Privacy policy
The protection of your privacy matters to the Hamburg Airport Group. We, Flughafen Hamburg GmbH, inform you below about which personal data we collect when you visit the Hamburg Airport website, for which purposes and on what legal basis we process it, to whom we disclose it, and what rights you have. In doing so, we fulfil our information obligations under Articles 12 to 14 GDPR.
1. Data controller and contact details
The controller within the meaning of the GDPR is
Flughafen Hamburg GmbH
Flughafenstraße 1–3
22335 Hamburg
Phone: +49 40 5075-2161
Email to Hamburg Airport
Hamburg Airport website
You can reach our Data Protection Officer via email to the Data Protection Officer, or by post at the address given above, adding “Attn: Data Protection Officer”.
Further details about the company can be found in the Hamburg Airport imprint.
2. Basis of processing
Terms. We use the terms defined in the GDPR. Personal data is any information relating to an identified or identifiable natural person (Art. 4 No. 1 GDPR). A controller is anyone who decides on the purposes and means of processing (Art. 4 No. 7 GDPR); a processor is anyone who processes data on behalf of and under the instructions of a controller (Art. 4 No. 8 GDPR).
Legal bases. We process your data on the basis of your consent (Art. 6(1)(a) GDPR), for the initiation or performance of a contract (Art. 6(1)(b) GDPR), to comply with legal obligations (Art. 6(1)(c) GDPR), or to safeguard our overriding legitimate interests (Art. 6(1)(f) GDPR).
Access to your terminal equipment. To the extent we store information on your device or access information already stored there — for example through cookies, pixels, or entries in your browser’s local storage — this is done only with your consent under Section 25(1) TDDDG (German Telecommunications and Digital Services Data Protection Act) in conjunction with Art. 6(1)(a) GDPR. Excepted are accesses that are strictly necessary for us to provide a service you have expressly requested, Section 25(2) No. 2 TDDDG. The subsequent processing of data is carried out on the basis of Art. 6(1) GDPR.
Withdrawal and objection. You may withdraw any consent given at any time with effect for the future (Art. 7(3) GDPR); this does not affect the lawfulness of processing carried out before the withdrawal. You may object to processing based on legitimate interests under Art. 21 GDPR. You can manage and withdraw your consent to cookies and comparable technologies at any time via Hamburg Airport’s cookie settings.
3. Use of our website
3.1 Server log files
Each time you access our website, our servers temporarily store:
•the IP address of your device
•the client’s file request (file name and URL)
•the HTTP status code
•the website from which you visit us
•the browser used, as well as the language and version of the browser software
•the operating system and its interface
This processing serves to deliver the website, to detect and remedy faults, and to uncover misuse such as spam and attack attempts. The legal basis is our legitimate interest in secure and fault-free operation (Art. 6(1)(f) GDPR). The log files are deleted as soon as they are no longer required for these purposes.
3.2 Cookies and consent management
Our website uses cookies and comparable technologies. Cookies are small text files that are stored on your device. Session cookies are deleted when you close your browser; persistent cookies remain stored for a set period.
Technically necessary cookies. These include, in particular, session cookies for the technical operation of the website, savedFlights for flight connections you have bookmarked, the session cookies of the booking widget, and the cookie that stores your consent decision. They are strictly necessary for operating the website or for the functions you have expressly requested (Section 25(2) No. 2 TDDDG, Art. 6(1) GDPR) and cannot be deselected.
Cookies requiring consent. We use all other cookies and technologies — in particular for statistics, preferences, and marketing — only with your consent (Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG).
Consent management. We use Cookiebot to obtain, manage, and document your consent. The service is provided by Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark. The consent data is processed on our behalf under a data processing agreement pursuant to Art. 28 GDPR. In particular, a consent ID, the date and time of the decision, consent status, user agent, HTTP referrer, the URL accessed, language, IP address, and approximate geolocation are processed. According to the provider, this technical data is not stored further once it has been used to deliver the consent banner. The CookieConsent cookie stores your consent status for one year. This processing serves the legally compliant management and evidencing of your consent decisions; the legal basis is our legitimate interest in fulfilling the accountability and evidencing obligations under Art. 5(2) and Art. 7(1) GDPR (Art. 6(1)(f) GDPR). Further information is available in Cookiebot’s privacy notice, Cookiebot’s legal notices, and Cookiebot’s data processing agreement. An up-to-date overview of the cookies and comparable technologies detected on our website, including provider, purpose, and retention period, is available in Hamburg Airport’s cookie settings.
