Privay policy
Our privacy policy gives you an overview of how your data is processed at DDSG.
Policy
When updating our privacy policy, you are at the heart of what we do.
Protecting the privacy and personal rights of our customers when they visit our website is of crucial importance for ensuring that our services can be used with confidence. When you use the website ddsg-blue-danube.at and its subpages, we process personal data. Naturally, we can and will only use your data if you have given your consent or where this is strictly necessary for the performance of our contracts.
In particular, we are committed to complying with the EU General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG) and applicable e-privacy legislation, which impose strict rules on the processing of personal data. This Privacy Policy is intended to give you a clear and accurate overview of the data processing activities associated with the services offered on our website. It explains which data we collect, for what purposes and how we use the data collected.
INFORMATION PURSUANT TO OUR LEGAL OBLIGATIONS
Data protection information for websites
The protection of your personal data is important to us. We process your data exclusively on the basis of the applicable legal provisions, in particular the General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG) and the Austrian Telecommunications Act 2021 (TKG 2021). Below, we explain which data we process when you visit our website, make a booking or contact us, for what purpose, on what legal basis and for how long.
Controller
The controller responsible for data processing is:
DDSG Blue Danube Schiffahrt GmbH
Schifffahrtszentrum, Handelskai 265
1020 Vienna, Austria
Telephone: +43 1 588 80-0
Email: [email protected]
Company register number: FN 136917z, Commercial Court of Vienna
Data Protection Coordinator and Data Protection Officer
Within DDSG Blue Danube, Mr Harald Markl is our Data Protection Coordinator and your first point of contact for all questions relating to data protection and the exercise of your rights. You can reach him at [email protected] or +43 1 588 80-0.
You can contact our Data Protection Officer, Mr Mag. Christian Kozaczynski, at: Österreichisches Verkehrsbüro AG, Datenschutz, Jakov-Lind-Straße 15, 1020 Vienna, Austria, email: [email protected] Opens in new window, telephone: +43 1 588 00-752.
Principles and Legal Bases
Personal data means any information relating to an identified or identifiable person, such as a name, email address or IP address. We process your data only to the extent necessary for the respective purpose. Depending on the processing activity, we rely on the following legal bases:
- Consent (Art. 6(1)(a) GDPR, Section 165(3) TKG 2021): for example, for newsletters and analytics and marketing cookies. You may withdraw your consent at any time with effect for the future.
- Performance of a contract and steps prior to entering into a contract (Art. 6(1)(b) GDPR): for example, ticket bookings, voucher purchases and quotations for groups and events.
- Legal obligation (Art. 6(1)(c) GDPR): for example, retention obligations under tax and company law.
- Legitimate interests (Art. 6(1)(f) GDPR): for example, the secure and stable operation of the website, responding to enquiries and the establishment, exercise or defence of legal claims. We specify the relevant legitimate interest for each individual processing activity.
Visiting the Website, Hosting and Server Log Files
When you access our website, the following data is automatically recorded in server log files for technical reasons: IP address, date and time of access, page accessed, amount of data transferred, browser type and version, operating system and the previously visited page (referrer).
This data is required to provide the website, ensure its stability and security and protect against attacks. The legal basis is our legitimate interest in providing a secure and functional website (Art. 6(1)(f) GDPR). The log files are deleted after 30 days unless they are required for a longer period to investigate a security incident.
Our website is operated using the following service providers, which process data on our behalf as processors:
- Hosting and delivery of the website and online shop: Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. Vercel uses a firewall to protect against attacks, which evaluates IP addresses and request data.
- Content management system: Sanity AS, Oslo, Norway, for managing website content. Personal data of website visitors is not stored there.
Where data is transferred to the USA in this context, such transfers are based on the EU-US Data Privacy Framework (see Section 13).
Cookies and Consent Management
Our website uses cookies and similar technologies. Cookies are small text files that your browser stores on your device. They do not cause any damage or contain malware.
When you first visit our website, we inform you about the cookies used via a cookie banner. We distinguish between:
- Technically necessary cookies: These are required for the operation of the website, for example to store your cookie preferences, language settings or the contents of your shopping cart. The legal basis is Section 165(3) TKG 2021 in conjunction with our legitimate interest in providing a functional website (Art. 6(1)(f) GDPR). These cookies cannot be disabled.
- Statistics cookies: These help us understand how the website is used. They are only set with your consent (Art. 6(1)(a) GDPR, Section 165(3) TKG 2021).
