Reviews

PRIVACY POLICY

Privacy policy

1. Privacy at a glance

General information

The following information provides a simple overview of what happens to your personal data when you visit our website. Personal data is any information that can be used to identify you personally. For detailed information on how we process your personal data, please refer to the Privacy Policy below.

Data collection on this website

Who is responsible for data collection on this website?

The data processing on this website is carried out by the website operator. You can find the operator’s contact details in the section “Controller” of this Privacy Policy.

How do we collect your data?

Some data is collected when you provide it to us voluntarily, for example by entering information into a contact form.

Other data is collected automatically, or with your consent, when you visit our website. This mainly includes technical information, such as your web browser, operating system and the time you accessed the website. This data is collected automatically as soon as you access our website.

What do we use your data for?

Some of the data is collected to ensure that our website functions properly. Other data may be used to analyse how visitors use our website. If contracts can be concluded or initiated through this website, the data you provide may also be processed for quotations, bookings, orders or other contractual enquiries.

What rights do you have regarding your data?

You have the right to obtain information about the origin, recipients and purpose of your stored personal data at any time, free of charge. You also have the right to request the correction or deletion of your personal data. If you have given your consent to data processing, you may withdraw that consent at any time with effect for the future. Under certain circumstances, you also have the right to request the restriction of the processing of your personal data. In addition, you have the right to lodge a complaint with the competent supervisory authority.

If you have any questions regarding data protection or the processing of your personal data, please feel free to contact us at any time.

Analytics and third-party tools

When you visit this website, your browsing behaviour may be analysed for statistical purposes. This is primarily carried out using analytics tools.

Further information about these analytics tools can be found in this Privacy Policy.

2. Hosting

We host the content of our website with the following provider:

RACK26

The provider is Kreativdenker GmbH, Mittelkämmererstraße 6, 67346 Speyer, Germany (hereinafter referred to as RACK26). For further information, please refer to RACK26’s Privacy Policy: https://rack26.de/datenschutzerklaerung/

RACK26 is used on the basis of Article 6(1)(f) GDPR. We have a legitimate interest in ensuring the reliable and secure presentation of our website. Where consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user’s device (e.g. device fingerprinting). Consent may be withdrawn at any time.

Data processing agreement

We have concluded a Data Processing Agreement (DPA) with the provider. This agreement ensures that personal data of our website visitors is processed only in accordance with our instructions and in compliance with the GDPR.

3. General information and mandatory information

Data protection

The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the applicable data protection laws and this Privacy Policy.

When you use this website, various types of personal data are collected. Personal data is any information that can be used to identify you personally. This Privacy Policy explains what data we collect, how we use it, and for what purpose.

Please note that data transmitted over the internet (for example, when communicating by email) may be subject to security vulnerabilities. Complete protection of data against access by third parties is not possible.

Controller

The controller responsible for data processing on this website is:

Bootsfahrten & Events Heidelberg GmbH
Bergstrasse 21
69120 Heidelberg, Germany

Phone: +49 (0) 172 44 08 88 8
Email: info@bootsfahrt.de

The controller is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data.

Data retention

Unless a more specific retention period is stated in this Privacy Policy, your personal data will remain with us until the purpose for processing no longer applies. If you request the deletion of your data or withdraw your consent to data processing, your personal data will be deleted unless we are legally required or otherwise permitted to retain it (for example, due to tax or commercial record-keeping obligations). In such cases, the data will be deleted once those legal obligations no longer apply.

Legal Basis for Data Processing

Where you have given your consent, we process your personal data on the basis of Article 6(1)(a) GDPR and, where special categories of personal data are involved, Article 9(2)(a) GDPR. Where you have expressly consented to the transfer of personal data to third countries, processing is also based on Article 49(1)(a) GDPR. If you have consented to the storage of cookies or to access information on your device (for example through device fingerprinting), processing is additionally based on Section 25(1) TDDDG. Consent may be withdrawn at any time. Where your data is required to perform a contract or to take steps prior to entering into a contract, processing is based on Article 6(1)(b) GDPR. Where processing is necessary to comply with a legal obligation, it is based on Article 6(1)(c) GDPR. Processing may also take place on the basis of our legitimate interests under Article 6(1)(f) GDPR. The applicable legal basis for each processing activity is explained in the relevant sections of this Privacy Policy.

