Skip to main content

Privacy Notice

This document contains two Privacy Notices. Please select the one relevant to you.

PRIVACY NOTICE

1. What this Privacy Notice covers

TUI UK Retail Limited (agent) acts on behalf of TUI Deutschland GmbH (principal) (referred to in this Notice as “we” or “us”), part of the TUI Group. We are committed to doing the right thing when it comes to how we collect, use and protect your personal data. Your privacy matters to us, so please do take the time to read our Privacy Notice which explains:

  • What types of personal data we collect and why we collect it.

  • When and how we may share personal data within the TUI Group and with other organisations.

  • The choices you have, including how to access and update your personal data.

We have tried to keep this Notice as simple as possible, but if you are not familiar with terms such as data controller, special categories of personal data, then read about these and some others in Key terms.

2. Personal data we collect When you register for any of our services, you may provide us with:

  • Your personal details, including your address, email address, phone number and date of birth.

  • Your account login details, such as your username and the password you chose.

When you browse our websites or use our mobile apps, we may collect:

  • Travel preferences.

  • Information about your browsing behaviour on our websites and mobile apps.

  • Information about when you click on one of our adverts, including those shown on other organisations’ websites.

  • Information about the way you access our digital services, including operating system, IP address, online identifiers and browser details.

  • Social preferences, interests and activities.

When you buy our products in our shops or online, we may collect:

  • Passenger information, passport details, other ID document details.

  • Insurance details.

  • Relevant medical data and any special, dietary, religious or disability requests.

  • Information about your purchases, including what you bought, when and where you bought it, how you paid for it and credit or other payment information.

  • Information about your browsing behaviour on our websites and mobile apps.

  • Information about when you click on one of our adverts, including those shown on other organisations’ websites.

  • Information about the way you access our digital services, including operating system, IP address, online identifiers and browser details.

  • Social preferences, interests and activities.

When you contact us or we contact you or you take part in promotions, competitions, surveys or questionnaires about our services, we may collect:

  • Personal data you provide when you connect with us, including by email, post and phone or through social media, such as your name, username and contact details.

  • Details of emails and other digital communications we send to you that you open, including any links in them that you click on.

  • Your feedback and contributions to customer surveys and questionnaires.

Other sources of personal data

  • We may use personal data from other sources, such as specialist companies that supply information, retail partners and public registers.

  • Your insurance company, their agents and medical staff may exchange relevant personal data and special categories of personal data with us in circumstances where we/they need to act on your behalf or in the interest of other customers or in an emergency.

  • If you log-in using your social network credentials to connect to our platforms and online services e.g. Facebook, Google+ and Twitter, you will agree to share your user details with us. For example, your name, email address, date of birth, location and any other information you choose to share with us.

  • We may use CCTV images, IP address and browser details collected in or in the immediate vicinity of our shops, premises, other buildings and cruise ships.

Personal data you provide about other individuals

  • We use personal data about other individuals provided by you, such as those people on your booking.

  • By providing other people’s personal data, you must be sure that they agree to this and you are allowed to provide it. You should also ensure that, where appropriate, they understand how their personal data may be used by us.

3. Using your personal data

We use your personal data in a variety of ways, as explained below.

To provide the products and services you request We need to process your personal data so that we can manage your account or booking, provide you with the products and services you want to buy and help you with any orders and refunds you may ask for.

To manage and improve our products, services and day-to-day operations We use personal data to manage and improve our products, websites, mobile apps, customer loyalty or recognition programme(s) and other services. We monitor how our services are used to help protect your personal data, detect and prevent fraud, other crimes and the misuse of services. This helps us to make sure that you can safely use our services. We may use personal data to respond to and to manage security operations, accidents or other similar incidents, including medical and insurance purposes.

We may use personal data to carry out market research and internal research and development, and to develop and improve our product range, services, shops, IT systems, security, know-how and the way we communicate with you.