3.3 Audience measurement with etracker
We analyse the use of our website using etracker. The service is provided by JustRelate Deutschland GmbH, Kitzingstraße 15, 12277 Berlin. The data is processed on our behalf under a data processing agreement pursuant to Art. 28 GDPR and, according to the provider, exclusively in Germany. In particular, the pages accessed, time spent, scroll depth, referral source, truncated IP address, and device and browser information are processed; personally identifiable information is anonymised or pseudonymised as early as possible.
To the extent etracker stores or reads cookies or comparable identifiers on your device for this purpose — such as _et_coid, et_cssSelectors, et_scroll_depth, or isSdEnabled — this occurs only with your consent (Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG). The et_allow_cookies cookie documents your decision. You can withdraw your consent at any time via Hamburg Airport’s cookie settings. Further information is available in etracker’s privacy notice.
The _et_coid identifier may be stored for up to two years; et_allow_cookies is stored for up to 180 days. The retention of server-side analytics data depends on the configuration agreed with etracker and ends once the data is no longer required for audience measurement and optimisation.
3.4 Advertising and retargeting
We advertise our offers on third-party advertising networks. In doing so, pseudonymous identifiers are stored on your device that allow you to be recognised when visiting other websites within the respective network, so that interest-based advertising can be shown to you. We ourselves generally only receive and use pseudonymous identifiers and aggregated evaluations, and do not attribute these to any named person. However, the operators of the advertising networks may combine the identifiers with other data they hold — for example, an existing user account — thereby establishing a link to your identity. We have no influence over this further processing.
The sole legal basis for all retargeting measures is your consent (Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG). You can withdraw this at any time via Hamburg Airport’s cookie settings.
Meta. Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland, sets identifiers such as _fbp, as well as lastExternalReferrer and lastExternalReferrerTime. For the collection and transmission of data to Meta, we and Meta are joint controllers under Art. 26 GDPR within the scope of the Meta Business Tools used; the subsequent processing is carried out under Meta’s own responsibility. Meta may also process the data outside the EU and the EEA. To the extent data is transferred to third countries, Meta states that it bases such transfers on applicable adequacy decisions, in particular the EU-U.S. Data Privacy Framework, or on standard contractual clauses. Details are provided in Meta’s data policy; you can also manage advertising settings in your Meta account.
The Trade Desk. For users in the EEA, The UK Trade Desk Ltd., 10th Floor, 1 Bartholomew Close, London EC1A 7BL, United Kingdom, is responsible. The identifiers TDCPM and TDID are set with a retention period of up to one year. An adequacy decision of the European Commission exists for transfers to the United Kingdom. According to its own statements, The Trade Desk bases further transfers to the USA on certification under the EU-U.S. Data Privacy Framework, supplemented by standard contractual clauses. According to the provider, pseudonymous data is stored for up to 18 months and subsequently retained in de-identified form for up to three years. Details and opt-out options are available in The Trade Desk’s privacy notice. Cross-network objections are also possible via Your Online Choices and the Digital Advertising Alliance’s opt-out page.
4. Contact and services
4.1 Enquiries by email
If you send us an email, we process your email address and the information contained in the message in order to handle your enquiry. The legal basis is our legitimate interest in responding to your enquiry (Art. 6(1)(f) GDPR); for service-related enquiries, the initiation or performance of a contract (Art. 6(1)(b) GDPR). Once your enquiry has been finally handled, we delete the data unless statutory retention obligations apply.
4.2 Contact form
Through our contact forms, we process title, first and last name, address, email address, phone number, and the details provided in the message field. Mandatory fields are marked as such; without them, we cannot process your enquiry.
