Privacy Policy
Privacy Policy - Salzburg Sightseeing Tours
1. Privacy notices
Version: June 2026
Your privacy is important to us. This notice explains how Salzburg Sightseeing collects and uses your data. Our aim is to provide you with the best possible booking experience.
2. Controller
SALZBURG SIGHTSEEING TOURS - Salzburg Sightseeing Tours Salzkraft GmbH
Mirabellplatz 2, 5020 Salzburg, Austria
Phone: +43 662 88 16 16
Website: www.salzburgsightseeing.at
Email: info@salzburgsightseeing.at
Further information about our company can be found in the legal notice on our website.
No data protection officer has been appointed, as this is not required by law.
3. General information on data processing - data minimisation
3.1 General information
In this Privacy Policy, we inform you about the most important aspects of data processing in the course of our activities as a provider of city tours and tours in and around Salzburg, namely:
- the organisation of tour programmes;
- our HOP ON HOP OFF service;
- client and supplier management;
- public relations and marketing for our own purposes;
- image processing at events;
- website functionalities;
- our newsletter; and
- customer surveys.
3.2 Data minimisation
We collect and process only those personal data that are necessary to fulfil our contractual, statutory and service-related obligations. In accordance with Article 5(1)(c) GDPR, we comply with the principle of data minimisation. This means that:
- only data that are strictly necessary for the respective purpose are collected;
- data that are no longer needed are deleted or anonymised without delay, subject to statutory retention periods;
- additional data are collected only with express consent, where this is required.
By regularly reviewing the data stored, we ensure that the scope of processing remains appropriate and complies with statutory requirements.
3.3 Storage periods
We store personal data only for as long as this is required for the respective processing purpose or prescribed by law. Specific periods:
- Booking and contract data: 7 years (tax and corporate law retention obligations).
- Payment information: until the end of the following year after completion of the transaction, unless longer statutory obligations apply.
- Contact form enquiries: 1 year after processing.
- Newsletter data: 3 years after the last active contact.
4. Purposes of processing operations
4.1 Processing operations
We carry out the following processing operations, which may be relevant to you as a customer, affiliate partner, client, natural person acting as contact person for clients and affiliates, supplier and contractor, marketing contact, newsletter subscriber or website visitor:
- tour management and handling;
- supplier and client management for the handling of our sales, purchasing and back office;
- contact forms on the website for responding to enquiries;
- call centre;
- contact database from public sources or business cards;
- public relations to present our activities;
- marketing, including customer surveys, to inform customers and interested persons and to acquire customers, with your consent;
- information about products and events by electronic mail to existing contacts on the basis of our legitimate interest in providing such information about our offers;
- newsletters for maintaining and informing existing B2B contacts on the basis of our legitimate interest in information about our offers;
- publication of your posts in our blog or review area.
4.2 Legal bases by process
- Performance of a contract (Article 6(1)(b) GDPR): tour bookings, customer management, back office.
- Consent (Article 6(1)(a) GDPR): newsletters, marketing tracking in the blog.
- Legitimate interest (Article 6(1)(f) GDPR): direct advertising to existing customers, internal data analysis, fraud prevention.
- Compliance with legal obligations (Article 6(1)(c) GDPR): tax retention, information to authorities.
4.3 Bookings and services on the website
In order to provide you with better service, we collect information from you. This information may enable us to identify you directly or indirectly. In some cases, we need personal data in order to enable you to use certain services on our website. For example, when you make a booking on our website, we request personal data such as first and last name, email address, billing address and hotel names, as well as payment information such as credit card number, expiry date and security code. We use this information for billing and the transaction. If there are problems processing the order, we use this information to contact you. We also use the information to ensure successful performance of the service.
4.4 Contract processing and retention
As controller, we process the data disclosed by you in the course of concluding a contract for the duration of the contractual relationship for the performance of the contract or steps prior to entering into a contract, for example in the case of enquiries about our products or services (Article 6(1)(b) GDPR). In addition, we process these data for as long as tax and fiscal law provisions require this (Article 6(1)(c) GDPR). The fiscal retention obligations amount to 7 years (§ 132(1) BAO and § 11(2), third subparagraph, UStG). In addition, processing operations may also be based on our legitimate interest or the legitimate interest of a third party (Article 6(1)(f) GDPR), unless such processing is covered by one of the aforementioned legal bases. According to the view of the European legislator, a legitimate interest may in particular be assumed where the data subject is a customer of the controller, for example for direct marketing purposes.
