This is a courtesy translation. The legally binding version is the German Datenschutzerklärung at /legal/privacy.

1. Data Controller and Contact

The data controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws of the Member States as well as other data protection provisions is:

Lakeside Park Capital GmbH

(hereinafter "we", "us" or "TakeMeTo")

Werinherstr.15, 83684 Tegernsee

Bavaria, Germany

Platform operator: www.takemeto.ai

General requests: [email protected]

Data protection and data subject rights: [email protected]

Data Protection Officer: Claudius Herz, [email protected]

A legal notice with further information (managing directors, commercial register, VAT ID) can be found at www.takemeto.ai/impressum.

2. Scope and Overview

This Privacy Policy informs you about the nature, scope and purpose of the processing of personal data (hereinafter "data") within our online services and the associated websites, features, content, mobile apps and external online presences (e.g. social media profiles), hereinafter jointly referred to as the "online services".

TakeMeTo is an AI-powered travel planning and booking platform that enables you to plan personalised trips, create your individual Travel DNA, share content and complete bookings with third-party providers (airlines, hotels, activity and transfer providers).

The terms used (e.g. "personal data" or "processing") are understood within the meaning of the definitions in Art. 4 GDPR.

3. Legal Bases of Processing

In accordance with Art. 13 GDPR we inform you of the legal bases of our data processing:

  • Art. 6(1)(a) GDPR – consent (e.g. analytics cookies, session recording, newsletter, social media integration)
  • Art. 6(1)(b) GDPR – performance of a contract and pre-contractual measures (e.g. registration, AI chat and travel planning, map display, bookings, payment processing)
  • Art. 6(1)(c) GDPR – compliance with legal obligations (e.g. retention obligations under commercial and tax law)
  • Art. 6(1)(f) GDPR – legitimate interests (e.g. operation, security, reach measurement)
  • Art. 9(2)(a) GDPR – explicit consent, where special categories of personal data are processed in individual cases

In addition, we observe the requirements of the TDDDG (German Telecommunications Digital Services Data Protection Act, which replaced the TTDSG in May 2024), in particular Section 25 TDDDG for cookies and comparable access to your device, and the requirements of the AI Regulation (Regulation (EU) 2024/1689, "AI Act") to the extent these apply to our AI systems.

4. Categories of Data Processed

We process the following categories of data:

  • Master data: e.g. names, addresses
  • Contact data: e.g. email, telephone numbers
  • Content data: e.g. text entries, photographs, uploaded travel content
  • Contract data: e.g. subject of contract, term, customer category
  • Payment data: e.g. bank details, payment history
  • Usage data: e.g. websites visited, interest in content, access times
  • Meta/communication data: e.g. device information, IP addresses
  • Travel and preference data: Travel DNA: travel mood, destination wishes, budget, travel months, travel style, duration, number of travellers
  • AI conversation data: chat messages, AI responses, session logs
  • Identity tags: e.g. "founder", "family traveller", derived from your inputs
  • Location data: where shared
  • Consumption and cost data of the AI functions: model used, number of tokens processed, cost incurred per request

5. Data Subjects

Visitors and users of the online services (hereinafter jointly "users").

6. Purposes of Processing

  • Provision of the online services and their functions
  • Registration, authentication, login identification
  • Creation and maintenance of the personal Travel DNA
  • Generation of AI-powered travel plans and recommendations
  • Execution of bookings with third-party providers
  • Payment processing
  • Communication with users
  • Ensuring platform security, fraud and abuse prevention
  • Reach measurement, product improvement
  • Detection and remediation of errors and outages
  • Billing as well as cost and consumption control of the AI functions
  • Newsletter and product information (with consent)
  • Compliance with legal obligations

7. Registration, User Account and Identification

You can register on our platform by providing personal data. Which data are mandatory or optional is indicated by the input forms. We use this data for authentication (login), contract performance and communication with you.

Legal basis: Art. 6(1)(b) GDPR.

You can withdraw your consent at any time with effect for the future.

8. Travel DNA – Creation of a Personal Travel Profile

On the basis of the data you actively provide to us (entries in forms, chat dialogues with our AI assistant, selection of destinations, interactions on the platform), we create a Travel DNA for you. This includes, among other things:

  • preferred travel pace, style and duration
  • interests, themes and activity preferences
  • preferred accommodation types
  • approximate budget range
  • preferred travel months and departure region
  • traveller identity tags (e.g. "founder", "family traveller")

Legal basis: Art. 6(1)(b) GDPR (performance of contract) and — where going beyond this — Art. 6(1)(a) GDPR.