We use CCTV images to help maintain the safety of anyone working in or visiting our shops, premises and other buildings, and for the prevention, detection and prosecution of criminal offences. We may also rely on the images to establish, exercise or defend our legal rights.

To personalise your experience

We want to ensure that marketing communications relating to our products and services, and those of our suppliers, retail partners and the TUI Group, including online advertising, are relevant to your interests.

To do this, we may use your personal data to better understand your interests so that we can try to predict what other products, services and information you might be most interested in. This enables us to tailor our communications to make them more relevant and interesting for you.

Looking at your browsing behaviour and purchases helps us to better understand you as a customer and it allows us to provide you with personalised offers and services.

We may also measure your responses to marketing communications relating to products and services we offer, which enables us to offer you products and services that better meet your needs as a customer.

If you do not want to receive a personalised service from us, you can change your preference online, over the phone or by writing (e.g. email) to us at any time. We will update our records as soon as we can.

To make contact and interact with you

We want to serve you better as a customer so if you contact us, for example by email, post, and phone or via social media, we may use personal data to provide clarification or assistance to you.

We need to process your personal data so that we can manage any promotions and competitions you choose to enter, including those we run with our suppliers and retail partners. For example, if you win a prize.

We may invite you to take part in customer surveys, questionnaires and other market research activities carried out by the TUI Group and by other organisations on our behalf.

To help us to better understand you as a customer, and to be able to provide you with services and marketing communications (including online advertising relevant to your interests), we may combine the personal data we collect when you make purchases in-shop with personal data collected from our websites, mobile apps and other sources.

We do not sell your personal data to third parties.

4. Marketing communications

From time to time we may send you relevant offers and news about our products and services in a number of ways, including by email. We may also send you information about other companies’ products and services that we believe may be of interest to you. We will only do this if you previously agreed to receive these marketing communications.

When you book or register with us we will ask if you would like to receive marketing communications. You can change your marketing preferences online, over the phone, using the ‘unsubscribe’ link in our marketing emails, replying STOP to the short code in our marketing text messages or by writing to us (e.g. email) at any time. Of course, the choice is entirely yours, but if you say you do not want to receive marketing information from us this will prevent you from receiving great offers or promotions that may be of interest to you.

You may still receive service-related communications from us. For example, confirming bookings you make with us and providing important information about the use of our products or services.

5. Market research

We like to hear your views to help us to improve our products and services, so we may contact you for market research purposes. You always have the choice about whether to take part or continue in our market research.

6. Sharing personal data with suppliers and retail partners

In order to provide products or services requested by you we may share personal data with suppliers of your travel arrangements, including airlines, hotels and transport companies.

We also work with carefully selected suppliers that carry out certain functions on our behalf. For example, companies that help us with IT services, storing and combining data, marketing, market research, processing payments and delivering products and services.

We may need to share personal data to establish, exercise or defend our legal rights; this includes providing personal data to others for the purposes of preventing fraud and reducing credit risk.

When we share personal data with other organisations we require them to keep it safe, and they must not use your personal data for their own marketing purposes.

We only share the minimum personal data that enable our suppliers and retail partners to provide their services to you and us.

7. Sharing personal data with regulatory authorities

So that you can travel, it may be mandatory (as required by government authorities at the point(s) of departure and/or destination) to disclose and process your personal data for immigration, border control, security and anti-terrorism purposes, or any other purposes which they determine appropriate.

Some countries will only permit travel if you provide your advance passenger data (for example Caricom API Data and US Secure Flight Data). These requirements may differ depending on your destination and you are advised to check. Even if not mandatory, we may assist where appropriate.

We may share the minimum personal data necessary with other public authorities if the law says we must, or we are legally allowed to do so.

8. Sharing personal data within the TUI Group

Our Privacy Notice applies to all of the services offered by the TUI Group but excludes services that have separate privacy notices that do not incorporate this Privacy Notice. We may share the minimum personal data necessary with other companies in the TUI Group, for example, to provide the products and services you request; to manage and improve our products, services and day-to-day operations; to help to personalise your experience; where appropriate, to make contact and interact with you; and, if allowed and appropriate, for marketing or market research purposes.

