zumflieger.de is a brand of T&M Limousinen Service Gesellschaft mbH. This privacy policy applies to the website zumflieger.de and to the services requested via it. Dated August 2026. This English version is provided for information purposes; the legally binding version is the German original (Datenschutzerklärung).
1. Scope
In this privacy policy we explain how T&M Limousinen Service Gesellschaft mbH processes personal data.
This privacy policy applies in particular to the use of our website, enquiries and offers, bookings and carriage services, chauffeur, limousine, van and bus services, communication with customers and passengers, cooperation with clients and business partners, payment and invoicing processes as well as application procedures.
It also applies where a service is booked or organised not by the data subject themselves but, for example, by a company, an employer, an assistance office, a hotel, a concierge, a travel agency, a tour operator or an event agency.
2. Controller
The controller for the processing of personal data is:
T&M Limousinen Service Gesellschaft mbH
Sportallee 74
22335 Hamburg
Germany
Telephone: +49 (0)40 500 18-20
E-mail: info@zumflieger.de
3. Data protection contact
If you have questions about data protection, about the processing of personal data or about exercising your data protection rights, you can contact our data protection contact:
T&M Limousinen Service Gesellschaft mbH
Sportallee 74
22335 Hamburg
Germany
E-mail: datenschutz@limousinenservice.de
4. Legal bases for processing
Depending on the processing operation, we process personal data in particular on the following legal bases:
Art. 6(1)(a) GDPR, where processing is based on your consent.
Art. 6(1)(b) GDPR, where processing is necessary for the performance of a contract with you or for the implementation of pre-contractual measures.
Art. 6(1)(c) GDPR, where processing is necessary for compliance with a legal obligation.
Art. 6(1)(f) GDPR, where processing is necessary for the purposes of our legitimate interests or those of a third party and no overriding interests or fundamental rights and freedoms of the data subject prevail.
In the case of special categories of personal data, the additional requirements of Art. 9 GDPR apply.
5. Enquiries, offers, bookings and provision of our services
If you enquire about, book or use a service from us, we may process in particular the following personal data:
- name and contact details,
- company and business function,
- invoicing and address data,
- telephone number and e-mail address,
- date and time of the requested service,
- pick-up location, destination and intermediate stops,
- number of passengers,
- requested vehicle or service category,
- booking and order numbers,
- information on air, rail or ship connections,
- scheduled and actual arrival times,
- special service requests,
- communication content,
- service, status and invoicing information as well as
- other information required to perform the order.
We process these data in particular for handling enquiries, preparing offers, accepting and managing bookings, planning and dispatching, performing the carriage service, communicating with customers and passengers, coordinating in the event of delays or changes, invoicing as well as handling complaints and claims.
We store order-related service notes and non-sensitive preferences (for example preferred beverages or air conditioning) in order to be able to perform follow-up orders at a consistent quality. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in a reliable service quality for returning customers.
If the data subject is themselves our contractual partner, processing takes place in particular on the basis of Art. 6(1)(b) GDPR.
If the passenger or contact person is not themselves a contractual partner, processing takes place in particular on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in the proper planning, performance and documentation of the service booked for the person concerned.
6. Bookings by third parties and origin of personal data
Not every person we carry contacts us themselves.
Personal data may originate in particular from:
- clients,
- employers,
- assistance and secretarial services,
- hotels and concierges,
- travel agencies and tour operators,
- event agencies,
- companies and public authorities,
- business partners as well as
- other persons or organisations who book or organise a service for the person concerned.
In this context, name, mobile number, e-mail address, pick-up and destination location, travel information and other details required for performance may in particular be transmitted.
In such cases we inform the data subject in accordance with Art. 14 GDPR. This takes place, taking the respective circumstances into account, within a reasonable period, at the latest within one month of receiving the data.
If direct communication with the data subject takes place beforehand, the information is generally provided at the latest at the time of the first communication.
If disclosure to another recipient is envisaged beforehand, the information is provided in accordance with the statutory requirements at the latest at the time of the first disclosure.
This does not apply where the data subject already has the required information or where a statutory exception to the information obligation applies.
7. Chauffeurs, partner and subcontracted companies
To provide our services we may deploy our own employees and chauffeurs as well as external driving service, limousine, hire car, bus and other service partners.
