Legal information
Privacy Policy
Legal Information
for the Website, Online Booking System and Customer Portal
Last updated: 01/01/2026
The protection of your personal data is important to us. This Privacy Policy explains, in accordance with the General Data Protection Regulation (GDPR), which personal data we process when you use our website, our public online booking system and our protected customer portal, for which purposes the data is processed, the legal bases on which the processing is based and which rights you have.
This Privacy Policy applies in particular to:
- our website at sk-ats.de,
- the public online booking system at wbook.disponline.de/sk-ats,
- the protected customer and corporate portal at sks.disponline.de/login,
- and the related email, SMS, payment, invoicing and communication processes.
1. Controller
Shuttle & Kurier Service ATS GmbH
Brixener Straße 8
86165 Augsburg
Germany
Phone: +49 (0)821 44963828
Email: mail@sk-ats.de
2. General Legal Bases
We process personal data in particular on the following legal bases:
- Art. 6(1)(b) GDPR for taking steps prior to entering into a contract and for the performance of transport, booking, payment and billing contracts,
- Art. 6(1)(c) GDPR for compliance with legal obligations, in particular retention obligations under commercial and tax law,
- Art. 6(1)(f) GDPR on the basis of our legitimate interests, in particular the secure operation of our systems, the organisation of journeys, communication with passengers, prevention of misuse and the establishment, exercise or defence of legal claims,
- Art. 6(1)(a) GDPR where we obtain your consent for a specific processing activity.
The requirements of the German Telecommunications Digital Services Data Protection Act (TDDDG) additionally apply where information is stored on your terminal device or access is made to information already stored there.
3. Your Rights
Subject to the applicable legal requirements, you have in particular the following rights:
- right of access under Art. 15 GDPR,
- right to rectification under Art. 16 GDPR,
- right to erasure under Art. 17 GDPR,
- right to restriction of processing under Art. 18 GDPR,
- right to data portability under Art. 20 GDPR,
- right to object under Art. 21 GDPR,
- right to withdraw consent under Art. 7(3) GDPR.
Withdrawal of consent applies for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.
To exercise your rights, you may contact us at mail@sk-ats.de.
4. Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority.
The supervisory authority generally responsible for our company is:
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach
Germany
Phone: +49 (0)981 180093-0
Email: poststelle@lda.bayern.de
Website: www.lda.bayern.de
5. Hosting and Server Log Files
Our website is hosted by:
IONOS SE
Elgendorfer Straße 57
56410 Montabaur
Germany
When you access our website, the following data in particular may be processed:
- IP address,
- date and time of access,
- page or file requested,
- referrer URL,
- browser type and browser version,
- operating system used,
- amount of data transferred,
- messages concerning successful or failed access attempts.
The processing is carried out to provide our website securely, reliably and without technical errors on the basis of Art. 6(1)(f) GDPR.
Server and security logs are stored only for as long as necessary for operation, troubleshooting and protection against attacks. Longer storage may take place where a security-related incident must be investigated or a legal claim must be established, exercised or defended.
Further information is available in the privacy information provided by IONOS.
6. Cookies and Consent Management
Our website uses cookies and similar technologies. We use Complianz as our consent management tool.
Complianz records which consent choices you have accepted, rejected or subsequently changed. Technically necessary cookies may be used in particular for the basic operation of the website, storage of your privacy preferences, protection of forms and provision of login and booking functions.
Non-essential analytics, statistics, marketing or external media services are activated only after the required prior consent has been obtained.
The applicable legal bases are:
- Section 25(1) TDDDG and Art. 6(1)(a) GDPR for technologies requiring consent,
- Section 25(2) no. 2 TDDDG and Art. 6(1)(b) or (f) GDPR for technologies that are strictly necessary.
You may change your selection at any time through the cookie settings on our website.
Further details can be found in our Cookie Policy (EU).
7. Contact Form and Email Communication
If you contact us using a contact form or by email, we may process in particular:
- your name,
- email address,
- telephone number,
- content of your message,
- date and time of contact,
- and, where applicable, booking, quotation or order information.
Processing is based on Art. 6(1)(b) GDPR where your request relates to steps prior to entering into a contract or the performance of a contract.
