Privacy policy

Last updated: 23 July 2026

1. Controller

The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:

Heide Reisen S.R.L.
Heide Göddert
Sat Sura Mare, Comuna Sura-Mare
Strada Adrian Paunescu Nr. 22
Sibiu (Hermannstadt), Romania

Phone (DE): +49 (0)162 258 44 94
Phone (RO): +40 (0)758 928 928
E-mail: info@heide-reisen.de

Legal representative: Heide Göddert
Register court: Commercial Register Sibiu (Oficiul Registrului Comerțului Sibiu)
Registration number: J32/1811/2021 (EUID: ROONRC.J32/1811/2021)
Tax number / VAT ID (CUI): RO 44912092
Travel agency / intermediary licence: No. 3014 of 09.05.2024, issued by the Romanian Ministry of Economy, Enterprise and Tourism.

We have not appointed a data protection officer, as there is no legal obligation to do so.

2. General information

Protecting your personal data is important to us. We process your data exclusively on the basis of the applicable statutory provisions (GDPR). In this privacy policy we inform you about the key aspects of data processing on our website.

Personal data is any data that can be used to identify you personally. Our website can generally be used without providing personal data. We do not use any analytics or tracking tools (such as Google Analytics) and do not use cookies for advertising or reach-measurement purposes.

3. Legal bases for processing

We process personal data on the following legal bases under the GDPR:

  • Art. 6(1)(a) GDPR (consent), where you have given us your consent for a specific processing operation;
  • Art. 6(1)(b) GDPR (contract or pre-contractual measures), for example when you submit a travel or booking enquiry via the contact form;
  • Art. 6(1)(f) GDPR (legitimate interests), e.g. in the technically secure, stable and functional operation of our website.

4. Hosting and provision of the website

This website is operated by an external service provider (host):

Vercel Inc.
440 N Barranca Ave #4133
Covina, CA 91723, USA

When you access our website, Vercel, acting as our processor on our behalf, processes technical access data automatically transmitted by your browser (see "Server log files"). The legal basis is our legitimate interest in a secure and efficient provision of the website (Art. 6(1)(f) GDPR). A data processing agreement pursuant to Art. 28 GDPR is in place with Vercel.

As Vercel is a US company, data may be transferred to the USA. Please see section 12 ("Data transfer to third countries").

5. Server log files

When you access the website, information is automatically collected in so-called server log files, which your browser transmits. These are in particular:

  • the IP address of the accessing device,
  • the date and time of access,
  • the page / file requested,
  • the amount of data transferred,
  • the referrer URL (the previously visited page),
  • the browser type and version and the operating system used.

This data is not merged with other data sources and is used solely for technical operation, security and error analysis. The legal basis is Art. 6(1)(f) GDPR. The data is stored only for the period necessary for these purposes.

6. Images and content via the Sanity CDN

The images and part of the editorial content on this website are delivered via the content management system and content delivery network (CDN) of Sanity:

Sanity Inc.
548 Market St PMB 96611
San Francisco, CA 94104-5401, USA

When images are loaded (domain: cdn.sanity.io), your IP address is technically transmitted to Sanity's servers, as this is necessary to deliver the image data to your browser. The legal basis is our legitimate interest in a fast and reliable presentation of the website (Art. 6(1)(f) GDPR). Here, too, a transfer to the USA may occur (see section 12).

7. Contact by e-mail or telephone

If you contact us by e-mail or telephone, your details (e.g. name, e-mail address or telephone number and your request) will be processed for the purpose of handling your enquiry and in case of follow-up questions. The legal basis is Art. 6(1)(b) GDPR (for contract-related enquiries) or Art. 6(1)(f) GDPR (for other enquiries). The data will be deleted once it is no longer required for the purpose and no statutory retention obligations prevent deletion.

8. Contact and enquiry form (Web3Forms)

For the contact / enquiry form on our website we use the service Web3Forms. The provider is:

Web3Forms – operated by Web3Creative
Kerala, India (registration: LCAS SH091040080115, Udyam UDYAM-KL-10-0039115)

When you submit the form, the data you enter (name, e-mail address, subject/selected offer and your message) is transmitted to Web3Forms' servers and forwarded to us as an e-mail. Web3Forms' servers are located in the USA (US-East region). According to the provider, the form content itself is not stored permanently but only processed and forwarded; any server log files containing personal data are deleted there at regular intervals. To prevent spam we use a technical check field ("honeypot"); no additional personal data is collected in the process.

