Travel Consultation:

Tourlane GmbH Privacy Policy

Version 1.3

Applicable as of September 4, 2019

As of 25 May, 2018, the provisions of the EU General Data Protection Regulation (hereinafter referred to as the GDPR) have applied throughout Europe. With the following information, we would like to inform you about the processing of personal data carried out by Tourlane GmbH according to these new regulations (see Art. 13 GDPR). Please read our data protection declaration carefully. Should you have any questions or comments regarding this data protection declaration, you can address them at any time to the email address listed under item 2.

1. Overview

The following data protection information provides information on the nature and extent of the processing of so-called personal data by Tourlane GmbH. Personal data is information that can be directly or indirectly assigned to your identity.

What is personal data?
Personal data is any information relating to an identified or identifiable individual (hereinafter "person concerned"). This includes information such as your name, address, postal address, IP address, telephone number or email address. This does not include information that isn’t directly associated with your real identity (such as favourite websites or number of users of a page).

What is anonymous data?
Every time you access the content of our website, general information is automatically stored (e.g. number and duration of users of individual pages, etc.). This data is not personal because it does not relate to an identified or identifiable natural person. The data is therefore processed anonymously. Information of this kind serves exclusively statistical purposes and is used by us for the optimisation of our website.

Data processing via the Tourlane website can essentially be divided into two categories:

• Tourlane processes all data required for the purpose of providing our services, in particular for the preparation of tailor-made travel offers and for the organisation of travel. This enables us to offer our customers and potential customers the best possible service. If third parties, e.g. tour operators, subcontractors, etc. are involved in the planning or the execution of the trip, your data will be passed on to them to the extent required.
• When you access Tourlane's website, various information is exchanged between your terminal device and our server. This may also involve personal data. The information collected in this way is used, among other things, to optimise our website or to display advertisements in the browser of your terminal device.
In accordance with the requirements of the GDPR, you have different rights which you can assert against us. These include the right to object to selected data processing, in particular data processing for advertising purposes. The possibility of objection is highlighted typographically. Should you have any questions regarding our data protection information, please feel free to contact our data protection officer at any time. Please find the contact details below.

2. Name and contact details of the controller and of the data protection officer
This data privacy policy applies to data processing by Tourlane GmbH, Köpenicker Straße 126, 10179 Berlin and to our website https://www.tourlane.co.uk/. The Tourlane GmbH data protection officer can be contacted at the above address (please mark attention to the data protection department) or at datenschutz@tourlane.de.

3. Purposes of data processing, legal bases and legitimate interests pursued by Tourlane or a third party and categories of recipients

3.1. Visiting our website
When you access our website, the browser used on your terminal device automatically sends information to the server of our website and temporarily stores it in a so-called log file. We have no influence over this.
The following information is recorded without your intervention and stored until it is automatically deleted:

• The IP address of the requesting Internet-enabled device
• The date and time of the access
• The website from which the access was made (referrer URL)
• Your individual campaign ID
• The browser you are using and, if applicable, the operating system of your Internet-capable computer as well as the name of your access provider.

The legal basis for processing the IP address is Art. 6 Para. 1 lit. f) GDPR. Our legitimate interest is outlined in the purposes of data collection listed below. At this point we would like to point out that we cannot and will not draw any conclusions about your identity from the data collected.
The IP address of your terminal device and the other data listed above are used by us for the following purposes:

• Ensuring a smooth connection setup
• Ensuring a convenient use of our website
• Evaluation of system safety and stability
• Other administrative purposes

The data is stored for the duration of the respective session and automatically deleted when the browser is closed. We also use cookies, tracking tools and a CRM system for our website. The exact procedures involved and how your data is used for such purposes will be explained in detail in Section 3.4 below.

3.2. Data processing for the provision of our offer and for the execution of the contract

3.2.1. Data processing to determine travel ideas in the questionnaire
The main objective of Tourlane is to offer custom-made trips to exotic destinations. The aim is to be able to offer the prospective customer a unique trip based on his or her preferences and needs. For this purpose, we provide a questionnaire on our website, which the interested party can use to provide information about their individual travel preferences. To this end, we process the data required for the preparation of our offers.

This includes:
• First and last name of the interested party
• Provided contact details
• Specified gender
• Information provided on travel ideas
• Browser information
• Host name of the accessing computer (IP address)
• Time of the server request

• The legal basis for this is Art. 6 (1) (b) GDPR. If we do not use your contact data for advertising purposes (see below 3.3.), we will store the data collected through the questionnaire until the expiration of the statutory limitation period. After this period has expired, we will retain the information of the contractual relationship required under commercial and tax law for the periods specified by law. For this period (usually ten years from the conclusion of the contract), the data will be reprocessed solely in the event of verification by the tax authorities.

3.2.2. Data processing for individual travel advice
If you have decided to make use of the services for individual travel advice and planning, we will try to identify in cooperation with you the key data and information important for your travel planning on the basis of Art. 6 Para. 1 lit. a) and lit. b) GDPR. The purpose of this processing is to provide you with the best possible service. In particular, the following data will be processed:

• Type of travel (round trip, safari, golf holiday, etc.)
• Estimated travel time
• Number of travellers
• Preferred destinations
• Type of accommodation
• Culinary preferences

We will store the data collected in this way until the end of the statutory limitation period. After this period has expired, we will retain the information of the contractual relationship required under commercial and tax law for the periods specified by law. For this period (usually ten years from the conclusion of the contract), the data will be reprocessed solely in the event of verification by the tax authorities.

