Zu den Hauptinhalten springen
Icon ZugIcon S-BahnIcon PlusBus
Symbol Auge

This text has been translated. Only the German version is legally binding.

Privacy Policy

Nahverkehrsservice Sachsen-Anhalt GmbH (NASA GmbH) takes the protection of your personal data very seriously. We want you to know when we collect information about you and how we use it. In the following, we inform you about the nature, scope and purpose of the collection, processing and use ("processing") of personal data ("data") in connection with the use of our Internet pages www.nasa.de, www.insa.de, www.mein-takt.de, www.sft-sachsen-anhalt.de and all associated subdomains (hereinafter referred to as "Internet pages"):

 

General Informationen

The controller within the meaning of the General Data Protection Regulation (hereinafter "GDPR") is

Nahverkehrsserhice Sachsen-Anhalt GmbH
represented by the Peter Panitz, managing director
Am Alten Theater 4
39104 Magdeburg
Deutschland
Phone: +49 (0)391 53631-0
E-Mail: info@nasa.de
Internetseite: www.nasa.de

We have appointed a Data Protection Officer for our company. You can contact our Data Protection Officer using the following details:

Mrs Meggie Dachner

DATA 4.0 Gesellschaft für Datenschutz und Datensicherheit mbH
Dornbergsweg 2
38855 Wernigerode
Deutschland
E-Mail: m.dachner@data40.de
Phone.: +49 (0)3943 509949-0

Description and Scope of Data Processing

Each time our website is accessed, our system automatically collects data and information from the computer system of the accessing workstation.

The following information is collected

  • Information about the type and version of browser used
  • the user's operating system
  • the user's internet service provider
  • User's IP address,
  • Date and time of access,
  • Website/source/reference from which the user's system accesses our website/content, and
  • Website/source/reference visited by the user's system on our website

This information is also stored in the log files of our system. This does not include the user's IP address or any other information that could be used to identify the user. These data are not stored together with other personal data of the user. The data collected is only used in anonymous form for statistical purposes and to improve the website. However, NASA GmbH reserves the right to check the server log files retrospectively if there are concrete indications of illegal use

Purpose of Data Processing

The temporary storage of the IP address by the system is necessary to enable the delivery of the Internet pages to the user's computer. For this purpose, the user's IP address is stored for the duration of the session.

The data is stored in log files to ensure the functionality of the web pages. In addition, we use the data to optimise the Internet pages and to ensure the security of our information technology systems. The data is not evaluated for marketing purposes.

Lawfulness of Processing

The legal basis for the temporary storage of the above-mentioned data and their logging in so-called log files is our legitimate interest as website operator pursuant to Art. 6 para. 1 (f) GDPR in connection with sect.25 para.  2 no. 2 TTDSG in an optimal provision of our online offer.

Transfer of Data to Third Parties

As a matter of principle, we only use your personal data within our company. If and to the extent that we involve third parties in the performance of contracts, they will only receive the personal data to the extent that the transfer is necessary for the respective service. In the event that we outsource certain parts of the data processing ("commissioned processing"), we contractually oblige the commissioned processors in accordance with Art. 28 DSGVO to use personal data only in accordance with the requirements of data protection laws and to ensure the protection of the rights of the data subject.

Further Permissions and Data Collection

If you use the push service, the email address you provide will be stored on a web server at our company in order to send the information to your device. This enables us to notify you of the current traffic situation of the connections you have subscribed to in the event of a delay or disruption.

Your email address will not be used for any other purpose. If you do not agree to this storage, please do not use the push service.

Duration of Storage

Data will be deleted as soon as it is no longer required for the purpose for which it was collected. It may be stored for longer if required by law.

Possibility of Objection and Removal

The collection of data for the provision of the web pages and the storage of the data in log files are absolutely necessary for the operation of the web pages. Consequently, there is no possibility for the user to object.

Description and Scope of Data Processing

We use cookies on our web pages. Cookies are text files that are stored on your terminal. They are stored either temporarily for the duration of a session (session cookies) or permanently (permanent cookies). Session cookies are automatically deleted at the end of your visit. Persistent cookies remain on your device until you delete them yourself or until they are automatically deleted by your web browser. A distinction is made between technically necessary cookies and cookies from possible third party providers.

Purpose of Data Processing

Technically necessary cookies enable us to provide our websites in an error-free and user-friendly manner. The use of cookies for marketing purposes enables us to continuously improve the user experience of our websites and to generate individual offers.

