Privacy Policy
Privacy Policy - Vienna Sightseeing Tours
1. Privacy notices
Version: June 2026
Your privacy is important to us. This notice explains how Vienna Sightseeing collects and uses your data. Our aim is to provide you with the best possible booking experience.
2. Data controller
VIENNA SIGHTSEEING TOURS - Wiener Rundfahrten GmbH & Co. KG
Opernring 3-5, Top 508-529, 1010 Vienna, Austria
Phone: 0043 (0)1 712 46 83 - 0
Fax: 0043 (0)1 714 11 41
Website: www.viennasightseeing.at
Email: office(at)viennasightseeing.at
Further information about our company can be found in the legal notice on our website.
No data protection officer has been appointed, as this is not required by law.
3. General information on data processing - data minimisation
3.1 General information
In our privacy notices we inform you about the most important aspects of data processing in the course of our activities as a provider of city tours and tours in and around Vienna, namely:
- the organisation of tour programmes;
- our HOP ON HOP OFF service;
- the administration and sale of our sightseeing card Vienna PASS and Flexi PASS; and
- additional processing activities:
- client and supplier management;
- public relations and marketing for our own purposes;
- image processing at events;
- functionalities of our website;
- our newsletter; and
- customer surveys.
3.2 Data minimisation
We collect and process only the personal data that are required to fulfil our contractual, statutory and service-related obligations. In accordance with Article 5(1)(c) GDPR, we comply with the principle of data minimisation. This means that:
- only data that are strictly necessary for the respective purpose are collected;
- data that are no longer required are deleted or anonymised without delay, subject to statutory retention periods; and
- additional data are collected only on the basis of express consent, where such consent is required.
We regularly review the stored data to ensure that the scope of processing remains appropriate and complies with the applicable legal requirements.
3.3 Retention periods
We store personal data only for as long as this is required for the respective purpose or prescribed by law. Specific periods:
- Booking and contract data, including PASS services: 7 years (tax and accounting retention obligations).
- Payment information: until the end of the following year after completion of the transaction, unless longer statutory obligations apply.
- Enquiries submitted via contact forms: 1 year after final processing.
- Newsletter data: 3 years after the last active contact (opt-in/withdrawal remains possible at any time).
4. Purposes of processing operations
4.1 Processing operations
We carry out the following processing operations which are relevant for you as a customer, affiliate partner, client, natural person acting as contact person of clients and affiliates, supplier and contractor, marketing contact, newsletter subscriber or website visitor:
- tour management and processing;
- administration, sale and reimbursement in connection with our sightseeing card Flexi PASS;
- supplier and client management for sales, purchasing and back office processes;
- contact forms on the website for answering enquiries;
- call centre;
- contact database based on public sources or business cards;
- public relations to present our activities;
- marketing including customer surveys to inform customers and interested persons and to acquire customers, based on your consent;
- information on products and events by electronic mail to existing contacts based on our legitimate interest in providing information about our offers; and
- newsletter for maintaining and informing existing B2B contacts based on our legitimate interest in providing information about our offers.
4.2 Information collected from you
In order to provide you with better service, we collect information from you. This information may identify you directly or indirectly. In some cases, the information we require constitutes personal data that enable you to use certain services on our website. For example, if you make a booking on our website, we ask you for personal data such as first and last name, email address, billing address and hotel name as well as payment information such as credit card number, expiry date and security code. We use this information for billing and transaction purposes. If problems arise in processing the order, we use this information to contact you. We also use the information to ensure successful performance of the service.
4.3 Contract processing and statutory retention
As controller, we process the data disclosed by you in the course of concluding a contract for the duration of the contractual relationship for contract performance or pre-contractual steps, for example in the case of enquiries about our products or services (Article 6(1)(b) GDPR), and thereafter for as long as tax and accounting provisions require this (Article 6(1)(c) GDPR). The accounting retention obligations are 7 years (§ 132(1) BAO and § 11(2), third subparagraph, UStG). In addition, processing operations may also be based on our legitimate interest or the legitimate interest of a third party (Article 6(1)(f) GDPR), provided that such processing is not covered by any of the above legal bases. A legitimate interest may, according to the European legislator, be assumed where the data subject is a customer of the controller, for example for direct marketing purposes.
4.4 Operation of the website (server log files)
When you access our website, your browser automatically transmits information to our web server, where it is temporarily stored in server log files. This includes in particular: IP address of the requesting device, date/time, requested URL/file, HTTP status code, amount of data transferred, referrer URL, browser used including version and operating system.
Purposes: ensuring connection setup and system security, misuse/fraud prevention, error analysis and technical administration.
Legal basis: Article 6(1)(f) GDPR (legitimate interest in the security and stability of our website).
Recipients: our hosting service provider as processor (Article 28 GDPR).
Retention period: maximum 3 months, then deletion; longer storage only on an event-related basis for evidence preservation in the event of security incidents.
Note: Where technically possible and appropriate, the IP address is shortened/anonymised. No combination with other data sources takes place.
