
Paul Kasten
Kollwitzstraße 76
10435 Berlin, Germany
Email: [email protected]
The following data is collected when you visit our website:
Your data is processed exclusively for the following purposes:
Your data is processed on the basis of Art. 6 (1) (a) GDPR (consent), Art. 6 (1) (b) GDPR (performance of a contract) and Art. 6 (1) (f) GDPR (legitimate interest in analyzing and optimizing our offering).
Your personal data is only passed on to third parties if:
We use Stripe (Stripe, Inc., 354 Oyster Point Blvd, South San Francisco, CA 94080, USA) for payments. Your payment data is processed directly by Stripe and is not stored on our servers. Stripe's privacy policy applies.
We use Resend (Resend, Inc.) to send emails. Email addresses are transmitted to Resend for the purpose of delivery. Resend's privacy policy applies.
You have the right to:
We use SSL encryption (Secure Socket Layer) for the secure transmission of your data. Our website is only accessible via HTTPS.
Our website is hosted by Railway (Railway Corp.). The servers are located in the EU and the USA. Railway's privacy policy applies.
Reisebegleiter is an app for the customers of travel agencies. It shows the booked trip, the travel documents belonging to it and the contact details of the travel agency. This section applies to the app only and adds to the sections above. You gain access by entering the nine-character trip code printed on your booking confirmation, or by requesting a sign-in code sent to the email address your travel agency has stored with your booking.
The controller for your travel data under the GDPR is the travel agency you booked with. We provide the app and the servers behind it and process your data solely on behalf of and on the instructions of that travel agency (processing on behalf of a controller under Art. 28 GDPR). You will find the name, address and contact details of your travel agency in the privacy area of the app and on its own legal pages, which the app links to from there.
Most of the data in the app does not come from you but from your booking at the travel agency:
In its own account, your travel agency can see which people have access to a trip, whether and when they last used the app, and what feedback they gave on the trip. Your travel diary is expressly not part of that.
One of the routes above needs an explanation of its own. If your travel agency forwards a booking confirmation to us so that the trip does not have to be typed in by hand, we have the text of that email read by a language model at OpenAI (openai.com). The text of the confirmation goes out as it stands there, your name and the booking number included. Unlike with the assistant (see 11.6) nothing can be left out here: what is to be read out sits in the same lines as your name. The result is a draft that your travel agency checks before the trip appears in the app. Only your travel agency uses this route, never the app on your device, and it does not happen at all when the agency enters the trip itself or the trip comes from its booking system.
Your travel agency places your documents in the app: booking confirmation, invoice, tickets, hotel vouchers, entry requirements and further information. These files usually contain your name, your address, the booking number and the trip price. They are stored on our server and can only be retrieved through the signed-in app. Every retrieval checks whether your account has access to exactly that trip. When you open a document, the app additionally stores it in the area of your device that is closed to other apps, so that you can read it without an internet connection. These files are removed from the device when you sign out and when you delete your account.
You can also add a document to your trip yourself, a boarding pass or a confirmation for instance. That file then sits with the booking and is therefore visible to your travel agency as well. What this means for the deletion of your account is described under 11.10.
The reminders before departure, for check-in and on the day of travel are created by the app itself on your device. No data leaves your device for this, and we do not learn whether or when a reminder was shown. You can switch the reminders off at any time in the settings of the app.
Messages from your travel agency are fetched by the app when you open it. You can also write to your travel agency in the app; what you write there is read by your travel agency, and it is notified about it by email (see below). In addition, the app can alert you by push notification to a new message from your travel agency or to an answer in a conversation. For this the app uses Firebase Cloud Messaging, a service by Google. Your device asks you first whether the app may show notifications. If you allow it, Firebase creates an identifier for that device, the push token. The token names the app installation on that device, not you as a person, and it contains neither your name nor your travel data. We store it together with the operating system, the app version, your language setting and the time it was last used, and we use it for one purpose only, namely to send the notification to the right device. When you sign out, the app hands the token back and we delete it, and the same happens when you delete your account. You can also switch notifications off at any time in the settings of your device.