- Marketing cookies: These are used to show you interest-based offers on other websites and to measure the success of advertising activities. They are only set with your consent.
You can change or withdraw your consent at any time via the cookie settings available through the link at the bottom of the page. You can also delete or block cookies in your browser settings. If technically necessary cookies are disabled, the functionality of the website may be restricted.
To manage your consent, we use the consent management platform provided by Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, Germany, as a processor. In this context, your consent choices as well as technical information relating to the time and device are processed. Your selection is stored on your device and requested again after 12 months. Evidence of consent is stored for 3 years. The legal basis is our legal obligation to provide evidence of consent (Art. 6(1)(c) in conjunction with Art. 7(1) GDPR).
The complete and up-to-date list of all services, including provider, purpose, category and storage period, can be found in the cookie settings, which you can access at any time via the link at the bottom of the page.
Contacting Us
If you contact us via our contact form, by email or by telephone, we process the information you provide, such as your name, email address, telephone number and the content of your enquiry, in order to handle your request and respond to any follow-up questions.
For enquiries relating to bookings, the legal basis is taking steps prior to entering into a contract (Art. 6(1)(b) GDPR); otherwise, the legal basis is our legitimate interest in responding to enquiries (Art. 6(1)(f) GDPR).
We store this data for 6 months after the enquiry has been concluded, provided that no booking is made and no statutory retention obligations apply. We do not disclose this data to third parties without your consent.
Online Shop and Ticket Bookings
In our online shop at ddsg-blue-danube.at, you can purchase tickets, combination tickets and vouchers. In this context, we process the data provided during the ordering process, in particular your name and email address, as well as booked cruises and services, travel date, number and category of passengers, payment status and billing information.
Processing is necessary to handle the booking, send the tickets and provide information about timetable changes or cancellations (Art. 6(1)(b) GDPR). We retain billing information in accordance with our obligations under tax law (Art. 6(1)(c) GDPR, Section 132 BAO).
For combination tickets involving partner companies, we only disclose to the respective partner the data required to redeem the relevant service.
Payment Processing
Payments in our online shop are processed through the payment service provider Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland (“Stripe”). You enter your payment details directly into an input field provided by Stripe. We do not receive this data, but only receive confirmation of payment and information about the selected payment method. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR).
For fraud prevention purposes, Stripe additionally evaluates device and connection data during the payment process, such as the IP address, browser and device type. This processing is based on the legitimate interest in ensuring secure payments (Art. 6(1)(f) GDPR); the Stripe cookies required for this purpose are technically necessary. Stripe acts as an independent controller for fraud prevention and compliance with its own legal obligations, such as anti-money laundering requirements. Stripe may transfer data to Stripe, Inc. in the USA; Stripe is certified under the EU-US Data Privacy Framework. Further information can be found in Stripe's Privacy Policy Opens in new window.
Group, Event and Charter Enquiries, On-Board Catering
For quotations relating to group trips, school excursions, corporate events, weddings or charter cruises, we process the contact and event information you provide, such as organisation, contact person, date, number of participants and menu preferences. The legal basis is taking steps prior to entering into a contract or the performance of a contract (Art. 6(1)(b) GDPR).
Catering services on board our ships are provided by the following contractual partners:
- MS Blue Danube, MS Wien and MS Vindobona (Danube Canal):
JBP Gastronomie GmbH, Handelskai 265, 1020 Vienna - All other ships in Vienna:
JP Donau Catering Gastronomie GmbH, Handelskai 265, 1020 Vienna
Telephone: +43 660 444 6 445
Email: [email protected] - Ships in the Wachau:
Fürst GmbH, Rechte Kremszeile 62a/8, 3500 Krems
Telephone: +43 664 242 80 72
Email: [email protected]
Where you book catering services, such as menus, buffets or combination tickets including meals, we transfer the information required for this purpose, including name, date, cruise, number of participants and menu selection, to the respective catering partner (Art. 6(1)(b) GDPR). The catering partners process this data as independent controllers for the provision of their services.
We only process information regarding allergies or intolerances if you provide it voluntarily and solely for the purpose of preparing the food (Art. 9(2)(a) GDPR).
Newsletter
Our newsletter provides information about current offers, events and news from DDSG Blue Danube. When you subscribe, we process the information provided in the registration form, including at least your email address. After registering, you will receive an email asking you to confirm your subscription (double opt-in). We store the date and time of registration and confirmation as well as the IP address in order to provide evidence of your consent.