Lawfulness of Processing

The legal basis for the use of functionally necessary cookies is sect.25 para. 2 no. 2 TTDSG. The legal basis for the setting of third-party cookies, which are not subject to any technical necessity but serve our marketing interests, is based on your granted consent in accordance with sect.25 para. 1 TTDSG. You can revoke this consent at any time. The legality of the data processing carried out until the revocation remains unaffected.

Duration of Storage

You have the option to change your cookie settings at any time and thus object to the processing of your data in whole or in part.

Description and Scope of Data Processing

On our websites, we use the cookie consent tool "Cookiebot" to obtain your consent to the storage of certain cookies on your terminal device or to the use of certain technologies and to document this in accordance with data protection law. The provider of this technology is Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark. When you visit our websites, the following personal information is transmitted to the provider:

  • Your consent(s) or withdrawal of consent(s).
  • Your anonymised IP address
  • Information about your browser
  • Website URL
  • Information about your device
  • Time you visited the website
  • Time of your visit to the website

 "Cookiebot" places a cookie in your browser in order to be able to allocate the consents granted to you or to revoke them. The data collected in this way is stored until you ask us to delete it, you delete the Cookiebot cookie yourself or the purpose for which the data was collected no longer applies.

Lawfulness of Processing

Cookiebot is used to obtain the legally required consent for the use of cookies. The legal basis is Art. 6 para. 1 (c) GDPR.

Further Information about Data Processing

The technical provider is responsible for further data processing. Further information on security and data protection can be found under the following link www.cookiebot.com/de/privacy-policy/ .

Scope of Personal Data Processing

We use the open source software tool Matomo (formerly PIWIK) on our website to analyse the browsing behaviour of our users. The software sets a cookie on the user's computer (see above for information on cookies). When individual pages of our website are accessed, the following data is stored

  • two bytes of the IP address of the user's calling system,
  • the web page requested,
  • the website from which the user came to our website (referrer),
  • the sub-pages that are accessed from the visited website,
  • the length of time spent on the website, and
  • the frequency with which the website is accessed.

The software runs exclusively on the servers of our website. The user's personal data is only stored there. The data is not shared with third parties.

The software is set so that IP addresses are not stored in full, but 2 bytes of the IP address are masked (e.g.: 192.168.xxx.xxx). In this way, it is no longer possible to assign the shortened IP address to the calling computer.

Purpose of Data Processing

The processing of users' personal data enables us to analyse the surfing behaviour of our users. By evaluating the data obtained, we are able to compile information on the use of the various components of our website. This helps us to continually improve our website and its user-friendliness. These purposes also constitute our legitimate interest in processing the data pursuant to Art. 6 para. 1 (f) DSGVO. The anonymisation of the IP address takes sufficient account of users' interests in the protection of their personal data.

Lawfulness of Processing

The legal basis for the processing of users' personal data is Art. 6 para. 1 (f) GDPR.

Duration of Storage

The data is deleted as soon as it is no longer required for our collection purposes. The cookies used by Matomo are stored on the user's computer and transferred from there to our pages. Therefore, as a user, you have full control over the use of cookies. Cookies can be deleted at any time. Most modern browsers have a "Do Not Track" option which allows you to tell websites not to track your activities. Matomo respects this option.

Objection and Removal Options

Cookies are stored on the user's computer and sent to our website by the user. Therefore, as a user, you have full control over the use of cookies. You can deactivate or restrict the transmission of cookies by changing the settings in your internet browser. Cookies that have already been stored can be deleted at any time. This can also be done automatically. If cookies for our websites are deactivated, you may not be able to use all the functions of the websites to their full extent.

You can opt out at any time by scrolling to the bottom of the Privacy Policy page and unchecking the box. In this case, Matomo will not collect any session data. However, if you reinstall our application, the setting will be deleted and you may need to disable it again.

You can find more information about the privacy settings of the Matomo software at the following link: matomo.org/docs/privacy/

 

We do not employ automated individual decision-making or profiling.

The use of contact data published in the context of the legal notice for the transmission of unsolicited advertising and information materials is hereby expressly objected to. The operators of the pages expressly reserve the right to take legal action in the event of unsolicited sending of advertising information, e.g. by spam mails.

We are committed to protecting your privacy. We therefore take appropriate technical and organisational measures to protect your personal data from misuse, alteration and loss.

Your information is protected during transmission on our websites using an SSL or TLS certificate. You can recognise that such a certificate is in use by the web address such as https:// or a closed padlock symbol next to the web address.

