Data Privacy Statement
Contents
1. Definitions
2. General Information
a. Objective and Responsibility
b. Legal Bases
c. Data Subject Rights
d. Data Erasure and Duration of Storage
e. Security of Processing
f. Transfer of Data to Third Parties, Subcontractors and Third Party Providers
3. Concrete Data Processing
a. Collection of Information on the Use of the Online Service
b. Contact Form and Contacting via E-Mail
c. Tag Manager
d. Google Analytics
e. Consent Management
f. Google Fonts
g. Links to Other Websites
4. Cookie-Policy
a. General Information
b. Objection Options
c. Cookie Overview
5. Changes to the Data Privacy Policy
6. Contact Details
1. Definitions
Data subject: any identified or identifiable natural person to whom the personal data processed relate.
Personal Data: any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Processing of Personal Data: an operation or set of operations which is performed upon Personal Data or set of Personal Data, whether or not by automatic means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure or destruction of data.
2. General Information
a. Objective and Responsibility
1. This Data Privacy Statement is to inform you about the nature, scope and purpose of the processing of personal data related to our online service and the related websites, features and contents (hereinafter collectively referred to as "online service" or "website").
2. The online service is provided by the Central and Eastern European Travel Association aisbl. (c/o Penta, 41 Rue de la Science, 1040 Brussels, Belgium) – hereinafter referred to as "provider", "we" or "us" – who is also legally responsible under the data protection law.
3. Our online service is hosted by Blacknight Internet Solutions Ltd. (Unit 12A, Barrowside Business Park, Sleaty Road, Graiguecullen, Carlow, Ireland). Server location is Ireland.
4. The term "user" encompasses all customers, interested people, employees and visitors of our online service.
b. Legal Bases
We collect and process personal data based on the following legal grounds:
1. Consent in accordance with Article 6 paragraph 1 (a) and Article 7 General Data Protection Regulation (GDPR). Consent meaning any freely given, specific, informed and unambiguous indication of agreement, which could be in the form of a statement or any other unambiguous confirmatory act, given by the data’s subject consenting to the processing of personal data relating to him or her.
2. Necessity for the performance of a contract or in order to take steps prior to entering into a contract according to Article 6 paragraph 1 (b) GDPR, meaning the data is required in order for us to fulfil our contractual obligations towards you or to prepare the conclusion of a contract with you.
3. Processing to fulfil a legal obligation in accordance with Article 6 paragraph 1 (c) GDPR, meaning that e.g. the processing of data is required by law or other provisions.
4. Processing in order to protect legitimate interests in accordance with Article 6 paragraph 1 (f) GDPR, meaning that the processing is necessary to protect legitimate interests pursued by us or by a third party, unless such interests are overridden by your interests or fundamental rights and freedoms which require the protection of personal data.
c. Data Subject Rights
You have the following rights with regards to the processing of your data through us:
1. The right to lodge a complaint with a supervisory authority in accordance with Article 13 paragraph 2 (d) GDPR and Article 14 paragraph 2 (e) GDPR.
2. Right of access in accordance with Article 15 GDPR
3. Right to rectification in accordance with Article 16 GDPR
4. Right to erasure („right to be forgotten“) in accordance with Article 17 GDPR
5. Right to restriction of processing in accordance with Article 18 GDPR
6. Right to data portability in accordance with Article 20 GDPR
7. Right to objection in accordance with Article 21 GDPR
Notice: Users may object to the processing of their personal data in accordance with legal allowances at any time with effect for the future. The objection may in particular be made against processing for the purposes of direct marketing.
Without prejudice to any other administrative or judicial remedy, you shall have the right to complain to a supervisory authority, in particular in the Member State of your place of residence, employment or the place of the alleged infringement, if you believe that the processing of your personal data violates the GDPR.
