Privacy Policy
Last updated: 03.08.2026
This English text is a convenience translation. In case of discrepancies, the German version prevails.
General Part
Introduction
Protecting your personal data is important to us. With this privacy policy we inform you which types of personal data (“data”) we process in connection with our online offering at www.museumsuferfest.de (the “website”), for which purposes and to what extent.
Controller
Publisher
Tourismus- und Congress GmbH Frankfurt am Main
Kaiserstraße 56
60329 Frankfurt am Main, Germany
Phone +49 (0) 69/24 74 55 - 400
Fax +49 (0) 69/24 74 55 - 379
E-mail: info@infofrankfurt.de
Authorised representative
Pursuant to Sec. 7(3) of the articles of association, the Managing Director represents the company in all judicial and extrajudicial matters. Managing Director: Thomas Feda
Further information
A company of the City of Frankfurt am Main
Chair of the Supervisory Board: Lord Mayor Mike Josef
Registered office: Frankfurt am Main
Register court: Local Court Frankfurt am Main, HRB 40156
VAT ID: DE 172998552
Data Protection Officer
Our Data Protection Officer is MFM Datenschutz-Consulting GmbH, Kaiser-Friedrich-Promenade 6, 61348 Bad Homburg vor der Höhe, Germany. Contact: datenschutz@datenschutzfrankfurt.de
Overview of Processing
Types of data: usage data (pages visited, interests); meta data (IP address, browser and device information); content data (form entries); contact data (e-mail, phone, address).
Categories of data subjects: users of the website; interested parties; persons who contact us.
Purposes: provision of the online offering; security; handling of enquiries and communication; reach measurement/analysis and interest-based and behaviour-based (re)marketing and conversion measurement (each only with consent).
Legal Bases
- Consent (Art. 6(1)(a) GDPR).
- Performance of a contract and pre-contractual measures (Art. 6(1)(b) GDPR).
- Legal obligation (Art. 6(1)(c) GDPR).
- Legitimate interests (Art. 6(1)(f) GDPR).
- Storage of / access to information on the terminal device with consent (Sec. 25(1) TDDDG).
- Strictly necessary storage of / access to information on the terminal device (Sec. 25(2) no. 2 TDDDG).
Security Measures
We take appropriate technical and organisational measures in accordance with Art. 32 GDPR. In particular, we use SSL/TLS to encrypt the transmission of data between your device and our server.
Transfer of Personal Data to Third Parties
In the course of our processing, data may be transferred to other parties. Recipients may include IT service providers (hosting, image and map delivery) and — after your consent — providers of analytics and marketing services. With processors we conclude agreements pursuant to Art. 28 GDPR. We disclose data to public authorities only where legally required.
Processing in Third Countries
Where we have data processed in a third country (in particular the USA; Google, Meta — each only after consent), this is done in accordance with Art. 44 to 49 GDPR. The transfer is based on the adequacy decision for the EU–US Data Privacy Framework where the recipient is certified, and additionally on the European Commission’s Standard Contractual Clauses (Art. 46 GDPR) together with supplementary safeguards.
General Note on Data Erasure
We erase data as soon as a consent is withdrawn or other legal grounds cease to apply, unless statutory retention obligations require further storage. Cookie lifetimes are shown per service in the consent manager.
Specific Part
Website Core Functions (Server Log Files)
When you access our website for information only, we collect the data your browser transmits by default: the page accessed, date and time, volume of data transferred, referrer where applicable, browser, operating system and IP address.
Purpose: stability, functionality and security of the website. Legal basis: Art. 6(1)(f) GDPR; Sec. 25(2) no. 2 TDDDG.
Hosting / technical implementation: [destination.data GmbH / neusta — processor, Art. 28 GDPR; confirm provider and address].
Interactive Map (self-hosted)
Programme and location information is displayed on an interactive map. The map is delivered from our own servers; no request is made to an external map provider. The information on server log files applies.
Use of Cookies
A “cookie” is a small text file stored on your device that serves to recognise the device beyond a single request-response cycle. The cookies we use are listed below.
Strictly necessary cookies
The request to set the following cookies is transmitted on first access to a page.
| Name | Domain | Explanation | Lifetime |
|---|---|---|---|
| custom_consent_google_ads | .museumsuferfest.de | documents your consent/refusal | 29d 23h |
| custom_consent_google_analytics | .museumsuferfest.de | documents your consent/refusal | 29d 23h |
| custom_consent_meta | .museumsuferfest.de | documents your consent/refusal | 29d 23h |
| Usercentrics consent cookie | .museumsuferfest.de | stores your consent decision | [add lifetime] |
Data processed: usage, meta and communication data. Data subjects: users of our website. Legal basis: these cookies are strictly necessary for operating the website and documenting consent, Art. 6(1)(f) GDPR and Sec. 25(2) no. 2 TDDDG.