The legal basis is our legitimate interest in handling your enquiry and in any follow-up communication (Art. 6(1)(f) GDPR); if your enquiry relates to a contract or its initiation, Art. 6(1)(b) GDPR applies. Where necessary for processing, we forward your enquiry to the responsible department or to another company within the Hamburg Airport Group. We additionally log the IP address and the time of submission to prevent misuse and for evidentiary purposes (Art. 6(1)(f) GDPR). The data is deleted once the purpose no longer applies. Where we process your data on the basis of legitimate interests, you may object to this processing at any time under Art. 21 GDPR, for example via email to the Data Protection Officer; this does not affect processing that is necessary for the initiation or performance of a contract.
4.3 Lost-property enquiries
The same data categories, legal bases, forwarding, and deletion rules described for the contact form under Section 4.2 apply to enquiries submitted via our lost-property form. The data is used exclusively to process your lost-property matter.
4.4 Newsletter and mailings
Sign-up. You will only receive our newsletter following your express consent (Art. 6(1)(a) GDPR). Your email address is required; title and first and last name are voluntary details that we use for personalisation. We use the double opt-in procedure: after signing up, you receive a confirmation email; if you do not confirm, we automatically delete the registration data after 48 hours. For evidentiary purposes, we store your consent declaration as well as the IP address and time of registration and confirmation. The legal basis is our legitimate interest in fulfilling the accountability and evidencing obligations under Art. 5(2) and Art. 7(1) GDPR (Art. 6(1)(f) GDPR).
Mailing for Slot&Fly users. As a Slot&Fly user, you can separately register for a one-off promotional mailing featuring offers from shops, restaurants, and services at Hamburg Airport. The legal basis is your consent (Art. 6(1)(a) GDPR). Following this, we may ask you for brief feedback as part of a survey. After the mailing and the survey have been sent, we delete your data unless you have consented to further communication.
Delivery service provider. We use mailingwork for the design, sending, and evaluation of our mailings. The service is provided by Positive Group Chemnitz GmbH, Schönherrstraße 8, 09113 Chemnitz; processing is carried out on our behalf under a data processing agreement pursuant to Art. 28 GDPR. Your data is stored on servers in Germany. The service provider does not use your data for its own purposes. Further information is available in mailingwork’s privacy notice.
Success measurement. If you have given separate consent, we evaluate whether and when you open our newsletters and which links you click; technical information such as browser, IP address, and access time is processed for this purpose. The legal basis is your consent (Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG). Success measurement is voluntary; without it, you will still receive the newsletter unchanged.
Unsubscribing. You may withdraw your consent at any time (Art. 7(3) GDPR), using the unsubscribe link in every newsletter or via email to the Data Protection Officer. After unsubscribing, we delete your data from the distribution list; we retain the consent documentation for evidentiary purposes.
4.5 Prize draws
Depending on the specific prize draw, we process email address, title, first and last name, date of birth, address, and phone number. The legal basis is the performance of the participation arrangement (Art. 6(1)(b) GDPR); this includes checking the participation conditions, determining the winner, notification, and dispatch of the prize. Where necessary, we pass on data to cooperation partners; details are set out in the respective participation conditions. We only publicly announce winners where the respective participation conditions provide for this transparently and our legitimate interest in communicating about the prize draw outweighs your interests in the individual case (Art. 6(1)(f) GDPR); in this case, you may object to the announcement at any time under Art. 21 GDPR. Where this is not the case — in particular where photos or further details would be published — the announcement is only made with your separate consent (Art. 6(1)(a) GDPR), which you may withdraw at any time with effect for the future. Once the prize draw has ended, we delete the data unless statutory retention obligations or evidentiary requirements apply.