We may also share personal data with an organisation we sell or transfer (or enter into negotiations to sell or transfer) any of our businesses or any of our rights or obligations under any agreement we may have with you. If the transfer or sale goes ahead, the organisation receiving your personal data can use your data in line with this Privacy Notice.

9. Protecting your personal data

We know how important it is to protect and manage your personal data. We take appropriate security measures to help protect your personal data from accidental loss and from unauthorised access, use, alteration and disclosure.

The security of your data also depends on you. For example, where we have given you or where you have chosen a password for access to certain services, you are responsible for keeping this password confidential.

The personal data that we collect from you may be transferred to, and stored at, a destination outside the European Economic Area ("EEA"). It may also be processed by organisations operating outside the EEA who work for us or for one of our suppliers. We put in place appropriate protections to make sure your personal data remains adequately protected and that it is treated in line with this Notice. These protections include, but are not limited to, appropriate contract clauses, such as standard contract clauses approved by the European Commission, and appropriate security measures.

10. Data retention

We will retain your personal data for only as long as it is necessary for the uses set out in this Privacy Notice and/or to meet legal and regulatory requirements. After this period, we will securely erase personal data. If data is needed after this period for analytical, historical or other legitimate business purposes, we will take appropriate measures to anonymise this data.

11. About cookies and similar technologies

Cookies are small data files that allow a website to collect and store a range of data on your desktop computer, laptop or mobile device. Cookies help us to provide important features and functionality on our websites and mobile apps, and we use them to improve your customer experience. Please see our separate Cookie Notice.

12. Links to other websites

Our websites or mobile apps may contain links to websites operated by other organisations that have their own privacy notices. Please make sure you read the terms and conditions and privacy notice carefully before providing any personal data on another organisation’s website as we do not accept any responsibility or liability for websites of other organisations.

13. Social media features

Our websites or mobile apps may contain social media features such as Facebook, X, Google+ and Pinterest that have their own privacy notices. Please make sure you read their terms and conditions and privacy notice carefully before providing any personal data as we do not accept any responsibility or liability for these features.

14. Accessing and updating your personal data; and complaints

You have a right to ask for a copy of the personal data we hold about you, although you should be able to access online the personal data associated with your account or booking. You can write to us asking for a copy of other personal data we hold about you.

Please include any details to help us identify and locate your personal data. Where we can provide data access, we will do so free of charge except where further copies are requested in which case we may charge a reasonable fee based on administrative costs.

We want to make sure that the personal data we hold about you is accurate and up to date. If any of the details we hold are incorrect, please let us know.

You can also ask for your personal data to be rectified or erased, to object to the processing of your personal data and, where technically feasible, to ask for personal data you provided to be transmitted to another organisation.

We will update or erase your data, unless we have to keep it for legitimate business or legal purposes.

You can also contact us if you have a complaint about how we collect, store or use your personal data. We aim to resolve complaints but if you are dissatisfied with our response, you may complain to the local data protection authority here.

Please submit your request or complaint in writing to the Data Protection Officer:

TUI UK Retail Limited (agent)

DataprotectionUK@tui.co.uk

TUI Deutschland GmbH (principal): Datenschutz@tui.de

Impressum | Der Landesbeauftragte für den Datenschutz Niedersachsen

Please note that we may ask you to verify your identity before we can act on your request or complaint. We may also ask you for more information to help ensure that you are authorised to make such a request or complaint when you contact us on behalf of someone else.

15. Legal basis for processing personal data

We will only collect and use your personal data if at least one of the following conditions applies:

  • We have your consent;

Example: Customer account You give us permission to process your personal data when you register for a customer account.

  • It is necessary for a contract with you or to take steps at your request prior to entering into a contract;

Example: To provide the products and services you request We need to process your personal data so that we can manage your account or booking, provide you with the products and services you want to buy and help you with any orders and refunds you may ask for.