International data transfers

Some of the tools we use are provided by companies located in countries outside the European Union that may not offer a level of data protection equivalent to that of the EU. We also use certain US-based providers that may not be certified under the EU–US Data Privacy Framework (DPF). If these tools are active, your personal data may be transferred to and processed in these countries. Please note that an equivalent level of data protection cannot always be guaranteed in countries that are not considered to provide an adequate level of protection.

The United States is generally recognised as providing an adequate level of protection where the recipient is certified under the EU–US Data Privacy Framework (DPF) or provides other appropriate safeguards. Further information about international data transfers and the recipients of your data can be found in this Privacy Policy.

Recipients of personal data

As part of our business operations, we work with a number of external service providers. In some cases, it is necessary to share personal data with these providers. We only disclose personal data where this is necessary for the performance of a contract, where we are legally required to do so, where we have a legitimate interest pursuant to Article 6(1)(f) GDPR, or where another legal basis permits the disclosure. Where we use data processors, personal data is shared only on the basis of a valid Data Processing Agreement. Where joint processing takes place, a Joint Controller Agreement is concluded.

For payment processing and ticketing, we use the following data processor:

Name: FareHarbor B.V.
Country: The Netherlands.

Withdrawal of Consent

Many processing activities are carried out only with your express consent. You may withdraw your consent at any time. The withdrawal of consent does not affect the lawfulness of any processing carried out before the withdrawal.

Right to object (article 21 GDPR)

Where your personal data is processed on the basis of Article 6(1)(e) or (f) GDPR, you have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data. This also applies to any profiling based on these provisions. The legal basis for each processing activity is explained in this Privacy Policy. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms or where the processing is necessary for the establishment, exercise or defence of legal claims.

Where your personal data is processed for direct marketing purposes, you have the right to object at any time to such processing. This also applies to profiling related to direct marketing. If you object, your personal data will no longer be used for direct marketing purposes.

Right to lodge a complaint

If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with the competent supervisory authority, in particular in the EU Member State of your habitual residence, place of work or the place of the alleged infringement. This right exists without prejudice to any other administrative or judicial remedies.

Right to data portability

You have the right to receive any personal data that we process automatically on the basis of your consent or for the performance of a contract in a commonly used, machine-readable format. Where technically feasible, you also have the right to request that this data be transferred directly to another controller.

Right of access, rectification and erasure

Within the scope of the applicable legal provisions, you have the right at any time to obtain information, free of charge, about your stored personal data, its origin, recipients and the purpose of processing. You also have the right to request the correction or deletion of your personal data. If you have any questions regarding your personal data, you are welcome to contact us at any time.

Right to restrict processing

You have the right to request the restriction of the processing of your personal data. You may contact us at any time to exercise this right. The right to restrict processing applies in the following cases:

  • If you contest the accuracy of the personal data we have stored about you, we will generally need time to verify its accuracy. During the verification period, you have the right to request that the processing of your personal data be restricted.
  • If your personal data has been or is being processed unlawfully, you may request the restriction of processing instead of the deletion of your data.
  • If we no longer need your personal data, but you require it for the establishment, exercise or defence of legal claims, you have the right to request the restriction of processing instead of the deletion of your personal data.
  • If you have objected to processing pursuant to Article 21(1) GDPR, a balancing of interests between your interests and ours must be carried out. Until it has been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.

Where you have restricted the processing of your personal data, such data may—apart from being stored—only be processed with your consent, for the establishment, exercise or defence of legal claims, for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or of a Member State.

SSL/TLS encryption

For security reasons and to protect the transmission of confidential information—such as bookings or enquiries that you send to us as the website operator—this website uses SSL/TLS encryption. You can recognise an encrypted connection by the change in your browser’s address bar from “http://” to “https://”, as well as by the padlock icon displayed in your browser.

When SSL/TLS encryption is enabled, any data you transmit to us cannot be read by third parties.

Objection to promotional emails

We hereby object to the use of the contact details published as part of our legal notice for the purpose of sending unsolicited advertising or informational material. The operators of this website expressly reserve the right to take legal action in the event of unsolicited promotional communications, including spam emails.