4.6 Online booking of products and services
Booking process. Through our website, you can purchase products and services, such as gift vouchers and tickets for events. For this purpose, we process first and last name, email address, phone number, and your comment. If the offer requires access to the security-restricted area under Sections 8 et seq. of the German Aviation Security Act (Luftsicherheitsgesetz), we additionally process the first name, last name, and date of birth of each participating person. We receive the invoice and payment number from the payment service provider. The legal basis is the initiation and performance of the contract (Art. 6(1)(b) GDPR), and for security-related information, additionally our legal obligation (Art. 6(1)(c) GDPR). We delete the data as soon as it is no longer required and no commercial or tax-law retention periods apply.
bookingkit booking system. We embed the booking system as a widget; the provider is bookingkit GmbH, Sonnenallee 223, 12059 Berlin, which processes the booking data on our behalf under a data processing agreement pursuant to Art. 28 GDPR. When the widget is loaded, a connection is established to bookingkit’s servers; in doing so, your IP address and the information that you have visited our website are also transmitted. Technically necessary session cookies such as BkOpSession and BkCheckoutSession are required for the shopping cart and payment window (Section 25(2) No. 2 TDDDG, Art. 6(1)(b) GDPR). Details are available in bookingkit’s privacy policy.
Usage analysis in the booking widget. For product analysis, the widget uses the PostHog service provided by PostHog, Inc., 2261 Market Street #4008, San Francisco, California, and may store identifiers such as ph_posthog, ph_primary_window_exists, ph_window_id, and an entry storing your consent decision. This occurs only with your consent (Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG), which you may withdraw at any time via Hamburg Airport’s cookie settings. It cannot be ruled out that PostHog also processes your data in the USA. For transfers to the USA, PostHog cites certification under the EU-U.S. Data Privacy Framework and standard contractual clauses. Further information is available in PostHog’s privacy notice.
Stripe payment processing. We process payments via Stripe. Stripe services in Europe are provided in particular by Stripe Technology Company, Limited and Stripe Payments Europe, Limited, both at One Wilton Park, Wilton Place, Dublin 2, D02 FX04, Ireland; the corporate group also includes Stripe, LLC, 354 Oyster Point Boulevard, South San Francisco, California. Which Stripe entity acts as controller or processor in a given case depends on the payment method chosen and the respective contractual arrangement. Depending on the payment method, we process first and last name or company name, address, bank details, where applicable credit card data, invoice amount, currency, and transaction number. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR); to the extent Stripe uses the data for fraud prevention and to fulfil its own regulatory obligations, Stripe acts in this respect under its own responsibility. According to its own statements, Stripe also processes data outside the EU, in particular in the USA, and bases such transfers on certification under the EU-U.S. Data Privacy Framework as well as on standard contractual clauses. Details are available in Stripe’s privacy policy and Stripe’s Privacy Center.
If you do not wish these service providers to process your data, please book the respective offers on site at Hamburg Airport.
5. Embedded third-party offers
5.1 Online parking booking
Our website contains a link to Hamburg Airport’s online parking booking portal. The booking portal is operated under its own address; the controller is Flughafen Hamburg Konsortial- und Service GmbH & Co. OHG, Flughafenstraße 1–3, 22335 Hamburg. The purposes, legal bases, recipients, and retention periods for the booking data are governed by the privacy notices provided on the booking portal. Merely clicking the link on our website does not involve us processing any data beyond what is described in Section 3.1.
5.2 Kiwi.com flight booking tool
For flight search, we embed a widget provided by Kiwi.com s.r.o., Rohanské nábřeží 678/25, 186 00 Prague 8-Karlín, Czech Republic. When the widget is loaded, a connection is established between your browser and Kiwi.com’s servers; your inputs, your IP address, and the information that you have visited our website are transmitted. Kiwi.com processes this data as an independent controller and uses its own identifiers such as dd_cookie_test and TDeeclocID.
To secure the widget, Kiwi.com uses Cloudflare, Inc., 101 Townsend St., San Francisco, California, as its own service provider for content delivery and web application firewall services. For this purpose, Cloudflare processes access data such as IP address, time of the request, user agent, hostname, and referring website. To the extent data is transferred to the USA, Cloudflare states that it bases the transfer on certification under the EU-U.S. Data Privacy Framework and, in addition, on standard contractual clauses.
