data privacy

Welcome to Heidelberg Marketing GmbH and our website, in particular www.heidelberg-marketing.de 

We are delighted that we have sparked your interest in our region and what we have to offer. We take the protection of your privacy and personal data very seriously. Your data is therefore always collected and used in accordance with the provisions of the General Data Protection Regulation (EU) 2016/679 (GDPR), the Federal Data Protection Act (BDSG) and the Telemedia Act (TMG). As the party responsible for data processing, we would therefore like to inform you below about what data we collect and how we process it.


1. Personal data 

Personal data within the meaning of the GDPR is any information relating to an identified or identifiable natural person; A natural person is considered identifiable if they can be identified directly or indirectly, in particular by association with an identifier such as a name, an identification number, location data, an online identifier or one or more special characteristics that express the physical, physiological, genetic, psychological, economic, cultural or social identity of that natural person. Personal data is only stored to the extent necessary to provide the booked service, to comply with legal requirements or for the purpose specified below.

 

2. Anonymised data / log files 

You can visit our website without having to provide any personal data. However, certain anonymised data is stored each time you visit our website, e.g. which page or offer was accessed. However, this data is not personal and is therefore not subject to the legal provisions of the GDPR or the BDSG. The website operator or page provider collects data about access to the page and stores it as "server log files". The following data is logged: website visited, time of access, amount of data sent in bytes, source/reference from which you accessed the page, browser used, operating system used, IP address used. The data collected is used solely for statistical analysis and to improve the website. However, the website operator reserves the right to check the server log files retrospectively if there are concrete indications of illegal use. Anonymous data is collected solely for statistical analysis in order to improve our offering. Please refer to the section "Right to information/right of revocation" for more information.

 

3. Purpose of collecting personal data 

However, the collection of personal data becomes essential if you wish to book a stay or other service via our portal, contact us, subscribe to our newsletter or use other offers on our site for which personal data is essential. This also includes voucher purchases and participation in competitions, which may also take place outside the portal. In accordance with legal regulations and in the interests of data economy, only data that is required for the provision of this particular service is usually collected. If we ask for further information in our forms, the provision of this information is always voluntary and marked as such.

The temporary storage of the IP address by the system is necessary to enable the website to be delivered to the user's computer. For this purpose, the user's IP address must remain stored for the duration of the session. Storage in log files also takes place to ensure the functionality of the website. In addition, the data helps us to optimise the website and to ensure the security of our information technology systems. The data is not evaluated for marketing purposes in this context. These purposes also constitute our legitimate interest in data processing in accordance with Art. 6 (1) lit. f GDPR. In the case of booking a stay or other service, the data collected for this purpose will be used for the processing of this booking, within the legal requirements for advertising purposes and for statistical purposes.

The legal basis for sending the newsletter following the sale of goods or services is Section 7(3) of the German Unfair Competition Act (UWG). If you subscribe to our newsletter, we also store and use the personal and travel details you provided when booking on the basis of Article 6(1)(f) of the GDPR in order to provide you with the best possible service as a newsletter subscriber. The legal basis for processing the data after the user has registered for the newsletter is Art. 6 (1) (a) GDPR, provided that the user has given their consent. We also use the personal data we store to maintain customer relationships, for customer service (e.g. information about the course of your stay), to carry out our own advertising and marketing measures (e.g. sending catalogues or other advertising mailings within the legally permissible framework, customer satisfaction surveys) and for order processing.


4. Legal basis for the processing of personal data 

Insofar as we obtain the consent of the data subject for the processing of personal data, Art. 6 (1) (a) of the EU General Data Protection Regulation (GDPR) serves as the legal basis. When processing personal data that is necessary for the performance of a contract to which the data subject is party, Art. 6 (1) (b) GDPR serves as the legal basis. This also applies to processing operations that are necessary for the implementation of pre-contractual measures. Insofar as the processing of personal data is necessary to fulfil a legal obligation to which our company is subject, Art. 6 para. 1 lit. c GDPR serves as the legal basis. In the event that vital interests of the data subject or another natural person require the processing of personal data, Art. 6 para. 1 lit. d GDPR serves as the legal basis.