4.5 HopPlay - web-based add-on to HOP ON HOP OFF tickets
HopPlay is a web-based add-on to certain HOP ON HOP OFF tickets. No app installation is required. HopPlay can be accessed via a link or QR code in the browser of the user's device.
No registration, email address or user account is required for HopPlay. Entry of an access code may be required for activation. To provide and use HopPlay technically, we process technically necessary data and pseudonymised usage data.
In particular, the following data may be processed:
- access code or pseudonymised ticket or session ID;
- IP address, time of access, browser and device data;
- technical log data and error data;
- information on the start and use of individual game functions, in particular questions played, selected answers, game progress and results;
- information on the redemption of coupons displayed in the game;
- language settings and other technical game settings;
- location data, where the user has enabled location sharing in the browser or device and this is required for GPS-controlled game functions;
- technically necessary cookies or local storage for continuing the session, recognition within HopPlay, misuse prevention, stability and billing.
Technical recognition serves exclusively to enable the game session, validate the access code, prevent multiple or abusive use, analyse technical errors and enable billing of use. HopPlay does not use registration, email entry or a user account. The processing is not carried out for advertising purposes, cross-site tracking or the creation of personal user profiles.
The legal basis for processing technically necessary data for providing HopPlay and billing its use is Article 6(1)(b) GDPR where HopPlay is part of the booked ticket or was purchased as an add-on. Where we process data for system security, error analysis, stability, misuse prevention and technical administration, we rely on our legitimate interest pursuant to Article 6(1)(f) GDPR.
Where individual functions require permission via the browser or operating system, in particular location permission, this permission is granted by the user on the respective device. Without location permission, GPS-controlled game functions cannot be used or can only be used to a limited extent. Exact location histories are not stored. Location data are processed only insofar as this is technically necessary for the respective game function.
Where maps or location functions are displayed in HopPlay via Google Maps, Google Maps may be integrated as a technical service. Further information can be found in our cookie information and in the settings available there.
For the technical implementation of HopPlay we use The Brand Father B.V. as processor. Hosting and technical infrastructure are generally provided within Europe in accordance with the data processing agreement concluded with The Brand Father B.V. Further subprocessors are used only in accordance with the contractual arrangements.
Pseudonymised ticket and session data relevant for billing are generally stored until 90 days after the end of the month. Technical security and error logs are generally stored for up to 90 days. Longer storage takes place only where this is necessary to clarify specific technical incidents, establish, exercise or defend legal claims, or comply with statutory obligations.
Further information on technically necessary cookies or local storage in connection with HopPlay can be found in our cookie information.
Your rights as a data subject are set out in section 10 of this privacy policy.
5. Categories of recipients
5.1 Recipients
In the course of processing operations, we transfer data to the following categories of recipients, where the recipients act on our behalf or the transfer is necessary to fulfil contractual or statutory obligations; for specific processing operations we identify specific recipients here:
- business partners and third parties involved or intended to be involved in business processing (e.g. tax advisers, auditors, liability and legal expenses insurers, other insurance undertakings, notaries, translators, lawyers);
- banks, credit card companies and payment service providers (PayPal, Adyen, VISA, Mastercard, Maestro, Google Pay, Apple Pay, Alipay, JCB, EPS, SEPA, Union Pay, Discover, DinersClub, WeChat Pay) and further payment service providers with whom we have concluded data processing agreements for payment processing;
- processors in IT and communication services (Palisis AG, software support, marketing service providers, network support and server/client support, email service providers and telephone service providers);
- authorities, where applicable upon request.
5.2 Disclosure obligations
In certain situations, we are legally obliged to disclose your data. This may be based on statutory requests by authorities concerning national security or law enforcement, or to protect the rights, property or safety of Vienna Sightseeing or others. This also includes customer fraud and misuse of the system, without being limited to those cases. We may also transmit customer data to third parties such as credit card institutions for the purpose of settling disputes.
5.3 International transfers
We do not intend to transfer data to international organisations or recipients in third countries. If a transfer to recipients in third countries should be necessary, it will take place on the basis of sufficient safeguards, such as standard contractual clauses, or under an adequacy decision.
6. Public forums
On our website we operate a publicly accessible blog and review functions. Please note that any information you publish in these areas may be read, stored and further used by third parties. By submitting a post, you consent to its publication (legal basis: Article 6(1)(a) GDPR).
For the technical provision, moderation and security of the forums, we rely on our legitimate interest in a functional and secure offering (legal basis: Article 6(1)(f) GDPR). Posts are checked on working days; manifestly unlawful content is removed without delay.
Deletion and moderation requests: If you would like personal data in a post to be removed, please contact office(at)viennasightseeing.at and identify the specific post (URL and, if possible, screenshot). We review deletion requests and generally respond within one month; in complex cases the period may be extended by up to two months pursuant to Article 12(3) GDPR. If deletion cannot take place, for example due to statutory retention obligations or third-party rights, we will inform you of the reasons.
