public relations
- Business processes and business management procedures
Applicable Legal Bases
Applicable legal bases under the GDPR: The following provides an overview of the legal bases of the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations may apply in your or our country of residence or domicile. Should more specific legal bases be relevant in individual cases, we will inform you of these in this privacy policy.
- Consent (Art. 6(1)(a) GDPR) – The data subject has given consent to the processing of their personal data for one or more specific purposes.
- Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR) – Processing is necessary for the performance of a contract to which the data subject is party, or for carrying out pre-contractual measures taken at the request of the data subject.
- Legal obligation (Art. 6(1)(c) GDPR) – Processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Art. 6(1)(f) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject.
National data protection regulations in Germany: In addition to the data protection provisions of the GDPR, national regulations on data protection apply in Germany. This includes, in particular, the Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG). The BDSG contains specific provisions on the right to information, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and transmission as well as automated individual decision-making, including profiling. Furthermore, data protection laws of the individual German federal states may apply.
Security Measures
We take appropriate technical and organisational measures in accordance with legal requirements, taking into account the state of the art, implementation costs, the nature, scope, circumstances and purposes of processing, as well as the varying likelihood and severity of the threat to the rights and freedoms of natural persons, to ensure a level of protection appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data, as well as access, input, disclosure, availability assurance and separation thereof. Furthermore, we have established procedures to ensure the exercise of data subject rights, deletion of data and responses to data threats. We also consider data protection in the development and selection of hardware, software and procedures, in accordance with the principle of data protection by design and by default.
Securing online connections through TLS/SSL encryption technology (HTTPS): To protect the data of users transmitted via our online services from unauthorised access, we use TLS/SSL encryption technology. When a website is secured by an SSL/TLS certificate, this is indicated by the display of HTTPS in the URL, serving as an indicator to users that their data is being transmitted securely and in encrypted form.
Transmission of Personal Data
In the course of processing personal data, it may happen that data is transmitted to or disclosed to other bodies, companies, legally independent organisational units or persons. Recipients of this data may include, for example, service providers commissioned with IT tasks, or providers of services and content integrated into a website. In such cases, we comply with legal requirements and, in particular, conclude appropriate contracts or agreements with the recipients of your data that serve to protect your data.
International Data Transfers
Data processing in third countries: Where we transfer data to a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or where this occurs in the context of using third-party services or disclosing or transmitting data to other persons, entities or companies, this is always carried out in compliance with legal requirements.
For data transfers to the USA, we primarily rely on the Data Privacy Framework (DPF), which was recognised as a secure legal framework by an EU Commission adequacy decision on 10 July 2023. In addition, we have concluded Standard Contractual Clauses with the respective providers that comply with the requirements of the EU Commission and establish contractual obligations for the protection of your data.
This dual safeguard ensures comprehensive protection of your data: the DPF forms the primary level of protection, while the Standard Contractual Clauses serve as additional security. Should changes occur within the DPF framework, the Standard Contractual Clauses will take effect as a reliable fallback option.
Further information on the DPF and a list of certified companies can be found on the website of the US Department of Commerce at https://www.dataprivacyframework.gov/.
General Information on Data Storage and Deletion
We delete personal data that we process in accordance with legal provisions as soon as the underlying consents are revoked or no further legal grounds for processing exist. This applies in cases where the original processing purpose ceases to apply or the data is no longer needed. Exceptions to this rule exist where legal obligations or special interests require longer retention or archiving of data.
Retention and deletion of data: The following general periods apply for retention and archiving under German law:
- 10 years – Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets and the working instructions and other organisational documents necessary for their understanding (§ 147(1) No. 1 in conjunction with (3) AO, § 14b(1) UStG, § 257(1) No. 1 in conjunction with (4) HGB).
- 8 years – Accounting records, such as invoices and cost receipts (§ 147(1) Nos. 4 and 4a in conjunction with (3) sentence 1 AO, § 257(1) No. 4 in conjunction with (4) HGB).
- 6 years – Other business documents: received commercial or business letters, copies of sent commercial or business letters, other documents insofar as they are relevant for taxation (§ 147(1) Nos. 2, 3, 5 in conjunction with (3) AO, § 257(1) Nos. 2 and 3 in conjunction with (4) HGB).
- 3 years – Data required to consider potential warranty and compensation claims or similar contractual claims and rights are stored for the duration of the regular statutory limitation period of three years (§§ 195, 199 BGB).
Rights of Data Subjects
As a data subject, you are entitled to various rights under the GDPR, arising in particular from Articles 15 to 21 GDPR:
- Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on those provisions. Where personal data concerning you is processed for the purpose of direct marketing, you have the right to object at any time to the processing.
- Right to withdraw consent: You have the right to withdraw any consent given at any time.
- Right of access: You have the right to obtain confirmation as to whether data concerning you is being processed and to receive information about such data, as well as further information and a copy of the data in accordance with legal requirements.
