Data controller
The operator of minis2028.de is the data controller for personal data processing on this website. Contact details are available in the legal notice and site legal pages.
Legal
This Privacy Policy explains how minis2028.de processes personal data when you use the website or submit a group request through our contact forms.
Last updated: May 30, 2026
The operator of minis2028.de is the data controller for personal data processing on this website. Contact details are available in the legal notice and site legal pages.
We process only the data necessary to handle group requests, provide communication, and maintain secure website operations.
Depending on the context, processing is based on Art. 6(1)(b) GDPR (pre-contractual steps), Art. 6(1)(c) GDPR (legal obligations), Art. 6(1)(f) GDPR (legitimate interests), or Art. 6(1)(a) GDPR (consent).
We apply technical and organizational measures to protect data against unauthorized access, loss, or misuse.
| Data category | Source | Purpose | Legal basis | Retention period |
|---|---|---|---|---|
| Contact data (name, email, phone, organization) | Directly provided via contact/group forms | Inquiry handling, proposal preparation, follow-up communication | Art. 6(1)(b) GDPR | Until inquiry completion and as required by law |
| Request data (dates, group size, services, notes) | Directly provided via forms | Planning, operational coordination, service delivery | Art. 6(1)(b) GDPR | Only as long as needed for processing and accountability |
| Technical data (IP address, anti-abuse and security signals) | Automatically collected during website access | Secure operation, stability, spam/attack protection | Art. 6(1)(f) GDPR | Short-term, depending on technical necessity |
| Cookie consent status | Cookie consent banner | Store and prove your consent choice | Art. 6(1)(c) and Art. 6(1)(f) GDPR | Up to 12 months |
Data is shared with service providers only when necessary to operate the website or handle your request (e.g., hosting, email infrastructure, technical operations). Data processing agreements under Art. 28 GDPR are in place where required.
If technical providers outside the EU/EEA are involved, transfers are performed in compliance with GDPR requirements, including appropriate safeguards such as EU Standard Contractual Clauses where applicable.
You may request access, rectification, erasure, restriction, portability, and objection to certain processing. You may withdraw consent at any time for future processing, and you may lodge a complaint with a supervisory authority.
For questions about personal data processing or to exercise your rights, please use the contact details provided in the legal notice or contact page.