The legal basis is your consent (Art. 6(1)(a) GDPR, Section 174(3) TKG 2021). You may unsubscribe from the newsletter at any time using the unsubscribe link in each newsletter or by emailing [email protected]. After you unsubscribe, we delete your data; your email address may be retained on a suppression list for up to 3 years in order to provide evidence of your previous consent (Art. 6(1)(f) GDPR).
For managing subscriptions and sending newsletters, we use Klaviyo, a service provided by Klaviyo, Inc., 125 Summer Street, Floor 6, Boston, MA 02110, USA, as a processor. Klaviyo stores data on servers in the USA. The transfer is based on Klaviyo's certification under the EU-US Data Privacy Framework and, additionally, on the European Commission's Standard Contractual Clauses contained in the data processing agreement (see Section 13). Our newsletters contain tracking pixels and personalised links. Klaviyo uses these to analyse whether and when a newsletter was opened and which links were clicked in order to improve sending times and content. This analysis forms part of your consent to receive the newsletter and ends when you unsubscribe.
Klaviyo registration forms and a Klaviyo script are integrated into our website. These use cookies that allow Klaviyo to associate website visits with registered newsletter recipients and are only loaded after you have given your consent via the cookie banner. Further information can be found in Klaviyo's Privacy Policy Opens in new window.
Competitions and Social Media Profiles
Competitions: When you participate in a competition, we process your participation data, such as your name, profile name, email address and, if you win, your postal address, for the purpose of administering the competition and notifying winners (Art. 6(1)(b) GDPR). The data is deleted once the competition has ended and the prizes have been delivered, and no later than 3 months thereafter. Competitions on Facebook or Instagram are not affiliated with Meta; the recipient of the data is DDSG Blue Danube Schiffahrt GmbH. The applicable terms and conditions of participation apply.
Social media profiles: We maintain profiles on Facebook and Instagram (Meta Platforms Ireland Ltd.), YouTube (Google Ireland Limited), LinkedIn (LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland) and TikTok (TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland). Our website merely contains links to these profiles. When you click on one of these links, you are redirected to the respective network. Only then does the respective operator collect data in accordance with its own terms and policies. For statistical data relating to our Facebook page and Instagram profile, we are joint controllers with Meta Platforms Ireland Ltd., Merrion Road, Dublin 4, Ireland (Art. 26 GDPR). The same applies to statistics relating to our LinkedIn company page, for which we are joint controllers with LinkedIn Ireland Unlimited Company. We process messages and comments that you send to us through these platforms on the basis of our legitimate interest in communicating with our guests (Art. 6(1)(f) GDPR). Information about processing by the respective platform operators can be found in their privacy policies.
Web Analytics and Marketing
With the exception of Vercel Web Analytics, we only use the following services if you have given your consent via the cookie banner (Art. 6(1)(a) GDPR, Section 165(3) TKG 2021). Without your consent, no data is transferred to these providers.
Google Analytics 4: The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics generates pseudonymous usage statistics, such as pages viewed, time spent on the website, device type and approximate location. IP addresses are truncated within the EU and are not stored. The data is deleted after 14 months.
Google Tag Manager: We use this tool from Google Ireland Limited to manage the integration of analytics and marketing services. Google Tag Manager itself does not set cookies; it only loads additional services after you have given your consent.
Google Ads and conversion tracking: We measure whether a booking resulted from one of our advertisements and may display advertisements to you on other websites (remarketing). The provider is Google Ireland Limited. Cookie storage period: up to 90 days.
Meta Pixel: The provider is Meta Platforms Ireland Ltd., Merrion Road, Dublin 4, Ireland. The pixel measures the success of advertisements on Facebook and Instagram and enables the creation of target groups. Cookie storage period: up to 90 days.
Vercel Web Analytics: We use Vercel Web Analytics from Vercel Inc. (address as stated in Section 4) to measure page views. The service does not set cookies and does not store information on your device. Visits are counted using a verification value generated from request data, which is discarded after 24 hours; recognition across multiple days or websites is not possible. The data collected includes the page accessed, referrer, country, browser, operating system and device type. The legal basis is our legitimate interest in privacy-friendly reach measurement in order to improve our website (Art. 6(1)(f) GDPR).
When using services provided by Google, Meta and Vercel, data may be transferred to the USA (see Section 13). You can withdraw your consent at any time via the cookie settings available at the bottom of the page.