- Right to rectification: You have the right to request the completion of data concerning you or the correction of inaccurate data concerning you in accordance with legal requirements.
- Right to erasure and restriction of processing: You have the right to request that data concerning you be erased without undue delay, or alternatively to request restriction of processing of the data in accordance with legal requirements.
- Right to data portability: You have the right to receive data concerning you that you have provided to us in a structured, commonly used and machine-readable format, or to request its transfer to another controller, in accordance with legal requirements.
- Right to lodge a complaint with a supervisory authority: You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work, or the place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the provisions of the GDPR.
Business Services
We process data of our contractual and business partners, e.g. customers and prospective customers (collectively referred to as “contractual partners”), in the context of contractual and comparable legal relationships and related measures, and in connection with communication with contractual partners (or pre-contractually), e.g. to respond to enquiries.
We use this data to fulfil our contractual obligations, including in particular the obligations to provide the agreed services, any update obligations, and remedies for warranty and other service disruptions. Furthermore, we use the data to safeguard our rights and for administrative tasks associated with these obligations, as well as for business organisation.
We delete data after the expiry of statutory warranty and comparable obligations, i.e. generally after four years, unless the data is stored in a customer account or must be retained for legal archiving purposes (e.g. for tax purposes, generally ten years).
Data types processed: Master data, payment data, contact data, contract data, usage data, meta/communication/process data.
Data subjects: Service recipients and clients; prospective customers; business and contractual partners.
Purposes: Provision of contractual services; security measures; communication; office and organisational procedures; business processes.
Legal bases: Performance of a contract (Art. 6(1)(b) GDPR); legal obligation (Art. 6(1)(c) GDPR); legitimate interests (Art. 6(1)(f) GDPR).
Payment Methods
In the context of contractual and other legal relationships, on the basis of legal obligations or otherwise on the basis of our legitimate interests, we offer data subjects efficient and secure payment options and use payment service providers in addition to banks and credit institutions for this purpose. Payment transactions are carried out exclusively via encrypted connections in accordance with the state of the art.
The terms and conditions and privacy notices of the respective payment service providers apply to payment transactions and can be accessed within the respective websites or transaction applications.
Legal bases: Performance of a contract (Art. 6(1)(b) GDPR); legitimate interests (Art. 6(1)(f) GDPR).
PayPal
Payment services (technical integration of online payment methods); Provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg; Legal basis: Performance of a contract (Art. 6(1)(b) GDPR); Website: https://www.paypal.com/de; Privacy policy: https://www.paypal.com/de/legalhub/paypal/privacy-full.
Provision of the Online Offering and Web Hosting
We process the data of users in order to provide them with our online services. For this purpose, we process the IP address of the user, which is necessary to transmit the content and functions of our online services to the user’s browser or device.
Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Hosting on Rented Server Space
We use storage space, computing capacity and software that we rent or otherwise obtain from a server provider (“web host”) for the provision of our online offering. Legal basis: Legitimate interests (Art. 6(1)(f) GDPR).
Collection of Access Data and Log Files
Access to our online offering is logged in the form of “server log files”. Server log files may include the address and name of the web pages and files accessed, date and time of access, data volumes transferred, notification of successful access, browser type and version, the user’s operating system, referrer URL, and generally IP addresses and the requesting provider. Log file information is stored for a maximum of 30 days and then deleted or anonymised. Legal basis: Legitimate interests (Art. 6(1)(f) GDPR).
1&1 IONOS
Services in the field of providing information technology infrastructure and related services (e.g. storage space and/or computing capacity); Provider: 1&1 IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany; Legal basis: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.ionos.de; Privacy policy: https://www.ionos.de/terms-gtc/terms-privacy.
Use of Cookies
The term “cookies” refers to functions that store information on users’ devices and read information from them. Cookies may also be used for various purposes, such as the functionality, security and comfort of online offerings, as well as the analysis of visitor flows. We use cookies in accordance with legal provisions. Where required, we obtain the prior consent of users. If consent is not necessary, we rely on our legitimate interests.
Storage duration: Temporary cookies (session cookies) are deleted at the latest after a user leaves an online offering and closes their device. Permanent cookies remain stored even after the device is closed, with a storage duration of up to two years unless otherwise stated.
General information on revocation and objection (opt-out): Users may revoke consent at any time and also object to processing in accordance with legal provisions, including through their browser’s privacy settings.
Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); consent (Art. 6(1)(a) GDPR).
Contact and Enquiry Management
When contacting us (e.g. by post, contact form, email, telephone or via social media) and in the context of existing user and business relationships, the information of the enquiring persons is processed insofar as this is necessary to respond to contact enquiries and any requested measures.
Data types processed: Contact data, content data, meta/communication/process data.
Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); performance of a contract (Art. 6(1)(b) GDPR).
