Privacy policy
What personal data we process when you use this site or submit a reservation request, why, on what legal basis, and how long we keep it.
Version 1.0 · Last updated: 1 July 2026
1. Controller
The controller for the processing described here is the operator of gedser-rostock.pro. Full company details and postal address appear in the site imprint. Data protection enquiries: [email protected].
2. What we process and why
| Purpose | Data | Legal basis |
|---|---|---|
| Handling a reservation request for a crossing | Name, email, telephone, country of residence, crossing and direction, travel dates, number of travellers per age group (under 18 / 18–64 / 65+), accessibility notes, vehicle type, gross weight, length, height, registration number, notes you write | Performance of a contract or steps prior to it (Art. 6(1)(b) GDPR) |
| Passing the reservation to the ferry operator so the crossing can be performed | The reservation data listed above, to the extent the operator needs it | Performance of a contract (Art. 6(1)(b) GDPR) |
| Operating and securing the website, defending against abuse | IP address, date and time of request, page requested, referrer, browser and operating system data, in server log files | Legitimate interests in a secure, functioning site (Art. 6(1)(f) GDPR) |
| Statistics on how the site is used | Pseudonymous usage data collected via analytics cookies | Your consent (Art. 6(1)(a) GDPR), given in the cookie banner |
| Keeping commercial and tax records | Reservation and correspondence records | Legal obligation (Art. 6(1)(c) GDPR) |
Providing reservation data is voluntary, but without it a reservation cannot be processed. Fields marked as optional in the form may be left blank.
3. Special categories of data
If you tell us that a traveller needs accessibility assistance, that information may indicate a state of health. We process it only to arrange the assistance requested, only with your explicit consent given by submitting the form with that box ticked, and we delete it once the crossing has taken place.
4. Recipients
- Ferry operators performing the crossing you have reserved. Passing the data on is necessary for carriage.
- Hosting and email providers acting as processors under written agreements, providing the servers and mail systems used to run this site.
- Analytics providers, but only if you have consented to analytics cookies.
- Advisers and authorities where we are legally obliged to disclose data.
We do not sell personal data and we do not pass it to third parties for their own advertising.
5. Transfers outside the EU/EEA
Our servers are located within the European Union. Where a processor exceptionally accesses data from a third country, we rely on an adequacy decision of the European Commission or on the EU standard contractual clauses together with additional safeguards. You may request a copy of the safeguards used.
6. Retention
- Reservation data: for the duration of the reservation and afterwards for as long as claims may arise from it, then deleted, unless retention periods under commercial or tax law require longer storage (generally up to ten years for records with accounting relevance).
- Requests that never became a reservation: deleted no later than twelve months after the last contact.
- Server log files: normally deleted or anonymised after a short period, usually within 30 days, unless an incident requires longer analysis.
- Consent records: kept for as long as needed to demonstrate that consent was given.
7. Cookies and local storage
This site uses strictly necessary cookies and local storage to remember your cookie choice and to keep the booking form working. Analytics cookies are set only after consent. Details, categories and storage periods are set out in the cookie policy. You can withdraw or change your choice at any time via cookie settings.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- have inaccurate data corrected and incomplete data completed;
- have data erased where the conditions for erasure are met;
- have processing restricted in the cases provided for by law;
- receive data you provided in a portable format and have it transmitted to another controller;
- object at any time to processing based on our legitimate interests, on grounds relating to your particular situation;
- withdraw consent at any time with effect for the future, without affecting the lawfulness of processing carried out before withdrawal;
- lodge a complaint with a supervisory authority, in particular in the member state of your residence or workplace.
To exercise any of these rights, write to [email protected]. We may ask for information to verify your identity before we act.
9. Automated decision-making
We do not use automated decision-making producing legal effects concerning you, and we do not carry out profiling within the meaning of Art. 22 GDPR.
10. Children
This site is not directed at children. Reservations that include travellers under 18 are made by an adult, who is responsible for the data provided about those travellers.
11. Changes to this policy
We update this policy when the service or the legal framework changes. The current version, with its version number and date, is always published on this page.