Other business-related enquiries are processed on the basis of Art. 6(1)(f) GDPR.
The data will be deleted once the enquiry has been fully dealt with, unless statutory retention obligations or legitimate reasons require further storage.
8. Communication via WhatsApp
If you voluntarily contact us via WhatsApp, we may process in particular:
- your telephone number,
- your WhatsApp name,
- message content,
- files transmitted,
- date and time of communication.
The provider is:
WhatsApp Ireland Limited
4 Grand Canal Square
Grand Canal Harbour
Dublin 2
Ireland
Processing is carried out for the purpose of responding to your enquiry and providing our services on the basis of Art. 6(1)(b) or Art. 6(1)(f) GDPR.
Use of WhatsApp is voluntary. You may alternatively contact us by email or telephone.
WhatsApp is generally used by us for text-based communication. Voice and video calls are not provided as a regular contact channel.
When WhatsApp is used, data may also be processed by companies of the Meta group outside the European Union or European Economic Area.
Further information can be found in WhatsApp’s privacy policy.
9. Google Analytics 4
Where you have provided consent through our cookie banner, we use Google Analytics 4.
The provider is:
Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland
Google Analytics may process in particular:
- pages visited,
- date, time and duration of visits,
- interactions with the website,
- approximate source or location of access,
- device, browser and operating system information,
- technical identifiers,
- and the IP address transmitted as part of the connection.
Processing takes place solely on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG.
You may withdraw your consent at any time through the cookie settings.
Processing by Google companies outside the European Union or European Economic Area cannot be completely excluded. Where required, transfers are made on the basis of an adequacy decision or other appropriate safeguards.
Further information can be found in Google’s privacy policy.
10. Google Maps
Google Maps may be embedded on our website.
The provider is:
Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland
Google Maps is generally loaded only after you have provided the required consent.
When the service is used, data such as your IP address, device information, location information and information relating to your use of the map service may be processed.
The legal basis is Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.
You may withdraw your consent at any time through the cookie settings.
11. Google reCAPTCHA
Where Google reCAPTCHA is used on our website or in forms, the service is used to detect and prevent automated or abusive submissions.
The provider is Google Ireland Limited.
The following data in particular may be processed:
- IP address,
- browser and device information,
- referrer URL,
- usage and interaction data,
- date and time of use.
Where reCAPTCHA is used, it is generally activated only after the required consent has been obtained.
The legal basis is Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.
Further information can be found in Google’s privacy policy.
12. Wordfence Security
We use Wordfence to protect our WordPress website against malware, attacks and unauthorised access.
The provider is:
Defiant, Inc.
1700 Westlake Avenue North, Suite 200
Seattle, WA 98109
USA
Wordfence may process in particular:
- IP addresses,
- requested URLs,
- technical request and header information,
- timestamps of access,
- failed or suspicious login attempts,
- other security-related usage information.
Processing is based on Art. 6(1)(f) GDPR.
Our legitimate interest consists of protecting our website, booking systems and the data processed through them.
Where data is transferred to the United States, this is carried out on the basis of the applicable legal transfer mechanisms.
Further information can be found in Wordfence’s privacy policy.
13. Public Online Booking via WBook
For public online bookings, we use WBook / DISPONLINE at:
wbook.disponline.de/sk-ats
The technical platform provider is:
RUK Software GmbH
Partnachweg 1
86165 Augsburg
Germany
During an online booking, the following information in particular may be processed:
- name and contact details of the booking customer,
- name and contact details of passengers,
- email address and mobile telephone number,
- pickup and destination address,
- date of journey, pickup time and, where applicable, return journey details,
- number of passengers and requested vehicle category,
- flight number and landing time,
- intermediate stops, luggage and child-seat information,
- selected additional services and booking protection options,
- booking, pricing, discount, amendment and cancellation information,
- payment method, payment status and invoicing information,
- messages and comments relating to the booking,
- technical logging and security information.
Processing takes place in particular for:
- calculating and displaying prices and availability,
- processing the booking request,
- creating and sending the booking confirmation,
- planning and performing the journey,
- communicating with customers and passengers,
- flight monitoring,
- payment and invoicing,
- processing amendments, cancellations and complaints.
