Privay Policy
Last updated: 18 August 2026
Protecting your personal data is very important to us. We therefore process your data exclusively in accordance with the applicable legal provisions, in particular the General Data Protection Regulation (GDPR), the Austrian Data Protection Act (Datenschutzgesetz – DSG) and the Austrian Telecommunications Act 2021 (Telekommunikationsgesetz 2021 – TKG 2021).
This Privacy Policy explains which personal data we process in connection with our website, guided tours, bookings, vouchers, contact enquiries, payments and, where applicable, newsletter services.
1. Data Controller
GabiTours / Mag. Gabriele Saeidi Razavi
State-certified tourist guide
Sedlitzkygasse 1 / 2 / 6
1110 Vienna
Austria
Telephone: +43 663 032 340 09
Email:
office@gabitours.at
If individual pages display different contact details, the controller identified above remains the point of contact for all data protection enquiries unless expressly stated otherwise.
2. General Information on Data Processing
We process personal data only to the extent necessary to provide our website, respond to enquiries, process bookings and voucher purchases, facilitate payments, comply with legal obligations or, where required, obtain your consent.
Depending on the relevant processing activity, we rely in particular on the following legal bases:
- Article 6(1)(a) GDPR, where you have given us your consent, for example for certain cookies, tracking, marketing or newsletter services.
- Article 6(1)(b) GDPR, where processing is necessary for the performance of a contract or in order to take steps at your request before entering into a contract, for example in connection with bookings, voucher purchases or enquiries about private guided tours.
- Article 6(1)(c) GDPR, where processing is necessary for compliance with a legal obligation, for example tax or corporate-law retention obligations.
- Article 6(1)(f) GDPR, where processing is necessary for the purposes of our legitimate interests, for example the secure, stable and user-friendly operation of our website, the handling of general enquiries, fraud prevention or the establishment, exercise or defence of legal claims.
- Section 165 TKG 2021, where information is stored on or accessed from terminal equipment, particularly in connection with cookies and similar technologies.
3. Access Data and Server Log Files
When you visit our website, data automatically transmitted by your browser to the server is processed for technical reasons. This may include in particular:
- IP address
- date and time of access
- page or file accessed
- volume of data transferred
- browser type and browser version
- operating system used
- referrer URL
- hostname of the accessing device
This data is processed in order to deliver the website, ensure system security, analyse errors and prevent misuse. The legal basis is our legitimate interest under Article 6(1)(f) GDPR.
Server log files are stored only for as long as necessary for these purposes. They are retained for longer only where this is necessary to investigate security incidents, preserve evidence or comply with legal obligations.
4. Cookies, Consent Management and Real Cookie Banner
Our website uses cookies and similar technologies. Some of these are technically necessary for the website, online shop, booking functions, shopping basket, payment processing, language settings or consent management to operate. Other services, particularly analytics, marketing, map, video or social-media services, are used only where valid consent is legally required and you have given that consent.
We use a consent management tool to manage consent. Your consent, refusal and any subsequent changes are recorded so that we can implement your privacy choices and demonstrate compliance. You may change your choices, withdraw your consent or review the history of your privacy settings at any time using the privacy links provided on the website.
We use technically necessary cookies and similar technologies pursuant to Section 165 TKG 2021 and on the basis of Article 6(1)(f) GDPR or Article 6(1)(b) GDPR where they are necessary to operate the website or perform a contract.
We use non-essential cookies and services, in particular for statistics, marketing, external media or social networks, only on the basis of your consent under Article 6(1)(a) GDPR and Section 165 TKG 2021. You may withdraw consent at any time with effect for the future.
The specific list of services, cookies, retention periods and providers used on our website is displayed in the consent banner and the website’s privacy settings.
5. Contact by Email, Telephone or Form
If you contact us by email, telephone or through a form, we process the data you provide in order to handle your enquiry. This may include in particular:
- first name and surname
- email address
- telephone number
- content of your message
- requested guided tour, date, group size or other details relating to your enquiry
Where your enquiry concerns a booking or quotation, the processing is necessary in order to take steps at your request before entering into a contract or to perform a contract under Article 6(1)(b) GDPR. In other cases, the processing is based on our legitimate interest in responding efficiently to enquiries under Article 6(1)(f) GDPR.
We retain data from contact enquiries only for as long as necessary to handle the enquiry, perform any resulting contract, comply with statutory retention obligations or establish, exercise or defend legal claims.