  • It is necessary for us to comply with a legal obligation;

Example: Sharing personal data with regulatory authorities So that you can travel, it may be mandatory (as required by government authorities at the point(s) of departure and/or destination) to disclose and process your personal data for immigration, border control, security and anti-terrorism purposes, or any other purposes which they determine appropriate.

  • It is necessary to protect your vital interests or those of another individual;

Example: In an emergency Your insurance company, their agents and medical staff may exchange relevant personal data and special categories of personal data with us in circumstances where we/they need to act on your behalf or in the interest of other customers or in an emergency.

  • It is in the public interest or we have official authority; or

Example: Security operations We may use personal data to respond to and to manage security operations, accidents or other similar incidents, including medical and insurance purposes.

  • It is in our or a third party’s legitimate interests and these are not overridden by your interests or rights.

Example: To personalise your experience We may use your personal data to better understand your interests so that we can try to predict what other products, services and information you might be most interested in. This enables us to tailor our communications to make them more relevant and interesting for you. Where we need to process special categories of personal data, for example health data for medical reasons, we will only do so if one or more additional conditions apply. For example, we have your explicit consent; it is necessary to protect the vital interests of you or another individual and you are physically or legally incapable of giving consent; it is necessary to establish, exercise or defend legal claims; it is necessary for reasons of substantial public interest.

16. Key terms

Agent: The person who is authorized to act on behalf of the principal.

Data controller: The data controller determines the purpose and manner in which personal data is used.

European Economic Area (EEA): EU Member States plus Norway, Iceland and Lichtenstein.

Online advertising: Marketing messages that you may see on the internet.

Principal: The person who is represented or on whose behalf the agent acts.

Special categories of data: These are categories of personal data revealing racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; genetic data, biometric data for the purpose of uniquely identifying a natural person; health data; and data concerning a natural person’s sex life or sexual orientation.

Caricom API Data: Some or all of the Caricom states have entered into an agreement with the USA whereby advance passenger data, required by and provided to Caricom states for border security purposes, will be passed to the USA Department for Homeland Security for processing on behalf of those Caricom states. Please see the Caricom website for more details.

US Secure flight Data: The Transportation Security Administration (TSA) requires you to provide your full name, date of birth and gender for the purpose of watch list screening. You may also provide your Redress Number, if available. Failure to provide details may result in denial of transport or denial of authority to enter the boarding area. TSA may share information you provide with law enforcement or intelligence agencies or others under its published system of records notice. Please see the TSA website for more details.

17. Changes to our Notice

This Notice replaces all previous versions. We may change the Notice at any time so please check it regularly on our website(s) for any updates. If the changes are significant, we will provide a prominent notice on our website(s) including, if we believe it is appropriate, electronic notification of Privacy Notice changes.

Last update: April 2024

TUI Deutschland GmbH Version

February 2026

PRIVACY NOTICE

Scope of this Privacy Notice

TUI Deutschland GmbH collects and processes your data as the controller. 
TUI Deutschland GmbH, Karl‑Wiechert‑Allee 23, 30625 Hanover, Germany. 
The controller is TUI Deutschland GmbH (referred to as “we” or “us” in this privacy notice), which is part of the TUI Group.

We are committed to doing the right thing when it comes to how we collect, use and protect your personal data. Below, we inform you about the processing of your personal data in connection with our services. Your privacy is important to us, so please take the time to read this privacy notice. It explains:

  1. which types of personal data we collect and why we collect them,

  2. when and how we may share personal data within the TUI Group and with other organisations,

  3. your options, including how you can access and update your personal data.

We have tried to make this notice as easy to understand as possible. If you are not familiar with terms such as “controller” or “special categories of personal data”, please refer to the section Key Terms for further explanations.

Personal Data We Collect We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). Personal data is processed by us for the performance of contractual obligations pursuant to Art. 6(1)(b) GDPR. In addition, we process your data to safeguard our legitimate interests pursuant to Art. 6(1)(f) GDPR.