Despite carefully selected security precautions, we would like to point out that, particularly when transmitting information by e-mail or using our web forms, no one hundred percent protection can be guaranteed. If you wish to send us confidential information, please send it by post to the address given in the imprint.

Our websites may contain links to third party websites that are subject to data protection legislation. If you access these links and thereby enable third parties to process your personal data (e.g. your IP address), we have no control over this processing and therefore cannot accept any responsibility for it.

We indicate the transfer to other telemedia providers at the appropriate places by means of colour, symbol or text.

The GDPR grants you certain rights with regard to the processing of your personal data. If you wish to exercise these rights, please send your request by e-mail or by post, clearly identifying yourself, to the Data Protection Officer mentioned under II.

Right of Access by the Data Subject (Art. 15 GDPR)

You have the right to obtain confirmation as to whether or not personal data concerning you are being processed; if this is the case, you have the right to be informed of such personal data and to receive the information specified in Art. 15 GDPR.

Right to Rectification (Art. 16 GDPR)

You have the right to request, without undue delay, the rectification of inaccurate personal data concerning you and, where appropriate, the completion of incomplete personal data.

Right to Erasure (Art. 17 GDPR)

You also have the right to request that personal data concerning you be deleted without undue delay, provided that one of the reasons listed in Art. 17 GDPR applies, for example if the data is no longer required for the purposes pursued.

Right to Restriction of Processing (Art. 18 GDPR)

You have the right to request the restriction of processing if one of the conditions listed in Art. 18 GDPR applies, for example if you have objected to the processing, for the duration of any review.

Right of Information (Art. 19 GDPR)

If you have exercised your right to rectification, erasure or restriction of processing against the controller, the controller is obliged to inform all recipients to whom the personal data concerning you have been disclosed of the rectification, erasure or restriction of processing, unless this proves impossible or involves a disproportionate effort.

You have the right to be informed of these recipients by the data controller.

Right to Data Portability (Art. 20 GDPR)

In certain cases, as detailed in Art. 20 GDPR, you have the right to obtain the personal data concerning you in a structured, common and machine-readable format or to request the communication of such data to a third party.

Right to Objection (Art. 21 GDPR)

If data are collected on the basis of Art. 6 para. 1 (f) GDPR (data processing for the protection of legitimate interests), you have the right to object to the processing at any time for reasons arising from your particular situation. We will then no longer process the personal data unless we can prove that there are compelling legitimate grounds for the processing which override the interests, or fundamental rights and freedoms of the data subject, or if the processing is necessary for the establishment, exercise or defence of legal claims.

Right to Withdraw your Data Protection Consent (Art. 7 GDPR)

You have the right to revoke your data protection consent at any time. The revocation of consent does not affect the lawfulness of the processing carried out on the basis of the consent until the revocation. This also applies to the revocation of consent given to us before the EU General Data Protection Regulation came into force, i.e. before 25 May 2018.

Right to Complain to a Supervisory Authority (Art. 77/78 GDPR).

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State where you reside, work or where the alleged infringement took place, if you consider that the processing of personal data concerning you is in breach of the GDPR.

The supervisory authority to which the complaint is made will inform the complainant of the status and outcome of the complaint, including the possibility of a judicial remedy under Art. 78 of the GDPR.

In the State of Saxony-Anhalt, the competent supervisory authority is the State Commissioner for Data Protection of Saxony-Anhalt, Leiterstraße 9, 39104 Magdeburg.

 

Our websites are subject to the technological progress that accompanies the operation and use of web offerings.

Special Types of Data Processing

1. Description and Scope of Data Processing

a) Business Contacts

NASA GmbH is a company wholly owned by the State of Saxony-Anhalt. NASA GmbH plans, orders and pays for local rail passenger transport on behalf of the state. Together with the Mitteldeutscher Verkehrsverbund and the participating transport companies, it also operates the timetable information system INSA and the intermodal transport information and information platform Mobility Portal Mitteldeutschland.

In accordance with our agency agreement with the state of Saxony-Anhalt and in close consultation with the Ministry of State Development and Transport, NASA GmbH is closely involved in the public transport plan and implements key parts of it.

NASA GmbH's diverse areas of activity include

  • networking rail and bus services with municipal partners,
  • developing the state's public transport network by planning, contracting and financing local rail passenger transport and by supporting the public road passenger transport authorities in planning and financing bus services in the state's network,
  • assisting transport companies in setting up flexible forms of public transport services
  • advises municipalities on the urban development of station areas,
  • operates the INSA information system together with the transport companies in the state and the Mitteldeutscher Verkehrsverbund (MDV) and is developing it into a real-time information system (INSA plus),
  • operates the INSA call centre, which provides information on all aspects of public transport and bookings for the individual transport companies,
  • rents on-board computers and other technology to transport companies,
  • operates the Intermodal Transport Information and Information System Mobility Portal Central Germany.