If you wish to make use of any of the above-mentioned rights, you can send us your dated, written or electronic request either by e-mail to secretariat@ceetra.org or by post to the provider. We will inform you within thirty days of your request at the latest. However, you should bear in mind that the above-mentioned rights are not absolute: there may be grounds on which we will not be obliged to respond to your request, or as a result of which we will only partially comply with your request. If necessary, we will inform you within thirty days of receipt of your request. To ensure that the request has been made by you, we may also ask you to send us a copy of your proof of identity. In this copy, please make your passport photo and national registry number black. Each request will be dealt with free of charge, unless the requests are manifestly unfounded or excessive, in particular because of their repetitive nature. In the event that requests prove to be manifestly unfounded or excessive, either a reasonable fee will be charged in view of the administrative costs involved in providing the requested information or communication and taking the requested measures, or the request will be refused. We will inform you of this at the latest within thirty days of your request.
d. Data Erasure and Duration of Storage
The personal data of the data subject will be erased or blocked as soon as the purpose of the storage is inapplicable. Storage of data beyond that may occur if such storage is required by the European or national legislator in EU regulations, laws or other regulations to which the controller is subject. Blocking or erasure of data also takes place when a retention period mandated by the standards mentioned expires, unless the continued storage of data is required for the conclusion of a contract or the fulfilment of contractual obligations.
e. Security of Processing
1. We have implemented appropriate and state-of-the-art technical and organisational security measures (TOMs). Thus, the data that is processed by us is protected against accidental or intentional manipulation, loss, destruction and unauthorised access.
2. These security measures include in particular the encrypted transfer of data between your browser and our server.
f. Transfer of Data to Third Parties, Subcontractors and Third Party Providers
1. A transfer of personal data to third parties only occurs within the framework of legal requirements. We only disclose personal data of users to third parties, if this is required e.g. for billing purposes or other purposes, if the disclosure is necessary to ensure the fulfilment of contractual obligations towards the users.
2. If we engage subcontractors for our online service, we have made appropriate contractual arrangements as well as adequate technical and organisational measures with these companies.
3. If we use content, tools or other means from other companies (hereinafter collectively referred to as "third party providers") whose registered offices are located in a third country, it is assumed that a transfer of data to the home countries of these third party providers occurs. The transfer of personal data to third countries takes place exclusively only, if an adequate level of data protection, the user’s consent or another legal permission is present.
3. Concrete Data Processing
a. Collection of Information on the Use of the Online Service
1. When using our online-service, information may be transferred automatically from the browser of the user to us; this information includes the name of the accessed website, file, date and time of the access, amount of data transferred, notification about successful access, browser type and version, the user's operating system, referrer URL (the previously visited page), IP address and the requesting provider.
2. The processing of this information takes place based on legitimate interests in accordance with Article 6 paragraph 1 (f) GDPR (e.g. to optimise the online service) as well as to ensure the security of processing in accordance with Article 5 paragraph 1 (f) GDPR (e.g. for the defence and clarification purposes of cyberattacks).
3. This information will be automatically deleted 4 weeks after the termination of the connection, unless any other retention periods require otherwise.
4. The collection of the data and the storage of the data in log files is essential for the provision of the online service. Therefore, users are not entitled to the options of erasure, objection or correction.
b. Contact Form and Contacting via E-Mail
1. When contacting us (via online form or e-mail), the data provided by the user will be processed exclusively for processing the inquiry and its handling.
2. Any other use of the data will only take place based on the given consent from the user.
c. Tag Manager
1. We use the Google Tag Manager on our website. The Google Tag Manager is a service of Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
2. Through the Google Tag Manager, we can integrate various codes and services on our website in an orderly and simplified manner. The Google Tag Manager implements the tags or "triggers" the embedded tags. When a tag is triggered, Google may process information (including personal data) and process it. In doing so, it cannot be ruled out that Google also transmits the information to a server in a third country.
3. In particular, the following personal data is processed by the Google Tag Manager:
• Online identifiers (including cookie identifiers)
• IP address
4. In addition, you can find more detailed information about the Google Tag Manager on the websites https://marketingplatform.google.com/about/analytics/tag-manager/use-pol... as well as at https://www.google.com/intl/en/policies/privacy/index.html (section "Data we receive based on your use of our services").