4. Data collection on this website

Contact form

If you send us an enquiry via our contact form, the information you provide in the form, including the contact details you enter, will be stored by us for the purpose of processing your enquiry and in case of any follow-up questions. We will not share this data without your consent.

The processing of this data is based on Article 6(1)(b) GDPR if your enquiry is related to the performance of a contract or is necessary in order to take steps prior to entering into a contract. In all other cases, processing is based on our legitimate interest in the effective handling of enquiries addressed to us (Article 6(1)(f) GDPR) or on your consent (Article 6(1)(a) GDPR), where such consent has been requested. You may withdraw your consent at any time.

The data you enter into the contact form will remain with us until you request its deletion, withdraw your consent to its storage, or the purpose for storing the data no longer applies (for example, once your enquiry has been fully processed). Mandatory statutory provisions—particularly statutory retention periods—remain unaffected.

Enquiries by email, telephone or fax

If you contact us by email, telephone or fax, your enquiry, including all personal data arising from it (such as your name and the details of your enquiry), will be stored and processed by us for the purpose of handling your request. We will not share this data without your consent.

The processing of this data is based on Article 6(1)(b) GDPR if your enquiry is related to the performance of a contract or is necessary in order to take steps prior to entering into a contract. In all other cases, processing is based on our legitimate interest in the effective handling of enquiries addressed to us (Article 6(1)(f) GDPR) or on your consent (Article 6(1)(a) GDPR), where such consent has been requested. You may withdraw your consent at any time.

The data you send to us by email, telephone or fax will remain with us until you request its deletion, withdraw your consent to its storage, or the purpose for storing the data no longer applies (for example, once your enquiry has been fully processed). Mandatory statutory provisions—particularly statutory retention periods—remain unaffected.

Google Calendar

Our website allows you to schedule appointments with us. We use Google Calendar for appointment scheduling. The service is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”).

To book an appointment, you enter the requested information and your preferred appointment time into the booking form provided. The information you submit is used to schedule, organise and, where necessary, follow up on your appointment. Appointment data is stored on Google’s servers. You can find Google’s Privacy Policy here: https://policies.google.com/privacy

The data you enter will remain with us until you request its deletion, withdraw your consent to its storage, or the purpose for storing the data no longer applies. Mandatory statutory provisions—particularly statutory retention periods—remain unaffected.

The legal basis for processing this data is Article 6(1)(f) GDPR. We have a legitimate interest in making it as easy as possible for prospective customers and clients to schedule appointments with us. Where consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user’s device (e.g. device fingerprinting). Consent may be withdrawn at any time.

The transfer of data to the United States is based on the European Commission’s Standard Contractual Clauses (SCCs). Further information is available here: https://workspace.google.com/terms/dpa_terms.html and https://cloud.google.com/terms/sccs

Google is certified under the EU–US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards when personal data is transferred to the United States. Every company certified under the DPF has committed to complying with these data protection standards. Further information is available here: https://www.dataprivacyframework.gov/participant/5780

FareHarbor (online booking system)

We use the FareHarbor booking platform, provided by FareHarbor B.V., Herengracht 597, 1017 CE Amsterdam, The Netherlands, to process online bookings for our boat tours.

When you access our booking function, FareHarbor content is embedded into our website. In the process, technically required information may be transmitted to FareHarbor, including your IP address, the date and time of access, browser type and version, operating system, language settings and other technical information. When you make a booking through our booking system, FareHarbor also processes the information you provide, including your name, contact details, the booked service and, where applicable, payment information, insofar as this is necessary to complete your booking.

FareHarbor uses cookies and similar technologies to provide the booking function, process bookings, ensure the security of the system and maintain the functionality of the booking platform. Where analytics or marketing cookies are used, they are processed solely on the basis of your consent in accordance with Article 6(1)(a) GDPR and Section 25(1) TDDDG. Technically necessary cookies are processed on the basis of Article 6(1)(b) GDPR for the performance of pre-contractual measures or the fulfilment of a contract, as well as Article 6(1)(f) GDPR to ensure the secure and reliable operation of our online booking system.

Further information about how FareHarbor processes personal data can be found in the provider’s Privacy Policy: https://fareharbor.com/legal/privacy/

Data processing agreement

We have concluded a Data Processing Agreement (DPA) with the provider. This agreement ensures that personal data of our website visitors is processed solely in accordance with our instructions and in compliance with the GDPR.