This applies in particular to services outside our own area of operation as well as for larger events, international bookings or capacity peaks.
We generally provide the chauffeurs and partner companies deployed only with those personal data which are required to perform the respective order.
These may include in particular:
- name of the passenger,
- mobile number,
- pick-up and destination location,
- service time,
- travel or flight information,
- agreed intermediate stops as well as
- necessary special service information.
Payment information, credit information or other commercial data not required for the specific performance are generally not made available to chauffeurs and driving service partners.
Depending on the specific allocation of tasks and roles, external companies may act as processors or as independent controllers under data protection law.
8. Special carriage requirements and health data
In connection with a booking, information about special carriage or assistance requirements may be communicated to us in individual cases, for example regarding required accessibility, the carriage of a wheelchair or necessary support measures.
We ask that you provide us only with the information required for the specific planning and performance of the requested service.
In particular, we generally do not need diagnoses or detailed medical information.
We use such information exclusively for planning and performing the respective carriage; it is not combined into profiles, not evaluated for other purposes and only kept on a booking-related basis.
Where such information reveals details about a person’s state of health and therefore constitutes special categories of personal data within the meaning of Art. 9 GDPR, we process it only if, in addition to a legal basis under Art. 6 GDPR, the additional requirements of Art. 9(2) GDPR are also met.
Where processing is based on explicit consent, it takes place on the basis of Art. 9(2)(a) GDPR. Consent given may be withdrawn at any time with effect for the future.
Where another statutory exception under Art. 9(2) GDPR applies in an individual case, processing may take place on that basis.
Special carriage and assistance information is made accessible only to those employees, chauffeurs and, where applicable, partner companies deployed who require this information to perform the specific service.
It is generally not kept operationally available for longer than is necessary for the respective purpose.
9. Location data and GPS tracking of vehicles
Our vehicles deployed in the driving service may be recorded via GPS or tracking systems during business use.
The following may in particular be processed:
- current location of the vehicle,
- route travelled and
- direction of travel.
The location information is used in particular for real-time dispatching, the optimal allocation of vehicles and orders, the coordination of ongoing carriage services, route planning, determining vehicle availability, providing status and arrival information as well as for service-related documentation and invoicing.
Where location data can be attributed to a person in connection with a specific booking, they may constitute personal data.
Processing takes place, where applicable, on the basis of Art. 6(1)(b) or (f) GDPR.
Our legitimate interest lies in particular in the reliable and efficient performance and dispatching of our carriage services.
Vis-à-vis our chauffeurs deployed in the driving service, processing in the employment context takes place on the basis of section 26(1) of the German Federal Data Protection Act (BDSG) in conjunction with Art. 88 GDPR. Here too, tracking serves exclusively vehicle dispatching, resource planning and invoicing, including evidence of journey extensions or delays. Our chauffeurs are informed separately about the processing concerning them.
Access to location data is limited to authorised persons.
Location data are generally stored for 28 days and then deleted, unless their further processing is required in an individual case on account of a specific damage event, a complaint, legal proceedings or another statutory legal basis.
This storage period is necessary because the location data also serve service-related invoicing as well as the subsequent review of journey times, waiting times, journey extensions, delays and other deviations relevant to invoicing. It takes into account the period within which the services concerned are invoiced and queries or complaints regarding invoicing are typically dealt with.
A general automated performance or conduct evaluation of our chauffeurs on the basis of the location data does not take place.
10. Payment processing and credit card data
To handle payments, security authorisations, refunds and other payment transactions, we may use payment service providers.
Depending on the payment method chosen or used, these include in particular:
- PayPal,
- Stripe,
- Saferpay / Worldline,
- Mollie and
- SumUp.
In the course of payment transactions, the following may in particular be processed:
- name of the payer or cardholder,
- invoicing and contact data,
- payment amount,
- payment method,
- card brand,
- truncated or masked card data,
- transaction and authorisation numbers,
- payment status,
- information on refunds,
- failed payments,
- chargebacks as well as
- fraud and security information.
Full credit card numbers and card verification numbers are processed directly by the respective payment service provider and are not stored permanently by us.
Only tokens, reference numbers, masked card data and transaction information are stored in our own systems.
Processing takes place in particular on the basis of Art. 6(1)(b) GDPR for payment processing and, where applicable, Art. 6(1)(f) GDPR for protection against payment defaults, misuse and fraud.