The execution of the tasks entrusted to us by law and the organisation of our internal business operations are inextricably linked to a large amount of personal data of business contacts (e.g. to ministries, public authorities, other duty bearers or companies in various sectors).

In this context, we only process personal data that we receive directly from the contacts concerned (e.g. by e-mail, telephone, post, business card) in the course of the business relationship or in the course of initiating a business relationship. In addition, to the extent necessary for our business relationship, we process personal data that we permissibly obtain from publicly accessible sources (e.g. commercial register, press, Internet).

b) Customer Contacts (contact forms/e-mail/telephone or personal visit)

Our website contains contact forms that can be used for electronic contact. When a user makes use of this option, the data entered in the input mask is transmitted to us and stored.

These data are

  • salutation,
  • first name, surname,
  • e-mail address,
  • address (street, postcode, town) and
  • any comments.

The data will be processed automatically and without your express consent once the contact form has been sent. In order to comply with our legal obligation to inform you, we give you the choice of being informed of this privacy policy.

Alternatively, you can contact us via the e-mail address provided or by visiting us in person. In this case, the user's personal data sent by e-mail or exchanged in a personal meeting will be stored.

Telephone customer contact is also available via the INSA call centre. The INSA call centre receives orders for the on demand bus service for the transport companies in the state and forwards them to the respective service providers. The following information is recorded and passed on

  • first name, surname,
  • on demand bus connection,
  • telephone number and
  • e-mail address, if available

Before each call, the customer is informed about the processing of personal data and has the opportunity to cancel the call. The processing takes place after the call centre agent has recorded the above data in special software. As this is an outsourcing of data processing ("commissioned processing"), we contractually oblige the INSA call centre service provider as a processor in accordance with Art. 28 GDPR to use personal data only in accordance with the requirements of data protection law and to ensure the protection of the rights of the data subject.

2. Purpose of Data Processing

a) Business Contacts

We use personal data exclusively for the purpose of establishing and/or expanding business relationships or for the fulfilment of the tasks assigned to us by law, as well as for negotiations, the conclusion of contracts and/or the fulfilment of other contractual obligations.

b) Customer Contacts

The personal data provided in the form will be stored and used exclusively for the purpose of responding to your request, for contacting you, for related technical administration and for “Rufbus“ orders. In the case of contact by e-mail, this also constitutes the necessary legitimate interest for the processing of the data.

The other personal data processed during the sending process are used to prevent misuse of the contact form and to ensure the security of our IT systems.

3. Lawfulness of processing

a) Business Contacts

The legal basis for processing the data is the performance of a task assigned to us by law, in accordance with Art. 6 para.1(e) GDPR. Insofar as we process the data for the performance of a contract or for pre-contractual measures, the legal basis for processing the data is Art. 6 para. 1 (b) GDPR. Furthermore, the legal basis for the processing of the data is Art. 6 para.1 (a) GDPR, insofar as we have received prior consent to process the data when the contact data was provided (e.g. handing over a business card).

b) Customer Contacts

The legal basis for processing the data is the performance of a task assigned to us by law pursuant to Art. 6 para. 1(e)  GDPR and our legitimate interest in responding to your request pursuant to Art. 6 para. 1 (f) GDPR. If the purpose of your contact is the conclusion of a contract, the additional legal basis for the processing is Art. 6 para. 1 ( b) GDPR.

4 Recipients of Personal Data

If your request does not fall within our area of responsibility or if we need information from a third party (e.g. associations, transport companies or other public transport authorities), we will forward your request to the person responsible for processing your request.

5. Duration of Storage

a) Business Contacts

We use personal data for the duration of the business relationship and delete it promptly when we no longer need it. Please note that we may also process some limited information about you beyond this time in the knowledge that you have left the organisation you represent, so that we can continue our relationship with you seamlessly if and when we contact you again if you represent another organisation.

b) Customer Contacts

Data is kept until it is no longer necessary for the purpose for which it was collected. This is the case for personal data from the input mask of the contact form, as well as for data sent by e-mail/transmitted by telephone or exchanged in the course of a personal meeting, at the latest after a period of one year, if it can be deduced from the circumstances that we have conclusively dealt with the user's request or the matter concerned, or the purpose of the storage has otherwise ceased to apply, and provided that there are no statutory retention periods to the contrary.

