Privacy
Privacy notice for the TourAPI console and the TourAPI interface
Controller
eMind Software GmbH, Otto-Wels-Straße 12, 52477 Alsdorf, Germany
Phone: +49 2404 5966810, email: info@emind.de
Data protection officer
Meschke-Datenschutzbeauftragter, Am Haarberg 27, 52080 Aachen, Germany, email: info@datenschutz-aachen.de
Purpose
TourAPI is a platform for tour operators to maintain hotel and contract data and to make it available to their sales partners. We process personal data only as far as required to operate, secure and trace the platform.
Data we process
- User account: username, name, role, assigned tour operator; the password only as a secure hash.
- Sign-in and session: a session cookie (technically necessary, valid for at most 12 hours) and a device cookie that recognises a known device to protect against lock-out attempts by others (valid for up to 90 days; we store only a hash). Both cookies can only be read by this application.
- Abuse protection: IP address and time of failed sign-in attempts are kept briefly in memory to slow down attacks.
- Change log: changes to data (who, when, what) are logged so that tour operators can trace them.
- Server logs: when a page is requested, the web server processes technically necessary data (IP address, time, requested address, status code).
- Booking data transmitted by sales partners through the interface is processed on behalf of the respective tour operator.
- The console stores recently opened pages locally in your browser (localStorage); this data does not leave your browser.
Hosting
The platform runs on servers of Hetzner Online GmbH in Germany. Hetzner processes the data on our behalf (Art. 28 GDPR).
API playground on tourapi.com
The public playground sets no cookies. To prevent misuse we log, per request, the time, the shortened IP address (IPv4 shortened to /24, IPv6 to /48), the chosen template and the result, never the form input. Test bookings made in the playground carry fixed test names and contain no personal data.
AI contract assistant (only when enabled)
If a tour operator has enabled the AI assistant, the chat messages and the contract data needed for them are sent to a language model. They are sent via the routing service Requesty (EU endpoint) to a model in a data centre in Germany; storage of the content by the model provider is switched off. If a message contains an e-mail address, phone number or IBAN, the console does not send it. We store conversations and proposals with the respective tour operator so that they can be traced.
No analytics or advertising services and no third-party content are embedded. All transmission is encrypted (TLS).
Legal bases
Art. 6(1)(b) GDPR (performance of the contract with the tour operator or sales partner), Art. 6(1)(f) GDPR (legitimate interest in secure and traceable operation), Art. 28 GDPR for processing on behalf of tour operators.
Retention
Account data as long as the account exists; change log and booking data as long as the tour operator contract exists and statutory retention periods require; session and device cookies as stated above; web server logs 14 days, system logs 30 days.
Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and objection. Please use the contacts above. You may also lodge a complaint with a data protection supervisory authority, in particular the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW).