 

5. Disclosure of personal data to third parties 

Your personal data will only be disclosed in accordance with the relevant provisions, in particular those relating to data protection and competition law. Insofar as this is necessary for the performance of our contractual obligations or legal obligations, your data will also be disclosed to subcontractors or service providers for the performance of services on our behalf or on our instructions (e.g. technical processing of postal and email correspondence, payment processing, customer service).

In addition, the data will be passed on to persons or companies for the purpose of processing your booking, in particular to airlines, tour operators, hotels, travel agencies, car rental companies, cruise lines, authorities, etc. Please note that the data protection regulations at the registered office of these persons and companies may differ from those in the United Kingdom. 

Your data will also be disclosed and transferred to third parties if we are obliged to do so by law or as a result of legally binding court proceedings.

You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used and machine-readable format. You also have the right to transmit this data to another controller without hindrance from the controller to whom the personal data was provided.

 

6. Storage and deletion of data 

Your personal data will be stored for the purposes specified under "Purpose of collecting personal data". The personal data of the data subject will be deleted or blocked as soon as the purpose of storage no longer applies. Storage may also take place if this has been provided for by European or national legislators in EU regulations, laws or other provisions to which the controller is subject. The legislator has enacted various storage obligations and periods. The data will also be blocked or deleted when a storage period prescribed by the aforementioned standards expires, unless there is a need for further storage of the data for the conclusion or fulfilment of a contract.

 

7. Use of cookies 

We use cookies (small computer files containing text information that the web server sends to your internet browser) to improve your experience when visiting our online offerings. For example, some notices only appear once if you allow us to set a cookie. Our cookies also have an expiry date. If you manually delete your cookies before they expire, you will receive a new one the next time you visit the site, unless you block the storage of cookies. The technical specifications stipulate that only the server that sent a cookie can read it. We assure you that we do not store any personal data in cookies. Unfortunately, use of our services is only possible to a limited extent without accepting cookies. We therefore recommend that you permanently enable cookies for our website. Most internet browsers are set to automatically accept cookies. However, you can deactivate the storage of cookies and set your internet browser to notify you as soon as cookies are sent. The legal basis for the processing of personal data using cookies is Art. 6 (1) lit. f GDPR.


The legal basis for the processing of personal data using cookies for analysis purposes is Article 6(1)(a) GDPR, provided that the user has given their consent.

 

8. Use of Matomo 

Heidelberg Marketing GmbH uses the web analytics service Matomo on this website for statistical analysis. We view this analysis as an integral part of our online services. Our intention is to continuously improve the website and tailor it even more closely to the needs of our users.

The following data, among others, is processed when using Matomo:

  • IP address (truncated/anonymized)
  • Pages visited
  • Referrer URL
  • Time spent on the site
  • Browser and device type used

Matomo places cookies in users' browsers to collect anonymous statistical information. Data processing takes place provided you have given your consent via our cookie banner. You can revoke your consent at any time via our cookie settings.

For more information on data protection at Matomo, please visit: https://matomo.org/privacy-policy/

 

9. Facebook social plugins 

This website uses social plugins ("plugins") from the social network facebook.com, which is operated by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA ("Facebook"). The plugins can be recognised by one of the Facebook logos (white "f" on a blue tile or a "thumbs up" sign) or are marked with the addition "Facebook Social Plugin". The list and appearance of Facebook social plugins can be viewed here: developers.facebook.com/plugins. When a page of this website that contains such a plugin is accessed, the browser used establishes a direct connection to the Facebook servers. The content of the plugin is transmitted directly from Facebook to the browser used and integrated into the website. The provider therefore has no influence on the extent of the data that Facebook collects with the help of this plugin and therefore provides information according to its level of knowledge: by integrating the plugins, Facebook receives the information that the corresponding page of our website has been accessed.

 

 

If the visitor is logged into Facebook, Facebook can assign the visit to their Facebook account. If the visitor interacts with the plugins (for example, by clicking the "Like" button or posting a comment), the corresponding information is transmitted directly from their browser to Facebook and stored there. If the visitor is not a member of Facebook, it is still possible for Facebook to find out and store their IP address. The purpose and scope of the data collection and the further processing and use of the data by Facebook, as well as the relevant rights and setting options for protecting privacy, can be found in Facebook's privacy policy: www.facebook.com/policy.php. If the visitor is a Facebook member and does not want Facebook to collect data about them via this website and link it to their membership data stored on Facebook, the visitor must log out of Facebook before visiting this website. It is also possible to block Facebook social plugins with add-ons for the browser used, for example with the "Facebook Blocker".

