Privacy Policy

Introduction and Overview

We have prepared this Privacy Policy (version dated 15 May 2026) to explain to you, in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable national laws, which personal data (“data”) we process as the data controller, which data may be processed in the future, and what lawful rights you have as a data subject. The terminology used in this Privacy Policy is gender-neutral.

In short: We provide comprehensive information about the personal data we process concerning you.

Privacy policies often sound highly technical and contain legal terminology. This Privacy Policy, however, is intended to describe the most important aspects as clearly and transparently as possible. Where it enhances understanding, technical terms are explained in a user-friendly manner, links to additional information are provided, and visual aids may be used.

We inform you in clear and simple language that we only process personal data within the scope of our business activities when a valid legal basis exists. This approach is intended to provide transparency and clarity regarding our data processing activities.

If you still have questions after reading this Privacy Policy, please contact the responsible party listed below or in our legal notice (Imprint). Additional information may also be available through the referenced external websites.

Scope of Application

This Privacy Policy applies to all personal data processed by our company and to all personal data processed on our behalf by contracted service providers (processors).

For the purposes of this Privacy Policy, “personal data” means any information relating to an identified or identifiable natural person within the meaning of Article 4(1) GDPR, including but not limited to:

  • Name
  • Email address
  • Postal address
  • Other information that can directly or indirectly identify an individual

The processing of personal data enables us to provide and bill our services and products, whether online or offline.

This Privacy Policy applies in particular to:

  • All websites and online services operated by us
  • Social media profiles and activities
  • Email communications
  • Mobile applications for smartphones and other devices

In short: This Privacy Policy applies to all areas in which personal data is processed in a structured manner through the channels listed above. If we enter into legal relationships with you outside these channels, we will provide separate information where required.

Legal Bases

In this Privacy Policy, we provide transparent information regarding the legal principles and provisions that allow us to process personal data.

With regard to European Union law, we refer to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation – GDPR).

We process your personal data only if at least one of the following legal bases applies:

1. Consent

(Article 6(1)(a) GDPR)

You have given your consent to the processing of your personal data for one or more specific purposes.

Example: storing information submitted through a contact form.

2. Performance of a Contract

(Article 6(1)(b) GDPR)

Processing is necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract.

Example: processing personal information required to conclude a purchase agreement.

3. Legal Obligation

(Article 6(1)(c) GDPR)

Processing is necessary for compliance with a legal obligation to which we are subject.

Example: retention of invoices and accounting records required by law.

4. Legitimate Interests

(Article 6(1)(f) GDPR)

Processing is necessary for the purposes of our legitimate interests, provided such interests are not overridden by your fundamental rights and freedoms.

Example: ensuring the secure and efficient operation of our website.

Additional legal bases, such as processing necessary for the performance of a task carried out in the public interest or for the protection of vital interests, generally do not apply to our activities. Should such legal bases become relevant, they will be specified in the respective section.

National Data Protection Laws

In addition to the GDPR, national data protection laws may apply.

Austria: Federal Act concerning the Protection of Personal Data (Datenschutzgesetz – DSG)

Germany: Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG)

Where further regional or national regulations apply, we will inform you accordingly in the relevant sections of this Privacy Policy.

Contact Details of the Data Controller

If you have any questions regarding data protection or the processing of personal data, please contact:

Onyx Travel Management Consulting
Stefanos Markou
Böblinger Str. 45
70199 Stuttgart
Germany

Authorized Representative: Stefanos Markou

Email: info@onyx-tmc.de

Legal Notice (Imprint):
https://www.onyx-tmc.de/impressum

Privacy Policy

Data Retention

As a general principle, we store personal data only for as long as is strictly necessary to provide our services and products.

This means that personal data is deleted as soon as the purpose for which it was processed no longer exists.

In certain cases, however, we are legally required to retain specific data even after the original purpose has ceased to apply, for example to comply with accounting, tax, or commercial law obligations.