5. Categories of recipients
5.1 Recipients
In the context of the processing operations, we transmit data to the following categories of recipients, where the recipients act on our behalf or the transfer is necessary to fulfil contractual or statutory obligations:
- business partners and third parties involved, or intended to be involved, in business processing, such as tax advisers, auditors, liability and legal expenses insurers, other insurance companies, notaries, translators and attorneys-at-law;
- banks, credit card companies and payment service providers (PayPal, Adyen, VISA, Mastercard, Maestro, Google Pay, Apple Pay, Alipay, JCB, EPS, SEPA, Union Pay, Discover, DinersClub, WeChat Pay) and further payment service providers with whom we have concluded processor agreements for payment processing;
- processors in the area of IT and communication services (Palisis AG, software support, marketing service providers, persons supporting our network and the servers and clients, email service providers and telephone service providers, CleverReach GmbH & Co KG as newsletter provider);
- authorities, where applicable, upon their request.
5.2 Disclosure obligations
In certain situations, we are legally obliged to disclose your data. This may occur on the basis of lawful requests from authorities, for example for national security or law enforcement purposes, or to protect the rights, property or safety of Salzburg Sightseeing or others. This includes, in particular, customer fraud and misuse of the system. We may also transmit customer data to third parties such as credit card institutions for the purpose of resolving disputes.
5.3 Third countries
It is not intended to transfer data to international organisations or recipients in third countries. Where a transfer to recipients in third countries should be necessary, this will be carried out on the basis of appropriate safeguards, such as standard contractual clauses, or on the basis of an adequacy decision.
6. Public forums
On our website, we offer a publicly accessible blog and reviews. Please note that all information you publish in these areas may be read, stored and further used by third parties. By submitting a post, you declare that you agree to its publication (Article 6(1)(a) GDPR).
For the technical provision, moderation and security of the forums, we rely on our legitimate interest in a functional and secure offer (Article 6(1)(f) GDPR). Posts are reviewed on working days; manifestly unlawful content is removed without delay.
Notice regarding third-party content: On our blog, we occasionally publish posts that are provided in whole or in part by external partners. The respective partners are responsible for ensuring that they have the necessary legal bases, such as consents, for the transfer and publication of the content. Such posts are published with clear source or author attribution.
Deletion and moderation requests: If you wish personal data in a post to be removed, please contact info@salzburgsightseeing.at and indicate the specific post (URL and, if possible, screenshot) as well as the reason for the deletion request. We review deletion requests and generally respond within one month; in complex cases, this period may be extended by up to two months in accordance with Article 12(3) GDPR. If deletion cannot be carried out, for example due to statutory retention obligations, protection of legitimate interests of third parties or other legal reasons, we will inform you of the reasons for refusal.
Please note that removal from our website does not necessarily result in the deletion of copies or distributions by third parties, such as reposts, search engine caches or social media shares.
If you wish to publish personal data of third parties, please ensure that you have the required consents or other legal bases. Posts containing sensitive personal data will generally not be published by us or will be removed without delay.
7. How your data are protected
We implement technical and organisational measures pursuant to Article 32 GDPR to ensure the confidentiality, integrity and availability of your personal data. These include, in particular, transport encryption, such as TLS, encryption of sensitive data at rest, role-based access concepts and individual user rights, multi-factor authentication for administrative access, logging and monitoring of security-relevant access, regular backups and recovery plans, timely security updates and regular penetration tests. We also conduct mandatory awareness and training measures for our employees.
We conclude binding processor agreements with all service providers used (Article 28 GDPR) and regularly review their security standards. This brief description is provided in line with the transparency requirement (Article 12 GDPR; Recital 60). Further technical details are provided upon request where a legitimate interest is demonstrated.
If you transmit personal data to us, we encrypt the relevant forms. Please note, however, that no method of data transmission over the internet is 100% secure. We implement all economically reasonable technical and organisational measures but cannot guarantee absolute security.