Where a credit card authorisation or reservation of an amount is carried out to secure a booking, the expected service amount as well as a reasonable security amount may be authorised or reserved.
In the case of additional services, waiting times or order extensions, an adjustment or further authorisation may be necessary.
Where the cardholder differs from the contractual partner, we may request suitable evidence or additional confirmations in order to prevent unauthorised use of the card.
11. Credit checks
In the case of certain business relationships, we may obtain information on the creditworthiness and payment default risk of a customer or potential contractual partner before or during a contractual relationship.
A credit check does not take place for every customer.
It may in particular be carried out in the case of:
- new business relationships,
- larger order volumes,
- requested payment by invoice,
- payment terms or credit limits granted,
- outstanding or overdue receivables or
- other specific economic risk circumstances.
For this purpose we may in particular use the following credit agencies:
Creditreform Hamburg von der Decken KG
Wandalenweg 8–10
20097 Hamburg
Germany
SCHUFA Holding AG
Kormoranweg 5
65201 Wiesbaden
Germany
The data processed may include in particular identity and contact data, company information, payment experience, credit information and probability or score values provided by the respective credit agency.
Where personal data are affected, processing takes place in particular on the basis of Art. 6(1)(f) GDPR.
The requirements of section 31 of the German Federal Data Protection Act (BDSG) apply in addition to the use of probability or score values; from 20 November 2026, section 37a BDSG replaces it. Where we base a decision on such a probability value from that date, the data subject has, with regard to that decision, in particular the rights under section 37a(5) BDSG to contest it, to express their own point of view and to obtain a decision by a natural person. Supplementary rights to information regarding the data and criteria used to create a probability value, their weighting as well as the values created and their recipients are governed by section 37a(4) BDSG vis-à-vis the party responsible for creating the probability value.
Our legitimate interest lies in protection against payment defaults as well as in structuring payment terms and business relationships in a manner appropriate to the risk.
Credit information may in particular be taken into account when deciding whether a service is offered against invoice, against advance payment, against credit card security or under other payment or security conditions.
We generally do not take any decision on the establishment, performance or termination of a business relationship solely on an automated basis using a score or credit value.
The credit information is taken into account as one factor within an individual assessment.
12. Contact form, e-mail and other communication
If you contact us via the contact form, by e-mail or by other electronic means, we process in particular the contact, enquiry, booking and communication data you transmit.
Depending on the occasion, processing takes place on the basis of Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR.
Our legitimate interest lies in the efficient and reliable handling of business communication.
Where our contact form contains a declaration stating that the privacy policy has been noted, this declaration serves to document that the data protection information was provided.
It does not constitute consent to processing operations for which another legal basis exists.
For the technical transmission or delivery of the data entered via our contact form to our e-mail system, we use the service Brevo provided by Brevo SAS, 106 boulevard Haussmann, 75008 Paris, France. Brevo processes these data on our behalf on the basis of a contract pursuant to Art. 28 GDPR; the processing takes place within the European Union.
13. Telephone communication
If you contact us by telephone or if we speak to you by telephone in connection with an enquiry, booking or business relationship, the following data may in particular be processed:
- telephone number,
- name,
- time of contact,
- information on the booking or service concerned as well as
- notes on the conversation.
If the telephone conversation relates to the initiation or performance of a contract with the data subject, processing takes place in particular on the basis of Art. 6(1)(b) GDPR.
In the case of other business communication, processing takes place, where necessary, on the basis of Art. 6(1)(f) GDPR.
For our telecommunications we use in particular services provided by:
1&1 Versatel GmbH
Wanheimer Straße 90
40468 Düsseldorf
Germany
Vodafone GmbH
Ferdinand-Braun-Platz 1
40549 Düsseldorf
Germany
as well as Microsoft Teams and Microsoft 365.
Within the scope of their own statutory and contractual responsibility, the telecommunications providers may in particular process telephone numbers, connection times, connection duration as well as technical traffic and connection data.
We generally do not record telephone conversations.
Should a recording be envisaged in an individual case in future, it will take place only in compliance with the statutory requirements and after prior information to the parties to the conversation.
Where consent is required for a recording of a conversation, the recording will only begin after such consent has been given.
14. Microsoft 365
For our business communication and collaboration we use Microsoft 365, in particular Microsoft Exchange or Outlook and Microsoft Teams.