The purpose of processing is to handle your travel, booking or other enquiry. The legal basis is Art. 6(1)(b) GDPR (pre-contractual or contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries). Where required, a data processing agreement is in place with the provider.

Your details will remain with us until you ask us to delete them, withdraw your consent, or the purpose of storage no longer applies; mandatory statutory retention periods remain unaffected.

9. Ticket booking via Regiondo

On our tickets page we embed a booking widget provided by the service Regiondo, which displays current ticket offers and allows you to book them directly online. The provider is:

Regiondo GmbH
Karlsplatz 3 (c/o Office Club)
80335 Munich
Germany

When you open the tickets page, the widget's content is loaded from Regiondo's servers. For technical reasons, your IP address is transmitted to Regiondo in the process; the widget cannot be displayed without this transmission. During the booking process, Regiondo may also use technically necessary cookies or similar storage technologies (e.g. for the shopping basket).

If you book tickets via the widget, Regiondo processes the data you provide during the booking process (e.g. name, e-mail address, payment details) in order to handle the booking. The legal basis is Art. 6(1)(b) GDPR (initiation or performance of a contract) and otherwise Art. 6(1)(f) GDPR (legitimate interest in a simple online booking process). For further information, please refer to Regiondo's privacy policy (available at regiondo.com).

10. Cookies and tracking

This website does not use any tracking cookies or web analytics services. No usage profiles are created. Technically necessary functions (e.g. JavaScript for displaying and submitting the form) run without setting personal cookies. A cookie banner is therefore not required.

11. Fonts (locally hosted)

To display fonts consistently, we use self-hosted fonts (via Fontsource, delivered from our own server / host). There is no connection to third-party servers such as Google Fonts. No personal data is transmitted to external providers for this purpose when the page is loaded.

12. Data transfer to third countries (USA)

Some of the service providers we use (in particular Vercel, Sanity and possibly Web3Forms) may process data in the USA or other third countries. A third country is a country outside the European Union or the European Economic Area where a level of data protection comparable to the GDPR does not necessarily apply.

Where such a transfer takes place, it is based on appropriate safeguards within the meaning of Art. 44 et seq. GDPR, in particular the Standard Contractual Clauses (SCC) provided by the EU Commission and – where the respective provider is certified – on the basis of the EU-U.S. Data Privacy Framework. For further information, please refer to the privacy policies of the respective providers.

13. Links to social networks

Our website contains links (simple links, not embedded "social plugins") to our profiles on Facebook and Instagram (provider: Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland). Only when you actively click on such an icon will you be redirected to the respective network's page and data will be transmitted to the provider. We have no influence over the data processing that takes place there; the privacy policy of the respective network applies.

14. SSL/TLS encryption

For security reasons and to protect the transmission of confidential content, this website uses SSL/TLS encryption. You can recognise an encrypted connection by "https://" in your browser's address bar and by the padlock symbol.

15. Your rights as a data subject

Under the GDPR you have the following rights:

  • right of access (Art. 15 GDPR),
  • right to rectification (Art. 16 GDPR),
  • right to erasure (Art. 17 GDPR),
  • right to restriction of processing (Art. 18 GDPR),
  • right to data portability (Art. 20 GDPR),
  • right to object to processing (Art. 21 GDPR),
  • right to withdraw consent with effect for the future (Art. 7(3) GDPR).

To exercise your rights, an informal message to the contact details listed under section 1 is sufficient.

Right to lodge a complaint with a supervisory authority: without prejudice to any other legal remedy, you have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your data infringes the GDPR. The competent authority includes the Romanian supervisory authority:

Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, Romania
www.dataprotection.ro

You may also contact the supervisory authority in your member state of residence.

16. Storage period

Unless a more specific storage period is stated in this policy, your personal data will remain with us until the purpose of the data processing ceases to apply. If you assert a justified request for erasure or withdraw consent, your data will be deleted unless we have other legally permissible reasons for storing it (e.g. retention periods under tax or commercial law).

17. Currency and amendment of this privacy policy

As our website develops, or due to changed legal or regulatory requirements, it may become necessary to amend this privacy policy. The current version can always be found on this page.