6. Possibility of Objection and Deletion

The user has the possibility, at any time and without giving reasons, to object to the processing of personal data with effect for the future or to revoke the consent given for this purpose. In such a case, the conversation cannot be continued and the user's request or the matter in question cannot be finally processed.

You can send your objection or revocation to NASA GmbH by post, e-mail or fax. You will not incur any costs other than postage or transmission costs in accordance with the applicable basic rates.

The data stored by us will be deleted as soon as it is no longer required for the intended purpose and the deletion does not conflict with any statutory retention obligations. If the user data is not deleted because it is required for other and legally permissible purposes, its processing will be restricted, i.e. the data will be blocked and not processed for other purposes. This applies, for example, to user data that must be retained for commercial or tax reasons. In accordance with legal requirements, data is stored for 6 years pursuant to sect. 257 para. 1 HGB (commercial books, inventories, opening balances, annual financial statements, commercial letters, accounting vouchers, etc.) and for 10 years in accordance with sect. 147 para. 1 AO (books, records, management reports, accounting vouchers, commercial and business letters, tax-relevant documents, etc.).

Description and Scope of Data Processing

We embed timetable services into our websites and applications. The timetable is embedded into our pages using a template loader.

When you access these pages, a connection is established between your browser and our servers. This involves processing information about you, such as your IP address and the device you used to visit the site, and your interactions within the timetable applications.

Please note that in certain applications, e.g. if you actively select your current location as a start or destination in the mobile timetable information, your location will be processed for the purpose of finding the connection and transmitting the data, subject to your consent.

Description and Scope of Data Processing

Public transport users can book an on-demand bus via the INSA hotline (+49 391 5363180) or via our RBUS web application. In order to make a booking in our RBUS web application, it is necessary to create a user account.

Purpose of Data Processing

Certain transport services (in this case "Rufbus") can be booked with participating transport companies through the channels provided. NASA GmbH does not provide transport services itself.

Lawfulness of processing

The booking of a "Rufbus" is a pre-contractual measure according to Art. 6 para. 1 (b) GDPR with the transport company. The transport contract is concluded upon payment to the transport company.

If you provide your personal data (e.g. name, telephone number, e-mail address) within the framework of a "Rufbus" order or the associated creation of a user account, this is done on the basis of your consent in accordance with Art. 6 para. 1 (a) GDPR.

Recipients of Personal Data

Journey bookings are transmitted to the transport company/subcontractor responsible for the transport. In the event of operational disruptions, the transport company/subcontractor will contact you if you have provided contact details during the booking process.

Duration of Storage

You may cancel your travel bookings until the end of the pre-registration period. You can delete your user account if you have no open bookings.

Description and Scope of Data Processing

We take photographs and video footage at public events and for our individual public relations purposes for the national public transport system and, where appropriate, obtain personal statements from passengers. These are published in our print publications and on our websites and social media channels.

Purpose of Data Processing

Your personal data will be used to meet the public's need for information and to fulfil our public image functions, which are in the public interest.

Lawfulness of Processing

We process personal data on the basis of Art. 6 para. 1(a) GDPR on the basis of an individual declaration of consent and Art. 6 para.1 (e) GDPR for the performance of a task carried out in the public interest or in the exercise of official authority vested in us.

Recipients of Personal Data

The data collected are generally intended for publication in public media (print and web), so that any user of these media can be considered a recipient.

Duration of Storage

Your data will be kept for as long as necessary for press and public relations purposes or until you revoke your consent.

Description and Scope of Data Processing

As part of our competitions, we collect personal data from entrants (e.g. email address, name) and the address of the winner. This data is required to validate participation in the competition and to notify the winner.

The address data we request from the winner by e-mail in order to notify the winner will only be used for the purpose of sending the prize.

Purpose of Data Processing

The processing of your data is necessary for the participation and administration of the competition. Participation in our contests is voluntary. Data collected in connection with the competition (e.g. surveys) will only be processed anonymously.

Lawfulness of processing

We process the personal data provided to us in connection with the competition in order to carry out the competition and to fulfil our obligations as the organiser under the law of obligations (Art. 6 para. 1 (b) GDPR).

Insofar as your data is processed on the basis of your consent for purposes other than those mentioned above, the processing is based on Art. 6 para. 1 (a) GDPR.

Recipients of Personal Data

We will only share personal data with third parties if this is necessary to administer the competition, in particular to send the prize. For example, in order to send the prize to the participant, the name, first name and address of the winner may be passed on to a shipping service provider.

