This policy explains what personal data we collect when you visit exploring-heidelberg.de or book a walking tour with us, why we collect it, how long we keep it, and what rights you have. We have tried to write it in plain English rather than legal boilerplate. Our tours are offered in English, so this policy is written in English; it applies in full under German and EU law.
1. Who is responsible
The controller for data processing on this website, within the meaning of Art. 4(7) GDPR, is:
Yatin AroraExploring Heidelberg
Ottheinrichweg 2
69181 Leimen
Germany
Email: rythyma.sharma.2000@gmail.com
We are not required to appoint a Data Protection Officer under Art. 37 GDPR. For any question about your data, write to the address above and we will answer.
Full company details are on our Impressum.
2. In short
- You can read every page of this site without accepting anything and without telling us who you are.
- We do not sell, rent or trade your data. Ever.
- Analytics is optional and off until you say yes. The map only loads when you ask it to.
- Fonts and scripts are served from our own server, so browsing does not send your IP to any third party.
- We ask for the minimum needed to run a tour: a name, an email, a date.
3. Server log files
Like every web server, ours records a short technical entry for each request. What makes ours different is that the visitor's IP address is discarded before the entry is written. Our reverse proxy is configured to drop the client address and the forwarding headers that would otherwise reveal it, so the stored log line cannot be traced back to you or your connection.
| What is stored | Date and time, page requested, HTTP status and response size, request duration, protocol and TLS version |
|---|---|
| What is not stored | Your IP address, X-Forwarded-For and X-Real-IP headers, or any other identifier of your device |
| Why | Delivering the site, diagnosing errors, and understanding traffic and attack patterns |
| Legal basis | Art. 6(1)(f) GDPR — our legitimate interest in a working, secure website. Because the entries carry no identifier, the intrusion on you is minimal |
| Kept for | Up to 12 months, then deleted automatically |
The IP address is of course still used momentarily, in memory, to route the response back to your browser — that is how the internet works and it cannot be avoided. It is simply never written to disk. These logs are not combined with any other data and cannot be used to identify individual visitors.
4. Cookies & local storage
No cookie is set on your device before you agree to one. When you first arrive, a banner asks whether you want to allow analytics. Until you press Accept, no analytics cookie exists.
| Name | Type | Purpose | Duration |
|---|---|---|---|
cookie_consent |
Local storage, strictly necessary | Remembers whether you accepted or rejected analytics, so we do not ask again on every page | Until you clear your browser storage |
_ga, _ga_* |
Optional, analytics | Google Analytics — tells apart returning and new visitors | Up to 2 years; deleted immediately if you withdraw consent |
The cookie_consent entry is strictly necessary under § 25(2) TDDDG: it exists
only to store your own choice, so it needs no consent of its own.
Changed your mind? You can withdraw or give consent at any time, with effect for the future. Withdrawing is exactly as easy as accepting, and we delete the Google Analytics cookies from your browser when you do.
5. Google Analytics
If — and only if — you accept in the cookie banner, we use Google Analytics 4, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to understand which pages visitors find useful. Without your consent, no analytics cookie is written and no analytics identifier is created.
| What | Pages viewed, time on page, approximate location (city level), device and browser type, referring site, shortened IP address |
|---|---|
| Why | To see which tours and pages people actually read, so we can improve them |
| Legal basis | Art. 6(1)(a) GDPR — your consent, and § 25(1) TDDDG for storing the cookie |
| Kept for | Up to 14 months in Google Analytics, then deleted automatically |
We have IP anonymisation enabled, so your IP address is shortened before it is stored and cannot be traced back to you. We do not use Google Signals, advertising features, or cross-device tracking, and we do not link analytics data to any booking.
Google may transfer data to servers in the United States. Google LLC is certified under the EU–US Data Privacy Framework, which the European Commission has recognised as providing an adequate level of protection (adequacy decision of 10 July 2023). Details of Google's processing are at policies.google.com/privacy.
You can withdraw consent at any time using the button in section 4, or install Google's browser opt-out add-on from tools.google.com/dlpage/gaoptout.
6. Google Maps
Our route page shows a map of the Old Town. That map is not loaded when the page opens. In its place you see a static panel with a "Load map" button. Nothing is requested from Google until you press it.
When you do press it, your IP address, browser information and the map coordinates are sent to Google Ireland Limited, and Google may set its own cookies. This is your active choice each time, and it is the legal basis for that transfer (Art. 6(1)(a) GDPR). If you never press the button, Google never learns you were here.
Google's terms for Maps are at policies.google.com/privacy. The plain "Open in Google Maps" link opens Google in a new tab only when clicked, like any other external link.
7. Fonts & scripts
The typefaces (Inter and Playfair Display) and the animation library used on this site are stored on our own server and delivered from our own domain. They are not loaded from Google Fonts, from a content delivery network, or from any other third party, so simply opening a page does not transmit your IP address anywhere except to our own host.
We made this choice deliberately: loading fonts from an external CDN would send your IP address to a third country every time a page opens, without any way for you to refuse it first.
