Privacy policy
myTuur publishes this document in German and English. What follows is the English text.
Last updated: 4 August 2026
This policy describes what personal data we process when you visit this website — mytuur.com and all its pages. The myTuur app has its own privacy policy (section 9). What you read here applies to your visit to the website; what you read there applies to the app.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
myTuur GmbH
Münchner Straße 15
89073 Ulm
Germany
Phone: +49 7315504111-0
E-mail: info@mytuur.com
Managing directors: Christian Thoma, Arton Ritter-Kodra, Jürgen Mayer. Commercial register: Local Court (Amtsgericht) of Ulm, HRB 748325.
For data protection matters please write to info@mytuur.com, call +49 7315504111-0, or post to myTuur GmbH, Münchner Straße 15, 89073 Ulm, Germany.
2. How we handle data
This website is deliberately built to need as little data as possible. When you merely visit it:
- We set no cookies; the single cookie this website knows is written only when you pick a language yourself (section 6).
- We use no analytics or audience measurement, no statistics tools, no tracking pixels.
- We use no advertising or tracking technology, no retargeting, no profiling.
- We embed no third-party content that your browser would have to fetch (section 5).
- We ask for no registration; the website has no user accounts.
- There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR.
That leaves exactly one processing operation that cannot be avoided technically: our server delivering the pages to you (section 3). It happens because you asked for a page, not because it suits us — which is why it rests on performance of your request rather than on any legitimate interest of ours. Everything else happens only because you set it in motion — by choosing a presentation or a language (section 6) or by signing up for the newsletter (section 7).
If any of that ever changes, we change this policy first — and, where the law requires it, obtain your consent before the processing starts.
3. Serving the website, hosting and server log files
The pages of this website are rendered on the server and delivered to your browser. The website is hosted on an Amazon Web Services (AWS) EC2 server instance in the eu-central-1 region. The servers of that region stand in Frankfurt am Main, Germany — and therefore in the European Union. Nothing sits in front of that server: no content delivery network, no external proxy. Your request reaches it directly.
Delivering the page you asked for. For a page to reach you, your browser has to ask us for it, and that request carries the details we build the response from and send it back with. Without them there is no response and no page. This is not a balancing act on our side; it is the condition of your request being answered at all:
| Data | Purpose | Legal basis |
|---|---|---|
| your device's IP address | delivering the response to you — without a return address there is no way back | Art. 6(1)(b) GDPR |
| the address (URL) requested | selecting and rendering the very page you called up | Art. 6(1)(b) GDPR |
| browser and operating system identifier (user agent) | serving a version your browser can display | Art. 6(1)(b) GDPR |
the language you picked, if you have picked one (the mytuur-language cookie, section 6) | sending you to the language edition you chose when you call up an address that carries no language | Art. 6(1)(b) GDPR |
your browser's language header (Accept-Language), where it sends one | choosing the language edition when you call up an address that carries no language and have picked none | Art. 6(1)(b) GDPR |
| technical data of the transfer: time, HTTP method, status code, volume of data transferred | opening, carrying out and completing the transfer | Art. 6(1)(b) GDPR |
The legal basis is Art. 6(1)(b) GDPR: you request a page, we deliver it, and processing these details is necessary to perform exactly that. We expressly do not rest delivery on a legitimate interest — it happens on your request, and without this data it would be technically impossible.
Log files: security and fault-finding. The web server additionally writes connection data to log files. That is a separate processing operation with a purpose of its own — no longer delivery, but spotting attacks, abuse and faults — and so it has a legal basis of its own:
| Data | Purpose | Legal basis |
|---|---|---|
| IP address of the requesting device | detecting and repelling attacks and abuse | Art. 6(1)(f) GDPR |
| date and time of the request | troubleshooting, tracing incidents | Art. 6(1)(f) GDPR |
| the address (URL) requested and the volume of data transferred | spotting overload and abuse patterns, capacity planning | Art. 6(1)(f) GDPR |
| HTTP status code | detecting failed responses | Art. 6(1)(f) GDPR |
| referrer address, where your browser sends one | troubleshooting | Art. 6(1)(f) GDPR |
| browser and operating system identifier (user agent) | spotting automated access | Art. 6(1)(f) GDPR |
Our legitimate interest is a website that works, stays available and is protected against attack: without logs, attacks could be neither detected nor repelled, and faults could not be traced. We do not combine these log entries with any other data and we do not use them to identify or recognise visitors.
