Privacy Policy
General Information
Information about the responsible entity:
Tourismusverband Chemnitz Zwickau Region e. V.
Innere Klosterstraße 6 – 8
09111 Chemnitz
Germany
Management: Marika Fischer, Ina Klemm
Chairman of the Association: Carsten Michaelis
Tel.: 03716461410
Email: info@chemnitz-zwickau-region.de
Register: Association Register
Registration Number: VR5880
Registry Court: Amtsgericht Chemnitz
VAT Identification Number according to § 27 a German VAT Act: DE 361882256
Contact details of the Data Protection Officer:
Lawyer Dr. Sebastian Kraska, IITR Datenschutz GmbH, Marienplatz 2, 80331 Munich, email@iitr.de, Tel.: +49 (0)89 1891 7360
General Data Processing Information
Data Processed:
Personal data is only collected if you voluntarily provide it to us. No other personal data is collected. Any processing of your personal data beyond the scope of legal permission is only carried out on the basis of your explicit consent. We may transfer personal data to other entities within our organization or grant them access to this data. If this transfer is for administrative purposes, the transfer of data is based on our legitimate business and operational interests or occurs if it is necessary for the fulfillment of our contractual obligations or if the data subject has given consent or there is a legal permission.
Purpose of Processing:
Contract execution.
Categories of Recipients:
- Public bodies where overriding legal provisions exist.
- External service providers or other contractors.
- Other external bodies insofar as the data subject has given their consent or a transfer is permissible due to overriding interests.
Third Country Transfers:
In the context of contract execution, processors outside the European Union may also be used.
Data Storage Duration:
The duration of data storage is determined by statutory retention obligations and is generally 10 years.
Specific Information on the Website
Usage Data
When you access our websites, you transmit data (due to technical necessity) via your internet browser to our web server. The following data is recorded during an ongoing connection for communication between your internet browser and our web server:
- Date and time of the request
- Name of the requested file
- Page from which the file was requested
- Access status (file transferred, file not found, etc.)
- Web browser and operating system used
- Full IP address of the requesting computer
- Amount of data transferred.
For reasons of technical security, particularly to ward off attack attempts on our web server, we store this data temporarily. It is not possible for us to draw conclusions about individual persons based on this data. After a short period at the latest, the data is anonymized by shortening the IP address at the domain level, so that it is no longer possible to establish a connection to an individual user. In anonymized form, the data is also processed for statistical purposes; no comparison with other data sets or transfer to third parties, even in extracts, takes place.
Use of proprietary “cookies” required for website display
This website does not use cookies.
Information on Further Data Processing Procedures
Specific Information on the Application Process
Data Processed:
Application details
Purpose of Processing:
Execution of the application process.
Categories of Recipients:
Public bodies where overriding legal provisions exist. External service providers or other contractors, including for data processing and hosting. Other external bodies insofar as the data subject has given their consent or a transfer is permissible due to overriding interests, including customers and prospective clients as part of order acquisition.
Third Country Transfers:
In the context of contract execution, processors outside the European Union may also be used, including email providers.
Data Storage Duration:
Application data is generally deleted within four months after the decision has been communicated, unless consent for longer data storage in the context of inclusion in the applicant pool has been given.
Specific Information on the Processing of Customer Data/Prospective Client Data
Data Processed:
Data provided for contract execution; optionally, additional data for processing based on your explicit consent.
Purpose of Processing:
Contract execution, including offers, orders, sales and invoicing, quality assurance.
Categories of Recipients:
- Public bodies where overriding legal provisions exist.
- External service providers or other contractors, including for data processing and hosting, for shipping, transport and logistics, service providers for printing and sending information.
- Other external bodies insofar as the data subject has given their consent or a transfer is permissible due to overriding interests.
Third Country Transfers:
In the context of contract execution, processors outside the European Union may also be used, including email providers.
