GDPR
Privacy policy
This website is a pure information service. There is no sign-up, no ticket sale and no payment data. The enquiry form sends nothing to our server – it opens your own mail programme. Below you can read which data is processed anyway and what happens to it.
Last updated: 2026-07-28
1. Controller
The controller for data processing on this website within the meaning of Art. 4 (7) GDPR is:
[Name / Firma des Betreibers]
[Straße und Hausnummer]
[PLZ Ort]
[Land]
E-mail: [email protected]
No data protection officer has been appointed, as the conditions of Art. 37 GDPR are not met. Please direct all privacy enquiries to the address above.
2. Principle: as little data as possible
- There is no user account and no registration.
- There is no ticket sale, so we hold no names, addresses or payment details.
- What you enter in the enquiry form (date, direction, vehicle) stays in your browser and is never sent to our server – the enquiry is composed as an e-mail in your own mail programme.
- We run no newsletter and no server-side contact form.
3. Hosting and server log files
The website is hosted by an external provider: [Name und Anschrift des Hosting-Anbieters]. The provider processes access data on our behalf under a data processing agreement pursuant to Art. 28 GDPR.
Each time a page is requested, the server automatically records the access data your browser transmits:
| Data | Purpose |
|---|---|
| IP address (usually stored truncated) | delivering the page, defending against attacks |
| date and time of the request | error analysis, security |
| requested address and volume of data transferred | technical operation |
| referrer (previously visited page) | technical operation |
| browser type, version and operating system | compatibility and troubleshooting |
The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest lies in the technically sound and secure operation of the website. Log files are deleted after 14 days at the latest, unless they are needed longer to investigate a specific security incident. This data is not combined with other sources.
4. Enquiry form and e-mail correspondence
The form on this site runs entirely in your browser. Submitting it transfers no record to any server: your selection (route, direction, dates, number of travellers, vehicle category and any voluntary notes) is simply written as text into an e-mail that opens in your own mail programme. You decide whether to send that message, and you can edit it first.
We only receive data once you actually send the e-mail: your sender address, your name as far as it is set in your mail account, and the content of the message. We process it solely to answer your enquiry. The legal basis is Art. 6 (1) (b) GDPR (steps taken at your request prior to a contract) or Art. 6 (1) (f) GDPR, our legitimate interest in answering enquiries.
Enquiries are deleted once they have been dealt with, at the latest after 12 months, unless statutory retention duties apply. We do not pass them on – in particular we do not book on your behalf and do not forward your details to a ferry operator. Please do not send us identity, payment or health data; none of it is needed to answer a ferry question.
The route to a booking is yours
We do not forward you automatically and we do not hand your enquiry to the ferry operator. If you book after our reply, you do so yourself on that company’s website, where its privacy policy alone applies.
5. Cookies and local storage
Strictly necessary storage: your cookie decision is stored in your browser’s local storage under the key ferry_consent, so you are not asked again on every page. This storage is exempt from consent because it provides a function you explicitly requested; the subsequent processing is based on Art. 6 (1) (f) GDPR.
All other cookies – statistics and marketing – are only set after you have agreed in the cookie banner. The legal basis is Art. 6 (1) (a) GDPR together with the national ePrivacy rules. Details on each individual cookie are in our cookie policy.
6. Google Analytics and Google Ads (consent only)
Where measurement and advertising services are enabled on this website, we use Google Analytics and/or Google Ads conversion tracking provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. This lets us see how the site is used and whether an ad led to a visit. Your truncated IP address, device and browser data and a pseudonymous identifier may be processed.
These services are governed by Google Consent Mode v2 and only load cookies or identifiers after your explicit consent. The legal basis is Art. 6 (1) (a) GDPR. Your consent is voluntary and can be withdrawn at any time with effect for the future – via the “Cookie settings” button in the footer of every page.
7. Recipients and transfers to third countries
The only recipients of data are our hosting provider and, where consent has been given, Google. When Google services are used, a transfer to the USA cannot be ruled out. Google LLC is certified under the EU-US Data Privacy Framework; in addition, the European Commission’s standard contractual clauses apply pursuant to Art. 46 (2) (c) GDPR. There is a residual risk that US authorities may access transferred data.
8. Retention periods
Server log files: 14 days maximum. Consent record: up to 6 months, or until you clear your browser storage. Statistics and marketing cookies: the periods stated in the cookie policy. Enquiries and e-mail correspondence: until the matter has been dealt with, at the latest after 12 months, then subject to statutory retention periods.
9. Your rights
- Access to the data held about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR) and restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of consent with effect for the future (Art. 7 (3) GDPR)
An informal message to [email protected] is enough to exercise any of these rights.
10. Right to lodge a complaint
Under Art. 77 GDPR you have the right to lodge a complaint with a data protection supervisory authority – for example the authority where you habitually reside, where you work, or where the alleged infringement took place.
11. Changes to this policy
We update this policy whenever the legal situation or the services we use change. The version published on this page, with the date shown above, always applies.