3.2.3. Data processing for payment processing via Concardis
If a customer opts for a credit card payment, we will transmit the payment data provided by the customer such as name, address, account number, bank sort code, any credit card number, invoice amount, currency and transaction number to our payment service provider Concardis GmbH, Helfmann-Park 7, 65760 Eschborn (hereinafter referred to as "Concardis") in order to ensure smooth payment processing and on the basis of Article 6 (1) (b) GDPR. The data is used by Concardis exclusively for the execution and realisation of the respective payment processing and transmitted securely via the "SSL" encryption procedure. Concardis is certified as a service provider based in Germany according to PCI DSS (Payment Card Industry Data Security Standard). For more detailed information on data protection at Concardis, please refer to the provider's privacy policy or contact the provider's data protection officer directly at Datenschutzbeauftragter@concardis.com or at the above address.

3.2.4. Data processing for the provision of individual travel brochures via Wetu
In order to provide our customers with a brochure with comprehensive information for the booked journey, we use the content management and presentation tool of Wetu, a service of Wetu B.V., Overschiestraat 184-B, 1062 XK, Amsterdam, Holland (hereinafter "Wetu") on the basis of Art. 6 para. 1 lit. f) GDPR.
For this purpose, we transmit the following data:

• The advertisement that the visitor used to reach us
• Travel dates
• Details of the trip
• Email address

to Wetu, so that we can send our customers an email with comprehensive information material, such as photos, videos, descriptions, documentation, travel tips, etc. for the upcoming trip before the start of the journey. This data processing thus serves to optimise our services and, in particular, to ensure smooth travel processing, which is to be regarded as our legitimate interest. You can object to this data processing at any time by informing us that you no longer wish this processing to take place in the future. Please use the contact details of our data protection officer for this purpose. You can also address your request directly to Wetu's data protection officer, who can be reached at privacy@wetu.com or the above address of the provider. Further comprehensive information on data protection at Wetu can be found in the provider's privacy policy.

3.2.5. Data processing for flight booking via Conso
If a customer decides to travel by air, we shall transmit the data required for this purpose on the basis of Art. 6 Para. 1 lit. b) GDPR as well as for "co-booked" persons on the basis of Art. 6 Para. 1 lit. f) GDPR for the purpose of the respective flight booking, such as

• First name, surname and address of the passengers
• Gender of air passengers
• Dates of birth of air passengers
• Passport numbers of air passengers
• Contact details provided
• Data concerning the desired flight, such as travel dates, departure and destination airports of the trip, etc.
• The information provided on the baggage
• Where applicable, information on special needs

to our booking partner for air travel Conso, a service of Aerticket GmbH, Boppstraße 10, 10967 Berlin (hereinafter: "Conso"). The data will be exclusively used by Conso for the processing of our enquiry and for the execution and realisation of the respective flight booking and transmitted securely via the "SSL" encryption procedure. If the data required for this is not collected directly from the person concerned, the data processing serves the fulfilment of our contractual obligations, namely the processing of the enquiry and the booking of the flight, which is to be regarded as our legitimate interest. You can object to this data processing at any time by informing us that you no longer wish this processing to take place in the future. Please use the contact details of our data protection officer for this purpose. You can also address your request directly to the data protection officer of the provider, Prof. Dr. Lauser, who can be reached at rolf@lauser-nhk.de or the address Dr. Gerhard-Hanke-Weg 31, 85221 Dachau. Further detailed information on data protection at Conso can be found in the provider's data protection declaration.

3.2.6. Data processing for contract execution
If you decide to book an individual tour proposed by us, we will use the data provided by you on the basis of Art. 6 Para. 1 lit. b) GDPR to fulfil the contract, i.e. in particular to plan and prepare your flights and other planned activities.

The data required for this purpose includes:

• First name, surname of travellers
• Addresses
• Dates of birth
• Arrival and departure day
• Passport numbers
• Payment and booking details

This data will be transferred to the extent necessary to the companies involved, such as affiliated tour operators, airlines, hotels, local activity organisers, shuttle service. This transmission is necessary in order to carry out the individual activities and thus ensures smooth contractual processing. We have made a contract for order processing with all partners in accordance with the GDPR, which is why your data will only be processed in accordance with specific regulations. We will store this travel master data until the statutory limitation period expires. After this period has expired, we will retain the information of the contractual relationship required under commercial and tax law for the periods specified by law. For this period (usually ten years from the conclusion of the contract), the data will be reprocessed solely in the event of verification by the tax authorities.

3.2.7. Data processing for billing purposes via Billomat
To prepare our invoices, we use the accounting services of Billomat GmbH & Co. KG, Barbiergasse 6, 90443 Nuremberg (hereinafter: "Billomat ") on the basis of Art. 6 Para. 1 lit. b) GDPR. If you book a trip via us, we will create the necessary invoice documents via the online application provided by Billomat. For this purpose, the data required for the respective execution shall be processed via the Billomat servers, in particular:

• Name
• Address
• Email
• Booking details

We have made an agreement with Billomat for order data processing in accordance with Art. 28 GDPR, whereby "Billomat" agrees to process the user data only in accordance with our instructions and to comply with the EU data protection level. The data will be deleted after the expiration of the storage obligations under commercial and tax law. Additional information regarding Billomat and the data protection of the provider can be found in their data protection declaration. If you have any questions about data processing at Billomat, you can also contact the Billomat data protection officer, Mr. Dominik Fünkner, directly at any time: datenschutz@billomat.com.

3.2.8. Data processing via the Tourlane Customer Portal
If you have decided to complete our questionnaire in accordance with section 3.2.2, we will provide you with access to our Customer Portal on the basis of Art. 6 (1) (b) GDPR in order to better manage your data and travel. The purpose of this processing is to provide you with the best possible service by allowing you to manage and process your data, travel and preferences yourself. In particular, the following data may be processed for this purpose:

• The data transmitted by you according to section 3.2.2
• Additional information provided by you and stored in the Customer Portal

We store the data collected in this way until the end of the statutory limitation period. After this period has expired, we will retain the information of the contractual relationship required under commercial and tax law for the periods specified by law. For this period (usually ten years from the conclusion of the contract), the data will be reprocessed solely in the event of verification by the tax authorities.