If you request the deletion of your data or withdraw your consent to data processing, the data will be deleted as quickly as possible, provided that no legal retention obligations prevent such deletion.

Where additional information is available, we will specify the respective retention periods in the relevant sections of this Privacy Policy.

Rights under the General Data Protection Regulation (GDPR)

Pursuant to Articles 13 and 14 GDPR, we inform you of the following rights to ensure fair and transparent processing of your personal data:

Right of Access (Article 15 GDPR)

You have the right to obtain confirmation as to whether we process personal data concerning you.

Where this is the case, you have the right to receive a copy of the personal data and information regarding:

Right to Rectification (Article 16 GDPR)

You have the right to request the correction of inaccurate personal data and the completion of incomplete personal data.

Right to Erasure ("Right to be Forgotten") (Article 17 GDPR)

You have the right to request the deletion of your personal data under the conditions set out in Article 17 GDPR.

Right to Restriction of Processing (Article 18 GDPR)

You have the right to request that the processing of your personal data be restricted under certain circumstances.

Right to Data Portability (Article 20 GDPR)

You have the right to receive the personal data concerning you in a structured, commonly used, and machine-readable format and to transmit that data to another controller.

Right to Object (Article 21 GDPR)

You have the right to object at any time to the processing of your personal data where processing is based on:

Upon receipt of your objection, we will review whether compelling legitimate grounds exist to continue processing your data.

Direct Marketing

Where your personal data is processed for direct marketing purposes, you have the right to object at any time. Following such objection, your data will no longer be processed for direct marketing purposes.

Profiling

Where personal data is processed for profiling purposes, you may object to such processing at any time. Following your objection, your personal data will no longer be used for profiling purposes.

Rights Related to Automated Decision-Making (Article 22 GDPR)

Under certain circumstances, you have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

Right to Lodge a Complaint (Article 77 GDPR)

You have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data infringes the GDPR.

In short: You have extensive rights regarding your personal data. Please do not hesitate to contact us using the contact details provided above.

Competent Supervisory Authority

If you believe that the processing of your personal data violates applicable data protection laws or that your data protection rights have otherwise been infringed, you may lodge a complaint with the competent supervisory authority.

For our company, the responsible supervisory authority is:

Baden-Württemberg Supervisory Authority

State Commissioner for Data Protection and Freedom of Information Baden-Württemberg

Commissioner: Prof. Dr. Tobias Keber

Address:
Lautenschlagerstraße 20
70173 Stuttgart
Germany

Telephone:
+49 (0)711 615541-0

Email:
poststelle@lfdi.bwl.de

Website:
https://www.baden-wuerttemberg.datenschutz.de

Security of Data Processing

To protect personal data, we have implemented appropriate technical and organizational measures.

Where possible, personal data is encrypted or pseudonymized. By doing so, we make it as difficult as reasonably possible for unauthorized third parties to derive personal information from processed data.

Article 25 GDPR refers to this principle as “Data Protection by Design and by Default.” This means that both software and hardware systems are designed and configured with privacy and security considerations in mind.

Where necessary, additional security measures are described in the relevant sections of this Privacy Policy.

TLS Encryption (HTTPS)

We use TLS encryption (Transport Layer Security) and HTTPS (Hypertext Transfer Protocol Secure) to ensure the secure transmission of data over the Internet.

This means that all data transferred between your browser and our web server is protected against unauthorized access by third parties.

By implementing TLS encryption, we comply with the principle of Data Protection by Design pursuant to Article 25(1) GDPR and ensure the confidentiality and integrity of transmitted information.

You can recognize a secure connection by:

TLS encryption provides an additional layer of security and helps protect confidential information during transmission.
Communication

Communication Summary

Data Subjects:
All individuals who communicate with us via telephone, email, or online forms.

Purpose of Processing:
Handling and responding to inquiries, customer communications, business correspondence, and related business processes.

Processed Data:
Depending on the communication channel, this may include:

Retention Period:
For the duration necessary to process the request and in accordance with applicable statutory retention obligations.