5. Analytics and advertising

We use the open-source web analytics platform Matomo to analyse the use of our website and to continuously improve our online offering.

Matomo is hosted on our own web server. No personal data is transferred to third parties or to countries outside the European Union in connection with our web analytics.

Matomo is configured not to store analytics cookies on your device. Instead, only privacy-friendly, anonymised usage data is processed. Your IP address is shortened before it is stored (IP anonymisation), so that it can no longer be directly linked to you.

As part of our web analytics, the following information may be processed in particular:

  • Pages and files accessed
  • Date and time of access
  • Referrer URL (the website visited immediately before ours)
  • Browser type and browser version
  • Operating system used
  • Screen resolution
  • Browser language settings
  • Approximate geographic origin of the visit (based on the anonymised IP address)
  • Page loading times and other technical information relating to the display of the website

This data is processed solely for the purpose of analysing the use of our website, identifying technical issues, and continuously improving the usability and performance of our online services.

The legal basis for this processing is Article 6(1)(f) GDPR. We have a legitimate interest in ensuring the user-friendly design, optimisation and secure operation of our website.

The data collected is processed exclusively by us and is not combined with any other datasets. It is stored only for as long as necessary to fulfil the purposes described above and is then deleted or anonymised.

You have the right to object to the processing of your data at any time. If you exercise this right, your visit will no longer be included in our anonymised website statistics.

6. Newsletter

If you subscribe to our newsletter, we process the information you provide in the subscription form, in particular your email address. Any additional information (such as your name) is provided voluntarily and is used solely to personalise our communications with you.

We use Brevo, provided by Brevo SAS, 106 Boulevard Haussmann, 75008 Paris, France, to send our newsletters. Brevo processes your data exclusively on our behalf under a Data Processing Agreement in accordance with Article 28 GDPR.

The data entered in the subscription form is processed solely on the basis of your consent pursuant to Article 6(1)(a) GDPR. Subscription takes place using the double opt-in procedure. After registering, you will receive an email asking you to confirm your subscription by clicking a confirmation link. This ensures that only the owner of the email address provided can subscribe to the newsletter.

To document your consent, we also store the date and time of your registration and confirmation, as well as the IP address used during registration.

You may withdraw your consent at any time with effect for the future. To do so, simply click the unsubscribe link included in every newsletter or contact us using the details provided in this Privacy Policy. The lawfulness of any processing carried out before your consent was withdrawn remains unaffected.

Your data will be stored for as long as you remain subscribed to the newsletter. If you unsubscribe, your personal data will be removed from the active mailing list. Your email address may subsequently be stored on a suppression list (blacklist) to ensure that you do not receive any further newsletters. This processing is based on our legitimate interest pursuant to Article 6(1)(f) GDPR in complying with your unsubscribe request and the legal requirements applicable to newsletter distribution. The data on the suppression list is used solely for this purpose and is not combined with any other data.

As part of the newsletter service, Brevo collects statistical information, such as whether a newsletter has been opened and which links have been clicked. This information is used exclusively to analyse and improve our newsletter service.

7. Plugins and Tools

ManageWP

We use ManageWP to manage this website. The provider is GoDaddy.com WP Europe, Trg Republike 5, 11000 Belgrade, Serbia (hereinafter referred to as ManageWP).

ManageWP enables us to monitor the security and performance of our website, perform updates and create automatic backups. As a result, ManageWP has access to all content on the website, including our databases. ManageWP is hosted on the provider’s servers.

ManageWP is used on the basis of Article 6(1)(f) GDPR. We have a legitimate interest in the efficient and secure operation of our website. Where consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user’s device (e.g. device fingerprinting). Consent may be withdrawn at any time.

The company is certified under the EU–US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards when personal data is transferred to the United States. Every company certified under the DPF has committed to complying with these data protection standards. Further information is available from the provider at: https://www.dataprivacyframework.gov/participant/4957

Data processing agreement

We have concluded a Data Processing Agreement (DPA) with the provider. This agreement ensures that personal data of our website visitors is processed solely in accordance with our instructions and in compliance with the GDPR.

Last updated: 30 June 2026