 

10. Facebook conversion pixel 

This website uses the "Facebook pixel" from Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA ("Facebook"). This allows the behaviour of users to be tracked after they have seen or clicked on a Facebook advertisement. This process is used to evaluate the effectiveness of Facebook advertisements for statistical and market research purposes and can help to optimise future advertising measures.

The data collected is anonymous to us, meaning that it does not allow us to identify users. However, the data is stored and processed by Facebook, allowing it to be linked to the respective user profile and enabling Facebook to use the data for its own advertising purposes in accordance with the Facebook Data Use Policy (https://www.facebook.com/about/privacy/). The user can allow Facebook and its partners to place advertisements on and outside of Facebook. A cookie may also be stored on their computer for these purposes. By visiting our website and our Facebook page, you consent to the use of cookies. To generally object to the use of cookies on your computer, you can set your internet browser so that no more cookies can be stored on your computer in future or so that cookies already stored are deleted. However, disabling all cookies may mean that some functions on our website can no longer be performed. Users can also deactivate the use of cookies by third-party providers such as Facebook on the following website of the Digital Advertising Alliance: http://www.aboutads.info/choices/

 

11. Use of the Instagram button 

This website uses social media plug-ins from the social network Instagram, which is operated by Instagram Inc., 1601 Willow Road, Menlo Park, California, 94025, USA. The Instagram plug-in can be recognised by the "Instagram button" on our homepage. If you click on the Instagram button while you are logged into your Instagram account, content from our website can be linked to your Instagram profile. This allows Instagram to associate your visit to our website with your user account.


We expressly point out that, as the provider of these pages, we have no knowledge of the content of the data transmitted or its use by Instagram. Further information on this can be found in Instagram's privacy policy at: http://instagram.com/about/legal/privacy
 

12. YouTube 

This website uses a link to YouTube, which is operated by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. When embedding, we use the "extended data protection mode" so that usage information is only transferred when the video is started. In this case, the specific page of our website that you are visiting and the video you are watching will be transmitted. If you are logged into your YouTube account, you enable YouTube to associate your page views directly with your personal profile. For more information about the collection and processing of your data by YouTube, please refer to the relevant privacy policy at www.youtube.com. If you want to ensure that no data about you is stored by YouTube, do not click on the embedded videos.


13. Eye-Able® Assistant
Eye-Able® is a software of Web Inclusion GmbH to ensure barrier-reduced access to information on the Internet for all people. The necessary files such as JavaScript, stylesheets and images are loaded from an external server. Eye-Able uses the local storage of the browser to save the settings when functions are activated. All settings are only stored locally and are not transferred further.

In order to fend off attacks and provide our service in near real time, Eye-Able® uses the Content Delivery Network (CDN) of BunnyWay d.o.o. (Cesta komandanta Staneta 4A, 1215 Medvode, Slovenia). This is used for the purpose of fulfilling contracts with our customers (Art. 6 para. 1 lit. b DSGVO) and in the interest of a secure, fast and efficient provision of our online offer by a professional provider (Art. 6 para. 1 lit. f DSGVO). All transmitting data and servers remain in the EU at all times to enable data protection-compliant processing in accordance with DSGVO. Web Inclusion GmbH does not collect or analyze personal user behavior or other personal data at any time.

In order to ensure data protection-compliant processing, Web Inclusion GmbH has concluded commissioned processing contracts with our hosters IONOS and BunnyWay.