Profiling (Art. 4(4) GDPR): The creation of the Travel DNA constitutes profiling. However, it has no legal effect and no similarly significant adverse impact within the meaning of Art. 22 GDPR. It serves exclusively to personalise your travel suggestions.

Your rights: You can view the Travel DNA in your profile settings at any time, edit or delete individual tags and attributes. You can also object to the profiling at any time ([email protected]).

9. AI Travel Planning and Data Exchange with AI Third-Party Providers

Our platform (web and mobile app) includes an AI-powered travel planning chatbot that helps you create personalised travel plans and recommendations. For this purpose we share certain data with third-party AI providers and with services that retrieve the underlying travel information.

9.1 Purposes of Processing

(a) Generation of personalised travel recommendations and routes in real time based on your inputs.

(b) Derivation and storage of travel preferences to improve future suggestions.

(c) Quality monitoring, security and prevention of abuse.

9.2 Categories of Data Processed

  • Chat content: your messages in the travel-planning chat as well as AI-generated responses
  • Session metadata: timestamps, session IDs, interaction logs
  • Travel details: destination, dates, budget, preferences, number of travellers
  • Travel planning parameters: travel mood, travel month, departure city, budget range
  • Destination matching inputs: travel style, duration, number of travellers, budget per person, travel month
  • Traveller identity tags: e.g. "founder", "family traveller"; editable and deletable in profile settings
  • Meta/communication data: IP address, device/network information

9.3 Recipients

  • Google LLC (Gemini) – location USA; language model for chat, travel planning and the associated web search. Transfer mechanism: EU-US Data Privacy Framework (DPF) pursuant to Art. 45 GDPR.
  • Anthropic, PBC (Claude) – headquarters USA; language model for individual chat and planning steps. Processing takes place — as contractually assured — on EU infrastructure. For third-country transfers: Standard Contractual Clauses (SCCs).
  • Groq, Inc. – location USA; conversion of your voice input into text. Only the audio recording you made is transmitted, with no reference to your account.
  • SerpAPI – location USA; retrieval of search results for places, accommodation, restaurants, flights and events. The search terms are transmitted, with no reference to your account.
  • Firecrawl – location USA; reading of publicly accessible web pages to determine prices and availability. Only the web addresses to be retrieved are transmitted, with no reference to your account.
  • Open-Meteo (Europe) – weather data for the destination. Only coordinates or the place name of the destination are transmitted, with no reference to your account.
  • OSRM routing service (router.project-osrm.org) – distances between the stops of a route. Only coordinates are transmitted, with no reference to your account.

Clarification: we use neither OpenAI/ChatGPT nor Perplexity. Earlier versions of this policy named these providers; that was incorrect. There is also no ChatGPT app integration.

9.4 Legal Basis

Art. 6(1)(b) GDPR (performance of a contract). The AI-powered travel planning chat is not an additional feature but the service itself that you obtain by using TakeMeTo. Transmitting your inputs to the service providers named in section 9.3 is necessary in order to provide that service and therefore cannot be deselected separately — for the same reason as the map display (section 11.7).

We do not obtain consent for the AI chat. Earlier versions of this policy claimed that we did and presented the function as consent-dependent, although no such choice ever existed; that was incorrect. If you do not agree to this processing, you cannot use the service. Your rights to access, rectification, erasure and data portability remain unaffected (sections 9.6 and 18).

9.5 Retention Periods

  • Conversation data (messages, AI responses, session metadata): you can delete individual chats yourself in the app at any time. If you delete your account, they are irreversibly removed once the 90-day grace period has expired (section 17.2). As long as you keep your account, your chats are retained so that you can access them.
  • Derived travel preference profiles (Travel DNA): until account deletion or until you remove individual entries.

9.6 Your Rights and Control

  • A transmission to the service providers named in section 9.3 takes place only when you submit a request. You decide what you enter into the chat.
  • Data minimisation before every transmission: we pass on only what is necessary for the respective request.
  • Deletion of chat history in the app settings.
  • Full export: directly in the app via the "Export data" button in your profile. You receive a JSON file containing all data stored for your account. Alternatively an email to [email protected] is sufficient.
  • Rights regarding AI chat data (access, deletion, portability): email [email protected] with subject "AI Data Request". Reply within 30 days.