8. Booking calendar
Tour slots are booked through an external calendar hosted by Cal.eu. Clicking the booking link takes you to that provider's own page, where their privacy policy applies in addition to this one.
| What | Name, email address, chosen date and time, number of participants, any note you add |
|---|---|
| Why | To reserve your place, confirm it and contact you if plans change |
| Legal basis | Art. 6(1)(b) GDPR — performance of a contract you asked for |
| Kept for | Until the tour is complete, then up to 3 years for possible claims |
We do not use your booking email for marketing. You will hear from us about your own tour and nothing else, unless you separately ask to be told about future dates.
9. PayPal deposits
The 50% deposit is paid through PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg. When you pay, you deal with PayPal directly: your payment details (card number, bank details, PayPal login) go to PayPal and never reach us. We see only that a payment arrived, from which name, and for which booking.
| What we receive | Payer name, payment amount, date, transaction reference, the email used for PayPal |
|---|---|
| Why | To confirm your booking and to keep proper records of payments received |
| Legal basis | Art. 6(1)(b) GDPR (contract) and Art. 6(1)(c) GDPR (record-keeping obligations) |
| Kept for | As required by German tax and commercial law, generally up to 10 years |
The remaining balance is paid in cash on the day of the tour, which involves no data processing at all. PayPal's own privacy statement is at paypal.com.
10. Email contact
If you email us, your message, your address and anything you choose to include are stored in our mailbox so we can reply and refer back to the conversation. Our mailbox is hosted by Google (Gmail).
| Legal basis | Art. 6(1)(b) GDPR where the message concerns a booking; otherwise Art. 6(1)(f) GDPR — our legitimate interest in answering enquiries |
|---|---|
| Kept for | As long as needed to deal with the matter, then deleted; tax-relevant correspondence is kept for the statutory period |
Ordinary email is not encrypted end-to-end and can in principle be read in transit. Please do not send sensitive information (health details, payment card numbers) by email.
11. Photos on tour
We sometimes take photos during a tour and may use them on this website or on social media. We ask before taking a photo in which you are recognisable, and we only publish it if you agree. That consent is voluntary (Art. 6(1)(a) GDPR) and you can withdraw it at any time by emailing us — we will remove the photo from anything under our control.
Saying no makes no difference to your tour, and we will never make it awkward.
12. Hosting
This website is hosted on a server operated by Hostinger International Ltd., 61 Lordou Vironos str., 6023 Larnaca, Cyprus. The server itself stands in Frankfurt am Main, Germany, so the data needed to deliver these pages never leaves the country.
Our host processes data strictly on our instructions, under a data processing agreement pursuant to Art. 28 GDPR, and only to the extent needed to keep the site online. Where the host engages sub-processors of its own, it is contractually required to bind them to equivalent obligations, and any transfer outside the EEA is covered by EU Standard Contractual Clauses.
13. Transfers outside the EU
Everything needed to display this site stays inside the EU. Data leaves the EU only in these cases, and only where you have chosen it or a contract requires it:
- Google Analytics — only after you accept the cookie banner. Google LLC is certified under the EU–US Data Privacy Framework.
- Google Maps — only after you press "Load map".
- Gmail — if you choose to email us, since our mailbox is hosted by Google.
Where a transfer relies on the EU–US Data Privacy Framework, the European Commission has decided that the United States offers an adequate level of protection for certified companies. Where that is not available, we rely on Standard Contractual Clauses under Art. 46(2)(c) GDPR.
14. How long we keep data
We keep personal data only as long as we need it for the purpose it was collected for, or as long as the law requires:
| Data | Kept for |
|---|---|
| Server logs (no IP addresses) | 12 months |
| Analytics data | 14 months |
| Booking details | Up to 3 years after the tour |
| Payment records | Up to 10 years (tax law) |
| General email correspondence | Deleted once the matter is closed |
When a retention period ends, the data is deleted or irreversibly anonymised.
15. Your rights
Under the GDPR you have the following rights in relation to your personal data. Exercising them is free and we will respond within one month.
- Access (Art. 15) — ask what data we hold about you and get a copy.
- Rectification (Art. 16) — have incorrect data corrected.
- Erasure (Art. 17) — have your data deleted, where no legal duty requires us to keep it.
- Restriction (Art. 18) — have processing paused while a dispute is resolved.
- Data portability (Art. 20) — receive your data in a machine-readable format.
- Objection (Art. 21) — object to processing based on legitimate interest, on grounds relating to your particular situation.
- Withdraw consent (Art. 7(3)) — at any time, with effect for the future. Withdrawal does not affect processing carried out before it.
To use any of these rights, email rythyma.sharma.2000@gmail.com. We may ask one question to confirm it is really you, so that we do not hand your data to someone else.
16. Right to complain
If you believe we have handled your data improperly, please tell us first — we would rather fix it. You also have the right to complain to a supervisory authority (Art. 77 GDPR). The authority responsible for us is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-WürttembergLautenschlagerstraße 20
70173 Stuttgart
Germany
baden-wuerttemberg.datenschutz.de
You may also complain to the supervisory authority where you live or work.
17. Changes to this policy
We update this policy when the site or the law changes — for example if we add a new service. The date at the top always shows the current version. Continued use of the site after a change means the updated policy applies; where a change requires your consent, we will ask for it again.