When you register for our services, you may provide us with:

  1. your personal details, such as your address, email address, telephone number and date of birth,

  2. your account login details, such as your username and the password you have chosen.

When you book travel or other products from our offerings

If you book travel or other products from our services, we collect data necessary for the performance of your contract with us, in particular:

  1. your personal details (e.g. address, email address, telephone number and date of birth),

  2. the personal details of your fellow travellers,

  3. payment data (e.g. credit card details, bank account information, billing address),

  4. your booked products or services,

  5. your mobile phone number for the SMS assistant for flight schedule changes and transfer pick‑ups at the holiday destination,

  6. your mobile phone number for the SMS assistant solely for notifications from TUI crisis management in a potential crisis or incident situation,

  7. your mobile phone number for short‑term contact (SMS/telephone) to clarify urgent questions regarding outstanding payments in order to secure the booked service or journey.

When you browse our websites or use our mobile apps, we may collect:

  1. travel preferences,

  2. information about your browsing behaviour on our websites and mobile apps,

  3. information about when you click on one of our advertisements, including those displayed on websites of other organisations,

  4. information about how you access our digital services, including operating system, IP address, online identifiers and browser details,

  5. social preferences, interests and activities.

When you purchase our products in our shops or online, we may collect:

  1. information about the traveller, passport data, other identification documents and insurance information,

  2. relevant health data as well as any special dietary requirements or other requirements based on religious reasons or physical impairments,

  3. information about your purchases, such as what you purchased, when and where you purchased it, how you paid and credit card or other payment information,

  4. information about your browsing behaviour on our websites and mobile apps,

  5. information about when you click on one of our advertisements, including those shown on websites of other organisations,

  6. information about how you access our digital services, including operating system, IP address, online identifiers and browser details,

  7. social preferences, interests and activities.

When you contact us or we contact you, or when you participate in promotions, competitions or surveys

In these cases, we may collect:

  1. personal details you provide when contacting us via email, post, telephone or social media, such as your name, username and contact details,

  2. details about emails and other digital communications we send to you that you open, including links you click on,

  3. your feedback and contributions to customer surveys.

Other Sources of Personal Data We may also use personal data from other sources, such as:

  1. companies that provide information and data, business partners and public registers,

  2. your insurance company, its representatives and medical staff, who may exchange relevant personal data and special categories of personal data with us where we or they must act on your behalf, in the interests of other customers or in an emergency,

  3. social networks, if you log in using your social media credentials to connect with our platforms and online services (e.g. Facebook, Google or Twitter), thereby consenting to the sharing of your user data with us (e.g. name, email address, date of birth, location and other information),

  4. CCTV recordings, IP addresses and browser data collected in or near our shops, offices, other buildings or cruise ships.

Personal Data About Other Persons You Provide to Us If you provide us with personal data about other persons (e.g. fellow travellers):

  1. we will use this data only for the purposes described in this privacy notice,

  2. you must ensure that these persons have consented to the disclosure of their data and that you are authorised to provide it,

  3. you should also ensure that these persons are aware of how their personal data may be used by us.

Use of Your Personal Data

We use your personal data in various ways as explained below.

To provide products and services you request We must process your personal data in order to manage your account or booking, provide you with the requested products and services and assist you with orders or any requested refunds.

To manage and improve our products, services and daytoday operations

We use personal data to manage and improve our products, websites, mobile apps, loyalty programmes and other services. We use anonymised personal data for quality and training purposes for artificial intelligence applications, for example to develop and improve chatbots. We monitor how our services are used in order to protect your personal data and to detect and prevent fraud, criminal offences and misuse of services. We may use personal data to respond to and manage security incidents, disruptions or similar events, including those of a medical or insurance‑related nature. We may use personal data for market research and internal development in order to develop and improve our range of products, services, shops, IT systems, security, expertise and methods of communication with you. CCTV recordings are used to ensure the safety of everyone working in or visiting our shops, offices and other buildings, and to detect, prevent and prosecute criminal offences. Images may also be used to exercise or defend legal claims.