Recipients and Transfers to Third Countries
We only disclose your data where this is necessary for the purposes described above, where we are legally obliged to do so or where you have given your consent. Recipients may include:
- IT service providers for hosting, consent management, newsletter distribution and applicant management, acting as processors contractually bound to confidentiality
- Payment service providers and banks for processing payments
- Catering and cooperation partners where you have booked their services
- Tax advisers, auditors and legal representatives for compliance with legal obligations or the establishment, exercise or defence of legal claims
- Authorities and courts where disclosure is legally required
Some of our service providers are based outside the European Economic Area (EEA), particularly in the USA. For certified companies in the USA, the European Commission has adopted an adequacy decision under the EU-US Data Privacy Framework (Art. 45 GDPR). Where this does not apply, we base the transfer on the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR). A copy of these safeguards is available on request at [email protected].
The providers concerned are Vercel Inc. (hosting, Web Analytics), Klaviyo, Inc. (newsletter), Google LLC (Google Analytics, Tag Manager, Google Ads), Meta Platforms, Inc. (Meta Pixel) and Stripe, Inc. (payment processing). All of the companies listed are certified under the EU-US Data Privacy Framework. The list of certified companies is available at dataprivacyframework.gov.
Storage Periods
We store your data only for as long as necessary for the respective purpose or for as long as statutory retention obligations apply. It is then deleted or anonymised.
- Server log files: 30 days; reason: security and operation
- Contact enquiries without a booking: 6 months after completion; reason: follow-up questions
- Booking and billing data: 7 years from the end of the calendar year; reason: Section 132 BAO, Section 212 UGB
- Booking data relating to outstanding claims: until expiry of the limitation period, generally 3 years; reason: establishment, exercise or defence of legal claims
- Newsletter data: until unsubscribing; reason: consent
- Evidence of newsletter consent: 3 years after unsubscribing; reason: obligation to provide evidence
- Cookie consent: 12 months, with evidence retained for 3 years; reason: obligation to provide evidence
- Competition data: until the prize has been delivered, maximum 3 months; reason: administration of the competition
- Application documents: 7 months after rejection; reason: limitation period under the Austrian Equal Treatment Act
Obligation to Provide Data and Automated Decision-Making
Our website can be used without providing personal data. For a booking, voucher purchase or the processing of an enquiry, we require the information marked as mandatory. Without this data, we cannot conclude the contract or process your enquiry. There is no statutory obligation to provide this information.
No automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place.
Your Rights
You have the following rights in relation to the personal data we process about you:
- Access to the data stored about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure, provided that no statutory retention obligation prevents deletion (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability in a commonly used, machine-readable format (Art. 20 GDPR)
- Objection to processing based on our legitimate interests (Art. 21 GDPR); you may object to direct marketing at any time without stating any reason
- Withdrawal of consent at any time with effect for the future (Art. 7(3) GDPR); the lawfulness of processing carried out before withdrawal remains unaffected
To exercise your rights, please contact [email protected]. We will respond to your request within one month. To protect your data, we may request proof of your identity.
Right to lodge a complaint: If you believe that the processing of your data infringes data protection law, you may lodge a complaint with us or with the competent supervisory authority.
In Austria, the competent authority is:
Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
Barichgasse 40–42
1030 Vienna, Austria
Telephone: +43 1 52 152-0
Email: [email protected]
www.dsb.gv.at Opens in new window
Data Security
We protect your data through appropriate technical and organisational measures against loss, manipulation and unauthorised access. The transmission of data between your browser and our website is encrypted using TLS, as indicated by the padlock symbol and “https”. Access to personal data is limited to employees who require it to perform their duties.
Applications and Whistleblowing System
Applications: We accept applications through our recruitment portal, which is operated by rexx systems GmbH, Süderstraße 75–79, 20097 Hamburg, Germany, as a processor. We process your application documents, such as contact details, CV, references and cover letter, for the purpose of conducting the recruitment process (Art. 6(1)(b) GDPR). Only those persons involved in the recruitment process have access to the data. If no employment relationship is established, we delete the documents after 7 months in order to defend against any potential claims under the Austrian Equal Treatment Act. Longer retention for future vacancies takes place only with your consent. The privacy information provided in the recruitment portal also applies.
Whistleblowing system: A whistleblowing platform operated by the Wien Holding Group is available for reports under the Austrian Whistleblower Protection Act. Information on data processing can be found on our Compliance page.
Changes to this Privacy Policy
We update this Privacy Policy whenever our data processing activities or the applicable legal requirements change. The version currently published on this page applies.
Last updated: September 2026