Optional cookies
We set the following cookies only after you have given your consent. Legal basis: consent (Art. 6(1)(a) GDPR) and Sec. 25(1) TDDDG.
| Name | Provider | Purpose | Lifetime |
|---|---|---|---|
| _ga | distinguishes website visitors (client ID) | up to 2 years | |
| _ga_<ID> | session assignment per GA4 property | up to 2 years | |
| _gcl_au | Google Ads conversion attribution | approx. 90 days | |
| _fbp | Meta | Meta Pixel — event attribution | approx. 90 days |
Objection: You can withdraw your consent at any time with effect for the future via the “Cookie settings” link on this website.
Use of Device Storage
We use the storage areas provided by your browser (sessionStorage, localStorage) only to the extent technically necessary. Legal basis: Sec. 25(2) no. 2 TDDDG.
Contact
If you contact us by e-mail or via a contact form, we process the contact and content data you provide as well as your IP address in order to handle your enquiry. Legal basis: Art. 6(1)(b) GDPR (where a contract is involved) or Art. 6(1)(f) GDPR.
External Service Providers and Processors
destination.one GmbH – image/media delivery (CDN)
To deliver image material efficiently we use the service img.destination.one. Request data (including your IP address) is processed.
Legal basis: Art. 6(1)(f) GDPR; processing agreement under Art. 28 GDPR. Provider: destination.one GmbH, [add address], EU.
Usercentrics GmbH – consent management
This website uses the consent technology of Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, Germany, to obtain and document your consent. Transmitted are your consent(s)/withdrawal, IP address, browser and device information and the time of your visit; a consent cookie is also stored.
Legal basis: Art. 6(1)(c) in conjunction with Art. 7 GDPR; Sec. 25(2) no. 2 TDDDG.
Google Ireland Ltd. – only after consent
Legal basis in each case Art. 6(1)(a) GDPR and Sec. 25(1) TDDDG. Provider: Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, USA). For third-country transfers see the general part.
- Google Tag Manager: tool for managing and deploying further tags; processes usage and meta data. Domains: www.googletagmanager.com (incl. subdomains).
- Google Analytics 4: reach analysis; processes a pseudonymous client ID, a shortened IP address, pages accessed, dwell time, referrer and approximate region (cookies _ga, _ga_<ID>). Domains: analytics.google.com, region1.google-analytics.com, www.google-analytics.com (incl. subdomains).
- Google Ads – conversion tracking and remarketing: measurement of advertising effectiveness and interest-based (re)marketing via pseudonymous user profiles. Domains: www.google.com, googleadservices.com, doubleclick.net (incl. subdomains).
Meta Platforms Ireland Limited – Meta/Facebook Pixel – only after consent
We embed the Meta Pixel to evaluate the effectiveness of advertisements on Facebook/Instagram for statistical and market-research purposes and to optimise future advertising. Event data (e.g. page view) is transmitted to Meta and the cookie _fbp is set.
Joint controllership (Art. 26 GDPR): for the collection and transmission of data to Meta we are jointly responsible with Meta (basis: Meta “Controller Addendum”); for Meta’s subsequent own processing, Meta is solely responsible. Data may be transferred to the USA; Standard Contractual Clauses of the European Commission are in place for this.
Legal basis: consent (Art. 6(1)(a) GDPR, Sec. 25(1) TDDDG). Provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland (parent company: Meta Platforms, Inc., One Hacker Way, Menlo Park, CA 94025, USA).
External Platforms (links to social media)
Our website embeds social networks only in the form of links. Data is transmitted to the respective platform only when you actively click the link. We maintain profiles on Instagram and Facebook (Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland). The platform operators are responsible for processing on their platforms; data may be processed outside the EU. Details are available in the providers’ privacy notices.
Rights of Data Subjects
- Right to object (Art. 21 GDPR): you may object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(e) or (f) GDPR. You may object to direct marketing at any time.
- Right of access (Art. 15 GDPR).
- Right to rectification (Art. 16 GDPR).
- Right to erasure and restriction (Art. 17, 18 GDPR).
- Right to data portability (Art. 20 GDPR).
- Right to withdraw consent (Art. 7(3) GDPR): with effect for the future, e.g. via “Cookie settings”.
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR): in particular the Hessian Commissioner for Data Protection and Freedom of Information, Postfach 3163, 65021 Wiesbaden, Germany, poststelle@datenschutz.hessen.de.
Glossary
Personal data (Art. 4(1) GDPR), processing (Art. 4(2) GDPR), controller (Art. 4(7) GDPR) and processor (Art. 4(8) GDPR) as defined by law. Click tracking allows tracing whether and which button a user clicked and where that click led.