Retention: the web server rotates its log files daily, and they are deleted after 14 days at the latest. We keep individual entries longer only where a specific incident — an attack on our systems, for instance — requires it; the entries concerned are then restricted until the matter is closed and deleted afterwards.
Content from our own system: the page content about cities, places and tours is fetched by our server from our own content interface. Your browser does not make that request, and neither your IP address nor your browser identifier is passed on with it.
4. Encrypted transmission
This website is served over HTTPS. The connection between your browser and our server is encrypted and integrity-protected with TLS. Requests that reach us over HTTP are answered with a redirect to HTTPS.
5. Fonts, images and embedded content
To display this website, your browser loads nothing from other people's servers:
- Fonts: this website's font files sit on our own server and are loaded from there. There is no connection to Google Fonts or any other font service; no font provider learns that you are here.
- Images, icons and scripts are held on our server. That includes the Apple and Google download buttons: we host the official artwork ourselves.
- No map, video, font or social media widgets are embedded. The pages therefore also contain no third-party content delivery network embed that your browser would have to fetch. Nothing sits in front of our server on the delivery path either — no content delivery network and no external proxy (section 3).
Links are a different matter. If you follow a link to the Apple or Google app stores, to our support area, to our offering for tourism partners, to our social media channels or to the newsletter form, you leave this website. From that moment the privacy policy of the service you have gone to applies, and your data — your IP address at the very least — is processed there. We have no influence over that processing.
6. Storage on your device — this is also our cookie statement
This website sets a single cookie, and only if you ask it to. There is none for statistics, none for advertising, none belonging to anyone else, and none that recognises you or follows you to another site. The one cookie holds the language edition you picked yourself. Because it does nothing but give you what you picked, you still see no consent banner here: there is nothing for you to consent to.
Two items are stored on your device, and each of them only if you bring it about yourself:
| Data | Storage | Content | Purpose | Legal basis | Duration |
|---|---|---|---|---|---|
the presentation you chose (mytuur-theme) | your browser's localStorage | light or dark | remembers the light or dark presentation you chose | Section 25(2) no. 2 TDDDG (strictly necessary, no consent required) | until you reset it or clear your browser data |
the language you chose (mytuur-language) | a cookie set by this website | the code of the language edition, en for example | remembers the language you chose, so you need not pick it again on every visit | Section 25(2) no. 2 TDDDG (strictly necessary, no consent required); for our reading of the value, Art. 6(1)(b) GDPR | one year from your last choice, or until you clear your browser data |
Neither entry comes about by visiting: the presentation entry appears when you switch the presentation yourself, the language cookie when you pick a language from the selector at the foot of the page. Neither holds an identifier, a number or anything that points to you — just the word light or dark, and a language code such as en.
Where they differ is who gets to see them. The presentation entry stays on your device and is never transmitted to us or to anyone else; our server does not learn what you chose. The language cookie is sent back to us by your browser with every request to this website, because that is the only way our server can know your choice before it answers. We read it in exactly one situation: when you call up an address that carries no language — the site's root address, or the inherited addresses of the legal pages — so that we can send you to the edition you picked instead of guessing from your browser's language header (section 3). We store it nowhere on our side, we combine it with nothing, and we use it for nothing else.
Because this storage serves solely to give you the presentation and the language edition you expressly asked for, it is strictly necessary within the meaning of Section 25(2) no. 2 TDDDG (the German Telecommunications Digital Services Data Protection Act) and requires no consent. Our reading of the language cookie is part of delivering the page you called up and rests on the same basis as the rest of that delivery: Art. 6(1)(b) GDPR (section 3).
Language and address: which language edition you are reading is always part of the page address as well (/en/, for example). The cookie never overrides that — open a link to /de/ and you get the German edition, whatever you once picked — it only spares you choosing again at an address that carries no language. Delete it and the website works exactly as it did before.
Removing them: set the presentation back to "system" and that entry is gone; pick another language and the cookie is replaced by your new one; clearing this site's data in your browser removes both, and the site then behaves as it did on your first visit.