At this time push notifications are not yet in operation. For as long as no Firebase project is set up for them, no push token is created on your device, none is transmitted to us, and no push notification is sent.
You will only receive promotional messages from your travel agency if you have expressly agreed to them; information about your trip is not advertising and does not depend on that consent.
Four things in the app trigger an email. These emails are sent through our service provider Resend (see 11.8):
The app shows the weather at your destination for your travel days. To do so, our server queries the coordinates of the destination and the dates of your trip at the weather service Open-Meteo (open-meteo.com). Only the place you are travelling to is transmitted, never your own location, never your name and never an identifier of your device. Your device does not connect to Open-Meteo itself, so no IP address of yours becomes known there either. The answer is briefly cached on our side, so that one query serves all travellers heading to the same destination. The app never asks for the location of your device and holds no permission to do so.
Our server fetches the remaining facts about the destination country the same way: the exchange rate from Frankfurter (frankfurter.dev) and the travel advisory from the German Federal Foreign Office (auswaertiges-amt.de). For the exchange rate, only a currency code such as "TRY" is transmitted. To the Federal Foreign Office not even that: our server fetches the complete list of countries from there and picks out the one for your trip itself. Neither service learns anything about you.
When the app shows the current status of a booked flight, meaning delay, terminal and gate, our server queries the flight data service AeroDataBox for it. Only the flight number and the date of the flight are transmitted, the same two things that stand on every departure board at an airport. Your name, your booking number and your seat number do not go there, and here too your device does not connect to the service itself. We cache the answer briefly, so that one query serves everybody on the same flight.
You cannot trigger that query at all. It runs on our server on a schedule of its own, set off by the clock and not by anybody opening the app. The time of a request to that service therefore says nothing about when or how often you looked at your trip.
If your travel agency uses the assistant Nelly, you can ask questions about your trip in the app. Some of the answers are written on our server without any language model at all. Where that is not enough, the question goes to the language model of OpenAI (openai.com). What goes there: the text you typed, the earlier messages of the same conversation, and an extract of your trip.
That extract is not a promise, it is a list in the code: field by field it names what the model may see, and what is not on the list does not leave the building. Passed on are the trip title, the destination, the start and end dates, the number of travelling persons (not who they are), your services with their kind, title, provider and times, and per service these details only: flight number, airline, departure and arrival airport, terminals, baggage, board, room category, car class, pick-up station and duration. Further the current flight status, the titles and kinds of your documents, the weather at the destination, the time zone, the destination country with its exchange rate, socket type and whether a travel advisory exists, and the name and opening hours of your travel agency.
Not passed on are: the names of the travelling persons, your email address and phone number, file and booking number, booking references, insurance, seat and ticket numbers, the content of your documents and the address they are stored at, the contact details of your travel agency, and your travel diary. The model is given a trip with no people in it. Where an answer really needs one of those, our server writes that sentence itself. That is true of the assistant. For the one other route on which a language model sees more, the forwarded booking confirmation, see 11.2.
Your question itself goes out exactly as you typed it. Please do not write anything into it that is nobody else's business. We do not store the conversation; the app sends the history along again with every question. What stays with us are counters per travel agency and day, meaning the number of requests and of the computing steps used, without your questions and without any link to you.
Under every answer there is a link, "Report this answer". If you report an answer, exactly four things are transmitted: the reported answer, your question directly before it, the reason you picked ("This is not right", "This is inappropriate" or "Something else"), and the optional line, if you wrote one. The rest of the conversation is not sent, your travel data is not sent, and no identifier of your trip or of you is sent either.
