Privacy Policy
Information on the processing of personal data at Discover Weimar - Andrea Otto. Courtesy translation - only the German version is legally binding.
1. Controller
The controller responsible for data processing on this website is Andrea Otto, Discover Weimar, Karlstr. 9, 99423 Weimar, Germany, email: andrea.otto@discover-weimar.de, phone: +49 (0)151 53415763. I have not appointed a data protection officer, as this is not required by law.
2. Hosting and server log files
This website is hosted by Framer. The provider is Framer B.V., Rozengracht 207B, 1016 LZ Amsterdam, the Netherlands. Framer uses Amazon Web Services for hosting; this may involve a transfer to the USA (see section 8). When the website is accessed, technical data is recorded automatically: IP address, date and time of access, page accessed, referrer URL, browser and operating system used. This data is used to deliver and secure the website and is not combined with other data. Framer only stores the server log files for as long as is necessary to deliver and secure the website. The legal basis is Art. 6 (1) (f) GDPR; my legitimate interest lies in the secure and functional operation of the website. A data processing agreement pursuant to Art. 28 GDPR is in place with Framer.
3. Visitor statistics by Framer
Framer compiles visitor statistics for me (e.g. number of page views, pages accessed, approximate region of origin). No cookies are set and no profiles of individual visitors are created. The legal basis is Art. 6 (1) (f) GDPR; my legitimate interest lies in understanding which content is used in order to improve the offer.
4. Cookies
This website does not set any cookies for analytics or marketing purposes. Where technically necessary information is stored in the browser to display the website, this is based on § 25 (2) no. 2 TDDDG; consent is not required for this.
5. Fonts
The fonts used on this website are delivered directly from Framer’s servers. No connection is made to servers of Google or other font providers.
6. Contact form and contact by email or phone
If you send me a request via the request form, by email or by phone, I process the data you provide (name, email address, phone number if given, type of request, number of participants, message) in order to handle your request and, where applicable, arrange a tour with you. Mandatory fields are marked as such; without them I cannot process your request.
Form data is transmitted via Framer’s form feature, stored there and delivered to me by email. My mailbox is operated by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. A data processing agreement pursuant to Art. 28 GDPR is in place with IONOS. The legal basis is Art. 6 (1) (b) GDPR if your request relates to a booking, otherwise Art. 6 (1) (f) GDPR (legitimate interest in answering requests).
7. Booking and payment
For direct online booking I use the scheduling service Cal.com, Cal.com, Inc., 2261 Market Street #4382, San Francisco, CA 94114, USA. When you book, your name, email address, phone number, chosen date and any information you enter in the notes field (e.g. school and year group) are processed in order to arrange the appointment, send you a confirmation and a reminder, and carry out the tour. The legal basis is Art. 6 (1) (b) GDPR. A data processing agreement pursuant to Art. 28 GDPR is in place with Cal.com. Transfers to the USA are based on EU standard contractual clauses or, insofar as Cal.com is certified under the EU-US Data Privacy Framework, on that framework.
Payment is made on the day of the tour in cash or by card. For card payments I use a card terminal provided by SumUp Limited, Block 8, Harcourt Centre, Charlotte Way, Dublin 2, D02 K580, Ireland. Your card data is processed directly by SumUp; I do not receive full card details. SumUp is independently responsible for this processing, and SumUp’s privacy notice also applies. The legal basis is Art. 6 (1) (b) GDPR.
For school classes and corporate customers I issue an invoice containing the necessary data (name or institution, address, service). The legal basis is Art. 6 (1) (b) and (c) GDPR.
8. Recipients and transfers to third countries
Your data is only received by the service providers named above, insofar as this is necessary for the respective purpose: Framer (hosting via Amazon Web Services, statistics, form), IONOS (email), Cal.com (booking) and SumUp (card payment). Invoice data may be passed on to my tax advisor. I only pass on your data to other third parties if I am legally obliged to do so.
Where service providers process data in the USA, the transfer only takes place if the recipient is certified under the EU-US Data Privacy Framework (adequacy decision of the European Commission of 10 July 2023) or EU standard contractual clauses have been agreed with it.
9. Storage period
Requests that do not lead to a booking are deleted no later than six months after the correspondence has ended. Data on booked tours is stored for as long as it is needed for carrying out and invoicing the tour. Invoices and accounting records are retained for as long as required by law (usually eight years for accounting records, § 147 AO). The data is then deleted.
10. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR) and data portability (Art. 20 GDPR). Simply contact me at the address above. No automated decision-making, including profiling (Art. 22 GDPR), takes place.
11. Right to object
Where I process data on the basis of Art. 6 (1) (f) GDPR (legitimate interest), you have the right to object to this processing at any time on grounds relating to your particular situation (Art. 21 GDPR). I will then no longer process the data unless I can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims.
12. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for me is the Thüringer Landesbeauftragter für den Datenschutz und die Informationsfreiheit (TLfDI, Thuringia State Commissioner for Data Protection and Freedom of Information).
13. SSL/TLS encryption
This website uses SSL/TLS encryption. You can recognise an encrypted connection by the address in your browser beginning with https and a padlock symbol being displayed.
14. Changes
I update this privacy policy when the website, my services or the legal requirements change. The version published here applies.
Last updated: September 2026