For more information, please see the privacy statements:
https://eye-able.com/Privacy Policy /
https://bunny.net/privacy
 

14. Security, questions and suggestions, responsible party 

Security depends not least on your system. You should always treat your access information as confidential, never allow passwords to be stored by your web browser, and close the browser window when you finish visiting our website. This will make it more difficult for third parties to access your personal data. Use an operating system that can manage user rights. Set up multiple users on your system, even within your family, and never use the internet with administrator rights. Use security software such as virus scanners and firewalls and keep your system up to date. The controller responsible for this online presence within the meaning of the General Data Protection Regulation and other national data protection laws of the Member States as well as other data protection regulations is:
Heidelberg Marketing GmbH
Neuenheimer Landstraße 5
69120 Heidelberg
Tel: +49 6221 58 44 444
Fax: +49 6221 58 40 222
E-Mail: info@heidelberg-marketing.de
www.heidelberg-marketing.de


15. Right to information/right of withdrawal; other rights of data subjects 

You have the right: 

• pursuant to Art. 15 GDPR to request information about your personal data processed by us. In particular, you may obtain information about the purposes of processing, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right of appeal, the origin of your data if it was not collected by us, and the existence of automated decision-making, including profiling and, where applicable, meaningful information about its details;

• pursuant to Art. 16 GDPR, to request the immediate correction of inaccurate or incomplete personal data stored by us; • to request the erasure of your personal data stored by us in accordance with Art. 17 GDPR, unless the processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest or for the establishment, exercise or defence of legal claims; 

• to request the restriction of the processing of your personal data in accordance with Art. 18 GDPR, unless the accuracy of the data is disputed by you, the processing is unlawful, but you refuse to have it deleted and we no longer need the data, but you need it to assert, exercise or defend legal claims, or you have objected to the processing pursuant to Art. 21 GDPR; 

• pursuant to Art. 20 GDPR, to receive your personal data that you have provided to us in a structured, commonly used and machine-readable format or to request its transmission to another controller;

• to withdraw your consent at any time in accordance with Art. 7 (3) GDPR. As a result, we will no longer be permitted to continue processing data based on this consent in the future, and 

• to lodge a complaint with a supervisory authority in accordance with Art. 77 GDPR. As a rule, you can contact the supervisory authority of your usual place of residence or workplace or our company headquarters for this purpose. 

These rights are, of course, available to you free of charge. To withdraw your consent to the use of data, to request information or correction, blocking or deletion, or to exercise other rights of data subjects, please contact:

Heidelberg Marketing GmbH
Neuenheimer Landstraße 5
69120 Heidelberg
Tel: +49 6221 58 44 444
Fax: +49 6221 58 40 222
E-Mail: info@heidelberg-marketing.de


Below, we provide you with the contact details of our company's data protection officer. Our data protection officer is:
datenschutzbeauftragter@heidelberg-marketing.de

www.baden-wuerttemberg.datenschutz.de/kontakt

To exercise your rights as a data subject, such as the right to access, rectify, block or delete your personal data, please do not contact the data protection officer directly, but first contact the above-mentioned department of the data protection officer, who will process your request without delay. 


16. Newsletter unsubscription 

If you no longer wish to receive our newsletter or promotional emails, click on the "Unsubscribe from newsletter" link included at the end of all emails we send.


Recordings at events

Information on data protection

Regarding the processing of your personal data during the creation, distribution and public display of images
 

1. Responsible body:
Heidelberg Marketing GmbH, Mathias Schiemer (Geschäftsführer), Telefon: 06221-5840201, E-Mail: sekretariat@heidelberg-marketing.de

2. data protection officer:
Heidelberg Marketing GmbH, E-Mail: datenschutzbeauftragter@heidelberg-marketing.de

3. Recordings // Purpose and use // Disclosure to third parties // Legal basis:

  1. We will be taking photographs today and capturing images of events and scenes from our event, in which you may be recognisable.
  2. We use these recordings for our internal documentation, public relations work and as a review of our event. We will use the recordings in press releases and print media, online on our website and on our social media channels. In addition, we will use a selected image to promote our next event.
  3. The legal basis for this is our legitimate interest in public relations work for our event and documentation of our offerings and services; Art. 6(1)(f) EU GDPR.
  4. The images will be used by us for the duration of the communication measures or for permanent archiving and stored in an image archive. Our image database is regularly maintained and images that are no longer required are deleted.

4. Your rights as a data subject: 

We hereby inform you of your legal rights. You may, in accordance with

  • Art. 21 EU GDPR to lodge an objection;
  • Art. 15 EU GDPR to request information.
  • Art. 16 EU GDPR to request correction or completion;
  • Art. 17 EU GDPR Request erasure;
  • Art. 18 EU GDPR Request restriction of processing;
  • Art. 20 EU GDPR Request transfer;
  • Art. 77 EU GDPR Lodge a complaint with a supervisory authority.