7. How your data are protected
We take technical and organisational measures in accordance with Article 32 GDPR to ensure the confidentiality, integrity and availability of your personal data. These include in particular transport encryption (e.g. TLS), encryption of sensitive data at rest, role-based access concepts and individual user rights, multi-factor authentication for administrative access, logging and monitoring of security-relevant access, regular backups and recovery plans, timely security updates and regular penetration tests. We also conduct mandatory awareness and training measures for our employees.
We conclude data processing agreements with all service providers used (Article 28 GDPR) and regularly review their security standards. This short description is provided in accordance with the transparency requirement (Article 12 GDPR; Recital 60). Further technical details are provided upon request where a legitimate interest is demonstrated.
If you transmit personal data to us, we encrypt the relevant forms. Please note: No method of data transmission over the Internet is 100% secure. We use all economically reasonable technical and organisational measures, but cannot guarantee absolute security.
8. Opt-out options
We offer you the possibility to object to the use of your personal data for certain purposes. You cannot unsubscribe from transaction-related emails. You can also deactivate push notifications in your device settings. Location-based services can also be switched off there.
9. Newsletter
9.1 Newsletter subscription
Our newsletter can be received by a data subject only if:
a) the data subject has a functioning email address; and
b) the data subject registers for the newsletter mailing.
For legal reasons, a confirmation email is sent in the double opt-in procedure to the email address first entered by the data subject for newsletter mailing. This confirmation email serves to verify whether the holder of the email address, as data subject, has authorised receipt of the newsletter.
9.2 Newsletter mailing
When sending our newsletter, we process the following categories of personal data:
Email address, data for creating usage statistics, data on website use and logs of clicks on individual elements of the newsletter, and contact data such as name or email address.
Purpose of processing: electronic sending of direct advertising and optimisation of content, analysis of user behaviour.
9.3 Newsletter analysis (tracking)
Our newsletters contain so-called tracking pixels. A tracking pixel is a small graphic embedded in the newsletter that enables us to record and analyse log files. These data help us statistically evaluate the success or failure of our online marketing campaigns. The tracking pixel enables us to determine whether and when a newsletter was opened and which links in the newsletter were clicked. The personal data collected in this way are stored and evaluated by us in order to optimise newsletter mailing and better adapt its content to recipients' interests.
9.4 Legal basis for processing
Your consent (Article 6(1)(a) GDPR in conjunction with § 174(4) TKG).
You may withdraw your consent at any time within the statutory framework with effect for the future. A link to unsubscribe from the newsletter is included in every newsletter. You may also unsubscribe from the newsletter at any time directly on the website of the controller or inform the controller in another way, for example by email to office(at)viennasightseeing.at.
9.5 Data provision
You are not obliged to provide the data. If you do not provide the data, we cannot send you information.
9.6 Processor
Data are transferred to the processor CleverReach GmbH & Co. KG, Schafjückenweg 2, 26180 Rastede, Germany. We use CleverReach as newsletter provider. The privacy policy and information about the company can be found at https://www.cleverreach.com/de-de/datenschutz/. We have concluded a data processing agreement with CleverReach (Article 28 GDPR).
9.7 Retention period
We store the data provided to us when registering for the newsletter for a period of 3 years after the last contact.
9.8 B2B newsletter
Existing B2B customers are regularly sent newsletters for existing customer advertising or information purposes under § 174(4) TKG 2021 based on our legitimate interest in providing information about our offers.
10. Your rights as a data subject
10.1 No profiling
We do not create profiles of data subjects or other persons and do not carry out profiling; there is no automated decision-making in the course of our activities.
10.2 Data subject rights
As a data subject, you generally have the right of access, rectification, erasure, restriction of processing and data portability, each within the statutory framework. We point out that these rights may be restricted where providing information would endanger a business or trade secret of the controller or of third parties (§ 4(6) DSG).
10.3 Withdrawal of consent
If you have given us consent to process your data, you have the right to withdraw this consent at any time with effect for the future. The lawfulness of processing carried out until withdrawal remains unaffected. After withdrawal, the data are no longer used for the purpose for which you consented, such as sending an email newsletter.
10.4 Right to object
Where processing is based on legitimate interest, you have the right to object to it. If you object to processing for direct marketing purposes, the personal data will no longer be processed for those purposes. If we process data for other purposes based on legitimate interest, we will no longer process the personal data unless we have compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
10.5 Exercising your rights
To exercise your rights, please contact us, preferably by email at office(at)viennasightseeing.at, by telephone at 0043 (0)1 712 46 83 - 0 or by post to: Opernring 3-5, Top 508-529, 1010 Vienna, Austria. It would be helpful if you provided us with the information required to clearly identify you.
Information on the response period: We respond to requests under Articles 15-22 GDPR within one month of receipt; in the case of complex or numerous requests, this period may be extended by up to two months (Article 12(3) GDPR). You will be informed of any extension.
10.6 Complaint
If you believe that the processing of your personal data violates data protection law or that your data protection rights have otherwise been infringed, you may lodge a complaint with the Austrian Data Protection Authority. The website of the Austrian Data Protection Authority is www.dsb.gv.at.
11. Contact us
If you have any questions or concerns regarding your privacy or security on our website, please contact us at office(at)viennasightseeing.at.