9.7 Safeguards

We conclude data processing agreements (Art. 28 GDPR) with our AI and research service providers and apply appropriate safeguards for international data transfers (Google: DPF; Anthropic: EU processing, additionally SCCs; other US service providers: SCCs — see section 12). Data minimisation is a mandatory principle: to the research, weather and routing services (SerpAPI, Firecrawl, Open-Meteo, OSRM) we transmit search terms, web addresses and coordinates, but neither your name nor your account or contact data.

10. Booking Functions

If you use the booking functions of the platform, you grant us the right to share the travel details required for the booking with the following recipients:

  • Airlines
  • Hotel and accommodation providers
  • Providers of activities, tours and experiences
  • Transfer and mobility services

Only data necessary for the execution of the respective booking are shared (e.g. name, contact data, travel dates, preferences, ID data where applicable for flights, payment references).

Legal basis: Art. 6(1)(b) GDPR (performance of contract).

Location of recipients: varies by provider. For third-country transfers: Art. 49(1)(b) GDPR or SCCs/adequacy decision.

11. Recipients / Disclosure of Data to Third Parties

Overview of the main categories of recipients, legal bases and transfer mechanisms:

Recipient

Data

Legal basis

Location / mechanism

Hetzner Online GmbH (servers, hosting)

Master, contact, content, contract, usage, meta/comm. data

Art. 6(1)(b) / (f) GDPR

Germany

Supabase (database, sign-in, file storage) — operated by ourselves on the infrastructure named above

same data as for hosting

Art. 6(1)(b) / (f) GDPR

Germany

Cloudflare, Inc. (website delivery/CDN, "Turnstile" bot protection, cookieless web analytics)

IP address, timestamp, address requested, browser/device information

Art. 6(1)(b) / (f) GDPR

European data centres; parent company USA

Google LLC (Maps Platform)

IP address, device/browser information, map sections, place search terms

Art. 6(1)(b) GDPR — necessary part of the service, see section 11.7

USA — DPF

Google LLC (Gemini)

Chat content, travel planning data, search queries

Art. 6(1)(b) GDPR — necessary part of the service, see section 9.4

USA — DPF

Google LLC (Tag Manager)

Device data, IP address — loaded only after analytics consent

Art. 6(1)(a) GDPR

USA — DPF

Anthropic, PBC (Claude)

Chat content, travel planning data

Art. 6(1)(b) GDPR — necessary part of the service, see section 9.4

EU/DE, additionally SCCs

Groq, Inc. (speech recognition)

audio recording of your voice input — no account reference

Art. 6(1)(b) GDPR

USA — SCCs

SerpAPI (search results)

search terms for places, accommodation, restaurants, flights, events — no account reference

Art. 6(1)(b) / (f) GDPR

USA — SCCs

Firecrawl (price and availability retrieval)

web addresses to be retrieved — no account reference

Art. 6(1)(b) / (f) GDPR

USA — SCCs

Open-Meteo (weather data)

coordinates of the destination — no account reference

Art. 6(1)(b) GDPR

Europe

OSRM routing service (router.project-osrm.org)

start and destination coordinates for distance calculation — no account reference

Art. 6(1)(b) GDPR

open project service; only coordinates are transmitted

PostHog, Inc. (product analytics)

anonymous or — only with consent — pseudonymous usage events

Art. 6(1)(f) / (a) GDPR

European infrastructure (eu.i.posthog.com)

Stripe (payment processing)

Payment, contract data

Art. 6(1)(b) GDPR

EU/DE, SCCs for third countries

Resend (sending emails, e.g. confirmations, invitations, newsletter)

email address, content of the respective message

Art. 6(1)(b) / (a) GDPR

USA — SCCs

Twilio (notifications via WhatsApp/SMS)

telephone number, content of the notification

Art. 6(1)(a) / (b) GDPR

USA — SCCs

Booking partners (airlines, hotels, activities)

Travel details

Art. 6(1)(b) GDPR

varies by provider

Financial/legal advisers

Financial, contract data

Art. 6(1)(c) / (f) GDPR

EU

11.6 No Advertising Networks, No Third-Party Tracking

We use no advertising networks, no conversion pixels and no session recording by advertising service providers. In particular we use no Google Analytics, no Meta Pixel and no Meta Conversions API and no SmartLook. Earlier versions of this policy named these services including a joint controllership with Meta pursuant to Art. 26 GDPR — that was incorrect. No joint controllership exists.