Web Analytics, Monitoring and Optimisation
Web analytics (also known as “reach measurement”) is used to evaluate the visitor flows of our online offering and may include behaviour, interests or demographic information about visitors as pseudonymous values. With the help of reach analysis, we can, for example, recognise at what time our online offering or its functions or content are most frequently used, or invite reuse. We can also identify which areas require optimisation.
The IP addresses of users are stored, but we use an IP masking procedure (i.e. pseudonymisation by shortening the IP address) to protect users. In general, no clear data (such as email addresses or names) is stored in the context of web analytics, but pseudonyms.
Security measures: IP masking (pseudonymisation of IP address).
Legal bases: Consent (Art. 6(1)(a) GDPR); legitimate interests (Art. 6(1)(f) GDPR).
Google Analytics
We use Google Analytics for the measurement and analysis of the use of our online offering on the basis of a pseudonymous user identification number. This identification number does not contain any unique data such as names or email addresses. It is used to assign analytics information to a device in order to identify which content users have accessed within one or more usage processes, which search terms they used, or how they interacted with our online offering.
Google Analytics does not log or store individual IP addresses for EU users. Analytics provides coarse geographic location data by deriving metadata from IP addresses: city, continent, country, region, subcontinent. For EU traffic, IP address data is used exclusively for this derivation of geolocation data before being immediately deleted.
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Consent (Art. 6(1)(a) GDPR); Website: https://marketingplatform.google.com/intl/de/about/analytics/; Privacy policy: https://policies.google.com/privacy; Data processing agreement: https://business.safety.google/adsprocessorterms/; Third-country transfer basis: Data Privacy Framework (DPF), Standard Contractual Clauses; Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de; Ad display settings: https://myadcenter.google.com/personalizationoff.
Affiliate Programs and Affiliate Links
We integrate so-called affiliate links or other references (which may include, for example, search forms, widgets or discount codes) to the offerings and services of third-party providers into our online offering (collectively referred to as “affiliate links”). When users follow the affiliate links or subsequently take up the offerings, we may receive a commission or other benefits from these third-party providers (collectively referred to as “commission”).
In order to track whether users have taken up the offerings of an affiliate link used by us, it is necessary for the respective third-party providers to learn that users followed an affiliate link placed within our online offering. The assignment of affiliate links to the respective business transactions or other actions serves solely the purpose of commission accounting and is cancelled as soon as it is no longer required for the purpose.
Legal bases: Consent (Art. 6(1)(a) GDPR); legitimate interests (Art. 6(1)(f) GDPR).
Presences in Social Networks (Social Media)
We maintain online presences within social networks and process user data in this context in order to communicate with users active there or to offer information about us.
We point out that user data may be processed outside the European Union. This may entail risks for users, as enforcement of user rights could be made more difficult.
For a detailed description of the respective forms of processing and the options for objection (opt-out), we refer to the privacy policies and information provided by the operators of the respective networks.
Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Social network enabling the sharing of photos and videos, commenting on and favouriting posts, messaging, and subscribing to profiles and pages; Provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Website: https://www.instagram.com; Privacy policy: https://privacycenter.instagram.com/policy/; Third-country transfer basis: Data Privacy Framework (DPF).
Facebook Pages
Profiles within the social network Facebook – The controller is jointly responsible with Meta Platforms Ireland Limited for the collection and transmission of data from visitors to our Facebook page (“Fan Page”). Facebook uses this data to provide us with statistical analyses via the “Page Insights” service. The basis for this is an agreement with Facebook (“Information about Page Insights”: https://www.facebook.com/legal/terms/page_controller_addendum).
Provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/privacy/policy/; Third-country transfer basis: Data Privacy Framework (DPF), Standard Contractual Clauses.
Plugins and Embedded Functions and Content
We integrate functional and content elements into our online offering that are obtained from the servers of their respective providers (hereinafter referred to as “third-party providers”). These may be, for example, graphics, videos or maps (hereinafter uniformly referred to as “content”).
The integration always requires that the third-party providers of this content process the IP address of the users, as without the IP address they could not send the content to their browsers.
Legal bases: Consent (Art. 6(1)(a) GDPR); legitimate interests (Art. 6(1)(f) GDPR).
Google Maps
We integrate the maps of the “Google Maps” service. The data processed may include, in particular, IP addresses and location data of users; Provider: Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland; Legal basis: Consent (Art. 6(1)(a) GDPR); Website: https://mapsplatform.google.com/; Privacy policy: https://policies.google.com/privacy; Third-country transfer basis: Data Privacy Framework (DPF).
Changes and Updates
We ask you to regularly inform yourself about the content of our privacy policy. We adapt the privacy policy as soon as changes in the data processing carried out by us make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g. consent) or other individual notification.
DB Travels – David Brachnak | Böhringer Steige 17, 78628 Rottweil, Germany | info@db-travels.com
Last updated: June 2026