Data Storage Duration:
The duration of data storage is determined by statutory retention obligations and is generally 10 years.
Specific Information on the Processing of Employee Data
Data Processed:
Data provided for contract execution; optionally, additional data for processing based on your explicit consent.
Purpose of Processing:
Contract execution within the scope of the employment relationship.
Categories of Recipients:
- Public bodies where overriding legal provisions exist, including tax authorities, social security institutions, professional associations.
- External service providers or other contractors, including for data processing and hosting, for payroll accounting, for travel expense accounting, for insurance services.
- Other external bodies insofar as the data subject has given their consent or a transfer is permissible due to overriding interests, including for insurance services.
Third Country Transfers:
In the context of contract execution, processors outside the European Union may also be used, including email providers.
Data Storage Duration:
The duration of data storage is determined by statutory retention obligations and is generally 10 years.
Specific Information on the Processing of Supplier Data
Data Processed:
Data provided for contract execution; optionally, additional data for processing based on your explicit consent.
Purpose of Processing:
Contract execution, including inquiries, purchasing, quality assurance.
Categories of Recipients:
- Public bodies where overriding legal provisions exist, including tax authorities, customs.
- External service providers or other contractors, including for data processing and hosting, accounting, payment processing.
- Other external bodies insofar as the data subject has given their consent or a transfer is permissible due to overriding interests.
Third Country Transfers:
In the context of contract execution, processors outside the European Union may also be used, including email providers.
Data Storage Duration:
The duration of data storage is determined by statutory retention obligations and is generally 10 years.
Specific Information on the Use of Video Conferencing/Webinar Software
| Data Processed: | Data provided for the use of video conferencing software or webinar software (in particular first name, last name, email address; optional: audio transmission; optional: image transmission; optional: questions when using chat functions); processing of data from your system to the technically required extent to establish a connection with the conference software provider |
| Purpose of Processing: | Conducting video conferences or webinars. |
| Categories of Recipients: | Public bodies where overriding legal provisions exist. External service providers or other contractors, including for data processing and hosting. Other external bodies insofar as the data subject has given their consent or a transfer is permissible due to overriding interests. |
| Third Country Transfers: | Processors outside the European Union are used (here: United States of America); standard contractual clauses have been concluded with the service provider accordingly. |
| Data Storage Duration: | Video conferences are only recorded with the prior documented consent of the participants. Technical data is deleted when it is no longer required. Otherwise, the duration of data storage is determined by statutory retention obligations and is generally 10 years. |
Presences on Social Networks
We maintain online presences within social networks and process user data in this context to communicate with active users there or to offer information about us.
We point out that user data may be processed outside the European Union. This may result in risks for users, for example, because the enforcement of user rights could be made more difficult. With regard to US providers who are certified under the Privacy Shield or offer comparable guarantees of a secure level of data protection, we point out that they thereby undertake to comply with the data protection standards of the EU.
Furthermore, user data within social networks is generally processed for market research and advertising purposes. For example, usage profiles can be created based on user behavior and resulting user interests. These usage profiles can then be used to display advertisements within and outside the networks that presumably correspond to the users’ interests. For these purposes, cookies are generally stored on the users’ computers, in which the users’ usage behavior and interests are stored. Furthermore, data can also be stored in the usage profiles independently of the devices used by the users (especially if the users are members of the respective platforms and are logged in to them).
For a detailed description of the respective processing forms and the objection options (opt-out), we refer to the privacy policies and information of the operators of the respective networks.
Also, in the case of information requests and the assertion of data subject rights, we point out that these can be asserted most effectively with the providers. Only the providers have access to the users’ data and can directly take appropriate measures and provide information. Should you still need assistance, you can contact us.
Types of data processed: Inventory data (e.g., names, addresses), contact data (e.g., email, phone numbers), content data (e.g., text input, photographs, videos), usage data (e.g., visited websites, interest in content, access times), meta/communication data (e.g., device information, IP addresses).