11.7 Google Maps Platform — a Necessary Part of the Service

Maps, place search and the display of places and routes are provided via the Google Maps Platform of Google LLC (USA). When a map loads, your IP address as well as device and browser information are transmitted to Google; for a place search, additionally the search term you entered.

Until 31 July 2026 the map display was listed in the cookie banner as a separate consent category. We removed that choice because it suggested an option the product did not honour: the map is an inseparable part of travel planning. We therefore no longer obtain separate consent for it. The legal basis is Art. 6(1)(b) GDPR (performance of the user contract). The associated transfer to the USA cannot be deselected — if you do not want it, you cannot use the service. Details of the transfer mechanism are in section 12.

12. Processing Outside the EU/EEA

We transfer data in part to third countries (in particular the USA). This takes place exclusively in compliance with Art. 44 et seq. GDPR.

Transfer mechanisms used:

  • Google LLC (Maps Platform, Gemini, Tag Manager): EU-US Data Privacy Framework (DPF).
  • Anthropic, PBC: processing on EU infrastructure as contractually assured; additionally Standard Contractual Clauses (SCCs).
  • Other service providers based in the USA (Cloudflare, Groq, SerpAPI, Firecrawl, Resend, Twilio, Stripe for third-country elements, PostHog as parent company): Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR or — where the provider is certified — the EU-US Data Privacy Framework.
  • Open-Meteo processes in Europe; for the OSRM routing service we transmit only coordinates with no account reference.
  • The actual processing by PostHog takes place on European infrastructure; Cloudflare delivers our content via European data centres. Our own database and all account, chat and log data stored in it are located in Germany.

Cannot be deselected: both the map display via the Google Maps Platform (section 11.7) and the AI travel planning via the service providers named in section 9.3 (section 9.4) are necessary parts of the service. The associated transfers are based on Art. 6(1)(b) GDPR in conjunction with the mechanism named above in each case and cannot be deselected individually.

The EU-US Privacy Shield, mentioned in earlier versions of this policy, was declared invalid by the CJEU in July 2020 and is no longer relied upon.

In addition, we may process data outside the EEA in individual cases to fulfil contractual obligations, on the basis of your consent, due to legal requirements or out of legitimate interests.

13. Cookies and Similar Technologies

13.1 What are Cookies?

Cookies are small text files that are stored on your device when you visit our website. We use cookies in particular to store sessions and ensure the platform's functionality.

13.2 Categories

Our cookie banner has exactly three categories: necessary (always active, cannot be deselected), analytics and session recording. There are no further options. Legally, the storage and measurement we use is classified as follows:

  • Technically necessary storage (session, login, security, "Turnstile" bot protection by Cloudflare): Section 25(2) no. 2 TDDDG, Art. 6(1)(b)/(f) GDPR. No consent required.
  • Functional storage (language, currency, your consent decision itself): Section 25(2) no. 2 TDDDG, Art. 6(1)(b)/(f) GDPR. These values are required for the service you requested and are not evaluated for analytics purposes.
  • Analytics with recognition (PostHog identifier in localStorage, Google Tag Manager): Section 25(1) TDDDG, Art. 6(1)(a) GDPR. Only with your consent.
  • Session recording (PostHog Session Replay): Section 25(1) TDDDG, Art. 6(1)(a) GDPR. Only with a separate, additional consent; input fields are masked.
  • Anonymous, cookieless measurement (PostHog base measurement, Cloudflare Web Analytics): no information is stored on or read from your device, therefore Section 25 TDDDG does not apply and no consent is required (Art. 6(1)(f) GDPR) — see section 14.
  • We do not use marketing or advertising cookies.

13.3 Consent and Withdrawal

Before any non-necessary storage on your device and before any analytics involving recognition we obtain your consent via our consent banner. There are no pre-ticked boxes, and "Reject all" is available on the first level.

You can withdraw your consent at any time with effect for the future: via the "Cookie settings" entry in the footer of every page, via the cookie settings in the app, or informally by email to [email protected]. After a withdrawal the extended measurement ends and stored identifiers are removed.