The widget is only loaded after your consent (Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG); you can withdraw your consent at any time via Hamburg Airport’s cookie settings. Kiwi.com may also transfer data to recipients outside the EEA to carry out your flight search and booking, and for necessary transfers relies in particular on Art. 49(1)(b) GDPR. Further information on subsequent processing is available in Kiwi.com’s privacy notice and Cloudflare’s privacy notice.
5.3 Rental car offers
For rental car search, we embed a widget from DiscoverCars provided by AS Discover Car Hire, Kārļa Ulmaņa gatve 2, Riga, LV-1004, Latvia. The provider processes your inputs and usage data as an independent controller and stores identifiers such as currency and _gcl_ls; _gcl_ls is a Google Ads identifier used by the DiscoverCars widget. This does not mean that Hamburg Airport uses Google Analytics or Google Ads as its own web analytics or remarketing service on this website. This integration is carried out only with your consent (Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG), which you may withdraw at any time via Hamburg Airport’s cookie settings. DiscoverCars may also process data outside the EEA and cites standard contractual clauses in particular for this purpose. Details are available in DiscoverCars’ privacy policy.
5.4 Regional leisure and experience offers
To display tourism offers, we embed a whitelabel widget of the imx.Platform, which is technically provided by infomax websolutions GmbH, Aichfeld 2, 83224 Grassau, and operated in a tourism context by Hamburg Tourismus GmbH, Wexstraße 7, 20355 Hamburg. When loaded, connection data including your IP address is transmitted to the servers of the providers involved; in addition, entries such as i18n_redirected, bookmarkCollectionIds, currentWhlPageType, previousWhlModuleType, and previousWhlPageTypes are stored in your browser’s local storage, for example for language selection, navigation, and bookmarked offers. This integration is carried out with your consent (Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG), which you may withdraw at any time via Hamburg Airport’s cookie settings. Further information is available in infomax’s privacy notice and Hamburg Tourismus GmbH’s privacy policy.
6. Our presence on social networks
6.1 General
We maintain presences on social networks in order to inform people about the airport and to engage with you. Our website pages contain only links to these presences and no social media plug-ins; clicking a link takes you away from our website. This does not affect the advertising and retargeting technologies described in Section 3.4. We have no influence over the nature, scope, and duration of processing carried out by the platform operators, over links to user profiles, or over disclosures to third parties.
If you contact us via a platform — for example by direct message or comment — we process your username and the content of your message in order to respond to your enquiry. The legal basis is our legitimate interest in communicating with users (Art. 6(1)(f) GDPR). Once your enquiry has been finally handled, we delete the data within our own sphere of control, unless retention obligations apply. We can edit and delete content within our own account — such as direct messages and comments — within the scope of the respective platform functions. We have no determining influence over storage beyond this on the platform side, over log data, or over deletion periods there; these are governed by the terms and settings of the respective operator. Comments are publicly visible to other users.
We receive aggregated statistics from the platforms about the use of our presences. We evaluate these in order to align our content with the interests of our target audiences; the legal basis is our legitimate interest in needs-based public relations work (Art. 6(1)(f) GDPR). You can assert your rights under Section 13 both against us and against the respective platform operator.
6.2 Facebook and Instagram
Facebook and Instagram are offered by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. For the collection and transmission of data generated when creating Page Insights, we are joint controllers together with Meta under Art. 26 GDPR. The essential content of this arrangement is set out in Meta’s Controller Addendum and Meta’s Page Insights Controller Addendum. The joint responsibility is limited to collection and transmission; the subsequent processing of the data by Meta is carried out under Meta’s sole responsibility. How Meta uses data, what transfers to third countries take place, and what settings and objection options exist are described in Meta’s data policy. The lead supervisory authority for Meta is the Irish Data Protection Commission.
6.3 YouTube
Our YouTube channel is operated for the EEA by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. We receive aggregated statistics from YouTube on channel and video views, traffic sources, devices, and demographic characteristics, which do not allow conclusions to be drawn about individual persons; this evaluation is carried out on the basis of our legitimate interest (Art. 6(1)(f) GDPR). When you access our channel directly, YouTube processes its own usage data and may establish a link to your identity in doing so. We may be able to attribute comments and subscriptions to your publicly visible profile. Details are available in Google’s privacy policy; you can manage your settings in your Google Account.