3.3. Data processing for customer support, customer care, feedback or newsletter mailing

3.3.1. Newsletter registration via Double-Opt-In
On our website we offer you the possibility to subscribe to our newsletter. In order to make sure that no mistakes were made when entering the email address and that the email belongs to the actual owner, we use the so-called double-opt-in procedure: after you have entered your email address in the registration field, we will send you a confirmation link. Only when you click on this confirmation link will your email address be added to our mailing list. You can revoke your consent at any time in the future. To do this, just send a short note by email to the email address provided under section 2.

3.3.2. Feedback via Trustpilot
The satisfaction of our customers is our highest priority. Therefore, we occasionally ask our customers for their feedback after returning home. In order to obtain customer evaluations, we use the evaluation service Trustpilot, a service of Trustpilot, Inc., 245 5th Avenue, 5th floor, New York, NY 10016, USA (hereinafter: "Trustpilot") via an interface on the basis of Art. 6 Para. 1 lit. f) GDPR. You are, of course, free to submit an assessment. If you help us with an evaluation of your trip, then the data generated here, such as in particular
• Name
• Email
• The contents of the evaluation

will be processed and stored on Trustpilot's servers in the USA. If you want to avoid this kind of data processing, you should not participate in such a survey. This data processing to improve our products and services is to be regarded as our legitimate interest. If you submit your rating by clicking on the link contained in our invitation, you agree to the Trustpilot Privacy Policy and Terms and Conditions. By participating in this feedback system, your rating will be published on our website and on Trustpilot's website. The data will not be passed on to third parties. We have entered into a contract with Trustpilot for this order data processing so that the European standards for lawful data processing are guaranteed. Additional information on Trustpilot and data protection can be found in the provider's privacy policy. You can also object to this data processing at any time. Please use the contact details of our data protection officer or contact Trustpilot directly: support@trustpilot.com.

3.3.3. Feedback, scheduling and communication via Typeform

In order to control surveys, record user experiences, communicate in pre-sales or to arrange appointments, we use the survey tool of Typeform, a service of Typeform S.L., Carrer Bac de Roda 163, 08018 Barcelona, Spain (hereinafter referred to as "Typeform") on the basis of Art. 6 para. 1 lit. f) DSGVO. If you use our survey tool or request a callback, data generated such as

• Name
• Email address
• Reference number
• Telephone number
• Booking number
• Travel destination
• The contents of the rating or entires and the individual ratings
• The telephone number, if provided

will be processed and stored on the Typeform servers. This data processing for the improvement of our products and services is to be regarded as our legitimate interest. If you wish to avoid this type of data processing, you should not participate in such a survey. If you take part in a survey system, the data generated in this way will be published by us and the Typeform server. The data will not be passed on to third parties. We have entered into a contract with Typeform for this order data processing, so that the European standards for a legally compliant data processing are guaranteed. Additional information on Typeform and data protection can be found in the provider's data protection declaration. You can also object to this data processing at any time. Please contact Typeform directly by using the contact form.

3.3.4. Facebook fan page
For marketing purposes and to communicate with our customers via Facebook, we maintain a Facebook fan page on the platform, which is operated by Facebook Inc., 1601 South California Avenue, Palo Alto, CA 94304, USA ("Facebook"). In accordance with the opinion of the data protection authorities, we are jointly responsible with Facebook for the data processing carried out in this way in accordance with Art. 26 GDPR. Therefore, together with the provider, we have determined the purposes and means of processing. We use the Facebook fan page in particular for statistical evaluation, but also for communication with our customers. In particular, the following information can be assigned and processed by us and Facebook for a specific profile:

• If you “like” or “follow” our page
• Given ratings and comments
• "Sharing" our posts or posts that link to our page
• "Checking in " when using our guest network in the Berlin office

Other statistical aggregated information, such as visitor numbers, page promotions, etc., cannot be attributed by us to any specific or identifiable person and are therefore not personally identifiable to us. The legal basis for the aforementioned processing is Article 6 para. 1 lit. b) GDPR. We have no influence on the further data processing carried out by Facebook. The purpose and scope of the data collection by Facebook and the further processing and use of the data as well as your rights in this regard and setting options to protect your privacy can be found in the relevant data protection information from Facebook.

3.3.5. MailChimp
In order to optimise our newsletter service and to monitor customer satisfaction, we use the mailing tool MailChimp (hereinafter: "MailChimp") on the basis of Art. 6 Para. 1 lit. b) GDPR, an offer from The Rocket Science Group, LLC, 512 Means St., Suite 404 Atlanta, GA 30318, USA. If you have subscribed to our newsletter, the following data will be processed via the MailChimp servers:

• Name
• Email address
• Travel preferences (destination, travel time, travel type)
• Login process
• Date of birth, if applicable
• Data about interactions with Tourlane emails

Mailchimp is certified according to the "Privacy Shield Framework" and thus meets the European standards for legally compliant data processing. Additional information on MailChimp and data protection at MailChimp can be found in the provider's privacy policy as well as in their further explanations on GDPR. If you have any questions about data processing at MailChimp, you can also contact MailChimp's data protection officer directly: privacy@mailchimp.com. You can object to this processing at any time. To do so, please use the contact details for our data protection officer.