Two categories were discontinued as of 31 July 2026. Map display: the map is a necessary part of travel planning, so offering a choice would not have been honest — see section 11.7. Voice output: we have discontinued the feature that read AI responses aloud; no speech synthesis service is embedded any more, so there is nothing left to consent to. Voice input — dictating a message into the chat — is not affected and continues unchanged (section 9.3).

14. Product Analytics, Reach Measurement and Our Own Records

This section describes in full what we record about the use of our service — both via external tools and on our own servers. Advertising or tracking networks are not among them; we do not use any (section 11.6).

14.1 PostHog (product analytics, EU hosting)

For reach measurement and product improvement we use PostHog (PostHog, Inc.; processing via European infrastructure, eu.i.posthog.com). It is used in two stages:

  • Anonymous, cookieless measurement (without consent): as long as you have not given analytics consent, we process exclusively anonymous, aggregated events (e.g. opening a landing page, submitting the waiting-list form). No cookies or comparable information are stored on or read from your device (storage only transiently in memory for the duration of the page visit), no personal profile is created, and the IP address is discarded and not stored. Since no access to your device takes place (Section 25 TDDDG does not apply) and no personal data are stored, no consent is required for this. Legal basis, in so far as any personal reference should exist at all: Art. 6(1)(f) GDPR (legitimate interest in anonymous reach measurement).
  • Extended measurement (only with consent): only with your consent does PostHog store a recognisable identifier in your browser (localStorage), link events across sessions and create — if you additionally consent — pseudonymised session recordings (Session Replay; input fields are masked). Also only after consent do we load the Google Tag Manager. Legal basis: Art. 6(1)(a) GDPR, Section 25(1) TDDDG.

You can withdraw your consent at any time with effect for the future via our consent tool; the extended measurement then ends and stored identifiers are removed. The anonymous, cookieless measurement contains no personal data.

14.2 Cloudflare (delivery, bot protection, web analytics)

Our website is delivered via Cloudflare. In doing so, Cloudflare processes technically necessary connection data (IP address, timestamp, address requested, browser and device information) in order to deliver content and to fend off attacks and automated mass access. During sign-in and on forms, the "Turnstile" bot protection additionally checks whether the request originates from a human. Legal basis: Art. 6(1)(b) and (f) GDPR (provision and protection of the service).

Cloudflare Web Analytics additionally counts page views. In doing so, no cookies are set and no information is stored on or read from your device; no cross-device identifier and no personal profile are created. The evaluation is purely statistical and is viewed exclusively by us in our internal dashboard. Section 25 TDDDG does not apply for want of access to your device; the legal basis is Art. 6(1)(f) GDPR.

14.4 Cost and Token Records of the AI Functions

For every AI request we record which model was used, how many tokens were processed, what costs were incurred and which chat this relates to — in each case linked to your account. We need this in order to bill your credit correctly, to show you your consumption and to detect misuse and cost outliers. Legal basis: Art. 6(1)(b) GDPR (billing of the user contract) and Art. 6(1)(f) GDPR (cost control, misuse detection). These records contain consumption and cost figures, not the text of your messages. They are removed upon final account deletion (section 17.2).

14.5 Error Records of the Processing Chain

If a step of our travel planning processing fails, we store an error entry with timestamp, the step affected, the error message and the error type. Such an entry may also contain the triggering request, that is the information passed within it such as destination, travel dates or your chat input — otherwise an error cannot be reproduced. Credentials and keys are not stored with it. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a functioning service). We keep such entries only for as long as this is necessary for error analysis; upon account deletion the reference to your account is removed and the entry remains without any personal reference. Access is limited exclusively to persons involved in fixing the error.

14.6 Anonymous Time on Page

We count, aggregated per page and per day, how often and how long pages were open. This counter contains no identifier whatsoever — neither to your account nor to your device, no IP address — and permits no conclusions about individual persons. It is kept identically for consented and non-consented visits because it contains no personal data within the meaning of Art. 4(1) GDPR.

14.7 Time of Last Activity

For every account we store when it was last active. We use this to identify inactive accounts, to delimit the scope of a possible security incident and to plan capacity. Only the respective most recent timestamp is stored — it is overwritten, so no activity history is created. Legal basis: Art. 6(1)(f) GDPR.

15. Newsletter

We send newsletters with promotional content only with your express consent using the double-opt-in procedure.