Cookiebot Notice

List of cookies, including their purpose and storage duration

Cookies Neos

Cookie NameDescriptionStorage Duration

Neos.Neos.last

VisitedNode

Used to redirect the user to the same page on the website before and after the login process.Session Cookie.

Session cookies do not have an expiration date; instead, they are typically deleted when the browser is closed or exited.
mein_toubiz_sessionUsed only for the mein.toubiz #infosystem.The expiration time is 60 minutes.
XSRF-TOKENEnsures a secure browsing experience for visitors by preventing cross-site request forgery. This cookie is essential for the security of the website and the visitor.The expiration time is 60 minutes.
vuexVuex is a local store where user input and retrieved data are cached (for the duration of the session). This information is stored for the NVBM interface (on-site mobility) and, in the future, also for displaying the weather, to determine whether the mobility data and weather have already been retrieved. If so, no new request is made; instead, the data is retrieved from the (Vuex) store. This session cookie remembers certain queries/API calls so that they do not have to be made repeatedly during a session.Session Cookie.

Session cookies do not have an expiration date; instead, they are typically deleted when the browser is closed or exited.

 


Cookies for Map

Maptoolkit

Publisher
Toursprung GmbH

Description
Maptoolkit is a service provided by Toursprung GmbH
Fritz-Arnold-Str. 16
78467 Konstanz | Deutschland
+49 7531 710 96 10
buero@toursprung.com
www.toursprung.com,

which provides a map on our website.

Link to the privacy policy
https://www.toursprung.com/impressum/

What Data is collected?
IP adress
Referrer-URL
device information
interactions with the service

Purpose of data collection
We use the Maptoolkit map service to help you find your way to locations listed on the website, as well as to provide an overview of cycling and hiking tours, places to stop for refreshments, charging stations for e-bikes, and service stations. 

Legal basis
The use of the Maptoolkit map service is based on Article 6(1)(f) of the GDPR (legitimate interest).

Place of Processing
European Union

 

mein.toubiz #elements

We use the plugin “mein.toubiz #elements” from the provider land in sicht AG on our website. 

This plugin displays database content, for which cookies are technically necessary. The data collected includes:

  • IP adress
  • Referrer-URL
  • Device information
  • Interactions with the Plug-In

The data will be deleted as soon as it is no longer needed for the purposes of processing. 

If consent has been requested (e.g., consent to the storage of cookies), processing is carried out exclusively on the basis of Article 6(1)(a) of the GDPR; consent may be withdrawn at any time. The information generated by the cookie regarding the use of this website is not shared with third parties. You can prevent the storage of cookies by adjusting your browser settings accordingly; however, we would like to point out that in this case, you may not be able to use all features of this website to their full extent. 

If you do not consent to the storage and use of your data, you can disable the storage and use here. In this case, an opt-out cookie will be stored in your browser, which prevents usage data from being stored. If you delete your cookies, this will result in the opt-out cookie being deleted as well. The opt-out must be reactivated when you visit this website again.

Name of the service provider
land in sicht AG

Name of the integration
mein.toubiz

Description of the service
The mein.toubiz elements are module widgets with a results page and a details page that are integrated into websites as a plugin. 

Adress of the service provider in the EU
land in sicht ag
Wiesentalstr. 5
79115 Freiburg

Purpose of the service
Display of database content. Technically necessary.

Technologies used by the service provider

Accept cookies

If consent has been requested (e.g., consent to the storage of cookies), processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR; consent may be revoked at any time. The information generated by the cookie regarding the use of this website is not shared with third parties. You can prevent the storage of cookies by adjusting your browser settings accordingly; however, we would like to point out that in this case, you may not be able to use all functions of this website to their full extent.

Data collected by the service provider
IP adress
Referrer-URL
Device information
Interactions with the Plug-In

Location of processing
Germany

Retention period
The data is deleted as soon as it is no longer required for the purposes of processing

Who processes the data
land in sicht AG

Link or email to the data protection officer at the service
datenschutz@land-in-sicht.de

Transfer of service data to third countries
Germany