3.3.6. Timekit
In order to simplify the scheduling of customer and consultation discussions, we use the services of the Timekit Inc., 325 9th Street, San Francisco, CA 94103, USA (hereinafter called "Timekit") on basis of Art. 6 Abs.1 1 lit. b) GDPR. Timekit offers an external platform for making and planning appointments. When you provide your telephone number, we store the information collected and provided on Timekit servers. This includes in particular:

• Provided email address
• Name
• Telephone number provided
• IP Address

This data processing by Timekit considerably simplifies our scheduling, which serves our legitimate interest. The data provided will not be passed on to third parties at any time and will only be used for appointment scheduling and planning as well as internal statistics. We have concluded a contract with Timekit for order processing in accordance with Art. 28 GDPR, in which Timekit agrees to process the data received only in accordance with our instructions and to comply with the EU data protection standards. In addition, Timekit is certified according to the "Privacy Shield Framework" and thus meets the European standards for legally compliant order data processing. Additional information about Timekit and Timekit's privacy policy can be found in the provider's privacy policy. If you have any questions about data processing at Timekit, you can also contact the provider directly at any time: yourfriends@timekit.io.

3.3.7. Salesforce
We use the CRM platform Salesforce, a service of salesforce.com Inc., The Landmark One Market Suite 300, San Francisco, CA 94105, USA (hereinafter: "Salesforce"), to manage our customer data and prospects. This helps us to collect customer data, communicate with customers, document this contact, and create desired offers. If you have contacted us, e.g. via the questionnaire, the following data will be processed via the Salesforce servers:

• Name
• Email address
• Travel preferences (destination, travel time, travel type)
• Offers for the customer
• Data transmitted by the customer over telephone calls
• Data about interactions with Tourlane emails

This processing is carried out on the basis of Art. 6 para. 1 lit. b) and lit. f) GDPR and serves to improve our services and customer care, which is to be regarded as our legitimate interest. Salesforce is certified according to the "Privacy Shield Framework" and thus meets the European standards for legally compliant data processing. For additional information about Salesforce and Salesforce's privacy, see Salesforce's Privacy Policy. You may object to this processing at any time. To do so, please use the contact details of our privacy officer.

3.3.8. ActiveCampaign
For the organization and analysis of our mailing campaigns, we use the services of ActiveCampaign LLC, 150 N. Michigan Ave Suite 1230, Chicago, IL, US, USA (hereinafter: "ActiveCampaign") on the basis of Art. 6 Para. 1 lit. f) GDPR. When you open an email sent with ActiveCampaign, a file contained in the email (known as a web beacon) connects to ActiveCampaign's servers, so that the mail-related data, in particular:

• Information about the newsletter
• Name
• Email address
• Opening and click rates
• IP address
• Browser type and operating system

is processed and stored on the servers of ActiveCampaign in the USA. This enables the system to determine whether a mail has been opened and which links have been clicked. This information can be assigned to the respective recipient. It is used exclusively for statistical analysis of our mailing campaigns. The results of these analyses can be used to make our campaigns more attractive, to avoid nuisances and to better adapt future newsletters to the interests of the recipients. Campaign analysis and optimisation is our legitimate interest. ActiveCampaign has a certification according to the "EU-US-Privacy-Shield", which you can see here and thus fulfils the European standards for a legally compliant order data processing. Additional information on ActiveCampaign and data protection at ActiveCampaign can be found in the provider's privacy policy and in the further explanations on GDPR and GDPR compliance. If you have any questions about data processing at ActiveCampaign, you can also contact ActiveCampaign's data protection officer directly: info@activecampaign.com.

If you do not want ActiveCampaign to analyse your data, you can opt out at any time by clicking on the unsubscribe buttons in the email or by simply clicking this link. Alternatively, you can inform us of your wish not to receive future mailings from us. To do so, please contact our data protection officer or contact the provider directly: info@activecampaign.com.

3.3.9. Sendgrid
For email correspondence with customers and interested parties, such as registration and appointment confirmations, we use the Sendgrid shipping software, a service of Sendgrid Inc., 1801 California Street, Denver, CO 80202, USA (hereinafter: "Sendgrid"), on the basis of Art. 6 Para. 1 lit. b) and lit. f) GDPR. Here the following data such as:

• Email address
• Name
• Opening and click rates
• Contents of the respective transaction
• IP-Address
• Login process

via the servers of Sendgrid in the USA. Sendgrid is used to process customer inquiries and is part of our service and customer support, which is our legitimate interest. Sendgrid is certified according to the "Privacy Shield Framework“ and thus meets the European standards for legally compliant order data processing. Additional information about Sendgrid and Sendgrid's privacy policy can be found in the provider's privacy policy. You may object to this data processing at any time by informing us that you do not want it processed in the future. Please use the contact details of our data protection officer for this purpose.

3.4. Online presence and website optimisation

3.4.1. Cookies – General information
We use so-called cookies on our website on the basis of Art. 6 Para. 1 lit. f GDPR. Our interest in optimising our website is to be regarded as legitimate in terms of the aforementioned provisions. Cookies are small files which your browser automatically creates and which are stored on your device (laptop, tablet, smartphone, etc.) when you visit our website. Cookies do not cause any damage to your device and do not contain any viruses, Trojans or other malware. Information is stored in the cookie, which results in each case in conjunction with the specifically used terminal device. This does not mean, however, that we will immediately become aware of your identity. The use of cookies serves firstly to make the use of our services more convenient for you.

3.4.2. Session Cookies
When you visit our website, we use so-called session cookies to recognise that you have already visited individual pages on our website. These are automatically deleted when you leave our site. Most browsers automatically accept cookies. However, you can configure your browser so that no cookies are stored on your computer or a message always appears before a new cookie is created. Note that if you disable cookies completely, you may not be able to use all the features on our website. The length of time that cookies are stored depends on their purpose and is not the same for everyone.