Legal Bases:

When you contact us via telephone, email, or an online form, personal data may be processed.

The data is processed solely for the purpose of handling your inquiry and any related business transaction.

The data will only be stored for as long as necessary to process the relevant matter or as required by applicable legal retention obligations.

Data Subjects

This processing affects all individuals who contact us through the communication channels provided by us.

Telephone

When you contact us by telephone, call-related data may be stored in pseudonymized form on the device used and by the telecommunications provider involved.

In addition, information such as your name and telephone number may subsequently be transmitted via email and stored for the purpose of responding to your inquiry.

The data will be deleted once the matter has been concluded and no statutory retention obligations prevent deletion.

Email

When you communicate with us by email, personal data may be stored on the devices involved (such as computers, laptops, smartphones, or tablets) and on the email servers used.

The data will be deleted as soon as the underlying business purpose has been fulfilled and statutory retention obligations permit deletion.

Online Forms

When you communicate with us via online forms, the data you provide is stored on our web server and may be forwarded internally via email.

The data will be deleted once the relevant business purpose has been fulfilled and no legal obligations require continued storage.

Legal Basis

The processing of communication data is based on the following legal grounds:

Consent

(Article 6(1)(a) GDPR)

You have given your consent to the storage and use of your data for purposes related to the handling of your inquiry.

Contractual Necessity

(Article 6(1)(b) GDPR)

Processing is necessary for the performance of a contract with you or for taking pre-contractual steps at your request, such as preparing quotations or proposals.

Legitimate Interests

(Article 6(1)(f) GDPR)

We have a legitimate interest in maintaining professional communication with customers, business partners, and interested parties. This includes the use of technical infrastructure such as email systems, telecommunications providers, and communication platforms.

Data Processing Agreement (DPA)

What is a Data Processing Agreement?

In the course of our business activities, we engage external service providers and partner companies.

Whenever a third party processes personal data on our behalf, that party acts as a processor within the meaning of Article 28 GDPR.

To ensure GDPR compliance, we enter into a Data Processing Agreement (DPA) with such processors.

The DPA governs the processing of personal data and ensures that processors act solely in accordance with our documented instructions.

Who is a Processor?

As the operator of this website and the responsible controller, we are responsible for all personal data processed by us.

In addition to controllers, the GDPR recognizes processors.

A processor is any natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller.

Examples include:

The GDPR relationship can generally be illustrated as follows:

Data Subject
(you)

↓

Controller
(our company)

↓

Processor
(service providers acting on our behalf)

Contents of a Data Processing Agreement

A Data Processing Agreement must be concluded before personal data is processed on behalf of a controller.

The agreement generally contains provisions regarding:

Furthermore, processors are contractually obligated to:

Cookies

Cookies Summary

Data Subjects:
Visitors to our website.

Purpose:
Depends on the specific cookie used. Detailed information is provided below and in the privacy information of the respective service provider.

Processed Data:
Depends on the specific cookie used and may include technical identifiers, user preferences, session information, and usage data.

Retention Period:
Varies depending on the cookie and may range from a few hours to several years.

Legal Bases:

What Are Cookies?

Our website uses HTTP cookies to store user-specific information.

Cookies are small text files stored by your browser on your device.

They enable websites to recognize users, remember preferences, and improve functionality.

Cookies are not software programs and do not contain viruses, malware, or other harmful code.

They cannot access information stored elsewhere on your device.

Types of Cookies

Strictly Necessary Cookies

These cookies are essential for the operation of the website and enable core functionality.

Examples include:

Without these cookies, certain services cannot be provided.

Functional Cookies

These cookies improve usability and website performance.

Examples include:

Analytics Cookies

These cookies collect information about how visitors use the website.

Examples include:

The information helps us improve the website and user experience.

Advertising Cookies

Advertising cookies (also known as targeting cookies) are used to deliver personalized advertisements based on user behavior and interests.

