Your personal rights are our highest priority, and we strive to protect them to the best of our abilities. This Privacy Policy informs you about the nature, purpose, and scope of the processing of personal data on our online services (website and integrated functions).
We have implemented numerous technical and organizational measures to ensure the most complete protection possible of the personal data we process. Our security measures are continuously improved in line with technological advancements. However, data transmission over the Internet may have security vulnerabilities, so absolute protection cannot be guaranteed. Therefore, you are free to transmit personal data to us by alternative means, such as by telephone.
1. Types and Purpose of Data Processing
Types of data processed:
Contact details (name, address, phone number, email)
Messages, uploaded images
Usage data, pages visited, access times
IP addresses and device metadata
Data subjects:
Visitors and users of our website
Purpose of processing:
Provision of online content and functions
Processing bookings and orders
Responding to contact requests and messages
Security measures
Statistical evaluations
2. Data Controller
Hagen Alpin Tours
Pulver-Schnee
Dorfbrunnenstr. 7
87466 Oy-Mittelberg
Germany
Tel. +49 8366 988893
Fax +49 8366 988894
[email protected]
3. Definitions
“Personal data” refers to any information that relates to an identified or identifiable individual.
“Processing” means any operation involving personal data, whether automated or not.
“Controller” means any entity that determines the purposes and means of processing personal data.
4. Your Rights
You have the right to:
Confirm whether your data is being processed (Art. 15 GDPR)
Access and receive a copy of your data
Request correction or completion of your data (Art. 16 GDPR)
Request deletion (Art. 17 GDPR) or restriction of processing (Art. 18 GDPR)
Receive your data in a structured format or request transfer to another controller (Art. 20 GDPR)
Object to processing at any time (Art. 21 GDPR)
Withdraw consent for future processing (Art. 7(3) GDPR)
File a complaint with the relevant supervisory authority (Art. 77 GDPR)
5. Legal Basis for Processing
The legal basis for our processing activities is Art. 6 GDPR. We process your data only if:
You have given consent for specific purposes
Processing is necessary to perform a contract or pre-contractual measures
Processing is required to fulfill legal obligations
Processing protects vital interests
Processing is in the public interest or based on official authority
Processing serves our legitimate interests, provided they do not override your fundamental rights
6. Data Retention
We comply with statutory retention periods. Once these expire, data is deleted unless needed for contractual purposes.
7. Deletion
Personal data is deleted or restricted as per Art. 17 & 18 GDPR when no longer needed or when legal retention expires, particularly for invoices, bookings, and business records.
8. Processors
Data is only shared with third parties if:
Legally permitted under Art. 6(1)(b) GDPR
You have consented
Required by law
Justified by our legitimate interests (e.g., contractors, web hosts)
We sign data processing agreements (Art. 28 GDPR) with all processors.
9. Tramino Software and Services
We use services from Tramino (Weststrasse 30, 87561 Oberstdorf, Germany) under Art. 6(1)(f) GDPR and Art. 28 GDPR. Tramino does not use or disclose personal data for its own purposes.
All personal data is stored on secure servers in Germany with limited, authorized access.
10. Hosting and Logfiles
We use Tramino’s hosting for:
Platform delivery
Software, storage, and databases
Security and maintenance
Each server access is logged (page name, time, data volume, browser, OS, referrer, IP address). Logs are deleted after 30 days unless needed for evidence.
11. Amazon CloudFront and S3
We use Amazon CloudFront CDN and Amazon S3 (Amazon Web Services EMEA SARL) to deliver website content efficiently. Transfers to the U.S. are based on EU Standard Contractual Clauses.
12. Cookies
We use cookies to:
Save cart contents
Store user settings
Track referrer links for analytics
Enable login persistence
Cookies can be blocked or deleted via browser settings, though this may limit site functionality.
13. SSL Encryption
Our website uses SSL encryption via HTTPS to protect data transmission.
14. Contact Forms
We process contact form submissions using Tramino software under Art. 6(1)(b) GDPR. Data is stored in a CRM and deleted when no longer needed. Reviewed every two years.
15. Bookings & Orders
Booking/order data (contact, communication details, companion info, allergies) is stored in our CRM and deleted when no longer required. Reviewed every two years.
16. Newsletter
Newsletter distribution is managed by Tramino under Art. 6(1)(f) GDPR and Art. 28 GDPR. Data is not used for other purposes. A double opt-in is used. Tracking pixels and link clicks are anonymized and used only for statistical optimization.
17. Social Media
We use social media platforms to communicate with users. Their own privacy policies apply.
18. YouTube
YouTube videos are embedded with privacy-friendly settings. Upon clicking play, data may be sent to YouTube/Google. Please refer to YouTube’s privacy policy.
19. Google Analytics
We use Google Analytics with IP anonymization and a processing agreement in place. Data is processed in the U.S. under Standard Contractual Clauses. You can opt out via browser plugin.
20. Google Maps
We use Google Maps to display geographic data. Data is transferred under EU Standard Contractual Clauses. Google’s privacy policy applies.
21. Google Fonts (local)
Fonts are hosted locally and not retrieved from Google servers.
22. Google ReCaptcha
We use ReCaptcha to detect bots. Data (e.g., IP, mouse movements) is processed by Google under Standard Contractual Clauses.
23. Policy Validity
By using our site, you agree to this privacy policy. Changes may be made as technology or legal requirements evolve.
For questions, contact:
HAGEN ALPIN TOURS – [email protected]