Art. 12–14 GDPR · § 25 TDDDG
Privacy policy
This notice explains how personal data is processed when you visit and use this website (Art. 13 GDPR). It must be easy to access at the time of collection.
1. Controller
Controller under the GDPR:
Be Mine Tourist
Owner: [Full name]
[Street, house number, postcode, city, Germany]
Email: email@beminetourist.com
Phone: +49 1520 2579014
No data protection officer is appointed (Art. 37 GDPR). Please send privacy requests to the contact details above.
2. Hosting, website delivery and log files
When you open the website, technically necessary data is processed so that pages can be delivered and IT security maintained (Art. 6 (1)(f) GDPR — legitimate interest in reliable, secure operation).
- IP address
- Date and time of the request
- Requested URL / referrer
- HTTP status, volume of data transferred
- Browser type and operating system
The site runs locally with DDEV and in production on a Plesk server (EU hosting intended). The host processes this data as a processor under Art. 28 GDPR once a corresponding contract is in place.
Retention: Session data ends with the connection. Server logs are kept as short as possible, usually no longer than 7–14 days unless needed to investigate attacks.
You may object to processing based on Art. 6 (1)(f) GDPR (Art. 21 GDPR). The website cannot operate without this processing.
3. Cookies, local storage and TDDDG
Storing information on your device is governed by § 25 TDDDG (formerly TTDSG). Strictly necessary storage is allowed without consent (§ 25 (2) TDDDG). Any other access requires prior informed consent (§ 25 (1) TDDDG, Art. 6 (1)(a) GDPR).
This website currently uses no tracking, analytics or marketing cookies. The banner lets you consent by category; analytics and marketing are prepared in the UI but are not set today.
- fe_typo_user (if the backend or a login is used): TYPO3 session cookie, strictly necessary.
- be_mine_tourist_cookie_consent in local storage: stores your cookie banner choice so it is not asked on every visit.
- bmt_theme in local storage: stores the chosen appearance (dark / light). This is a comfort setting and is stored only if you allow functional cookies.
The cookie banner appears at the bottom left on the first visit. After a choice, a floating icon stays at the bottom left so you can change settings at any time. Declining optional categories does not block essential functions.
4. Web fonts (Google Fonts) — third-country transfer
The fonts Plus Jakarta Sans and Playfair Display are currently loaded from fonts.googleapis.com / fonts.gstatic.com. Your browser then connects to Google servers. At least your IP address and browser information may be sent to Google, including to the USA (Art. 44 et seq. GDPR).
Case law (including LG München I, 20 January 2022 — 3 O 17493/20) and supervisory authorities generally treat dynamic Google Fonts as unlawful without valid consent and an adequate third-country level. The fonts should be hosted locally. Until that change, we disclose this processing. The only possible legal basis would be consent (Art. 6 (1)(a) GDPR); consent is not currently obtained before the fonts load.
5. Contact, booking and form enquiries
If you contact us by form, email, phone or messenger, or request a transfer/tour, we process the data you provide (typically name, email, optionally phone, requested service, date, message) to handle the enquiry and to perform a contract or pre-contractual steps (Art. 6 (1)(b) GDPR) and — for general correspondence — based on our legitimate interest in answering (Art. 6 (1)(f) GDPR).
Submission uses eID interfaces of this TYPO3 installation. Spam protection uses a hidden honeypot field (no Google reCAPTCHA transfer to the USA).
Retention: Enquiries are deleted when handled unless statutory retention rules apply (e.g. commercial or tax law, typically up to 6 or 10 years).
Name and email are required for a reply. Other fields are optional unless marked as required.
6. WhatsApp, Facebook, Zalo, Viber
We link to WhatsApp and Facebook and mention Zalo/Viber as contact channels. These are static links (no social plugin, no Facebook pixel). The provider’s privacy policy applies only when you click. WhatsApp and Facebook (Meta Platforms) may process data in the USA.
WhatsApp: Meta Platforms Ireland Ltd.; see the WhatsApp privacy policy. Facebook: Meta Platforms Ireland Ltd.
We do not load social SDKs and do not use tracking pixels.
7. Recipients
Personal data is shared only with those who need it for the stated purpose: us as controller, the host as processor, email transport when forms are sent, and — only after your click — messaging providers. There is no further transfer unless we are legally required (Art. 6 (1)(c) GDPR).
8. No automated decision-making
There is no automated decision-making including profiling within the meaning of Art. 22 GDPR.
9. Your rights
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR), where the conditions are met
- Objection to processing based on Art. 6 (1)(f) GDPR (Art. 21 GDPR)
- Withdrawal of consent with effect for the future (Art. 7 (3) GDPR)
- Complaint to a supervisory authority (Art. 77 GDPR)
The competent authority is the data protection authority of the federal state where the controller is established. An overview is published by the Federal Commissioner: bfdi.bund.de — state authorities. You may also contact any supervisory authority in the EU.
10. SSL/TLS
This website is served over HTTPS, encrypting the connection between your browser and the server.
11. Changes to this notice
We update this privacy policy when processing or the legal situation changes. The version published on this page applies.