Should we ever wish to use cookies or comparable technologies that go beyond what is strictly necessary, we will change this policy first and obtain your consent under Section 25(1) TDDDG and Art. 6(1)(a) GDPR.
7. Newsletter
In the footer of the website we link to the signup for our newsletter. The signup form is not served by this website but by our newsletter provider, Brevo, at their own address. Brevo is the trading name of Sendinblue SAS, 17 rue Salneuve, 75017 Paris, France, registered in the Paris Trade and Companies Register under number 498 019 298. Following that link takes you off this website; the form and the technical data it generates then sit with the provider.
What the newsletter processes, why, and on what basis:
| Data | Purpose | Legal basis |
|---|---|---|
| the e-mail address you enter | sending you the newsletter you asked for | Art. 6(1)(a) GDPR |
| any further details you provide voluntarily | addressing you personally in the newsletter | Art. 6(1)(a) GDPR |
| time and IP address of the signup and its confirmation | evidence that the signup really came from you | Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR |
- Roles: we are the controller for the newsletter itself. What Brevo does with the data beyond that is set out in the provider's own privacy information, linked below.
- Consent and confirmation: the basis for sending is your consent under Art. 6(1)(a) GDPR. Signups are confirmed by double opt-in; nothing reaches your inbox before that.
- Withdrawal: you can withdraw your consent at any time with effect for the future — through the unsubscribe link in every newsletter e-mail, or simply by writing to us. The lawfulness of processing up to that point is unaffected.
- Retention: until you withdraw; we then remove your address from the distribution list. We keep the record of your consent for as long as we need it to meet our accountability obligation under Art. 5(2) GDPR.
- The provider's own information: Brevo's privacy policy at https://www.brevo.com/legal/privacypolicy/
8. Your rights
You have the following rights in relation to us. An informal message to info@mytuur.com, or a letter to myTuur GmbH, Münchner Straße 15, 89073 Ulm, Germany, is enough to exercise any of them.
- Access (Art. 15 GDPR) — whether and what data we process about you, for what purposes, for how long, and to whom we disclose it, if anyone.
- Rectification (Art. 16 GDPR) — correction of inaccurate data and completion of incomplete data.
- Erasure (Art. 17 GDPR) — deletion, unless a statutory retention obligation stands in the way.
- Restriction of processing (Art. 18 GDPR).
- Data portability (Art. 20 GDPR) — where we process data you provided to us by automated means on the basis of your consent or to perform a contract, you receive it in a common, machine-readable format. The right does not extend to processing we base on a legitimate interest or a legal obligation — the log files in section 3, for instance — and the transfer must not adversely affect the rights and freedoms of others.
- Objection (Art. 21 GDPR) — against processing we base on a legitimate interest (here: the log files in section 3). We will then stop the processing unless we can demonstrate compelling legitimate grounds.
- Withdrawal of consent (Art. 7(3) GDPR) — at any time and with effect for the future, for the newsletter for instance.
We answer requests without undue delay and within one month at the latest (Art. 12(3) GDPR). Where a request is complex we may extend that period by up to two further months, and will tell you if we do.
Right to lodge a complaint (Art. 77 GDPR): independently of the above, you may complain to a data protection supervisory authority. The authority responsible for us is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
(State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg)
Heilbronner Straße 35, 70191 Stuttgart, Germany
(P.O. Box 10 29 32, 70025 Stuttgart)
Phone: +49 711 615541-0
E-mail: poststelle@lfdi.bwl.de
https://www.baden-wuerttemberg.datenschutz.de
You may equally turn to the supervisory authority where you habitually reside or where you work.
9. The myTuur app
This policy covers the website. The myTuur app processes different data for different purposes and therefore has its own privacy policy:
https://mytuur.com/wp-content/uploads/2025/03/dsgvo_mytuur_en.html
We do not link your visit to this website with your use of the app. If you tap a download button here, the link takes you to Apple's or Google's app store; from there their terms and their privacy policies apply.
10. Changes to this privacy policy
We revise this policy when we change the website, or when the law or case law requires it. The version published here is always the one that applies; its date is given at the top. If we introduce processing that needs your consent, we obtain that consent before the processing begins — not afterwards.