5. Furthermore, we have concluded an order processing contract with Google for the use of the Google Tag Manager (Article 28 GDPR). Google processes the data on our behalf in order to trigger the stored tags and display the services on our website. Google may transfer this information to third parties if required by law or if third parties process this data on behalf of Google.
6. If you have deactivated individual tracking services (e.g. by setting an opt-out cookie), the deactivation remains for all affected tracking tags that are integrated by the Google Tag Manager.
7. By integrating the Google Tag Manager, we pursue the purpose of being able to carry out a simplified and clear integration of various services. In addition, the integration of the Google Tag Manager optimises the loading times of the various services.
8. The legal basis for the processing of personal data described here as part of the measurement process is consent expressly granted by you in accordance with Article 6 paragraph 1 (a) GDPR.
9. The legal basis for the processing of those data that are processed in the context of obtaining consent is our legitimate interest pursuant to Article 6 paragraph 1 (f) GDPR. We have a legitimate interest in being able to prove that you have given your consent to the measurement procedure (Article 7 paragraph 1 GDPR).
d. Google Analytics
1. We use Google Analytics, a web analytics service, on the basis of your consent for the analysis, optimisation and economic operation of our online offer pursuant to Article 6 paragraph 1 (a) GDPR Google Analytics, a web analytics service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) – hereinafter "Google"). Google uses cookies and other technologies. The information generated by the service about the use of the online offer by the users is transmitted to a Google server in the USA and processed there.
2. Google acts on our behalf within the framework of order processing pursuant to Article 28 GDPR. We have concluded a data protection agreement with Google, which contains the EU standard model clauses.
3. In addition, we have concluded a shared responsibility agreement pursuant to Article 26 GDPR with Google for the use of Google's measurement services (see https://support.google.com/analytics/answer/9012600?hl=en). Within this framework, we have agreed with Google to be responsible for the fulfilment of information obligations and for ensuring data subject rights in accordance with Chapter 3 of the GDPR, as well as for the security of processing and reporting/notification obligations. (Articles 32 to 34 of the GDPR). Google will use the information to evaluate the use of our online offer by the users, to compile reports on the activities within this online offer and to provide us with further services related to the use of this online offer and internet use. In doing so, pseudonymous usage profiles of the users can be created from the processed data.
4. We use Google Analytics to display the ads placed within advertising services of Google and its partners only to users who have also shown an interest in our online offer or who have certain characteristics (e.g. interests in certain topics or products determined on the basis of the websites visited), which we transmit to Google (so-called "remarketing audiences", or "Google Analytics audiences"). With the help of remarketing audiences, we also want to ensure that our ads correspond to the potential interest of users and do not have a harassing effect.
5. We use Google Analytics with IP anonymisation enabled.
6. Google Analytics stores cookies in your web browser for a period of two years since your last visit. These cookies contain a randomly generated user ID that can be used to recognise you during future website visits. Users can prevent the storage of cookies by setting their browser software accordingly; users can also prevent the collection of data generated by the cookie and related to their use of the online offer to Google, as well as the processing of this data by Google, by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=en.
7. The recorded data is stored together with the randomly generated user ID, which enables the evaluation of pseudonymous user profiles. This user-related data is automatically deleted after 14 months. Other data remains stored in aggregated form indefinitely.
8. Further information on data use by Google, setting and revocation options can be found on Google's websites:
- https://policies.google.com/technologies/partner-sites?hl=en
(„Data use by Google when you use websites or apps of our partners“)
- https://policies.google.com/technologies/ads?hl=en-US
(„Data use for advertising purposes“)
- https://adssettings.google.com/authenticated
(„Manage information Google uses to serve ads to you“).
e. Consent Management
1. This website uses the cookie consent technology of the drupal module "EU Cookie Compliance (GDPR Compliance)" to obtain your consent to store certain cookies on your terminal device and to document this in accordance with data protection law. The provider of this technology is the Drupal Association (https://www.drupal.org/project/eu_cookie_compliance) – hereafter “EU Cookie Compliance”.