  • Legal basis: Art. 6(1)(a) GDPR, Section 7(2) UWG (German Act Against Unfair Competition).
  • Sign-up: logging (time, IP address, confirmation) as proof.
  • Unsubscribe: at any time via the link in every newsletter or by email to [email protected].

Records of consent are kept for up to three years after withdrawal.

The technical dispatch of the newsletter and of all transactional emails (e.g. confirmations, invitations, notices about your account) is carried out by our service provider Resend; your email address and the content of the respective message are transmitted there (see section 11). Notifications via WhatsApp or SMS are sent via Twilio; your telephone number is transmitted there.

16. Social Media Integrations (Instagram, TikTok, YouTube, Facebook)

16.1 General

When you access embedded content (videos, posts, buttons), personal data (in particular IP address, device/browser information, cookie IDs) may be transferred to the respective providers. Where technically possible we use two-click solutions so that data is only transmitted after your consent.

Legal basis: Art. 6(1)(a) GDPR (consent).

16.2 Instagram

Provider: Meta Platforms Ireland Ltd., Ireland / Meta Platforms Inc., USA. Privacy policy: https://privacycenter.instagram.com/policy. Transfer mechanism USA: DPF.

16.3 TikTok

Provider: TikTok Technology Limited, Ireland / TikTok Ltd.; additional processing in USA, Singapore, possibly China. Privacy policy: https://www.tiktok.com/legal/privacy-policy. Transfer mechanism: SCCs.

16.4 YouTube

Provider: Google Ireland Limited; Google LLC, USA. The embed is served via youtube.com and is loaded only after your click. Privacy policy: https://policies.google.com/privacy. Transfer mechanism USA: DPF.

16.5 Facebook

Provider: Meta Platforms Ireland Ltd., Ireland / Meta Platforms Inc., USA. We embed only individual video posts shared by users, and only after your click. We do not use a Meta Pixel, the Meta Conversions API or a Messenger integration (section 11.6). Privacy policy: https://www.facebook.com/privacy/policy. Transfer mechanism USA: DPF.

17. Retention and Deletion of Data

We store personal data only as long as is necessary for the respective purposes or as long as statutory retention obligations exist.

Category

Guideline

User account / master data

until account deletion

Contract and booking data

up to 10 years (Section 147 AO, Section 257 HGB)

Tax-relevant documents

10 years

Communication data (business)

6 years (Section 257 HGB)

AI conversation data (chats)

until you delete them; at the latest 90 days after account deletion

Travel DNA / preference profiles

until account deletion

AI cost and token records (section 14.4)

until account deletion

Error records of the processing chain (section 14.5)

as long as necessary for error analysis; personal reference removed on account deletion

Anonymous time-on-page counter (section 14.6)

permanently — contains no personal reference

Payment transactions, credit entries, subscription grants

10 years (Section 147 AO, Section 257 HGB) — after account deletion only in pseudonymised form, see section 17.3

Log and security data

30–90 days

Marketing/newsletter consent (proof)

3 years after withdrawal

After the retention periods expire, your data will be deleted or anonymised.

17.1 Deletion of Individual Content

You can delete individual chats, uploaded content and entries of your Travel DNA directly in the app at any time. This deletion takes effect immediately.

17.2 Account Deletion: Grace Period and Final Deletion

You delete your entire account in the account settings. Deletion proceeds in two steps:

  • Immediately: your account is marked as deleted and can no longer be used. Your profile details are anonymised, your email address is blocked from re-registration, and content you published is detached from the account.
  • After 90 days: an automatic job running daily irreversibly removes your personal data from all affected tables of our database, including your sign-in account, your chats, your Travel DNA and the cost and token records. Within the 90 days you can still revoke the deletion; afterwards the data cannot be restored — not even by us.

17.3 Exception: Accounting Records

Excluded from final deletion are payment transactions, credit entries and subscription grants. We are required to retain these records under commercial and tax law (Section 147 AO, Section 257 HGB); Art. 17(3)(b) GDPR therefore exempts them from the right to erasure.

Instead we decouple them from your person: on final deletion the reference to your account is removed and replaced by a pseudonym that permits no conclusions about you. The records then continue to exist only as pseudonymised accounting vouchers and are used exclusively to fulfil this statutory retention obligation — not for analytics, profiling or advertising.