Duration of Storage

We will process the entrant's personal data for as long as necessary for the purposes stated or for as long as legal retention periods require further storage.

Entrants may withdraw from the competition at any time by sending an email to datenschutz@nasa.de.

Please note that in the event of a withdrawal, further participation in the competition is excluded.

Additional information for the website www.nasa.de

Submission of Applications

By submitting your application to us, you expressly agree that NASA GmbH may use your personal data both for contacting you during the current application process and for the possible conclusion of a contract at a later date.

NASA GmbH assures you that your personal data will be treated in the strictest confidence and only used for the purposes of the application process in accordance with the applicable data protection legislation. Please note, however, that e-mails are generally sent unencrypted and that it is up to you, the applicant, to ensure that they are encrypted. We cannot therefore accept any responsibility for the transmission of the application between you and our server. For this reason, in addition to the option of applying by email, there is also the option of applying by post.

The purpose of the data collection is, firstly, to carry out a lawful assessment of your application as part of the application process. For this purpose, it is necessary to store the data you provide to us when submitting your application. On the basis of the data provided as part of your application, we will also consider whether you can be invited to an interview as part of the selection process. In the case of generally suitable candidates (m/f/d), we may then collect further personal data that is strictly necessary for the selection decisio

If you are selected for employment, you will be separately notified of the personal data to be collected as part of the recruitment process. The data and files provided by you in the application process may be processed and used by NASA GmbH for employment purposes.

The legal basis for the collection and processing of data is Art. 6 para. 1. (a) and (b) GDPR, Art. 88 para. 1 GDPR.

You have the right to withdraw your application at any time without giving reasons and thus to object to the processing of personal data with effect for the future or to revoke the consent given for this purpose. In such a case, we cannot and will not consider you further in the current application process, as the processing of your personal data is absolutely necessary both for contacting you and for the possible conclusion of a contract at a later date. If you request the deletion of your application data during the application process, this will be considered as a withdrawal of your application.

You can send your objection or withdrawal to NASA GmbH by post, e-mail or fax. You will not incur any costs other than postage or transmission costs according to the applicable basic rates.

In the event of an unsuccessful application or withdrawal of the application, we will destroy the data and files submitted by you as part of the application process six months after notification of rejection. For legal reasons, we are required to retain data for these periods in the event of legal action (e.g. possible claims under the General Equal Opportunities Act).

If you are hired, you will be separately informed of the then applicable rules for handling your personal data.

Description and Scope of Data Processing

Natural and legal persons may apply for grants for eligible projects using forms managed by the responsible person. As a general rule, the name, address, bank details and contact details of the applicant and, where applicable, other contact persons indicated are collected for this purpose.

Purpose of Processing

The data will be processed for the purpose of processing the application and implementing the project. Further information can be found in the Form Centre of the NASA GmbH.

Lawfulness of Processing

Personal data submitted in the context of the grant application will be processed on the basis of your consent pursuant to Art. 6 para. 1(a) GDPR. Applicants may revoke their consent to data processing during the application phase by sending an email to datenschutz@nasa.de. Please note that a revocation in accordance with data protection law will result in the revocation of the grant application.

The legal obligations for data processing according to Art. 6 para. 1   (c) GDPR in connection with sect. 23, 44 of the State Budget Code as well as the administrative regulations ANBest-P/-GK and the Administrative Procedure Act (sect. 48, 49, 49a VwVfG).

Recipients of your Data

The data processed in the context of the funding of charging infrastructure projects may be forwarded to the Ministry of Infrastructure and Digital Affairs (MID).

Duration of Data Storage

Applicants' personal data will be processed for a period of 10 years until revoked or from the date of confirmation of the grant.

Additional Information for the Website www.insa.de

NASA GmbH operates a mobile ticketing system in cooperation with the participating transport companies (customer contract partners) for the distribution of mobile tickets by the individual transport companies in the state of Saxony-Anhalt. For this reason, the following parties have jointly decided on the means and purposes of the processing of personal data within the INSA app and the Mobiportal app. The parties have concluded a joint responsibility agreement in accordance with Art. 26 GDPR, which regulates the existing data protection obligations between them.

For the booking of a mobile ticket via the app, we also refer to the validity of our General Terms and Conditions. These can be accessed via the following link: hub.insa.de/agb/de/.