3.4.3. Tourlane Cookies
We use our own cookies on the basis of Art. 6 Para. 1 lit. f) GDPR for the purpose of designing and continuously optimising our web pages in line with our needs. If you visit one of our websites, your browser will be assigned a pseudonymous identification number (ID). The cookie does not process any personal information, only technical data, such as

• Session-ID (Cookie name: visit_id)
• User-ID (Cookie name: tourlane_id),
• Referrer URL (the previously visited page)
• URL of the visited website
• Hostname of the accessing computer (IP address)
• Browser type/version
• Device name
• Operating system
• Time of the server request

The data will be processed via our servers and stored there. We use this information for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage for the purposes of market research and tailoring our websites to meet your needs, which is considered our legitimate interest. You can object to this processing at any time by either deleting the cookie from your device, downloading and installing a browser add-on such as "Cookie AutoDelete," using the deactivation service Network Advertising Initiative or informing us of your request. To do this, please use the contact details of our company data protection officer: datenschutz@tourlane.de

3.4.4. LinkedIn Pixel
In order to design, further optimise and measure the conversion of our job advertisements in line with requirements, we use an individual so-called visitor action pixel from LinkedIn, LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA (hereinafter "LinkedIn") on the basis of Art. 6 Para. 1 lit. f GDPR. This allows us to track the behaviour of site visitors after they have been redirected to our recruiting pages by clicking on a LinkedIn ad. This allows us to evaluate the effectiveness of our LinkedIn advertisements for statistical purposes and to optimise future advertising. In particular, the following information is processed during use:

• Timestamp
• Referrer-URL
• Campaign related information (especially specification of the impression, form field, activated button)
• Demographic information such as job title, seniority, company, company size, location, and country

The data collected in this way is anonymous to us and therefore does not allow us to draw any conclusions about the identity of the respective user. The processing for behavioural and interest-based advertising purposes is to be regarded as our recognised legitimate interest according to recital 47 of the GDPR. The data will be stored according to the legal retention periods and then automatically deleted. The data is also stored and processed by LinkedIn so that a connection to the respective user profile can be established and LinkedIn can use the data for its own advertising purposes in accordance with LinkedIn’s privacy policy. LinkedIn is certified according to the "Privacy Shield Framework" and thus meets the European standards for legally compliant order data processing. Additional information about LinkedIn and LinkedIn's privacy policy can be found in the provider's privacy policy. You can object to this specific data processing at any time by clicking this link and then clicking the "Reject" button.

3.4.5. Google Tag Manager
With Google Tag Manager we manage website tags (website code). This makes it easier for us to manage and develop our offering and shorten your loading time. Google Tag Manager only implements website code. Google Tag Manager does not set any cookies and does not collect any personal data. The tool only integrates website code that we store elsewhere, which may be used to collect information. The tool therefore serves to facilitate the control of the respective code and does not access the data processed by the code. We will inform you about all integrated tags in this privacy policy. Further information about Google Tag Manager and the usage guidelines can be found on Google.

3.4.6. Google Ads Conversion Tracking
To control and improve our campaigns, we use the online advertising program "Google AdWords" and the analysis tool Conversion-Tracking, a service of Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter: "Google") on the basis of Art. 6 Para. 1 lit. f) GDPR. When you click on an ad placed by Google, a conversion tracking cookie is placed on your computer. The information generated by the cookie includes:

• Clicked advertisements
• Browser type/version
• Operating system
• Location
• Referrer URL (the previously visited page)
• Host name of the accessing computer (IP address)
• Time of the server request

and are transferred to a Google server in the USA and stored there. These cookies lose their validity after 30 days, contain no personal data and are therefore not used for personal identification. If you visit certain pages on our website and the cookie has not yet expired, Google and Tourlane may recognise that you clicked on the ad and were directed to that page. Each Google AdWords customer receives a different cookie. As a result, there is no way that cookies can be tracked through AdWords customer websites. The information collected through the cookie is used to compile conversion statistics for us as AdWords customers. This tells us the total number of users who clicked on our ad and were directed to a page with a conversion tracking tag. However, we do not receive any personally identifiable information. This processing for behaviour- and interest-based advertising purposes is to be regarded as our recognised legitimate interest according to Recital 47 of the GDPR.

You can prevent this processing in advance through preventing the installation of cookies by setting your browser accordingly (using the deactivation option) or by setting your browser so that cookies are not accepted by the domain "googleleadservices.com." You can also object to the processing by setting the slider in your Google settings to "Off".

3.4.7. Google Analytics
For the purpose of the need-based design and continuous optimisation of our websites, we use the Google Analytics analysis service of Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter: "Google") on the basis of Art. 6 Para. 1 lit. f) GDPR. In this context, anonymous user profiles will be created and cookies will be used. Information generated by the cookie about your use of this website includes:

• Browser type/version
• Device name
• Operating system used
• Referrer URL (the previously visited page)
• Keywords/specific searches
• Service provider
• Host name of the accessing computer (IP address)
• Time of the server request

and will be transferred to a Google server in the USA and stored there. This information is used to evaluate the use of the website, to compile reports on activities and to provide other services relating to website and Internet use for market research purposes and to tailor these websites to meet specific needs. This information may also be transferred to third parties if this is required by law or if third parties process this data on behalf of third parties. Under no circumstances will your IP address be merged with other Google data. The IP addresses are anonymised so that an allocation is not possible (so-called IP masking). You can object to this data processing at any time by preventing the installation of cookies by setting the browser software accordingly; however, we would like to point out that in this case not all functions of our website may be fully usable. You can also prevent the collection of data generated by the cookie and relating to your use of the website (including your IP address) and the processing of this data by Google by downloading and installing this browser add-on. As an alternative to the browser add-on, especially for browsers on mobile devices, you can also prevent the collection by Google Analytics by clicking on this link. An opt-out cookie is set to prevent your information from being collected in the future when you visit this website. Please note that the opt-out cookie is only valid in the browser used and only for our website and will be stored on your device. If you delete the cookies in this browser, you must set the opt-out cookie again. You can find further information on data protection in connection with Google Analytics on the Google Analytics website.