For European business customers, the following entity in particular is
Microsoft Ireland Operations Limited
One Microsoft Place
South County Business Park
Leopardstown
Dublin 18
Ireland
involved in providing the services.
In the course of use, the following may in particular be processed:
- names and contact details,
- sender and recipient information,
- contents of e-mails and other communication,
- attachments and documents,
- appointment and calendar information,
- user and account information as well as
- technical log and diagnostic data.
These may in particular include data of customers, prospective customers, clients, passengers, applicants, employees, partner companies and other business contacts.
Depending on the specific operation, processing takes place in particular on the basis of Art. 6(1)(b), (c) or (f) GDPR as well as, in the case of employee and applicant data, in accordance with the statutory provisions applicable to this.
Where Microsoft processes personal data on our behalf within the enterprise services we use, this takes place in accordance with the requirements of Art. 28 GDPR.
Microsoft has established a so-called EU Data Boundary for numerous enterprise online services.
However, in the course of certain technical, security-related, support or other processing operations, personal data may also be processed outside the European Union or the European Economic Area.
Where a third-country transfer takes place in this context, the requirements of Art. 44 et seq. GDPR apply.
15. LimouERP / LimouSOLUTION / LimouApp
For the central administration and dispatching of our driving services we use software solutions provided by
2S Info & Media Management GmbH
Bürgermeister-Mahr-Straße 32
63179 Obertshausen
Germany.
The following may in particular be processed via these systems:
- customer and client data,
- contact and passenger data,
- enquiries, offers and bookings,
- pick-up and destination locations,
- travel and flight information,
- driver, personnel and vehicle information,
- details of partner and subcontracted companies,
- dispatching and service information,
- status information,
- invoicing and receivables information as well as
- documents and communication information.
Processing takes place in particular for customer and order administration, planning, dispatching, driver and partner communication, performance and documentation of the service as well as invoicing.
Where 2S Info & Media Management GmbH processes personal data on our behalf, this takes place on the basis of a contract pursuant to Art. 28 GDPR.
Access rights are granted according to the respective area of responsibility.
16. Hosting and server log files
Our website is hosted by
Host Europe GmbH
c/o Spaces
Gertrudenstraße 30–36
50667 Cologne
Germany
as our hosting provider.
Host Europe GmbH processes personal data in this context on our behalf on the basis of a data processing agreement pursuant to Art. 28 GDPR.
When you visit our website, the following technical data in particular are processed:
- IP address,
- date and time of access,
- page or file accessed,
- volume of data transferred,
- HTTP status,
- referrer,
- browser type and browser version,
- operating system as well as
- further technical connection information.
The processing serves in particular the technical provision of the website, ensuring stability and security, error diagnosis as well as detecting and preventing abusive access.
The legal basis is Art. 6(1)(f) GDPR.
Our legitimate interest lies in the secure, stable and reliable provision of our website.
Technical server log data are stored for 14 days and then deleted or anonymised.
Where data are required to investigate a specific security incident or to assert or defend legal claims, they may be stored for longer to the extent necessary.
17. Cookies and similar technologies
On our website we use cookies and comparable technologies such as local storage or other storage and access technologies.
Where a technology is strictly necessary in order to provide a digital service expressly requested by you, it may be used without consent in accordance with the statutory requirements.
For storage of, or access to, information on your device that is not strictly necessary, we generally obtain consent pursuant to section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG).
Where personal data are subsequently processed and consent is required for this, processing takes place on the basis of Art. 6(1)(a) GDPR.
Consent given may be changed or withdrawn at any time with effect for the future via the cookie settings of our website.
18. Consent management (cookie settings)
To manage your consent we use our own solution operated on our web server. No external consent management service is integrated; your consent decision is not transmitted to third parties.
When you first visit our website you are shown a notice with three categories:
- Necessary — technically required functions which may be used without consent,
- Statistics — reach measurement, currently Google Analytics 4,
- Marketing — advertising and conversion measurement, currently Google Ads.
Your decision is stored exclusively locally in your browser (local storage). The categories selected and the time of the decision are stored. This information is transmitted neither to us nor to third parties; we do not keep a server-side consent log.