6. Bookings, Guided Tours and Events
If you book or enquire about a guided tour, ticket, private tour or other service, we process the personal data required to prepare, provide and invoice the service. This may include in particular:
- name and contact details
- booking details
- selected guided tour or service
- date, number of participants and price
- payment status
- invoicing and accounting data
- any specific information you voluntarily provide in connection with your booking
The processing is necessary for the performance of a contract under Article 6(1)(b) GDPR and for compliance with legal obligations under Article 6(1)(c) GDPR. Where necessary, we also process data on the basis of our legitimate interests under Article 6(1)(f) GDPR, for example to organise guided tours, communicate changes of date or establish, exercise or defend claims.
Where necessary to provide a guided tour, relevant booking or contact details may be disclosed to participating individuals, cooperation partners or service providers, but only to the extent required.
7. Photographs, Video and Audio Recordings at Guided Tours and Events
In connection with guided tours, events and other GabiTours activities, we or photographers and videographers commissioned by us may take photographs and make video or audio recordings. These recordings are processed in particular for the following purposes:
- documenting our guided tours, events and other activities;
- editorial reporting and public relations;
- presenting and promoting GabiTours and future guided tours and events;
- publication on our website, in blogs and on the social-media platforms we use;
- use in printed and digital information, advertising and reporting materials, including brochures, flyers, posters, presentations, press materials and event reviews;
- disclosure to media companies, journalists, event partners, press partners, cooperation partners and other third parties for reporting, public-relations and agreed-use purposes; and
- establishing and maintaining an archive documenting the history of GabiTours through photographs and videos.
Legal Basis and Legitimate Interests
The taking and use of wide-angle, event and situational recordings is generally based on our legitimate interests under Article 6(1)(f) GDPR. Our legitimate interests are documenting our activities, informing the public, editorial reporting, public relations, presenting and promoting our services, and preserving a long-term record of GabiTours’ corporate and event history.
When selecting and publishing recordings, we take account of the legitimate interests, privacy and personality rights of the persons depicted. We do not publish recordings that show individuals in degrading, embarrassing, particularly private or otherwise detrimental situations.
Irrespective of the data-protection legal basis, photographs and recordings are published only in accordance with the applicable rights relating to a person’s image, including Section 78 of the Austrian Copyright Act (Urheberrechtsgesetz – UrhG).
Where processing cannot be based on legitimate interests, particularly in the case of targeted individual portraits, staged recordings or portrayals that give particular prominence to an individual, processing takes place only with consent under Article 6(1)(a) GDPR. For targeted recordings of minors, we obtain the prior consent of a parent or legal guardian where required.
Notice and Opportunity to Object
Where possible, notice that photographs or video recordings will be made is provided at the booking or announcement stage and again at the venue. Photographers and videographers engaged by us are identifiable at the event or are announced to participants.
If you do not wish to be recorded, please tell the photographer, videographer or a GabiTours staff member before or during the event. To the extent reasonably practicable from an organisational perspective, we will endeavour not to make identifiable recordings of you or not to use such recordings.
Group photographs will generally be announced. Participation is voluntary. If you do not wish to appear in a group photograph, please do not join the photograph or inform the photographer.
You may object at any time to processing based on legitimate interests on grounds relating to your particular situation. Please contact us at
office@gabitours.at and, where possible, specify the event, date and a description of the recording so that we can identify it.
Where an objection is justified, we will cease using the recording and, to the extent legally and technically possible, remove it from media under our control. If a recording has already been disclosed to media, cooperation partners or other recipients or made publicly available, we will inform them of a request for erasure or restriction to the extent required by law and reasonably practicable. We cannot guarantee the complete removal from the internet of content that has already been published and copied or redistributed by third parties.
Recipients and Publication on Social-Media Platforms
Recipients of recordings may include photographers, videographers, graphic designers, printers, web and marketing service providers commissioned by us; operators of social-media platforms; media companies and journalists; and event and cooperation partners.
When recordings are published on social-media platforms, the respective platform operators may further process them under their own data-protection responsibility. This may also involve processing in countries outside the European Union or the European Economic Area. The information on transfers to third countries in this Privacy Policy also applies.
Retention Period and Historical Archive
Unselected raw recordings and recordings that are no longer required will be deleted as soon as they are no longer needed for the stated purposes.
Selected recordings that have documentary, editorial or corporate-historical value may be retained in the GabiTours historical archive for up to 100 years from the date on which they were made. At appropriate intervals, we review whether continued retention remains necessary and consider its impact on the rights of the persons depicted.
Published recordings may be used and stored for as long as the relevant documentation, reporting, public-relations, advertising or archival purpose continues to apply and there are no overriding interests of the persons depicted or a justified request for erasure or objection that prevents their continued use.