Data subjects: Users (e.g., website visitors, users of online services).
Purposes of processing: Contact inquiries and communication, tracking (e.g., interest/behavior-based profiling, use of cookies), remarketing, reach measurement (e.g., access statistics, recognition of returning visitors).
Services Used and Service Providers:
Facebook: Social network; Service provider: Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, Parent company: Facebook, 1 Hacker Way, Menlo Park, CA 94025, USA; Website: https://www.facebook.com; Privacy Policy: https://www.facebook.com/about/privacy; Privacy Shield (Guarantee of data protection level when processing data in the USA): https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active; Objection option (Opt-Out): Ad settings: https://www.facebook.com/settings?tab=ads; Additional data protection notices: Agreement on joint processing of personal data on Facebook pages: https://www.facebook.com/legal/terms/page_controller_addendum, Data protection information for Facebook pages: https://www.facebook.com/legal/terms/information_about_page_insights_data.
Instagram: Social network; Service provider: Instagram Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA; Website:https://www.instagram.com; Privacy Policy:https://instagram.com/about/legal/privacy.
LinkedIn: Social network; Service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; Website: https://www.linkedin.com; Privacy Policy: https://www.linkedin.com/legal/privacy-policy; Privacy Shield (Guarantee of data protection level when processing data in the USA): https://www.privacyshield.gov/participant?id=a2zt0000000L0UZAA0&status=Active; Objection option (Opt-Out): https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
Further Information and Contacts
Furthermore, you can assert your rights to information, rectification or erasure, or to restriction of processing, or to exercise your right to object to processing, as well as the right to data portability, at any time. You have the option to contact us by email (info@chemnitz-zwickau-region.de) or letter (Tourismusverband Chemnitz Zwickau Region e. V., Innere Klosterstraße 6 – 8, 09111 Chemnitz). You also have the right to lodge a complaint with the data protection supervisory authority.
Feratel
On our website, we use the booking system of feratel media technologies AG (Maria-Theresien-Straße 8, 6020 Innsbruck, Austria; hereinafter: “feratel”). “feratel” is an online booking system that enables the mediation and booking of accommodation establishments. During the booking process, the personal data you enter (such as salutation, name, address, telephone number) is passed on to “feratel”. The purpose of the processing is to provide a simple and fast way to book accommodation via our website. The legal basis for the integration of the booking system is Art. 6 para. 1 sentence 1 lit. f) GDPR. Our legitimate interests lie in an efficient and secure booking process via our website and the user-friendly design of the booking process. Your data will be deleted as soon as it is no longer required for the processing purpose. Further information on the purpose and scope of processing by “feratel” and the storage duration can be found in “feratel”‘s privacy policy: https://www.feratel.de/datenschutz/.
You can object to the processing. Your right to object exists for reasons arising from your particular situation. You can send us your objection using the contact details provided in the “Controller” section.
Booking & more Account
You can create a customer account by registering with the following information:
- Email address and
- self-chosen password
- First and last name.
Furthermore, your IP address and the date and time of registration are processed at the time of registration. Otherwise, your data will be deleted as soon as it is no longer required for the purpose of processing. This is the case for data collected during the registration process if the registration on the website is cancelled or changed.
The following functions are available to you in the login area:
- Changing your profile data,
- Viewing completed bookings,
- Managing bookings,
- Online check-in.
If you use the login area of the website, for example, to edit your profile data or view completed bookings, we also process the data about your person required for initiating or fulfilling the contract, in particular address data and payment method details. The legal basis for processing is Art. 6 para. 1 sentence 1 lit. b) GDPR. The provision of your data is necessary and mandatory for the conclusion and/or execution of the contract. If you do not provide your data, you cannot register or use the login area, i.e., a contract cannot be concluded and/or executed. Your data will be deleted as soon as it is no longer required for the processing purpose. This is the case after the customer account has been deleted, unless we are obliged to retain the data due to legal regulations. In this case, we restrict processing. Due to mandatory commercial and tax law regulations, we are obliged to store your address, payment, and order data for a period of up to ten years.