To contact and interact with you

If you contact us (e.g. via email, post, telephone or social media), we may use personal data to handle your request as efficiently and quickly as possible. We must process personal data in order to manage promotions and competitions in which you choose to participate, including those organised together with suppliers and business partners (e.g. prize notifications). We may invite you to participate in customer surveys and other market research activities carried out by the TUI Group or other organisations for your benefit. To better understand you as a customer and to provide services and marketing communications (including interest‑based online advertising), we may combine personal data collected during in‑store purchases with personal data collected via our websites, mobile apps and other sources.

We do not sell your personal data to third parties.

Marketing Measures Based on Your Consent

From time to time, we would like to send you offers and news about our products and services via various channels, such as email, messaging services or telephone. We may also send you information about products and services offered by other companies which we believe may be of interest to you. We will only do so if you have previously consented to receive such marketing communications.

When you make a booking with us or register, we will ask you whether and via which channels you would like to receive marketing communications. We will also ask whether you would like to receive marketing communications from other companies within the TUI Group and whether we may share your data with TUI Group companies for this purpose.

We verify the contact details you provide to us online for marketing purposes once again. For example, when registering for email marketing, we ask you to confirm your registration using the so‑called double opt‑in procedure. This means that we will only send you marketing emails once you have activated the confirmation link sent to you. A similar procedure is used for advertising via SMS or messaging services.

You may withdraw your consent to receive marketing communications at any time, for example by using the unsubscribe link included in our marketing emails (e.g. newsletters), via the online form available at 
https://www.tui.com/service-kontakt/anliegen-zu-ihren-kundendaten/werbeerlaubnis-entziehen/, 
or by replying STOP to the short code used in our marketing SMS messages.

You may withdraw your consent in whole or in part. If you no longer wish to receive advertising via a specific channel (e.g. telephone), you may inform us accordingly. You may also revoke all marketing consents you have given. Any consent granted separately for marketing communications by companies of the TUI Group may also be withdrawn separately. Naturally, the choice is entirely yours. However, if you tell us that you do not wish to receive marketing communications, you may miss out on attractive offers.

Please note that you may nevertheless continue to receive service‑related communications from us, such as booking confirmations or important information regarding the use of our products and services.

Product Recommendations by Email

As a customer of TUI Deutschland GmbH, you will regularly receive product recommendations from us by email. These product recommendations are sent irrespective of whether you have subscribed to a newsletter or have expressly consented to receiving marketing communications by email. Through these recommendations, we aim to provide you with information about products from our range that may be of interest to you based on your previous purchases with us. In doing so, we strictly comply with the applicable statutory requirements.

Product recommendations sent by email are based on the legal basis of Art. 6(1)(f) GDPR and are also permissible by email under Section 7(3) of the German Act Against Unfair Competition (UWG) when sent to existing customers. Each time your contact details are used for advertising purposes, we expressly inform you of your right to object, which you may exercise at any time easily and without formalities.

If you no longer wish to receive product recommendations by email from us, you may object at any time. Naturally, each email contains an unsubscribe link. You may also notify us via the online form available at 
https://www.tui.com/service-kontakt/anliegen-zu-ihren-kundendaten/werbeerlaubnis-entziehen/.

Personalising Your Experience

We aim to ensure that marketing communications (including online advertising) relating to our products and services, as well as those of our suppliers, business partners and the TUI Group, are tailored to your interests.

To achieve this, we use the personal data you provide to us and data generated automatically to better understand your interests, enabling us to predict which products, services and information may be most relevant to you. This allows us to tailor our communications and make them more relevant for you. For this purpose, we use existing information such as email delivery and read confirmations, information about your computer and internet connection, operating system and platform, your order history, service history, date and time of website visits, and products you have viewed. This information is used exclusively in pseudonymised form.

This analysis helps us to better understand you as a customer and enables us to provide you with personalised offers and services. Our objective is to make our advertising more useful and interesting for you, meaning that we offer products and services that better match your preferences as a customer.