8. Online Shop, WooCommerce and Vouchers
Our website may provide functions for online bookings, ticket purchases, voucher purchases and the management of voucher credit. For these purposes, we process the data required for the order, performance of the contract, payment, invoicing, dispatch or electronic delivery, and customer service. This may include in particular:
- name, billing details and contact details
- email address
- products, tickets or vouchers purchased
- voucher value, voucher code and voucher balance
- where applicable, the voucher recipient’s email address
- any voluntary message to the voucher recipient
- order, payment and delivery status
- technical shopping-basket and session data
The processing is necessary for the performance of a contract under Article 6(1)(b) GDPR, compliance with legal obligations under Article 6(1)(c) GDPR and the secure and efficient operation of the online shop on the basis of our legitimate interests under Article 6(1)(f) GDPR.
Technically necessary cookies may be used for online-shop functions, for example to store the shopping basket, associate activity with a session or complete the ordering process. These cookies are necessary to provide the online shop.
Invoice and accounting data is generally retained for seven years in accordance with statutory retention obligations. Data may be retained for longer where necessary in connection with pending proceedings, claims or legal obligations.
9. Payment Processing through Stripe
We use Stripe as our payment service provider for online payments. Depending on the selected payment method, the following data may be processed in particular:
- name and contact details
- billing and payment data
- order amount and currency
- payment method
- transaction data
- technical data used for fraud prevention and payment security
Sensitive payment data, particularly full card details, is generally entered and processed directly through Stripe or the payment infrastructure provided by Stripe. As a rule, we receive only the information required to confirm, allocate and process the payment, such as payment status, transaction ID and payment method.
The legal basis for payment processing is Article 6(1)(b) GDPR where processing is necessary for the performance of a contract. Where we are legally required to retain payment and invoice data, processing is based on Article 6(1)(c) GDPR. Fraud-prevention and secure-payment measures may additionally be based on Article 6(1)(f) GDPR.
Stripe may also disclose data to affiliated companies, service providers or public authorities where necessary for payment processing, security, compliance, fraud prevention or legal obligations. This may involve transfers to third countries, particularly the United States. According to Stripe, such transfers are based on appropriate safeguards, particularly the EU–U.S. Data Privacy Framework, Standard Contractual Clauses or other lawful transfer mechanisms under the GDPR.
If you use payment methods such as a credit card, debit card, Apple Pay, Google Pay or online banking payment, the privacy policies of the relevant payment, card, bank or wallet provider may also apply.
10. Email Communication, Booking Confirmations and Transactional Messages
In connection with enquiries, bookings, ticket purchases, vouchers and payments, we send you necessary emails, such as booking confirmations, payment confirmations, invoice information, voucher emails or notices of changes to scheduled dates.
This processing is necessary for the performance of a contract under Article 6(1)(b) GDPR, compliance with legal obligations under Article 6(1)(c) GDPR and our legitimate interest in reliable customer communication under Article 6(1)(f) GDPR.
Where we use external email or delivery service providers for these purposes, they act on the basis of appropriate data processing agreements.
11. Newsletters and Email Marketing with Brevo
If we offer a newsletter or other electronic marketing communications, we use Brevo as our email-marketing and delivery service provider. The following data may be processed for the newsletter in particular:
- email address
- name, if provided
- time of registration and IP address used to register
- evidence of consent
- newsletter preferences
- technical delivery and transmission data
- where applicable, opening and click-through rates, if this function is enabled and a valid legal basis exists
Newsletters are generally sent only with your consent under Article 6(1)(a) GDPR and in accordance with Section 174 TKG 2021. You may withdraw your consent at any time, in particular by using the unsubscribe link in the relevant newsletter or by contacting us.
Where all requirements of Section 174(4) TKG 2021 are met, we may inform existing customers about our own similar services. The associated processing is based on our legitimate interest in direct marketing under Article 6(1)(f) GDPR. You may object to the use of your email address easily and free of charge when it is collected and whenever you receive a marketing message.
Brevo processes data on our behalf as a processor. According to Brevo, data is predominantly processed or stored on servers within the European Union. Data may be transferred to subprocessors in connection with the services provided by Brevo.
After you unsubscribe from the newsletter, we retain the data required to demonstrate that consent was previously given or to document its withdrawal for as long as necessary to protect our rights or comply with legal obligations.
12. Embedded Content, Maps, Videos and Social Networks
Our website may embed external content and services, such as maps, videos, social-media posts or other third-party content. This may include services provided by Google, YouTube, Meta/Facebook, Instagram or X/Twitter.
Such content may result in personal data, such as your IP address, device information, browser data, usage data or cookie information, being transmitted to the respective providers. Unless technically necessary, a service of this kind is not loaded until you have given your consent through the consent banner.