As long as no consent has been given, services requiring consent are not loaded. In particular, the Google Tag Manager is only loaded after consent to the Statistics or Marketing category; until then there is no connection to Google. In addition, we transmit your selection via Google Consent Mode v2, so that the services controlled by the Tag Manager operate only within the scope you have released.
A decision taken under an earlier version of our consent notice is carried over; in that case the request is not shown again.
Your selection can be changed or withdrawn at any time with effect for the future — via the “Cookie settings” link in the footer of every page. If you delete your browser’s local data, the request will appear again on your next visit.
19. Protection against spam and automated access
To secure our website and online forms, we use technical and organisational measures to detect and prevent automated access, spam, abusive use and other security risks.
Technically necessary connection and usage data may be processed in this context.
Where personal data are affected, processing takes place on the basis of Art. 6(1)(f) GDPR.
Our legitimate interest lies in protecting our website, communication systems and business processes against abusive or harmful use.
20. Google Tag Manager
We use the Google Tag Manager on our website.
The provider is in particular:
Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland
The Google Tag Manager serves the technical administration and control of website tags.
Analysis and marketing services in particular can be controlled via the Google Tag Manager.
The analysis and marketing services requiring consent that are controlled via the Tag Manager are activated in accordance with the consent decision you have made.
For this purpose we use a consent-dependent configuration.
Consent given may be changed or withdrawn at any time via the cookie settings of our website.
21. Google Analytics 4
Where you have consented to this, we use Google Analytics 4 for the statistical analysis and improvement of our website.
The provider is in particular:
Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland
The following may in particular be processed:
- pages viewed,
- time and duration of use,
- origin or referrer,
- interactions with our website,
- technical device and browser information,
- approximate geographical information,
- pseudonymous identifiers as well as
- event and conversion information.
The storage of, or access to, information on your device takes place, where necessary, on the basis of your consent pursuant to section 25(1) TDDDG.
The further processing of personal data takes place on the basis of Art. 6(1)(a) GDPR.
Our intended retention period for user-related Google Analytics data is generally 14 months.
In the course of our regular website analysis we do not transmit customer names, e-mail addresses or telephone numbers to Google Analytics.
Functions for the automatic detection or transmission of personal contact data provided by users are not used in our regular use of Analytics.
Consent given may be withdrawn at any time with effect for the future via the cookie settings.
22. Google Ads and conversion measurement
Where you have consented to this, we use Google Ads conversion tracking.
The provider is in particular:
Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland
This allows us to determine whether users carry out certain actions on our website after clicking a Google advertisement, for example submitting an enquiry.
The processing serves to measure and optimise our advertising campaigns.
The legal bases are, where respectively required, section 25(1) TDDDG and Art. 6(1)(a) GDPR.
Under our intended configuration, the corresponding Google tags requiring consent are activated only after the necessary consent has been given.
Consent given may be withdrawn at any time via the cookie settings of our website.
23. Social media presences
We maintain company presences on social networks, in particular:
- Instagram,
- LinkedIn and
- XING.
If you visit our profiles or interact with us there, the respective platform operators may process personal data in accordance with their own data protection provisions.
Where you contact us via a platform, comment on posts or otherwise interact directly with our profile, we also process the personal data transmitted in this context.
Depending on the occasion, processing takes place in particular on the basis of Art. 6(1)(b) or (f) GDPR.
Our legitimate interest lies in communicating with customers, prospective customers and business partners as well as in presenting our company externally.
Where the platform operators provide us with reach and interaction statistics regarding our company profiles (so-called insights), we are joint controllers with the respective operator in this respect within the meaning of Art. 26 GDPR. The essential content of the respective arrangement is made available by the platform operators (Meta/Instagram: “Information about Page Insights”; LinkedIn: “Page Insights Joint Controller Addendum”). You may also exercise your rights as a data subject directly vis-à-vis the respective platform operator.
A mere link to a social media profile does not result in a social media tracking service being activated simply by displaying the link.
Where social media pixels, insight tags or comparable tracking technologies are to be used on our website, they are integrated in accordance with the applicable statutory consent requirements.
24. Direct advertising and communication with existing customers
To the extent permitted by law, we may use personal data of customers and business contacts in order to maintain existing customer relationships, to provide information about our own services or to obtain feedback on services already provided.
For this purpose, name, company, contact details as well as information about the previous business relationship and the services used may in particular be processed.
Where processing is based on explicit consent, it takes place on the basis of Art. 6(1)(a) GDPR.