3.4.8. Google Dynamic Remarketing
We use the remarketing or "similar target group" tool of Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter: "Google") on the basis of Art. 6 Para. 1 lit. f) GDPR. This function serves the purpose of analysing visitor behaviour and interests. Google uses cookies to analyse website usage, which forms the basis for creating interest-related advertisements. The cookies are used to record visits to the website and anonymous data on the use of the website. There is no storage of personal data of website visitors. If you subsequently visit another website in the Google advertising network, you may see advertisements that are highly likely to include previously accessed product and information areas and may be similar to these.
Your data will be processed by the Google servers in the USA if necessary. The processing in this way for behavioural and interest-based advertising purposes is to be regarded as our recognised legitimate interest according to Section 47 of the GDPR.
You can object to this data processing at any time by downloading and installing this browser add-on. You can also permanently disable the use of third-party cookies by configuring the Network Advertising Initiative disable page accordingly. For detailed information about Google Remarketing and its privacy policy, please visit: https://www.google.com/privacy/ads/

3.4.9. GA Audiences
For the purpose of enabling interest-related control of our campaigns within the Google advertising network, we use the web analysis service of GA Audiences, a service of Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter: "Google") on the basis of Art. 6 Para. 1 lit. f) GDPR. In this context, anonymous user profiles may be created and cookies may be used. The information generated by the cookie about your use of this website such as:

• Browser type/version
• Device name
• Operating system
• Referrer URL (the previously visited page)
• Keywords/specific searches
• Service provider
• Host name of the accessing computer (IP address)
• Time of the server request

will be transferred to a Google server in the USA and stored there. The cookie makes it possible to recognize the visitor when he visits websites that belong to Google's advertising network. These pages may then display advertisements to the visitor that relate to content previously viewed by the visitor on websites that use Google's remarketing feature. The processing for behavioural and interest-based advertising purposes is to be regarded as our recognised legitimate interest according to Recital 47 of the GDPR. If you do not wish to receive interest-based advertising, you may opt-out of Google's use of cookies for these purposes by following the instructions on this link.

3.4.10. Bing Ads Conversion Tracking and Re-Marketing
We use the conversion tracking and remarketing tool of Bing, a service of Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA (hereinafter: "Bing") on the basis of Art. 6 Para. 1 lit. f) GDPR. This function serves the purpose of analysing visitor behaviour and visitor interests in order to create campaigns for our products which are tailored to the interests of the visitor, to direct them and to measure their effectiveness. If you reach our website via a Bing advertisement, a cookie is set on your terminal device. Bing UET tag, i.e. a code snippet, is integrated on our website and can be used in conjunction with the cookie to store data on the use of the website. Through this, Bing and Tourlane can recognise that the visitor has reached us via the advertisement and a conversion page. In particular, the cookie will collect the following anonymous data:

• The advertisement that the visitor used to reach us
• Browser type/version
• Device name
• Operating system
• Referrer URL (the previously visited page)
• Keywords/specific searches
• Service provider
• Host name of the accessing computer (IP address)
• Time of the server request
• Time spent on the website and sections visited
• Motion behaviour on the website

This data is processed via the servers of Bing and stored there for 180 days. The processing for behavioural and interest-based advertising purposes is to be regarded as our recognised legitimate interest according to Recital 47 of the GDPR. You can prevent the collection of the data generated by the cookie and related to your use of the website and the processing of this data before the cookie is set by changing the browser settings and deactivating cookies. In addition, you can object to this data processing at any time by setting the switch to "Off" via this link under "Interest-Related Advertising: This Browser." This causes a so-called opt-out cookie to be set on the terminal device used, whereby this cookie is only relevant for each browser and terminal device. If you visit our website with different browsers or terminals, you must activate the opt-out cookie for each browser or terminal. You can find detailed information about Bing and its privacy policy on the provider's product page or website.

3.4.11. Criteo
For marketing purposes, in particular to enable interest-related control of our campaigns, we use the cookie technology of Criteo SA, Rue Blanche, 75009, Paris, France (hereinafter: "Criteo") on the basis of Art. 6 Para. 1 lit. f) GDPR. For example, we use Criteo to provide our interested users with targeted product recommendations on third-party websites (so-called publishers). For this purpose, when you visit our website, a cookie is set which processes information about your visits to our website, in particular about the offers you view, travel destinations and surfing behaviour. This data processing is purely anonymous, i.e. the cookie can only be identified by a randomly generated ID. Thus, the information processed by the cookie cannot be used to identify a specific person. The cookie has a maximum lifespan of 6 months and is then automatically deleted. The processing for behaviour- and interest-based advertising purposes is to be regarded as our recognised legitimate interest according to Recital 47 to the GDPR.

For more information about Criteo's technology, please refer to the provider's privacy policy. In addition, you can object to this anonymous data processing on our website at any time by setting the switches under number 2 to "On" under this link. A new opt-out cookie will then be set so that Criteo will not process any further data. Please note that the opt-out cookie is only valid for the browser and device used.