The legal basis is generally Art. 6(1)(b) GDPR.
Where passenger data is entered by another customer or contracting party, processing is additionally based on Art. 6(1)(f) GDPR.
14. Protected Customer and Corporate Portal
We provide registered private and corporate customers with a protected customer portal at:
sks.disponline.de/login
This portal is also technically provided through DISPONLINE by RUK Software GmbH.
In addition to booking information, the following data in particular may be processed:
- company name, business address and contact persons,
- username, user account and contact details,
- administrator, employee and user roles,
- login times and security-related log information,
- customer, debtor and cost-centre information,
- individual pricing, discount and framework agreement information,
- individual and collective invoice information,
- enabled payment methods,
- date and version of accepted Terms and Conditions,
- suspension or deactivation of user accounts.
Processing takes place in particular for:
- setting up and administering customer accounts,
- providing and managing employee accounts,
- managing booking permissions,
- performing and documenting bookings,
- implementing individual pricing and framework agreement arrangements,
- producing individual or collective invoices,
- protecting the portal against unauthorised use,
- documenting the contractual terms accepted by users.
The legal bases are Art. 6(1)(b) and Art. 6(1)(f) GDPR.
15. RUK Software GmbH as Technical Service Provider
RUK Software GmbH provides the technical systems DISPONLINE, WBook and the protected customer portal.
In this context, it may process booking, customer, passenger, communication, payment, invoicing, login and logging data.
Where RUK Software GmbH processes personal data on our behalf, this processing takes place on the basis of a data processing agreement pursuant to Art. 28 GDPR.
Further information can be found in the privacy information provided by DISPONLINE.
16. Bookings for Employees, Guests and Other Passengers
Companies and other contracting parties may book journeys for employees, guests, customers, family members or other passengers.
In such cases, we do not receive the passenger’s information directly from the passenger but from the person or company placing the booking.
We may process in particular:
- passenger name,
- mobile telephone number and, where applicable, email address,
- pickup and destination address,
- date and time of journey,
- flight number and landing time,
- luggage, child-seat and required intermediate-stop information,
- other information necessary to perform the journey.
The data originates from the customer account or from the person or company commissioning the journey.
Processing takes place for the organisation, communication and performance of the booked transport service on the basis of Art. 6(1)(f) GDPR.
Our legitimate interest is the proper performance of the journey booked by the contracting party.
The contracting party must ensure that only correct information necessary for the journey is provided and that the passenger is informed about the disclosure of their personal data to ATS.
17. SMS Notifications for Both Booking Systems
Passengers may receive an SMS before pickup for bookings made through WBook as well as bookings made through the protected customer portal.
The SMS is generally sent one day before pickup.
For bookings made or amended at short notice, the SMS may be sent at a later time where technically and operationally possible.
The SMS may contain in particular:
- confirmed or scheduled pickup time,
- information about the pickup location,
- ATS telephone number,
- short-notice amendments,
- a brief privacy notice with a link to this Privacy Policy.
For SMS delivery, we process in particular:
- passenger’s mobile telephone number,
- pickup time and booking-related information,
- booking number,
- time of dispatch,
- delivery or error status.
Processing is carried out for performance of the booked transport service pursuant to Art. 6(1)(b) GDPR.
Where the passenger was booked by a third party, processing is additionally based on Art. 6(1)(f) GDPR.
The SMS is sent through the SMS functionality integrated into DISPONLINE and the SMS or telecommunications providers used for this purpose.
Only the information required for delivery is transmitted.
Dispatch and delivery information is retained only for as long as necessary to perform the journey, troubleshoot errors and demonstrate that the notification was sent.
18. Flight Numbers and Flight Monitoring
For airport pickups, we process the flight number provided and the scheduled landing time.
We may retrieve publicly available information or information available through flight information services, including in particular:
- scheduled landing time,
- actual landing time,
- delays,
- cancellations,
- and, where applicable, terminal information.
Processing is carried out for the planning and performance of the airport pickup on the basis of Art. 6(1)(b) and/or Art. 6(1)(f) GDPR.