Where personal data are processed for direct advertising on the basis of legitimate interests to the extent permitted by law, processing takes place on the basis of Art. 6(1)(f) GDPR.
Our legitimate interest lies in particular in maintaining existing customer relationships as well as in providing information about our own services.
For advertising by electronic mail we additionally observe the requirements of section 7 of the German Act Against Unfair Competition (UWG).
Where we use an e-mail address obtained in connection with the provision of a service for our own similar services without separate consent, we do so only if the statutory requirements for this are met.
You may object to the processing of your personal data for direct advertising purposes at any time with effect for the future.
25. Review and feedback requests
After a service has been provided, we may ask customers for feedback or for a review of our service to the extent permitted by law.
Review and feedback requests by e-mail may be classified as advertising under the law.
They are therefore only sent if corresponding consent has been given or if the statutory requirements for permissible communication with existing customers are met.
Where we rely on a statutory exception for existing customers, we observe in particular the statutory requirements regarding the notice of the right to object at any time and free of charge.
We generally do not use contact details of passengers which were transmitted to us exclusively by a client or other third party for the performance of a carriage service for our own review or advertising requests.
Review requests are formulated neutrally and are not made conditional on a positive review being given.
26. Recipients of personal data
Where this is necessary for the respective purpose, personal data may in particular be disclosed to the following categories of recipients:
- responsible employees within our company,
- chauffeurs,
- partner and subcontracted companies,
- hosting, IT, software and communication service providers,
- dispatching and ERP providers,
- payment service providers, banks and card companies,
- credit agencies,
- tax advisors, auditors and lawyers,
- insurers and loss adjusters,
- debt collection service providers,
- public authorities and courts as well as
- other service providers, where their involvement is necessary to carry out the respective operation.
In doing so we observe the principle of making personal data available only to the extent necessary for the respective purpose.
27. Processors and independent controllers
Where a service provider processes personal data exclusively in accordance with our instructions, we conclude – where legally required – a data processing agreement pursuant to Art. 28 GDPR.
However, not every external recipient is automatically a processor.
In particular, payment service providers, banks, credit agencies, insurers or independently operating carriage companies may act under their own data protection responsibility with regard to certain processing operations.
28. International data transfers
Within the scope of our international business, when deploying international driving service partners as well as in the case of certain IT, payment, analysis or communication services, personal data may be transferred to countries outside the European Union or the European Economic Area.
Such a transfer takes place in accordance with Art. 44 et seq. GDPR.
The following in particular may serve as a basis:
- an adequacy decision of the European Commission pursuant to Art. 45 GDPR,
- appropriate safeguards pursuant to Art. 46 GDPR, in particular standard contractual clauses, or
- in the exceptional cases provided for by law, the requirements of Art. 49 GDPR.
Where a transfer is made to a company certified under the EU-U.S. Data Privacy Framework and its certification covers the processing concerned, a transfer may take place on the basis of the corresponding adequacy decision.
In the case of regularly deployed driving service or performance partners in third countries, personal data are generally transferred on the basis of an adequacy decision pursuant to Art. 45 GDPR or using appropriate safeguards pursuant to Art. 46 GDPR, in particular the standard contractual clauses provided by the European Commission, where these are required.
In the case of an individual carriage service in a third country, a data transfer may be necessary so that the carriage booked for the customer or passenger can be performed by a local partner. Where exceptionally no corresponding transfer mechanism exists, a transfer may take place in suitable individual cases under the narrow statutory requirements of Art. 49 GDPR.
Where the data subject is themselves a contractual partner, Art. 49(1)(b) GDPR may in particular apply and, in the case of a contract concluded in favour of a passenger, in particular Art. 49(1)(c) GDPR.
Regular third-country transfers currently take place in particular in connection with the following services: Google (Google Tag Manager, Google Analytics 4, Google Ads) – transfer to Google LLC, USA, on the basis of the adequacy decision on the EU-US Data Privacy Framework; Microsoft (Microsoft 365) – transfer to Microsoft Corporation, USA, on the basis of the EU-US Data Privacy Framework, supplemented by standard contractual clauses.
