Version: August 2026
1. Privacy at a glance
General information
The following information provides an overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to identify you personally.
Data controller
Patrick HelmholzLupinenweg 10a
38110 Braunschweig
Germany
Email: info@padditravels.com
2. Data collection on this website
How do we collect your data?
Some data is collected when you provide it to us, for example through the contact form. Other data is collected automatically or with your consent by the IT systems used when you visit the website. This mainly includes technical data such as browser, operating system, and time of access.
SSL and TLS encryption
This website uses SSL or TLS encryption for security and to protect confidential transmissions. You can recognize an encrypted connection by “https://” and the lock icon in your browser.
Hosting via Netlify and server log files
We host this website with Netlify (Netlify, Inc., 512 2nd Street, Suite 200, San Francisco, CA 94107, USA). Netlify automatically collects server log files, including IP address, date and time, browser type, operating system, and referrer URL. The purpose is to provide the website securely, reliably, and efficiently and to prevent abusive access. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is a reliable and secure website. Netlify processes the data as our processor, and we have concluded a data processing agreement with Netlify.
Server log data is retained only for as long as required for operation, security, and troubleshooting and is then deleted unless statutory retention duties or security incidents require longer storage. Processing in the United States cannot be ruled out. According to Netlify, international transfers are based in particular on the EU-US Data Privacy Framework and the European Commission’s Standard Contractual Clauses. Further information: Netlify Privacy.
What do we use your data for?
Automatically collected technical data is used exclusively to provide the website reliably and securely. We currently do not analyze your user behavior.
No automated decision-making or profiling
No solely automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place. We do not create user profiles from data processed on this website.
Contact form
If you contact us via the contact form, we process your name, email address, subject, and message to handle the request and possible follow-up questions. The legal basis is Art. 6(1)(b) GDPR where the inquiry relates to entering into or performing a contract; otherwise Art. 6(1)(f) GDPR based on our legitimate interest in responding to inquiries.
The technical transmission and storage of submissions is handled by Netlify as our data processor. Your data is not disclosed to further recipients for their own purposes. Contact inquiries are deleted no later than six months after they have been conclusively handled, unless statutory retention obligations require longer storage.
Browser storage (LocalStorage)
This website uses your browser’s local storage to retain explicitly selected settings and local content caches. These include the language selection, 2D/3D map view, and locally cached gallery and travel-story data. Storing the language and map preferences restores the website state expressly requested by you (Section 25(2)(2) TDDDG). Content caches improve rendering speed and reduce repeated external requests. Data remains on your device until it is overwritten or deleted through your browser settings.
Interactive world map and 3D globe
The interactive world map and 3D globe are rendered entirely locally in your browser. No external map service is embedded. Location, mouse, or other interaction data is not transmitted to third parties. Only the last selected “2D” or “3D” view is stored locally.
Sanity CMS and image CDN
Travel stories, travel data, video collections, and gallery images are provided via Sanity (Sanity AS, Oslo, Norway, and Sanity US Inc., USA; in particular sanity.io, apicdn.sanity.io, and cdn.sanity.io). Requests may process IP address, time, requested resource, referrer, browser, and device information. The purpose is to provide current published content reliably and efficiently. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the reliable management and delivery of our editorial content. Sanity receives these technical request data and is used as a processor within the scope of the agreed services.
Access logs are deleted according to the retention periods determined by Sanity and the subscribed plan; CDN copies may remain until their respective cache period expires. Sanity may process data in the United States and other countries and, according to its information, uses Standard Contractual Clauses or other permitted safeguards. Further information: Sanity Privacy.
Instagram feed via Feedframer and Google Translate
When the homepage is opened, the Instagram area automatically loads current posts through Feedframer (feedframer.com and cdn.feedframer.com). This transmits data including the IP address, time, requested resource, referrer, browser, and device information to Feedframer. The returned data contains publicly available content from our Instagram profile and may reference media provided by Feedframer or Meta.
When the website is used in German, English Instagram captions are additionally translated through Google Translate (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; translate.googleapis.com). The respective caption, IP address, and technical connection data are transferred to Google. Processing by affiliated companies in the United States cannot be ruled out. Translations are retained in memory only for the current page view and are not stored in the browser.
The recipients of request data are Feedframer and, depending on the media source delivered, potentially Meta, as well as Google for translation. The integration is based on Art. 6(1)(f) GDPR. Our legitimate interest is the current and engaging presentation of our publicly available Instagram content. We do not independently retain the technical connection data generated by these requests. Retention by the recipients is governed by their respective privacy and deletion policies.
Further information: Feedframer Privacy, Meta/Instagram Privacy, and Google Privacy.
YouTube videos
The video overview loads individual preview images directly from YouTube (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; img.youtube.com). In video sections of individual travel stories, the privacy-enhanced YouTube player is embedded via youtube-nocookie.com. A connection to Google is therefore established when the relevant page or video section loads; no prior click is required. This may process IP address, referrer, browser and device information, and details of the requested preview image or video. Playing a video may result in further processing and information being stored on or read from your device.
Google receives the data generated when previews and videos are requested or played. The integration is based on Art. 6(1)(f) GDPR. Our legitimate interest is the clear and engaging presentation of travel videos and travel stories. We do not independently retain the technical connection data generated by YouTube requests. Retention by Google is governed by Google’s privacy and deletion policies. Processing by affiliated companies in the United States cannot be ruled out. According to Google, transfers are based, among other mechanisms, on the EU-US Data Privacy Framework and Standard Contractual Clauses. Further information: Google Privacy.
Recipients, international transfers, and retention
Recipients of personal data are limited to the service providers named in this privacy policy where this is necessary for the purposes described. We do not disclose the data for other purposes of our own. Where data is processed outside the European Economic Area, the relevant providers state that the transfer is based on an adequacy decision, in particular the EU-US Data Privacy Framework for certified companies, or appropriate safeguards such as the European Commission’s Standard Contractual Clauses. You may request information about the safeguards used via the controller’s contact details.
We retain personal data only for as long as required for the relevant processing purpose or while statutory retention duties apply. Data generated exclusively by external recipients is additionally subject to their stated retention and deletion periods. More specific criteria are provided in the relevant sections above.
Locally provided resources
The Inter, Outfit, and Caveat fonts, country flags, the 2D world map, and the 3D globe are loaded from this website. These resources therefore do not create an additional connection to Google Fonts, FlagCDN, or a map provider. YouTube preview images and players are loaded directly from Google as described above.
3. Your rights
Under the applicable statutory provisions, you have the right to:
- access stored personal data, its origin, recipients, and purpose (Art. 15 GDPR),
- rectification of incorrect or completion of incomplete data (Art. 16 GDPR),
- erasure of your stored data (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- withdraw consent with future effect (Art. 7(3) GDPR),
- object to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR),
- lodge a complaint with a competent supervisory authority (Art. 77 GDPR).
Competent data protection supervisory authority
Der Landesbeauftragte für den Datenschutz NiedersachsenPrinzenstraße 5
30159 Hannover
Germany
Phone: +49 511 120-4500
Email: poststelle@lfd.niedersachsen.de
Website: www.lfd.niedersachsen.de
For privacy questions, contact Patrick Helmholz at info@padditravels.com or use the address provided in the Legal Notice.