2. When you enter our website, the following personal data is transferred to EU Cookie Compliance:
• Your consent(s) or withdrawal of your consent(s)
• Your IP address
• Information about your browser
• Information about your terminal device
• Time of your visit to the website
3. Furthermore, EU Cookie Compliance stores a cookie in your browser in order to be able to assign the consent(s) granted to you or their revocation. The data collected in this way will be stored until you request us to delete it, delete the EU Cookie Compliance cookie yourself or the purpose for storing the data no longer applies. Mandatory legal storage obligations remain unaffected.
4. The use of EU Cookie Compliance takes place in order to obtain the legally required consent for the use of cookies. The legal basis for this is Article 6 paragraph 1 p. 1 (c) GDPR.
f. Google Fonts
1. In order to make the visit to our website attractive, we use fonts from Google (Google Inc., 1600 Amphitheatre Parkway Mountain View, CA 94043, USA), the so-called Google Fonts.
2. We have integrated the Google Fonts locally, i.e. on our web server. This means that there is no connection to Google servers and therefore no transmission of your data to Google.
g. Links to Other Websites
1. While using some of our services, you will be automatically redirected to other websites.
2. Please note that this privacy policy does not apply there. The privacy policy of the linked website may differ significantly from this one.
3. If we offer you links to websites that are not offered or managed by the provider, these links are provided for your information and convenience only. We advise you to carefully read the privacy policy of the other websites when accessing these websites. The provider cannot be held liable in any way for the policies or practices of the owner or operator of such third party websites.
4. Cookie-Policy
a. General Information
1. Cookies are information transmitted by our web server or third-party web servers to the users' web browsers where they are stored for later retrieval. Cookies can be in the form of small files or any other types of information storage.
2. In the case that users do not want that cookies are stored on their computer, they will be asked to disable the corresponding option in their browser's system settings. Saved cookies may be deleted in the system settings of the browser. The exclusion of cookies can lead to functional impairments of this online service.
b. Objection Options
After giving your consent, you can object to the use of cookies that are used for range measurement and advertising purposes at any time via this button:
c. Cookie Overview
Name: _ga
Domain: ceetra.org
Provider: Google
Purpose: Registers a unique ID that is used to generate statistical data on how the visitor uses the website.
Duration: 1 year
Name: _ga_#
Domain: ceetra.org
Provider: Google
Purpose: Used by Google Analytics to limit the request rate.
Duration: 1 year
Name: SESS#
Domain: ceetra.org
Provider: CEETRA
Purpose: Session related cookie.
Duration: Browser session
Name: cookie-agreed
Domain: ceetra.org
Provider: CEETRA
Purpose: Used by CEETRA to determine whether the user has accepted cookies or not.
Duration: 1 month
Name: cookie-agreed-version
Domain: ceetra.org
Provider: CEETRA
Purpose: Used by CEETRA to determine the version of the cookie code.
Duration: 1 month
Name: has_js
Domain: ceetra.org
Provider: CEETRA
Purpose: Used by CEETRA to determine whether the user has activated javascript or not.
Duration: Browser session
5. Changes to the Data Privacy Policy
a. We reserve the right to change this Data Privacy Policy with regards to the data processing, in order to adapt it to changed legal situations, to changes of the online service or of the data processing.
b. If users' consents are required or if elements of the Data Privacy Policy contain provisions in regards to the contractual relationship with the users, the changes will only be made with the consent of the users.
c. Users are requested to keep themselves informed about the content of this Data Privacy Policy on a regular basis.
6. Contact details
If you have further questions or comments about the processing of your personal data as described in this policy, you can always contact us:
Central and Eastern European Travel Association aisbl.
c/o Penta, 41 Rue de la Science, 1040 Brussels, Belgium
secretariat@ceetra.org
Version: August 2024