The question and the answer are, by their nature, about your trip. They can therefore contain flight numbers, places, times and names. That is exactly what makes a report usable: without the passage in question, a wrong answer cannot be judged. The report is read by us, not by your travel agency, because Nelly is our build and only we can change anything about her. What is recorded is which travel agency the answer came from, not who reported it: you do have to be signed in, but there is no follow-up question and no reply to a report, so your name is not needed for it.
One consequence of that is worth knowing before you report anything. Because a report is stored with no link at all to your account, we cannot connect it back to you afterwards. If you delete your account, the report is therefore not deleted with it, and we cannot pick it out in answer to a deletion request: there is no feature we could search on. We do not have to keep additional information for the sole purpose of finding you in it, and we do not want to (Art. 11 GDPR). Time is the limit instead: we keep a report for three months, after which it is deleted automatically. If you would rather nothing from your trip were stored that way, please do not report the answer, or write the optional line without any details about yourself.
Reporting is voluntary. The app works exactly the same if you never report anything. The legal basis is our legitimate interest in improving the assistant (Art. 6(1)(f) GDPR).
The app contains no analytics or tracking components and no ad networks, and it builds no usage profile. The fonts are contained in the app and are not loaded from anywhere else.
If the app crashes, it sends us a fault report so that we can find the fault. It contains the kind of error with its technical message and where in the program it occurred, the operating system, the version of the app and the screen size of your device. The report goes to our own server, not to a crash reporting service, and it is sent without your sign-in: it contains neither your name nor an identifier of your account or your device, and we cannot connect it to you. Before it is stored, email addresses, identifiers and long runs of digits in the text are replaced by placeholders. Identical faults are folded into one entry with a counter and deleted once the same fault has not occurred for 90 days.
Images are loaded from elsewhere in one place. When Nelly suggests a destination or an offer, your device fetches the photograph belonging to it directly from the image service Pexels (pexels.com). In doing so your IP address and the technical identifier of your device become known to Pexels, as they do with any request to an outside address. All that is transmitted is which photograph is to be loaded; your travel data, your name and your question to Nelly do not go there.
Beyond the cases named under point 5, data from the app is passed on to:
We read booking data out of the booking system of your travel agency (myJACK by Bewotec) if the travel agency has set up that connection. No data from the app flows back into it.
You can delete your account directly in the app, in the settings under "Signing in" with "Delete account". This deletes: your account record with name, email address, phone number, passport expiry date and language setting, all sign-ins and sign-in codes, the registered devices including their push tokens, your access to trips, your packing lists, your travel diary with all its text and photos, your messages to your travel agency together with the replies to them, your feedback on trips, the record of which messages you have read, and enquiries you sent through your travel agency website. You are signed out on all devices, and the downloaded documents are removed from your device.
The booking itself is not deleted. It belongs to your travel agency, which is required to keep it. The link to your account is severed, however, so the trip can no longer be reached from any sign-in in the app.
A trip whose documents have already been deleted and that only remains as a memory (see 11.9) is deleted along with your account, once no account can reach it any more. That happens around 30 days after the last account that could still open it was deleted.
Documents you added to a trip yourself (see 11.3) are not deleted either. They sit with the booking and are therefore part of the travel documents the agency keeps. After your account is deleted, all that is gone is the record that you were the one who added them. If you also want the booking data and those documents deleted, please contact your travel agency.
Reported answers of the assistant (see 11.6) and fault reports after a crash (see 11.7) are not deleted along with it. Neither of them records who it came from, so there is no record belonging to your account and none we could pick out on request either. Both are deleted on their own after the periods named above instead.
If you no longer have access to the app, you can also request the deletion at sendsite.live/konto-loeschen.
For your data in the app you have the same rights as described under point 8: information, correction, deletion, restriction of processing, data portability, objection to processing, withdrawal of any consent given, and lodging a complaint with a supervisory authority. Please address these matters to your travel agency, which is the controller for them. You may also contact [email protected]; we will forward your request to your travel agency and carry out its decision.