3.4.12. Outbrain Conversion Pixel
In order to use our campaigns as needed, to further optimise them and to measure their conversion, we use an individual so-called pixel of Outbrain Inc., 39 West 13th Street, New York, NY 10011, USA (hereinafter: "Outbrain") on the basis of Art. 6 para. 1 lit. f) GDPR. This pixel is embedded in the code of our website. This enables us to ensure that campaigns initiated by us are only displayed to users who have shown an interest in our services. In addition, we want to ensure that our campaigns correspond to the potential interest of the respective user and do not disturb them. On the other hand, it allows us to track users' actions after they have seen or clicked on one of our campaigns. This helps us measure conversion for statistical, market research and billing purposes. The following information is processed during use:

• Clicked display
• Browser type/version
• Operating system
• Location
• Referrer URL (the previously visited page)
• Host name of the accessing computer (IP address)
• Time of the server request

The data collected in this way is anonymous for us and therefore does not allow us to draw any conclusions about the identity of the respective user. The processing for behavioural and interest-based advertising purposes is to be regarded as our recognised legitimate interest according to Recital 47 of the GDPR. The data will be stored according to the legal retention periods and then automatically deleted. Further information on data protection at Outbrain can be found in their privacy policy. You can object to this special data processing at any time by clicking the opt-out button under number 4.

3.4.13. DoubleClick
For the purpose of the need-based design and continuous optimisation of our websites, we use the Doubleclick analysis service, a service of Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter: "Doubleclick") on the basis of Art. 6 Para. 1 lit. f) GDPR. A pseudonymous identification number (ID) is assigned to your browser to check which ads were displayed in your browser and which ads were viewed. The cookies do not contain any personal information. The use of DoubleClick cookies only allows Google and its affiliates to serve ads based on previous visits to our or other Internet sites. The information generated by the cookie about your use of this website such as

• Browser type/version
• Operating system
• Referrer URL (the previously visited page)
• Host name of the accessing computer (IP address)
• Time of the server request

will be transferred to a Google server in the USA and stored there. This information is used to evaluate the use of the website, to compile reports on activities and to provide other services relating to website and Internet use for marketing research purposes and to tailor these Internet pages to meet customer requirements. You can object to this processing at any time by either downloading and installing the browser add-on available under the following link or by deactivating the double-click cookies on the page of the Digital Advertising Alliance under the following link.

3.4.14. Pardot
For the purpose of the need-based design and continuous optimisation of our websites, we use the marketing tool Pardot, a service of Salesforce Inc., The Landmark at One Market, Suite 300, San Francisco, CA 94105, USA (hereinafter: "Pardot") on the basis of Art. 6 Para. 1 lit. f) GDPR. The tool helps us to better understand the usage behaviour of our visitors and to gain insights from this for further optimisation needs. Through the use of Pardot, the following data is processed:

• Data about the use of our website
• Name
• Email
• Travel preferences (destination, travel time, travel type)
• Data about interactions with Tourlane emails

and transferred via the Pardot servers to the USA and stored there. This can be used to create user profiles which we use exclusively for the aforementioned purposes. This processing for the optimisation of our offers is to be regarded as our recognised legitimate interest. You can object to this data processing at any time by informing us that you no longer wish this processing to take place in the future. Please use the contact options of our data protection officer for this purpose.

3.4.15. Visual Website Optimizer
For the purpose of the need-based creation and continuous optimisation of our web pages we use the analysis service Visual Website Optimizer, a service of the providers Wingify, 14th Floor, KLJ Tower North, Netaji Subhash Place, Pitam Pura, Delhi 110034, India (hereinafter: Visual Website Optimizer) on the basis of Art. 6 para. 1 lit. f) GDPR. The tool helps us to better understand the usage behaviour of our visitors and to gain insights for further optimisation needs. Through the use of Pardot, the following data is processed:

• Device information (type, brand, operating system)
• The IP address of the device used
• Data about the use of our website
• Name of the provider (e.g. Vodafone)

and transferred via the Visual Website Optimizer servers and stored there. From this anonymous usage profiles can be created, which we use exclusively for the aforementioned purposes. This processing for the optimisation of our offers is to be regarded as our recognised legitimate interest. You can object to this data processing at any time by activating the "Disable VWO" button via this opt-out link.

3.4.16. Facebook Custom Audiences
For the target group-optimised control of Facebook campaigns and to measure their conversion, we use the possibility of the formation of so-called Facebook-Lookalike-Audiences, which is provided to us by Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (hereinafter "Facebook"), on the basis of Art. 6 para. 1 lit. f) GDPR. Further information on Facebook Look-Alike campaigns can be found on Facebook at: https://www.facebook.com/business/help/365463786964246. This processing for behavioural and interest-based advertising purposes is to be regarded as our recognised legitimate interest in accordance with Recital 47 of the GDPR. In the event that you are a Facebook Look-Alike Audience, we will provide your email address and device ID to Facebook. You can object to this particular data processing at any time by either changing your Facebook settings: https://www.facebook.com/settings/?tab=ads or informing us that you no longer wish this processing to take place in the future. To do this, please use the contact options provided by our data protection officer.

3.4.17. Google Maps-Einbindung
On our website we use the Google Maps API of Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter: "Google") on the basis of Art. 6 Para. 1 lit. f) GDPR. This enables us to display interactive maps directly on the website and enables you to use the map function conveniently. A cookie may be used in this context. The information generated by the cookie about your use of our website such as

• the visit of the corresponding subpage
• Browser type/version
• Operating system
• Referrer URL (the previously visited page)
• Host name of the accessing computer (IP address)
• Time of the server request

This processing for the improvement of our website and the user experience is to be regarded as our recognised legitimate interest. You can find further information on data protection in connection with Google Maps in the Google privacy policy. You can opt out of this data processing by changing your privacy settings or Google's activity settings.