19. Disclosure to Drivers and Subcontractors
For the performance of a journey, necessary booking and passenger information may be disclosed to:
- our dispatch team,
- our own drivers,
- subcontractors used by us,
- drivers employed by those subcontractors,
- other cooperation partners where required.
Only information required for the specific journey is disclosed, in particular:
- passenger name and mobile telephone number,
- pickup and destination address,
- pickup time and flight number,
- number of passengers,
- luggage and child-seat information,
- instructions required to perform the journey.
Processing and disclosure are based on Art. 6(1)(b) and/or Art. 6(1)(f) GDPR.
20. Payment by Invoice and Bank Transfer
Where payment is made by invoice or bank transfer, we may process in particular:
- name or company name,
- billing address,
- booking and invoice number,
- service and booking information,
- invoice amount,
- bank and payment information,
- payment status,
- and, where applicable, reminder information.
Processing takes place for performance of the contract pursuant to Art. 6(1)(b) GDPR and for compliance with statutory accounting and retention obligations pursuant to Art. 6(1)(c) GDPR.
21. Payment via PayPal
Where PayPal is offered and selected as a payment method, ATS may create an individual payment link and send it to the email address stored in the passenger profile or booking.
The provider is:
PayPal (Europe) S.à r.l. et Cie, S.C.A.
22–24 Boulevard Royal
L-2449 Luxembourg
The following information in particular may be transmitted to PayPal:
- email address of the payment-link recipient,
- name or company name,
- payment amount and currency,
- booking or invoice number,
- payment reference,
- payment status.
PayPal processes data entered during payment under its own data protection responsibility.
ATS generally does not receive or store complete PayPal login credentials.
Processing by ATS takes place for contract and payment processing pursuant to Art. 6(1)(b) GDPR.
Further information can be found in PayPal’s privacy policy.
22. Credit Card Payments
Where credit card payment is offered and selected, ATS may create an individual payment link through the payment service provider used and send it to the email address stored for the booking.
The following information in particular may be processed or transmitted:
- email address of the payment-link recipient,
- name or company name,
- payment amount and currency,
- booking or invoice number,
- payment reference,
- payment status.
Credit card details are generally entered directly on the secure website of the payment service provider.
ATS generally does not store complete credit card numbers or card verification codes.
The specific payment service provider is identified in the payment link or on the payment page.
The provider’s own privacy information additionally applies to payment data entered directly with that provider.
Processing by ATS takes place for contract and payment processing pursuant to Art. 6(1)(b) GDPR.
23. Sending Payment Links by Email
Payment links for PayPal or credit card payments are sent to the email address stored in the passenger profile or booking.
This email address may belong to the passenger, an employee, a contact person or another person designated by the contracting party.
The contracting party must ensure that it is authorised to provide the relevant email address for this purpose.
24. Booking Confirmations and Other Booking-Related Emails
After a booking has been made, we send booking confirmations and, where applicable, additional booking-related communications by email.
For this purpose, we process in particular:
- stored email address,
- booking number,
- journey and pricing information,
- delivery status.
Processing takes place for performance of the contract pursuant to Art. 6(1)(b) GDPR.
25. Individual and Collective Invoices
After a journey has been performed, individual or collective invoices may be issued depending on the agreed billing arrangement.
For this purpose, we process in particular:
- customer and company information,
- billing address,
- booking and service information,
- prices, surcharges and additional services,
- payment information,
- booking and invoice numbers,
- tax-related information required by law.
Invoices are generally sent electronically to the email address stored in the customer profile.
Where necessary, information may be disclosed to:
- tax advisers,
- accounting service providers,
- banks,
- payment service providers,
- tax authorities,
- legal advisers,
- debt collection providers.
The legal bases are Art. 6(1)(b) and Art. 6(1)(c) GDPR.
26. Documentation of Acceptance of Terms and Conditions
The protected customer portal may record when and by which user account a specific version of our Terms and Conditions was accepted.
The following information in particular may be processed:
- user account and customer or company assignment,
- date and time,
- version of the Terms and Conditions accepted,
- technical log information.
Processing takes place for contract administration and evidence of the incorporation of contractual terms on the basis of Art. 6(1)(b) and Art. 6(1)(f) GDPR.