They may be set by us or by third-party advertising partners.

Purpose of Cookie Processing

The specific purpose depends on the individual cookie used.

Cookies generally serve to:

Detailed information is provided in the descriptions of the individual services used on this website.

Cookie Retention Period

Retention periods vary depending on the specific cookie.

Some cookies are deleted immediately after the browser session ends, while others may remain stored for several years.

You may delete cookies manually at any time via your browser settings.

Cookies that are based on your consent are deleted after consent is withdrawn, without affecting the lawfulness of processing carried out before withdrawal.

Right to Object and Cookie Management

You may decide whether and to what extent cookies are stored on your device.

Most browsers allow you to:

Please note that disabling cookies may limit the functionality of this website.

Legal Basis for Cookie Processing

Under European data protection law, the storage of cookies generally requires your prior consent.

Accordingly, the legal basis for the processing of personal data through non-essential cookies is:

Article 6(1)(a) GDPR (Consent)

For cookies that are strictly necessary for the operation of the website, processing is based on:

Article 6(1)(f) GDPR (Legitimate Interests)

Our legitimate interest consists in providing a secure, functional, and user-friendly website.

Where non-essential cookies are used, they are only activated after you have provided your consent.

Web Hosting

Web Hosting Summary

Data Subjects:
Visitors to the website.

Purpose of Processing:

Processed Data:

Retention Period:
Depending on the hosting provider; generally up to two weeks unless otherwise specified.

Legal Basis:
Article 6(1)(f) GDPR (Legitimate Interests)

What Is Web Hosting?

Whenever you visit a website, certain information is automatically generated and stored, including personal data.

To make a website accessible on the Internet, the website files must be stored on a web server operated by a hosting provider.

A web hosting provider supplies the technical infrastructure required to ensure the secure, stable, and efficient operation of a website.

During the connection between your browser and the web server, personal data may be processed.

This includes information generated by your device and information required by the server to provide the requested content.

Why Do We Process Personal Data Through Web Hosting?

We process personal data for the following purposes:

  1. Providing a secure and professionally operated website.
  2. Maintaining system integrity and operational security.
  3. Detecting technical errors and security incidents.
  4. Analyzing website usage in an anonymized form.
  5. Asserting, exercising, or defending legal claims where necessary.

What Data Is Processed?

When you visit our website, our web server may automatically store the following information:

Retention Period

Unless a longer retention period is required for security or legal reasons, server log data is generally stored for approximately two weeks and then automatically deleted.

Data will only be retained beyond this period where necessary to investigate misuse, cyberattacks, technical incidents, or legal claims.

Legal Basis

The processing of personal data in connection with web hosting is based on our legitimate interest in operating a secure, reliable, and user-friendly online presence.

Legal basis:
Article 6(1)(f) GDPR (Legitimate Interests)

Where required by law, a Data Processing Agreement pursuant to Article 28 GDPR is concluded with the hosting provider.

1&1 IONOS Web Hosting Privacy Policy

Summary

Data Subjects:
Visitors to the website.

Purpose of Processing:

Processed Data:

Retention Period:
Visitor data is generally retained for up to eight weeks.

Legal Basis:
Article 6(1)(f) GDPR (Legitimate Interests)

What Is IONOS?

To host this website, we use services provided by:

IONOS SE
Elgendorfer Straße 57
56410 Montabaur
Germany

IONOS is one of the largest web hosting providers in Europe and offers hosting, cloud services, domain registration, email services, server infrastructure, and website solutions.

As part of providing hosting services, IONOS processes technical information necessary for delivering website content and ensuring secure operation.

Why Do We Use IONOS?

We use IONOS because it provides:

These services help us maintain a secure and efficient online presence.

What Data Is Processed by IONOS?

When you visit our website, IONOS may process the following information:

According to IONOS, the anonymized IP address is used solely for determining the geographical origin of website access and for security-related purposes.

How Long Is Data Stored?

Data is stored on IONOS servers located within the European Union.