6.4 X
Our profile on X is provided, for users in the EU, the EFTA, and the United Kingdom, by X Internet Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland. X processes both the information you provide and usage and log data such as IP address, browser type, operating system, pages accessed, and cookie information, and may use this for advertising and personalisation. Through our profile, we only receive non-personal metrics on post activity. We base the processing of your data for our public relations work on our legitimate interest (Art. 6(1)(f) GDPR). For transfers to the USA, X cites the EU-U.S. Data Privacy Framework and, where applicable, standard contractual clauses. Information on processing, transfers to third countries, and setting options is available in X’s privacy policy.
6.5 TikTok
Our TikTok presence is provided by TikTok Technology Limited, 10 Earlsfort Terrace, Dublin 2, D02 T380, Ireland. According to the provider, TikTok Technology Limited and TikTok Information Technologies UK Limited are joint controllers for the processing of data of users in the EEA. We receive aggregated statistics on our profile from TikTok and evaluate these on the basis of our legitimate interest in needs-based public relations work (Art. 6(1)(f) GDPR). We have no influence over TikTok’s further processing, including transfers to third countries. Details are available in TikTok’s EEA privacy policy; you can reach TikTok’s Data Protection Officer via TikTok’s contact form.
6.6 LinkedIn and LinkedIn Lead Gen Forms
Our LinkedIn page is provided by LinkedIn Ireland Unlimited Company. For the processing of personal data in connection with page statistics, we are joint controllers together with LinkedIn; the essential content is set out in LinkedIn’s Page Insights Joint Controller Addendum.
As part of acquiring prospective tenants, we use LinkedIn Lead Gen Forms. Through a form integrated into an advertisement, you can submit your contact details to us, which LinkedIn partially pre-fills from your profile. We process this data to make contact and pursue business opportunities on the basis of the consent you give via the form (Art. 6(1)(a) GDPR); we base subsequent communication on Art. 6(1)(b) GDPR. We delete your details once the purpose of contact no longer applies and no statutory retention obligations exist. Information on processing by LinkedIn is available in LinkedIn’s privacy policy and the overview of LinkedIn Lead Gen Forms.
7. Visitor tours at Hamburg Airport
To take part in a tour of the operational site, we collect first name, last name, and date of birth. This data is used solely to document access and to verify authorisation to enter the aviation security area. The legal basis is our legal obligation to grant access only to authorised persons (Art. 6(1)(c) GDPR in conjunction with Section 8(1) Nos. 4 and 5 of the German Aviation Security Act).
To fulfil this purpose, we pass the data to AIRSYS GmbH as our internal IT service provider, which handles IT operations on our behalf. In the case of criminally relevant incidents, the data may be transmitted to law enforcement authorities. We delete the data as soon as it is no longer required for access documentation under Sections 8 et seq. of the German Aviation Security Act and no statutory retention periods apply.
8. Disclosure of data
8.1 External service providers
We use service providers for the technical operation, maintenance, and further development of our online offering, who may thereby gain access to personal data — in particular Arvato Systems GmbH, Reinhard-Mohn-Straße 18, 33333 Gütersloh. These service providers process your data solely on our instructions and on the basis of data processing agreements under Art. 28 GDPR. Responsibility for protecting your data remains with us. The legal basis depends on the respective processing operation described in this policy.
8.2 Disclosure due to legal obligation
We disclose personal data where we are legally obliged to do so or where authorities or law enforcement agencies lawfully demand it (Art. 6(1)(c) GDPR). Beyond this, we only disclose data as described in this policy or where you have previously consented.
9. Data processing in the context of business relationships
This section applies to Flughafen Hamburg GmbH as well as to other companies of the Hamburg Airport Group (together, “we” or “us” below). If you are in a business relationship with us as a contracting party or as a contact person of a company, we process personal data that you provide to us in this context. The nature and scope of the processing depend on the capacity in which you are in contact with us.