In addition to NASA GmbH, the controller of the processing of personal data is

DB Regio Region Südost (DB), Richard-Wagner-Straße 1, 04109 Leipzig.
E-mail: kundendialog.suedost@deutschebahn.com

NASA GmbH is designated by the above-mentioned parties as the central data protection office for the mobile ticketing system. In this role, it will primarily receive inquiries, complaints, notices and requests for compliance with your data protection rights on behalf of the other parties. You are free to contact any of the other responsible parties listed directly.

The DB Regio Data Protection Officer can be contacted at the following address

DB Regio AG Datenschutz, Richard-Wagner-Straße 1, 04109 Leipzig,

E-Mail: datenschutz.regio@deutschebahn.com

Description and Scope of Data Processing

The following applies to the registration and purchase of a mobile Ticket:

To register as a user, all you need to do is enter your e-mail address and choose a password. In order to protect your account from third parties, we recommend that you choose a secure password. This means that your password should be at least 8 characters long and contain upper and lower case letters, numbers and special characters.

In principle, it is not necessary to register in order to purchase mobile tickets. If you do not wish to create a customer account to purchase mobile tickets, please use the guest order function.

The following information is required from both registered users and guest buyers when purchasing tickets

  • salutation,
  • first name,
  • surname,
  • date of birth,
  • postal address,
  • e-mail address.

The following applies to payment processing:

In addition to your personal data, the following information is required for payment processing, depending on the payment method selected

  • IBAN (bank account details),
  • credit card details.

The following applies to the security guarantee:

The mobile ticketing system creates log files (so-called error logs) if errors occur during the ordering process or if there is a suspicion of misuse of the system. Personal data contained in the log files are

  • IP addresses.

Purpose of Data Processing

The following applies to registration:

Your personal data is processed for the purpose of creating a user account. Services such as the cancellation or refund of mobile tickets can be carried out via this user account. Registration also enables you to view your purchase receipts online after your journey. In addition, your mobile tickets (both unused and expired) will be retained when you switch devices or clear the application cache. If you are not registered, your data will be irretrievably deleted when the application is uninstalled or the application cache is cleared.

The following applies to the purchase of a mobile ticket:

Your personal master data will be processed for the purpose of fulfilling the ticket purchase. This includes booking, payment processing, any refunds, sending or retrieving the purchase receipt and personalising your mobile ticket for verification by the ticket inspectors in the vehicles.

The following applies to payment processing:

Your personal data and information regarding your bank account or credit card details will be passed on to LogPay Financial Services GmbH for the purpose of payment processing and assignment of claims against you arising in connection with your purchase of a mobile ticket. Furthermore, our legitimate interest lies in the outsourcing of payment processing and claims management. The legitimate interest of LogPay Financial Services GmbH is to collect your data for the purpose of processing payments, managing claims, assessing the admissibility of payment methods and preventing payment defaults.

The following applies to the security guarantee:

The log files created in the event of errors help us to understand and correct the errors that have occurred. In addition, the collection and processing of your personal data serves to prevent so-called brute force attacks. These are attempts by unauthorised persons or algorithms to gain access to a user's account by randomly entering email addresses and passwords. Should this occur, and in the event of multiple failed login attempts, the IP address of the suspected external attacker is processed and temporarily blocked to prevent further attack attempts.

Lawfulness of Processing

The following applies to registration:

The legal basis is a contractual relationship (Art. 6 para. 1 (b) GDPR) or your consent (Art. 6 para. 1 (a) GDPR) when entering optional data. There is no legal or contractual obligation to provide optional data or to create a user account.

The following applies to the purchase of a mobile ticket:

The legal basis for this is the purchase contract concluded between you and the customer contracting party (Art. 6 para. 1 (b) GDPR) by accepting the General Terms and Conditions. Another legal basis is our interest in preventing fraud (Art. 6 para. 1  (f) GDPR). You are obliged to enter your personal data truthfully, otherwise you will not be able to purchase the desired mobile ticket.

The following applies to payment processing:

Your personal data will be passed on to the payment service provider for the purpose of processing the contract in accordance with Art. 6 para. 1 (b) GDPR.

The following applies to the guarantee of security:

The IP address of your terminal device contained in the error logs is processed for the purpose of error analysis and troubleshooting. We have a legitimate interest in ensuring that the mobile ticketing system functions properly and that all functions are available to you without any problems (Art. 6 para. 1 (f) GDPR). It is also in our and your interest to prevent misuse and the penetration of security measures (Art. 6 para. 1 (f) GDPR).

Recipients of Personal Data

The following applies to registration

The user account is stored by the service provider commissioned with the ticket shop (eos.uptrade GmbH). This service provider is contractually bound by an order processing agreement pursuant to Art. 28 GDPR.