Visitor-related data is generally retained for up to eight weeks.

Longer retention periods may apply where required:

According to IONOS, visitor data is not transferred to third parties for unrelated purposes and is generally not transferred outside the European Union.

Your Rights

You have the right at any time to:

Further information regarding cookie management can be found in the Cookies section of this Privacy Policy.

Legal Basis

We have a legitimate interest in using a professional hosting provider to ensure secure and efficient operation of our online services.

Legal Basis:
Article 6(1)(f) GDPR (Legitimate Interests)

Further information regarding IONOS data protection practices is available at:

https://www.ionos.de/terms-gtc/datenschutzerklaerung/

Data Processing Agreement (DPA) with IONOS

Pursuant to Article 28 GDPR, we have entered into a Data Processing Agreement (DPA) with IONOS.

This agreement ensures that personal data processed by IONOS on our behalf is handled exclusively in accordance with our instructions and in compliance with applicable data protection laws.

The agreement also regulates:

Web Analytics

Web Analytics Summary

Data Subjects:
Visitors to the website.

Purpose of Processing:

Processed Data:

Retention Period:
Depends on the analytics service used.

Legal Bases:

What Is Web Analytics?

Web analytics refers to the collection, measurement, and evaluation of visitor behavior on websites.

Analytics tools collect information about how users interact with a website and generate reports that help website operators improve content, performance, usability, and marketing activities.

These tools may use:

In some cases, pseudonymous user profiles may be created.

Why Do We Use Web Analytics?

We use web analytics to better understand how visitors use our website.

The information collected helps us:

What Data May Be Processed?

Depending on the analytics tool used, the following data may be processed:

Direct personal identifiers such as names, postal addresses, or email addresses are generally not processed for analytics purposes.

Duration of Processing

Personal data is retained only as long as necessary to fulfill the purposes described in this Privacy Policy or as required by law.

Specific retention periods may vary depending on the analytics provider.

Right to Withdraw Consent

You may withdraw your consent to analytics processing at any time.

You can do so by:

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

Legal Basis

Analytics tools are generally used only after obtaining your consent.

Article 6(1)(a) GDPR (Consent)

In addition, we have a legitimate interest in analyzing website usage to improve functionality, security, and efficiency.

Article 6(1)(f) GDPR (Legitimate Interests)

Where consent is required, analytics tools are only activated after such consent has been granted.

Google Analytics 4 Privacy Policy

Google Analytics Summary

Data Subjects:
Visitors to the website.

Purpose of Processing:

Processed Data:

Retention Period:
Configurable by the website operator. Unless otherwise specified, Google Analytics 4 data is retained for up to 14 months.

Legal Bases:

What Is Google Analytics 4?

We use Google Analytics 4 (GA4), a web analytics service provided by:

Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland

Google Analytics helps us understand how visitors interact with our website.

GA4 uses an event-based data model that records interactions such as:

Unlike previous versions of Google Analytics, GA4 places greater emphasis on event tracking and machine-learning-based modeling to better understand user behavior and trends.

How Google Analytics Works

Google Analytics is implemented through a tracking code embedded in our website.

When you visit our website, this code records interactions and transmits relevant information to Google servers.

The collected information is processed by Google and aggregated into reports that allow us to analyze user behavior and improve our services.

Examples of reports provided by Google Analytics include:

Audience Reports

These reports help us better understand our visitors, including demographic and behavioral characteristics.

Acquisition Reports

These reports show how users arrive at our website, such as through search engines, advertisements, referrals, or direct visits.

Behavior Reports

These reports help us understand how visitors interact with our website, including navigation paths, page views, and user engagement.

Conversion Reports

These reports help us measure whether desired actions are completed, such as:

Real-Time Reports

Real-time reports provide information about current visitor activity on the website.

Additional Features of Google Analytics 4

GA4 includes several advanced features, including:

Event-Based Data Collection

Specific user interactions can be defined and tracked individually.