If, as a natural person, you are yourself a party to a contract concluded with us (for example, as a sole trader or freelancer), we process the personal data provided by you and collected by us in the course of the initiation and performance of the contract. This data is processed exclusively for the purpose of establishing, performing, and settling the contractual relationship, including contract administration, ongoing communication, documentation of the cooperation, and billing. The legal basis is Art. 6(1)(b) GDPR.
If you are a contact person of a company, we process the personal data provided by you or your company and collected by us. This processing is carried out for the purpose of performing the contract with the company for which you work and maintaining the ongoing business relationship. This includes contract administration, communication, documentation of the cooperation, and billing. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the proper performance of the contracts concluded with your company and in maintaining a functioning business relationship.
10. Data transfer to third countries
We predominantly process your data in Germany and the European Union. A transfer to a country outside the EU and the EEA only takes place where the European Commission has determined an adequate level of protection for that country (Art. 45 GDPR), where appropriate safeguards exist under Art. 46 GDPR — in particular standard contractual clauses — or where an exception under Art. 49 GDPR applies.
For transfers to the USA, the European Commission’s adequacy decision on the EU-U.S. Data Privacy Framework of 10 July 2023 may be relied upon, provided the receiving company is certified accordingly. Further information is available from the European Commission on EU-US data transfers; you can check the certification status of individual companies in the Data Privacy Framework list of participants.
Which safeguards apply in each individual case is stated for the respective services in this policy; supplementary information can be found in the providers’ privacy notices linked there. For processing based on your consent, you can withdraw it at any time via Hamburg Airport’s cookie settings; the withdrawal has effect for the future and prevents the service from being loaded further as well as any future transfers. Transfers that have already taken place remain unaffected; in this respect, you can assert your rights under Section 13 against us and against the respective provider.
11. Retention period and deletion
We store personal data only for as long as is necessary for the respective purposes or as required by statutory retention periods. Thereafter, the data is deleted or its processing is restricted. Specific periods are stated for the individual processing operations; in addition, the following apply in particular:
•Registration data without confirmation under the double opt-in procedure: deleted after 48 hours
•Consent status in the CookieConsent cookie: one year
•Identifiers for audience measurement and retargeting on your device: in accordance with the respective stated cookie lifetimes, up to a maximum of two years; deviating server-side retention periods are described for the respective providers
•Contract and billing data: until the expiry of the applicable commercial and tax-law retention periods
12. Data security
We take state-of-the-art technical and organisational measures to protect your data against unauthorised access, loss, and misuse (Art. 32 GDPR). Data transmitted via our website is encrypted.
13. Your rights
You have the following rights against us:
•Access to the data processed about you, its origin, recipients, and purposes (Art. 15 GDPR)
•Rectification of inaccurate data and completion of incomplete data (Art. 16 GDPR)
•Erasure, to the extent the data is no longer required, consent has been withdrawn, a valid objection has been raised, or the processing was unlawful (Art. 17 GDPR)
•Restriction of processing (Art. 18 GDPR)
•Data portability for data you have provided to us that we process automatically on the basis of consent or a contract (Art. 20 GDPR)
•Objection to processing based on legitimate interests; in the case of direct marketing, the right to object applies without restriction (Art. 21 GDPR)
•Withdrawal of consent with effect for the future (Art. 7(3) GDPR)
To exercise your rights, please contact us by email to the Data Protection Officer or at the address given in Section 1.
14. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, your place of work, or the place of the alleged infringement (Art. 77 GDPR). The authority responsible for us is:
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
(Hamburg Commissioner for Data Protection and Freedom of Information)
Ludwig-Erhard-Str. 22, 7th floor
20459 Hamburg
Contact details and information on how to lodge a complaint are available from the office of the Hamburg Commissioner for Data Protection and Freedom of Information.
15. Version and changes to this privacy policy
We update this privacy policy when our offerings, the services we use, or the legal framework change. The version published on this page shall apply at any given time. The German-language version of this privacy policy is exclusively legally binding.
Last updated: 11 August 2026