COLLECTION, PROCESSING, STORAGE AND USE OF YOUR DATA WHEN USING DESTINATION.PAGES
GPS Location
The website requires access to the location of the customer’s device if, for example, the search results are to be sorted by „current location“ or the location is to be displayed on a map. User location data is only used for processing the request. The transmission of location data takes place via an encrypted connection. After the website use has ended, the location data is anonymized and statistically evaluated to improve the service. The location is regularly queried during use (the use is also visible on mobile devices via the displayed location arrow at the top of the display) and is stored in a cookie.
Wishlist
If users create a wishlist, it is also stored in a cookie so that the list can be displayed the next time it is used. The items in the wishlist are additionally stored on our servers to give the customer the option to share the wishlists with other users.
Contact Form „Inquiry“
We use the data you provide to process your inquiry for the offer you have selected. For this purpose, we forward your provided data in the form of an email to the provider of the offer and a copy of the email to the responsible operator of the website. Your provided data will also be stored for three months on our servers in a log file and then automatically and irrevocably deleted. No data is passed on to third parties, and to prevent unauthorized third-party access to your provided data, the contact form is encrypted using SSL technology.
Contact Form „Report a Problem“
We use the data you provide to process your inquiry to the responsible author of the offer. For this purpose, we forward your provided data in the form of an email to the responsible author. Your provided data will also be stored for three months on our servers in a log file and then automatically and irrevocably deleted. No data is passed on to third parties, and to prevent unauthorized third-party access to your provided data, the contact form is encrypted using SSL technology.
Contact Form „Submit Event“
We use the data you provide for the further processing of your submitted event. For this purpose, we forward your provided data via our web-based editorial system destination.data to the responsible editorial team. After a content review by the editorial team, your submitted event will be published or rejected. For details on the requirements for when events may be published, please contact the website operator in the imprint.
Contact Form „Holiday Exchange“
We use the data you provide to process your inquiry to all hosts within this website. For this purpose, we forward your provided data via our web-based editorial system destination.data for a limited period and to a limited number of hosts. By default, the period is 14 days and the number of hosts is limited to 25. This limitation is determined by the website operator. Furthermore, your provided data is sent in the form of an email to the responsible operator of the website. No data is passed on to third parties, and to prevent unauthorized third-party access to your provided data, the contact form is encrypted using SSL technology.
Contact Form „Book“
We use the data you provide to process your booking for the offer you have selected. For this purpose, we transmit your provided data using SSL technology to the booking system of the selected offer. Your provided data will also be stored for three months on our servers in a log file and then automatically and irrevocably deleted. No data is passed on to third parties, and to prevent unauthorized third-party access to your provided data, the contact form is encrypted using SSL technology.
Contact Form „Print“
We use the data you provide for the delivery of the PDF document by email. Your provided data will be stored for three months on our servers in a log file and then automatically and irrevocably deleted. No data is passed on to third parties, and to prevent unauthorized third-party access to your provided data, the contact form is encrypted using SSL technology.
Function „Share“
None of the provided data is further processed or stored on our server here. When using the corresponding function (e.g., Facebook or email), a direct link is made to the respective website of the provider.
CLOUDFLARE
We use the Content Delivery Network of the service provider Cloudflare Inc. to increase loading times in all our products.
Further information on the processing of your data by Cloudflare can be found at: www.cloudflare.com/de-de/privacypolicy
MAPBOX
We use the client API of the service provider Mapbox for displaying geographical maps.
Further information on the processing of your data by Mapbox can be found at: www.mapbox.com/legal/privacy
MAPTILER
We use the service provider Maptiler for the preparation and provision of geographical maps.
Further information on the processing of your data by Maptiler can be found at: www.maptiler.com/privacy-policy