When using our payment service providers PayPal, Stripe, Saferpay / Worldline, Mollie and SumUp, personal data may also be processed outside the European Union or the European Economic Area, depending on the service used, the payment method and the companies involved. Where a third-country transfer takes place in this context, the requirements of Art. 44 et seq. GDPR apply. Depending on the recipient, adequacy decisions of the European Commission, including the EU-U.S. Data Privacy Framework, or appropriate safeguards such as standard contractual clauses may in particular apply.
Brevo (France) and Host Europe GmbH (Germany) process personal data within the European Union in the context of the services we use. You may request a copy of the respective applicable safeguards using the contact details given in section 3.
29. Storage periods
We generally store personal data only for as long as this is necessary for the respective processing purpose or as long as a statutory retention obligation or another legal basis justifies further storage.
The following principles apply in particular:
Enquiries and offers without a contract
Data from enquiries and offers that were not accepted are generally deleted once it is established that they are no longer required.
As an internal standard period, deletion is generally provided for after approximately twelve months following completion or the last significant communication, unless there is a particular reason for longer storage.
Contractual and business correspondence
Commercial and business letters and corresponding electronic business correspondence are generally stored in accordance with the statutory retention periods.
For such commercial or business letters, the statutory retention period is generally six years.
Not every e-mail automatically constitutes a business letter subject to retention. The content and function of the communication are decisive.
Invoices and accounting records
Invoices, accounting records and comparable documents relevant for tax purposes are generally retained in accordance with the statutory retention obligations.
For such accounting records, a retention period of eight years generally applies.
Books and annual financial statements
For certain commercial and tax law documents, in particular books, annual financial statements and comparable documents, retention periods of ten years generally apply.
Operational passenger data
The fact that certain business documents must be retained for longer does not mean that all personal information must remain visible in the operational driving service system or to chauffeurs throughout that entire period.
Operational access rights and information are restricted or deleted where possible as soon as they are no longer required to perform the respective service.
Location data
For GPS tracking data, the standard storage period of 28 days already mentioned generally applies.
Special carriage and health information
Information about special assistance or health requirements is generally deleted or removed from the operational view as soon as it is no longer required to perform the specific service.
Legal disputes, complaints and damage events
Where personal data are required to assert, exercise or defend legal claims, they may be stored until final clarification and, where applicable, until the expiry of the relevant limitation periods.
30. Applications
If you apply to us for an advertised position or on your own initiative, we process the personal data required for the application and selection procedure.
Applications may be submitted in particular via the application channels provided for this purpose as well as by e-mail to karriere@limousinenservice.de or bewerbung@limousinenservice.de.
In the course of an application procedure, we may in particular process the following personal data:
- name and contact details,
- address,
- date of birth, where provided,
- curriculum vitae and professional career,
- evidence of training, qualifications and previous activities,
- driving licences and other authorisations required for the respective position,
- references and testimonials,
- application photo, where provided voluntarily,
- information about the desired position,
- contents of the communication with the applicant as well as
- other information transmitted in the course of the application.
We ask applicants to transmit only such personal data as are required for the respective application procedure.
Processing takes place for the purpose of reviewing the application, carrying out the selection procedure, communicating with the applicant and deciding on the establishment of an employment relationship.
The legal basis is in particular section 26(1) of the German Federal Data Protection Act (BDSG) in conjunction with the relevant provisions of the GDPR.
Within our company, only those persons have access to applicant data who are involved in carrying out the application and selection procedure or in deciding on filling the position.
If an application does not lead to an employment relationship, we generally store the application documents for six months after completion of the application procedure or notification of the rejection.
Storage after completion of the application procedure takes place, where it serves to assert, exercise or defend legal claims, on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in legal defence and in being able to demonstrate a proper application procedure.
The applicant data are then deleted unless longer storage is required to assert, exercise or defend legal claims or another legal basis permits further storage.
If an employment relationship is established, those data and documents which are required for carrying out the employment relationship are transferred to our personnel administration.
If we wish to retain an application after completion of the specific application procedure for possible later vacancies, we do so only on the basis of an existing legal basis for this, in particular separate voluntary consent.
If applicants are included in an applicant pool, we generally store the relevant application data for a maximum of twelve months, unless a shorter period has been agreed.
Consent given for this purpose may be withdrawn at any time with effect for the future.
Where application documents contain special categories of personal data within the meaning of Art. 9 GDPR, we process these only to the extent that the statutory requirements for this are met.