Examples include:

Advanced Analytics

GA4 allows segmentation of audiences and detailed analysis of user behavior patterns.

Predictive Analytics

Using machine learning, GA4 may generate predictions regarding future user behavior and business trends.

Cross-Platform Analysis

Where applicable and consent has been provided, user interactions across websites and mobile applications may be analyzed collectively.

Why We Use Google Analytics

We use Google Analytics to improve our website and services.

The insights gained help us:

This allows us to provide a more relevant and user-friendly experience.

What Data Does Google Analytics Process?

Google Analytics may process the following categories of information:

Technical Data

Usage Data

Location Data

Google may derive approximate geographic information from IP-related signals.

Event Data

Interactions with website elements, such as:

Technical Identifiers

Google Analytics may use:

These identifiers are generally pseudonymous and do not directly identify an individual.

IP Addresses

According to Google, IP addresses collected from users within the European Union are not permanently stored in Google Analytics 4.

IP information is used only temporarily for geographic determination and security purposes and is deleted before being permanently stored.

Google states that IP addresses are not logged or stored within GA4 reports.

Google Analytics Cookies

Google Analytics may use cookies to distinguish users and sessions.

Examples include:

_ga

Purpose:
Distinguishes individual visitors and assigns a pseudonymous user identifier.

Retention Period:
Up to 2 years.

_gid

Purpose:
Distinguishes users for statistical purposes.

Retention Period:
24 hours.

_gat

Purpose:
Limits request rates and improves system efficiency.

Retention Period:
Typically 1 minute.

The actual cookies used may vary depending on the Google Analytics configuration implemented on the website.

Data Retention

Retention periods within Google Analytics can be configured by the website operator.

Unless otherwise specified, personal data collected through Google Analytics is retained for up to 14 months.

Aggregated statistical reports may be retained beyond this period where they no longer contain personal data.

International Data Transfers

Google may process data on servers located outside the European Union.

Where personal data is transferred to countries outside the European Economic Area (EEA), Google states that appropriate safeguards are implemented pursuant to Articles 44 et seq. GDPR.

These safeguards may include:

How Can You Prevent Data Collection?

You can prevent Google Analytics from collecting your data by:

Withdrawing Cookie Consent

You may change your consent preferences at any time through our cookie settings.

Browser Settings

You may disable or delete cookies through your browser settings.

Google Analytics Opt-Out Browser Add-on

Google provides a browser extension that prevents Google Analytics from collecting data:

https://tools.google.com/dlpage/gaoptout

Legal Basis

Google Analytics is used only where you have provided your consent.

Article 6(1)(a) GDPR (Consent)

Additionally, we have a legitimate interest in analyzing website performance and improving our services.

Article 6(1)(f) GDPR (Legitimate Interests)

Where consent is required under applicable law, Google Analytics is activated only after such consent has been obtained.

Further Information

Further information regarding Google's handling of personal data can be found in Google's Privacy Policy:

https://policies.google.com/privacy

Additional information regarding Google Analytics is available at:

https://support.google.com/analytics

Email Marketing

Email Marketing Summary

Data Subjects:
Individuals who subscribe to newsletters, marketing communications, or other email-based information services.

Purpose of Processing:

Processed Data:

Retention Period:
Until consent is withdrawn or the purpose no longer applies, unless legal retention obligations require otherwise.

Legal Basis:
Article 6(1)(a) GDPR (Consent)

What Is Email Marketing?

Email marketing refers to the electronic distribution of information, offers, newsletters, and promotional content to interested individuals.

Where you subscribe to our newsletter or other marketing communications, we process your personal data for the purpose of sending you relevant information about our services, products, and business activities.

Registration and Double Opt-In

Subscription to our newsletter generally takes place using a double opt-in procedure.

This means:

  1. You register using your email address.
  2. You receive a confirmation email.
  3. Your subscription becomes active only after you confirm the registration.

This process ensures that no third party can subscribe using your email address without your authorization.

What Data Is Processed?