18. Your Rights as a Data Subject

You have the following rights vis-à-vis us regarding the personal data concerning you:

  • Right of access – Art. 15 GDPR
  • Right to rectification – Art. 16 GDPR
  • Right to erasure ("right to be forgotten") – Art. 17 GDPR
  • Right to restriction of processing – Art. 18 GDPR
  • Right to data portability – Art. 20 GDPR
  • Right to withdraw consent given – Art. 7(3) GDPR
  • Right to lodge a complaint with a supervisory authority – Art. 77 GDPR

To exercise these rights please contact [email protected] (data protection matters) or [email protected] (general requests). We will respond to your request within 30 days in accordance with the GDPR.

Access and data portability without going through us: in your profile you will find a button with which you can trigger a full export of your data yourself. You immediately receive a JSON file containing all data stored for your account — account and profile details, chats, Travel DNA, favourites, payment and credit entries, consent decisions as well as the cost and error records described in section 14. If you would prefer to receive the export by email, a message to [email protected] is sufficient.

18.1 Right to Object (Art. 21 GDPR)

You have the right, on grounds relating to your particular situation, to object at any time to processing of personal data concerning you which is based on Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on those provisions.

Where your personal data are processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing; this also applies to profiling to the extent that it is related to such direct marketing. If you object to processing for direct marketing purposes, your personal data will no longer be processed for those purposes.

You can send the objection informally to [email protected].

18.2 Competent Supervisory Authority

As Lakeside Park Capital GmbH has its registered office in Tegernsee (Miesbach district, Bavaria), the data protection supervisory authority competent for us as a non-public body is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA — Bavarian State Office for Data Protection Supervision)

Promenade 18

91522 Ansbach

Germany

Telephone: +49 (0) 981 180093-0

Fax: +49 (0) 981 180093-800

Email: [email protected]

Web: https://www.lda.bayern.de

Without prejudice to your right to contact any other supervisory authority in an EU Member State, in particular the authority of your habitual residence, place of work or the place of the alleged infringement (Art. 77(1) GDPR).

For information — for public-law matters in Bavaria:

Bayerischer Landesbeauftragter für den Datenschutz (BayLfD — Bavarian Commissioner for Data Protection)

Wagmüllerstraße 18, 80538 München

Email: [email protected]

Web: https://www.datenschutz-bayern.de

Note: For Lakeside Park Capital GmbH as a private company, the BayLDA in Ansbach is the relevant supervisory authority; the BayLfD is listed for information only.

19. Automated Decision-Making

Solely automated decision-making within the meaning of Art. 22 GDPR which produces legal effects concerning you or similarly significantly affects you does not take place. The profiling within the Travel DNA and the destination matching serves exclusively to personalise your travel suggestions.

20. Use of Generative AI – Transparency under the AI Act

Our platform uses AI systems to generate travel content and suggestions. In accordance with the transparency obligations under Art. 50 Regulation (EU) 2024/1689 (AI Act) we note the following:

  • Responses from our travel planning chatbot may be AI-generated.
  • AI outputs may contain errors, inaccuracies or fictitious statements; essential booking details must be verified before concluding a contract.
  • We do not perform biometric categorisation, emotion recognition or social scoring within the meaning of the AI Act.
  • We do not use high-risk AI systems within the meaning of Annex III of the AI Act, nor practices prohibited under Art. 5 of the AI Act.
  • AI-generated content is labelled visibly and/or in a machine-readable manner in accordance with Art. 50 of the AI Act.

Please direct reports of AI misconduct or AI-related harm to [email protected].

21. Data Security

We take appropriate technical and organisational measures (TOM) pursuant to Art. 32 GDPR to protect your data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access. These include in particular:

  • Transport encryption (TLS 1.2+)
  • encrypted database storage of sensitive fields
  • access controls on a need-to-know basis
  • regular security updates and penetration tests
  • logging of critical accesses

22. Minors

Our online services are not directed at persons under 16 years of age. Minors may not submit personal data to us without the consent of their legal guardians. If we become aware of such processing, we will delete the data immediately.

23. Changes to this Privacy Policy

We reserve the right to adapt this Privacy Policy in order to bring it into line with changed legal situations or with changes to the service or data processing. We will inform you of material changes in good time in an appropriate manner (e.g. by email or notice in the app).

Updated: 31 July 2026 · Version: 1.1