The legal basis for non-essential external content is your consent under Article 6(1)(a) GDPR and Section 165 TKG 2021. You may withdraw your consent at any time through the website’s privacy settings.
Please note that third-party providers may process data under their own responsibility, particularly if you are logged in to their services or interact with embedded content.
13. Analytics, Marketing and Tracking Services
Where we use analytics, marketing or tracking services, we do so only after you have given your consent unless, exceptionally, the service is technically necessary. Such services may help us statistically analyse the use of our website, measure advertising or make content more user-friendly. The following data may be processed in particular:
- IP address or truncated IP address
- cookie and device identifiers
- pages visited
- click and usage behaviour
- technical browser and device data
- approximate location data
- interactions with advertisements or content
The legal basis is your consent under Article 6(1)(a) GDPR and Section 165 TKG 2021. You may withdraw your consent at any time through the website’s privacy settings.
The specific services, providers, purposes, retention periods and data transfers are shown in the consent banner and the website’s privacy settings. Services that are not actually used should not be listed in either the consent banner or this Privacy Policy.
14. Security Measures and Spam Protection
We take appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration or disclosure.
Forms may use simple security checks or technical safeguards to prevent spam and misuse. Where external services are used for this purpose, they are listed separately in the privacy settings and, where required, loaded only after consent has been given.
15. Recipients and Processors
Personal data is disclosed to third parties only where necessary to perform a contract, process a payment, provide the website, comply with legal obligations or pursue legitimate interests. Recipients may include in particular:
- hosting and IT service providers
- online-shop, booking and website service providers
- payment service providers, particularly Stripe
- email and newsletter service providers, particularly Brevo
- tax advisers, accountants and legal advisers
- banks and payment institutions
- authorities, courts or public bodies, where legally required
- participating individuals or cooperation partners, where necessary to provide a guided tour or fulfil a booking
Where required, we enter into data processing agreements with processors in accordance with Article 28 GDPR.
16. Transfers of Data to Third Countries
We prefer providers that process data within the European Union or the European Economic Area. However, certain services, particularly those offered by major technology, payment, analytics, marketing or social-media providers, may involve the transfer of personal data to third countries.
Such transfers take place only where a valid basis under the GDPR exists, for example:
- an adequacy decision by the European Commission;
- certification under the EU–U.S. Data Privacy Framework;
- Standard Contractual Clauses issued by the European Commission;
- supplementary safeguards;
- your explicit consent; or
- another legally permitted basis.
Details of specific transfers to third countries are provided in the consent banner or the website’s privacy settings where they relate to individual services.
17. Retention Periods
We retain personal data only for as long as necessary for the respective purposes or for as long as statutory retention obligations apply. Typical retention periods are:
- Server log files: only for as long as required for security and error analysis.
- Contact enquiries: for the duration of their handling and thereafter where required for follow-up questions, documentation or claims.
- Booking, invoice and payment data: generally seven years due to tax and corporate-law retention obligations.
- Voucher data: for the duration of redemption, validity and statutory retention obligations.
- Newsletter data: until you unsubscribe and thereafter only to the extent required to demonstrate consent or its withdrawal.
- Consent data: for as long as required to document, demonstrate and implement your privacy choices.
- Cookies: for the retention period specified in the consent banner.
Data may be retained for longer where necessary for the establishment, exercise or defence of legal claims or due to legal obligations.
18. Your Rights
Subject to the requirements of the GDPR, you have in particular the following rights:
- right of access
- right to rectification
- right to erasure
- right to restriction of processing
- right to data portability
- right to object to processing based on legitimate interests
- right to withdraw consent with effect for the future
- right to lodge a complaint with a data protection supervisory authority
The competent supervisory authority in Austria is the
Austrian Data Protection Authority (Österreichische Datenschutzbehörde):
www.dsb.gv.at.
If you wish to exercise any of your rights, please contact us at
office@gabitours.at.
19. Objection and Withdrawal of Consent
Where we process data on the basis of your consent, you may withdraw that consent at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before the consent was withdrawn.
Where we process data on the basis of legitimate interests, you may object to that processing on grounds relating to your particular situation. You may object to processing for direct-marketing purposes at any time without giving reasons.
20. No Automated Decision-Making
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.
Payment, security or fraud-prevention systems operated by external providers may use automated checks. These checks are intended in particular to ensure secure payment processing and prevent fraud and form part of the responsibility or technical processes of the relevant payment service provider.
21. Updates to this Privacy Policy
We may amend this Privacy Policy if our website, services, service providers or legal requirements change. The current version published on the website applies.