Depending on the service used, the following information may be processed:

Such data helps us maintain secure and legally compliant communication.

Email Tracking

Marketing emails may contain tracking technologies that enable us to determine whether:

These measurements help us evaluate and improve our communication.

Such tracking is only carried out where legally permissible and, where required, based on your consent.

Withdrawal of Consent

You may withdraw your consent at any time.

Each marketing email contains an unsubscribe link that allows you to stop receiving future communications.

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

Legal Basis

Newsletter subscriptions and email marketing communications are generally based on:

Article 6(1)(a) GDPR (Consent)

Where marketing communications are sent to existing customers under applicable legal exemptions, processing may additionally be based on:

Article 6(1)(f) GDPR (Legitimate Interests)

Online Marketing

Online Marketing Summary

Data Subjects:
Website visitors and users of online services.

Purpose of Processing:

Processed Data:

Legal Bases:

What Is Online Marketing?

Online marketing includes all digital measures used to promote products, services, and business activities through websites, search engines, social media platforms, and advertising networks.

Online marketing tools may collect information about user interactions in order to evaluate the effectiveness of marketing campaigns and improve future activities.

Purpose of Processing

The purposes of online marketing include:

Data Processing

Depending on the service provider used, the following information may be processed:

The exact categories of data depend on the specific online marketing services used.

Legal Basis

Online marketing technologies that are not strictly necessary are generally activated only after obtaining your consent.

Article 6(1)(a) GDPR (Consent)

In certain cases, processing may also be based on our legitimate interest in improving our marketing activities.

Article 6(1)(f) GDPR (Legitimate Interests)

Cookie Consent Management Platform

Summary

Purpose:
Management and documentation of user consent regarding cookies and tracking technologies.

Processed Data:

Legal Basis:

Purpose of Consent Management

We use a consent management platform to:

What Data Is Processed?

The consent platform may store:

This processing is necessary to demonstrate compliance with data protection regulations.

Retention Period

Consent records are retained for as long as necessary to demonstrate compliance with applicable legal obligations.

Legal Basis

The use of a consent management platform is necessary to comply with legal requirements regarding consent management and accountability.

Article 6(1)(c) GDPR (Legal Obligation)

In addition, we have a legitimate interest in documenting and managing user consent.

Article 6(1)(f) GDPR (Legitimate Interests)

Video Conferencing and Streaming

Summary

Data Subjects:
Participants in online meetings, webinars, virtual consultations, and streaming events.

Purpose of Processing:

Processed Data:

Legal Bases:

What Is Processed?

When participating in online meetings or streaming events, personal data may be processed depending on the functionality used.

This may include:

Purpose of Processing

The processing is necessary to:

Recordings

Meetings are recorded only where necessary and only after appropriate information has been provided and, where required, consent has been obtained.

Legal Basis

Depending on the circumstances, processing is based on:

Online Booking Systems

Summary

Data Subjects:
Customers and prospective customers using online booking functionality.

Purpose of Processing:

Processed Data:

Legal Bases:

Purpose of Processing

When you make a booking through our website or online systems, we process your personal data in order to:

Retention Period

Booking-related information is retained for as long as necessary to fulfill contractual obligations and comply with statutory retention requirements.

Legal Basis

The processing of booking-related data is generally necessary for the performance of a contract or for taking steps prior to entering into a contract.

Article 6(1)(b) GDPR

Where consent is obtained for specific processing activities:

Article 6(1)(a) GDPR

Final Remarks

We have made every effort to ensure that this Privacy Policy is clear, transparent, and easy to understand.

As our website, services, and legal obligations may evolve over time, we reserve the right to update this Privacy Policy where necessary.

The current version published on our website shall always apply.

If you have any questions regarding this Privacy Policy or the processing of your personal data, please contact us using the contact details provided above.


Controller:
Onyx Travel Management Consulting
Stefanos Markou
Böblinger Str. 45
70199 Stuttgart
Germany

Email: info@onyx-tmc.de