31. Data security
Taking into account the risk, the state of the art, the costs of implementation as well as the nature, scope and purpose of the processing, we take appropriate technical and organisational measures to protect personal data.
These include in particular measures to:
- ensure confidentiality, integrity and availability,
- grant access rights according to tasks and roles,
- secure user accounts,
- transmit data securely,
- back up and restore data,
- prevent unauthorised access,
- review the systems and service providers deployed as well as
- regularly adapt our security measures.
Our website uses an encrypted HTTPS/TLS connection.
When designing and selecting our systems, we also take into account the principles of data protection by design and by default.
However, absolute protection of electronic data processing against all risks cannot be technically guaranteed.
32. Necessity of providing personal data
Depending on the processing operation, the provision of personal data may be required by law or by contract or may be necessary for the initiation or performance of a contract.
For enquiries, bookings and the provision of our services we require in particular those details without which we cannot plan, offer, perform or invoice the requested service.
Depending on the order, these may include in particular identity and contact data, details of pick-up and destination locations, service time, number of passengers as well as further booking and service information required for the specific performance.
If required data are not provided, this may mean that we:
- cannot fully process an enquiry,
- cannot prepare an offer,
- cannot conclude a contract,
- cannot perform a booked service, or cannot perform it properly, or
- cannot take special service requests into account.
The provision of data beyond this is generally voluntary.
Where processing is based on consent, there is no obligation to give such consent.
Refusing or withdrawing consent does not affect services for the performance of which the processing concerned is not necessary.
33. Automated decisions
We generally do not take any decisions based solely on automated processing within the meaning of Art. 22 GDPR which produce legal effects concerning the data subject or similarly significantly affect them.
This applies in particular to credit decisions.
Credit or score values, where used, are generally taken into account only as one factor within an individual decision.
34. Your data protection rights
Where the statutory requirements are met, you have in particular the following rights with regard to the processing of your personal data:
- right of access pursuant to Art. 15 GDPR,
- right to rectification pursuant to Art. 16 GDPR,
- right to erasure pursuant to Art. 17 GDPR,
- right to restriction of processing pursuant to Art. 18 GDPR,
- right to data portability pursuant to Art. 20 GDPR,
- right to object pursuant to Art. 21 GDPR,
- rights in connection with automated decisions pursuant to Art. 22 GDPR as well as
- rights in connection with probability values from 20 November 2026, where applicable, pursuant to section 37a BDSG.
To exercise your rights you may in particular contact datenschutz@limousinenservice.de.
Withdrawal of consent
Where processing is based on your consent, you may withdraw it at any time with effect for the future.
The lawfulness of the processing carried out on the basis of the consent up to the point of withdrawal remains unaffected.
Consent to cookies, analysis or marketing services may in particular be changed or withdrawn via the cookie settings of the website.
Right to object
Where we process personal data on the basis of Art. 6(1)(f) GDPR, you may object to the processing at any time on grounds relating to your particular situation.
We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.
Where personal data are processed for direct advertising, you may object to processing for this purpose at any time.
Following such an objection, the personal data concerned will no longer be used for direct advertising.
In order to ensure that a declared advertising objection continues to be observed in future, the contact details required for this may be stored on a blocking list.
35. Right to lodge a complaint
Under Art. 77 GDPR you have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes data protection provisions.
On account of its registered office, the authority generally responsible for T&M Limousinen Service GmbH is:
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
Ludwig-Erhard-Straße 22
20459 Hamburg
Germany
Telephone: +49 (0)40 428 54-4040
E-mail: mailbox@datenschutz.hamburg.de
The right to contact another competent data protection supervisory authority in accordance with the statutory provisions remains unaffected.
36. Currency and amendments to this privacy policy
This privacy policy is dated August 2026.
We review our data protection information regularly and adapt it if our processing operations, technical systems, service providers deployed or the legal framework change.
The current version of this privacy policy is available on our website at https://zumflieger.de/en/privacy/.
Where we intend in future to further process personal data for a purpose other than that for which the data were originally collected, we will inform the data subjects about the new purpose and the further information required for this in accordance with the statutory requirements before such further processing.
Where a new or amended processing operation requires consent, that processing will not be carried out solely on the basis of an amendment to this privacy policy, but only after the legally required consent has been given.
Consent already given may be withdrawn at any time with effect for the future in accordance with the statutory provisions.