If you do not wish to receive personalised services, such as a personalised newsletter, you may object to the personalisation of advertising at any time, for example by telephone, in writing or by email (e.g. to Datenschutz@tui.de). In this case, you will receive non‑personalised standard advertising. You may also object to marketing communications as a whole or withdraw your consent at any time. We will update your data as soon as possible.

Use of Pixel Tags for Reach Analysis

To analyse reach, we use so‑called tracking pixels. These are small, invisible graphics that are loaded when a blog article is accessed. By using this technology, we are able to track how often individual articles are accessed. In addition, a client ID is generated and a so‑called “METIS session cookie” is set on the user’s device when the marked text is accessed. By means of this client ID and the session cookie, it can be determined whether the text has already been accessed by the same user within a browser session. At no time are personal data processed, neither through the session cookie used nor at any other point within the METIS access counting process.

Processing is carried out on the basis of Art. 6(1)(f) GDPR, as we have a legitimate interest in determining the likelihood of text copying. The likelihood of a text being copied constitutes the basis for the lawful distribution of remuneration pursuant to the German Copyright Act (UrhG) by VG WORT to the authors and publishers of such texts.

Data is transferred to VG WORT by Kantar GmbH, Landsberger Straße 284, 80687 Munich. The use of the tracking pixel was reviewed by the Bavarian State Office for Data Protection Supervision and assessed as being compliant with data protection law.

Market Research

Your opinion is important to us. In order to improve our products and services, we may contact you for market research purposes. You always have the choice as to whether or not you wish to participate in our market research.

Detailed information on the data collected in the questionnaire, in particular regarding anonymous evaluation, is provided in the accompanying information. The legal basis for this processing is Art. 6(1)(f) GDPR, as we have a vital interest in these evaluations and the resulting improvements to our offerings.

If customer satisfaction surveys are sent to you by email, we either have your explicit consent for marketing communications pursuant to Art. 6(1)(a) GDPR or, as our customer, we are permitted to contact you by email in accordance with Section 7(3) of the German Act Against Unfair Competition (UWG). If you do not wish to receive the questionnaire, you may simply inform us by email at Datenschutz@tui.de.

Trustpilot Reviews

We participate in the review process of Trustpilot A/S, Pilestræde 58, 5, 1112 Copenhagen, Denmark.

Trustpilot allows users to review TUI services. Users who have used our services are asked to consent to receiving a review invitation. If users have given such consent (for example during the TUI booking process), they will receive a review invitation including a link to a review page. To ensure that users have actually used our services, we transfer to Trustpilot the data necessary for this purpose relating to the user and the service used (including, for example, name, email address and a reference number). This data is used solely to verify the authenticity of the review and to contact the user.

The legal basis for processing user data within the scope of the Trustpilot review process is consent pursuant to Art. 6(1)(a) GDPR.

Further information on the processing of your data by Trustpilot, as well as on objection rights and other data subject rights, can be found in Trustpilot’s privacy policy at: 
https://de.legal.trustpilot.com/end-user-privacy-terms.

Sharing Personal Data with Suppliers and Business Partners

In order to provide the products and services you request, we must share personal data relating to your booked travel services with providers, including airlines, hotels and transport companies.

We also work with carefully selected service providers that perform certain functions for us, for example companies assisting us with IT services, data storage and integration, marketing, market research, payment processing, and the provision of products and services.

We may need to share personal data in order to protect or defend our legal rights, including the transfer of personal data to third parties to prevent fraud or reduce the risk of payment defaults.

When we share personal data with other organisations, we require them to keep the data secure. They are not permitted to use your personal data for their own marketing purposes.

We only share the minimum amount of personal data required to enable our suppliers and business partners to provide their services to you and to us. Where required for the performance of your travel arrangements, the transfer of data to third countries is also lawful pursuant to Art. 49(1)(b) GDPR.