27. Special Information and Free-Text Fields
Free-text fields should be used only for information required for booking and performing the journey.
Please do not enter confidential information or health information that is not necessary for the transport service.
Where special assistance or health-related information is required to provide safe transportation, such information will be processed only where a legal basis under Art. 9 GDPR applies, in particular explicit consent or another statutory exception.
28. Recipients and Categories of Recipients
Depending on the processing activity, personal data may be disclosed in particular to the following recipients or categories of recipients:
- IONOS SE as hosting provider,
- RUK Software GmbH as provider of DISPONLINE and WBook,
- IT, maintenance and support providers,
- SMS and telecommunications providers,
- drivers, subcontractors and cooperation partners,
- PayPal and credit-card payment service providers,
- banks and financial institutions,
- tax advisers and accounting providers,
- legal advisers and debt collection providers,
- public authorities and courts where required by law,
- Google, WhatsApp and Defiant/Wordfence where the respective services are used.
Where a service provider processes personal data solely on our behalf, the service provider is engaged in accordance with Art. 28 GDPR.
29. Transfers of Data to Third Countries
When certain services are used, personal data may be processed outside the European Union or European Economic Area.
This may apply in particular to services provided by:
- Google,
- Meta / WhatsApp,
- Defiant / Wordfence,
- international payment service providers.
Transfers are carried out only where the statutory requirements are met, in particular on the basis of:
- an adequacy decision of the European Commission,
- appropriate safeguards such as EU Standard Contractual Clauses,
- or another statutory exception.
30. Retention Periods
We retain personal data only for as long as necessary for the relevant purpose or where statutory retention requirements or legitimate reasons require continued storage.
30.1 Website and Security Data
Server, logging and security information is stored for as long as necessary for technical operation, system security and investigation of suspicious activity.
30.2 Customer Accounts
Information relating to an active customer account is generally retained for the duration of the business relationship.
Following termination or deactivation of the account, information is deleted or restricted where there are no statutory retention obligations, outstanding claims or other legitimate reasons requiring continued storage.
30.3 Booking and Journey Data
Booking and journey information is retained for performance of the journey and subsequently for handling possible enquiries, complaints, payment matters and legal claims.
Commercial and business correspondence may generally be retained for six years.
30.4 Invoices and Accounting Records
Invoices and accounting records are generally retained for eight years unless a longer statutory period or a specific retention reason applies.
30.5 Evidence of Consent and Acceptance
Evidence relating to consent, cookie decisions and accepted versions of the Terms and Conditions is stored for as long as necessary to comply with statutory accountability requirements or to establish, exercise or defend legal claims.
31. Obligation to Provide Data
Information identified as mandatory during the booking process is required to process and perform the booking.
Without this information, we may in particular be unable to:
- create a binding booking,
- plan the pickup,
- send a booking confirmation,
- contact the passenger,
- allocate a payment or invoice.
Optional information is identified accordingly or follows from the respective input field.
32. Automated Price and Availability Calculations
The booking systems may automatically calculate prices, available journey times, vehicle categories, surcharges and booking options based on the booking information entered.
As a general rule, this does not constitute a decision based solely on automated processing within the meaning of Art. 22 GDPR that produces legal effects or similarly significantly affects the data subject.
33. External Links
Our website and booking portals may contain links to external websites and services.
Simply displaying a standard link generally does not transfer data to the operator of the linked website.
A connection to the respective provider is generally established only when you click the link.
Any subsequent processing is governed by the privacy provisions of the respective provider.
34. SSL/TLS Encryption and Data Security
Our website and booking portals use SSL/TLS encryption.
We implement appropriate technical and organisational measures to protect personal data against:
- loss,
- manipulation,
- unauthorised access,
- and other forms of misuse.
Despite appropriate safeguards, transmission of data over the internet cannot be guaranteed to be completely risk-free.
35. Amendments to this Privacy Policy
We update this Privacy Policy where changes occur to:
- applicable legal requirements,
- technical systems,
- service providers used,
- or our processing activities.
The current version is permanently available at:
https://sk-ats.de/en/privacy-policy/
Shuttle & Kurier Service ATS GmbH