3.4.18. Facebook Connect
In order to register as easily as possible for our offers, we enable you to log in via Facebook, the so-called Facebook login function, a service of Facebook Inc., 1601 South California Avenue, Palo Alto, CA 94304, USA (hereinafter "Facebook"). This replaces the otherwise necessary registration. To log in, you will be redirected to the Facebook servers, where you can log in with your Facebook usage data. This links your Facebook profile to our offer. If you use this simplified login function, we will record various master data of your publicly viewable profile, in particular:

• Surname, first name
• Location
• Birthday
• Sex
• Email
• Time zone
• Friends or
• Profile picture

The legal basis for the processing operations referred to above is Article 6(1)(b) GDPR. The processing thus carried out serves the purpose of a simplified login as well as the contractual justification and execution or the provision of pre-contractual measures. This so processed information is necessary for the contract conclusion to be able to identify you. The purpose and scope of the data collection by Facebook and the further processing and use of the data as well as your rights in this regard and setting options to protect your privacy can be found in the relevant data protection information from Facebook as well as the provider's further information on the Facebook Connect function.

3.4.19. Unbounce
In order to provide our customers and interested parties with the best possible service, we use the analysis service of Unbounce Marketing Solutions Inc., Unit 415 -375 Water Street, Vancouver, BC, Canada V5T 4R4 (hereinafter referred to as "Unbounce") on various landing pages for A/B testing, in particular to optimise and tailor our actions and advertising campaigns to meet requirements, on the basis of Art. 6 Para. 1 lit. f) GDPR. For our promotions and advertising campaigns, individual platforms are hosted by Unbounce and used by us. If you visit these landing pages, your browser will communicate directly with Unbounce's servers, so that technical and statistical information, in particular:

• Log data
• Browser type/version
• Device name
• Operating system
• Referrer URL (the previously visited page)
• Host name of the accessing computer (IP address)
• Information provided by the user on the site
• Your email address, if applicable

can be processed via these servers and cookies can be set. We then receive an anonymous statistical evaluation of the activities of the users on the platforms we use. This data processing by Unbounce enables us to improve our landing pages and our products, which constitutes our legitimate interest.
We have entered into a contract with Unbounce for order processing in accordance with Art. 28 GDPR, in which Unbounce undertakes to process the data received only in accordance with our instructions and to comply with the EU data protection standards. In addition, the EU Commission has classified Canada as a secure third country so that this data processing guarantees a level of data protection in accordance with the European standard. Further information on Unbounce and data protection at Unbounce can be found in the provider's privacy policy. If you have any questions about data processing at Unbounce, you can also contact the provider directly at any time: support@unbounce.com.

4. Recipients Outside the EU

With the exception of the processing operations described under 2.4, we will not pass on your data to recipients domiciled outside the European Union or the European Economic Area. The processing mentioned under 2.4. causes a data transfer to the servers of the provider of web analysis technology commissioned by us (see above). These servers are located in the USA. The data transfer takes place according to the principles of the so-called Privacy Shield as well as on the basis of so-called standard contract clauses of the EU Commission. You can obtain a copy of these standard contractual clauses from us.

5. Your rights

5.1. Overview
In addition to the right to revoke your consent given to us, you are entitled to the following rights if the relative legal requirements are met:

• Right to information about your personal data stored with us according to Art. 15 GDPR
• Right to the rectification of incorrect data or to completion of correct data according to Art. 16 GDPR
• Right to the deletion of your data stored with us according to Art. 17 GDPR
• Right to limit the processing of your data according to Art. 18 GDPR
• Right to data transfer according to Art. 20 GDPR
A brief note to our data protection officer is sufficient to assert your rights. He can be reached via email datenschutz@tourlane.de or by post at Tourlane GmbH, at the attention of the data protection department, Köpenicker Straße 126, 10179 Berlin.

5.2. Right of objection
Under the conditions of the Art. 21 Abs. 1 GDPR the data processing can be objected to for reasons that arise from the special situation of the person concerned.

The above mentioned general right of objection applies to all processing purposes described in this data protection declaration that are processed on the basis of Art. 6 Para. 1 lit. f) GDPR. Unlike the special right of objection (see above) directed at data processing for advertising purposes, we are only obliged to implement such a general objection according to the GDPR if you give us reasons of overriding importance (e.g. a possible danger to life or health). In addition, it is possible to contact the supervisory authority responsible for Tourlane: Berlin Commissioner for Data Protection and Freedom of Information, Friedrichstraße 219, 10969 Berlin.

6. Data erasure and storage duration

Your personal data will be deleted or disabled as soon as the purpose of storage no longer applies or you revoke your consent. In addition, your personal data may be stored if the European or national legislator has provided for this in EU ordinances, laws or other regulations to which the person responsible is subject. If the storage purpose ceases to apply, if you revoke your consent or if a storage period prescribed by the European legislator or any other responsible legislator expires, the personal data will be blocked or deleted routinely and in accordance with the statutory provisions, unless there is a need for further storage of the data for the conclusion of a contract or fulfilment of a contract.

7. Data security

All data transmitted by you personally, including your payment data, is transmitted using the generally accepted and secure standard SSL (Secure Socket Layer). SSL is a secure and proven standard that is also used for online banking, for example. You can recognise a secure SSL connection by the s attached to the http (e.g. https://www.tourlane.de) in the address bar of your browser or by the lock symbol at the bottom of your browser.
We also make use of suitable technical and organisational security measures to protect your personal data stored with us against manipulation, partial or complete loss and against unauthorised access by third parties.

Applicable as of January 31, 2019.

Fast & easy travel planning

Individually designed dream trips

Personal advice from Tourlane experts

Flights, itineraries, guides - all from a single source

Free and non-binding offers