8. Opt-out options
We offer you the possibility to object to the use of your personal data for certain purposes. You cannot unsubscribe from transaction-related emails. You also have the option of disabling push notifications in the device settings. You may also disable location-based services there.
9. Newsletter
9.1 Newsletter subscription
Our newsletter can only be received by the data subject if the data subject has a functioning email address and registers for newsletter delivery. For legal reasons, a confirmation email is sent in the double opt-in procedure to the email address first entered by the data subject for newsletter delivery. This confirmation email serves to verify whether the owner of the email address, as data subject, has authorised receipt of the newsletter.
9.2 Newsletter delivery
When sending our newsletter, we process personal data in the following categories: email address, data for creating usage statistics, data on the use of the website, the logging of clicks on individual elements of the newsletter, and contact data such as name or email address. The purpose of processing is the electronic delivery of direct advertising, optimisation of content and analysis of usage behaviour.
9.3 Newsletter analysis (tracking)
Our newsletters contain so-called tracking pixels. This is a small graphic embedded in the newsletter that enables us to record and analyse log files. These data help us statistically evaluate the success or failure of our online marketing campaigns. Using the tracking pixel, we can determine whether and when a newsletter was opened and which links within the newsletter were clicked. The personal data collected in this way are stored and analysed by us in order to optimise newsletter delivery and better tailor its content to the interests of recipients.
9.4 Legal basis for processing
The legal basis is your consent (Article 6(1)(a) GDPR in conjunction with § 174(4) TKG 2021). You may withdraw your consent at any time within the statutory limits with effect for the future. A corresponding unsubscribe link for withdrawal of consent is included in every newsletter. It is also possible to unsubscribe from newsletter delivery directly on the website of the controller at any time or to notify the controller in another way, for example by email to info@salzburgsightseeing.at.
9.5 Provision of data
You are not obliged to provide the data. If you do not provide the data, we cannot send you information.
9.6 Processor
Data are transferred to the processor CleverReach GmbH & Co. KG, Schafjückenweg 2, 26180 Rastede, Germany. We use CleverReach as newsletter provider. The privacy policy and information about the company can be found at www.cleverreach.com/de-de/datenschutz/. We have concluded a processor agreement with CleverReach (Article 28 GDPR).
9.7 Storage period
We store the data provided to us when subscribing to the newsletter for a period of 3 years after the last contact.
9.8 B2B newsletter
Existing B2B customers are regularly sent newsletters within the scope of § 174(4) TKG 2021 for purposes of existing customer advertising and existing customer information on the basis of our legitimate interest in informing them about our offers.
10. Your rights as data subject
10.1 No profiling
We do not create profiles of data subjects or other persons and do not carry out profiling. There is no automated decision-making in the course of our activities.
10.2 Data subject rights
As a data subject, you generally have the right of access, rectification, erasure, restriction and data portability, in each case within the statutory limits. We point out at this stage that these rights may be restricted where providing access would endanger a trade or business secret of the controller or of third parties (§ 4(6) DSG).
10.3 Withdrawal
If you have given us consent to process your data, you have the right to withdraw this consent at any time with effect for the future. The lawfulness of processing up to the withdrawal remains unaffected. After withdrawal, the data will no longer be used for the purpose to which you consented.
10.4 Objection
Where processing is based on a legitimate interest, you have the right to object to it. If you object to processing for direct marketing purposes, the personal data will no longer be processed for those purposes. If we process data for other purposes on the basis of legitimate interests, we will no longer process the personal data unless we have compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
10.5 Exercising your rights
To exercise your rights, please contact us, preferably by email to info@salzburgsightseeing.at, by phone at +43 662 88 16 16 or by post to Mirabellplatz 2, A-5020 Salzburg. It would be helpful if you provide the information required to clearly identify your person when making a request.
10.6 Complaint
If you believe that the processing of your personal data violates data protection law or that your data protection rights have otherwise been infringed, you are free to lodge a complaint with the Austrian Data Protection Authority. The website of the Data Protection Authority can be found at www.dsb.gv.at.
11. Contact us
If you have questions or concerns regarding your privacy or security on our website, please contact us at info@salzburgsightseeing.at.