The following applies to the purchase of a mobile ticket:

The following recipients process your personal data when you purchase a Mobile Phone Ticket

  • the customer contract partner (your business partner in the GTC),
  • the order processor and operator of the applications (Apps) Hacon Ingenieurgesellschaft mbH,
  • the order processor and operator of the ticket shop eos.uptrade GmbH,
  • LogPay Financial Services GmbH, the service provider responsible for payment processing.
  • In the case of the purchase of mobile phone tickets from the German tariff or the long-distance tariff of Deutsche Bahn, the DB companies (DB Vertrieb GmbH, DB Fernverkehr AG and DB Regio AG) process personal data as joint controllers. The data protection regulations listed under the following link apply: www.bahn.de/datenschutz.

The following applies to payment processing:

Your personal data for the selected payment method will be forwarded directly to LogPay Financial Services GmbH. The data protection information of LogPay Financial Services GmbH can be viewed and accessed via the link datenschutzinformationen.pdf (logpay.de). Once the claim has been assigned to LogPay Financial Services GmbH, the latter is responsible for processing your personal data for the purpose of payment processing.

For the guarantee of security applies:

Your personal data will be passed on to our developers and order processors for the mobile ticket system, Hacon Ingenieurgesellschaft mbH and eos.uptrade GmbH.

Duration of Storage

The following applies to registration

Your personal data will be stored for as long as your user account exists. You can delete your user account in your profile settings. Your deletion request will then be automatically forwarded to our order processors for implementation. If there are legal retention periods (Art. 6 para. 1 (c) GDPR), these will be taken into account.

The following applies to the purchase of a mobile ticket

Your data will be stored until the purpose for which it was provided has been fulfilled, and beyond that due to any legal retention obligations. If your personal data is not deleted because it is required for other and legally permissible purposes, its processing will be restricted, i.e. the data will be blocked and not processed for other purposes. This applies, for example, to user data that must be retained for commercial or tax reasons. In accordance with the statutory provisions, data is stored for 6 years pursuant to sect. 257 para. 1 HGB (commercial books, inventories, opening balances, annual financial statements, commercial letters, accounting vouchers, etc.) and for 10 years in accordance with sect. 147 para. 1 AO (books, records, management reports, accounting vouchers, commercial and business correspondence, tax-relevant documents, etc.). Your data will be deleted immediately once the statutory retention period has expired or if it is no longer required for any other reason.

The following applies to the processing of payments:

LogPay Financial Services GmbH is responsible for the storage period of your personal data.

For the guarantee of security applies:

The IP addresses collected in the event of incorrect login entries are stored for the purpose of identifying attack patterns.

Right of Objection and Withdrawal

The following applies to payment processing:

You can object to the transfer of your personal data to LogPay Financial Services GmbH at any time. You will then no longer be able to place orders via the mobile ticketing system.

The following applies to security:

Your personal data will be deleted as soon as the retention of error logs is no longer required for the analysis and resolution of error causes and effects as well as stability problems in the mobile ticketing system.

 

Description and Scope of Data Processing

Via the platforms operated by NASA GmbH, you can order or cancel the "Deutschland-Ticket" with a transport company of your choice. For this purpose, a web-based application/cancellation form is available, in which the data of the purchaser (name, address, date of birth, e-mail address, bank details) and, if different, of the ticket holder (name, address, date of birth, e-mail address) required for the conclusion or cancellation of the contract are collected and transmitted in encrypted form to the transport company of your choice.

Purpose of Data Processing

The purpose of the processing is, on the one hand, to carry out pre-contractual measures in the form of the provision of the application so that the purchaser can conclude a subscription for the "Deutschland-Ticket" with the selected transport company. We will also forward your cancellation request to the contracted transport company. For the above purposes, NASA GmbH acts on behalf of the participating transport companies.

Lawfulness of Processing

The processing of your data is carried out in accordance with Art. 6 para. 1 l(b) GDPR for the fulfilment of the contract, including pre-contractual measures.

Recipients of Personal Data

We transmit your application data exclusively to the transport company selected by you. There is no transfer to third countries.

Duration of storage

Your application data will be deleted after the purpose has been fulfilled, i.e. after successful transmission to the transport company you have selected.

Further Information

For further information on the processing of your application data, please contact the transport company of your choice.

Additional Information for our Social Media Channels

Information on data protection last updatetd: 12.04.2023

Peter Panitz

Managing Director
Nahverkehrsservice Sachsen-Anhalt GmbH