Sharing Personal Data with Authorities

In order to enable you to travel, it may be mandatory (as required by law by authorities at the departure and/or destination location) to disclose and process your personal data for purposes of immigration, border control, security, counter‑terrorism or other purposes deemed appropriate by authorities. Some countries only grant travel authorisation if you provide enhanced passenger data (e.g. Caricom API data and U.S. Secure Flight data). These requirements may vary depending on your destination, and we recommend checking the relevant requirements on a case‑by‑case basis. Even where disclosure is not mandatory, we are happy to support you. We may share the minimum amount of personal data necessary with authorities where required by law or where legally permitted.

Sharing Personal Data within the TUI Group

This privacy notice applies to all services provided by the TUI Group, with the exception of services that have their own privacy notices which do not refer to this notice. TUI Deutschland GmbH is a wholly owned subsidiary of the TUI Group, headquartered in Hanover. Further information on the group companies can be found at: https://www.tuigroup.com/. We may share the minimum amount of personal data with other companies within the TUI Group, for example to provide the products and services you request, to manage and improve our products, services and day‑to‑day operations, to personalise your travel experience where appropriate, to contact and interact with you, and, where permitted and appropriate, for marketing or market research purposes. We may also share personal data with other companies where contractual agreements exist. In such cases, services or our rights and obligations under contractual arrangements with you may be sold or transferred. Where such a transfer or sale takes place, the company receiving your personal data may use it in accordance with this privacy notice. When sharing personal data with other organisations, we require them to keep the data secure and only share the minimum amount necessary to enable them to provide their services. Frequently used TUI Group service providers involved in the processing of travel bookings include:

  1. TUI InfoTec GmbH, Karl‑Wiechert‑Allee 23, 30625 Hanover, www.tui-tech.com, Info@tui-infotec.com

  2. TUI Musement, C/Rita Levi S/N, Edificio TUI, Parc Bit, 07121 Palma de Mallorca, Spain, gdprdx@tui.com

  3. TUI Business Services GmbH, Karl‑Wiechert‑Allee 23, 30625 Hanover, Datenschutz@tui.de

  4. TUI Global Business Services Tunesia SARL, Boulevard 14 Janvier au‑dessus de BIAT Khezama, 4011 Sousse, Tunisia, Datenschutz@tui.de

  5. TUI Customer Operations GmbH, Karl‑Wiechert‑Allee 23, 30625 Hanover, www.tui.com, Datenschutz@tui.de

  6. TUIfly Vermarktungs GmbH, Karl‑Wiechert‑Allee 23, 30625 Hanover, www.tui.com, Datenschutz@tui.de

We may receive personal data about you from other companies within the TUI Group or share data with them for the following purposes:

  1. to provide services (including making and managing bookings or processing payments);

  2. to provide customer service support;

  3. to detect, prevent and investigate fraudulent and other illegal activities as well as data protection violations;

  4. for analytical purposes and product improvement;

  5. for personalised offers and for sending advertising with your consent or where otherwise permitted by law.

These purposes are based on legitimate interests in receiving and transferring personal data. Where applicable, TUI Deutschland GmbH also relies on compliance with legal obligations, such as lawful requests from law enforcement authorities. Furthermore, companies within the TUI Group may exchange personal customer data to ensure that all users are protected against fraudulent activities on their online platforms.

Processing of Location Data

As part of our services, we collect and process location data in order to provide you with location‑based services. We process your IP address and other online identifiers to determine your approximate location. Location data is used exclusively for the following purposes:

  1. provision of location‑based services and information;

  2. improvement of our services through analysis of location data;

  3. personalisation of content and offers based on your location.

In this way, we ensure that we provide you with relevant content and tailored information. The processing of your location data is based on your consent pursuant to Art. 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future. We only store your location data for as long as necessary to fulfil the purposes described above or as required by statutory retention obligations.

Protection of Your Personal Data

We recognise how important it is to protect and appropriately manage your personal data. We implement suitable security measures to help protect your personal data against accidental loss and against unauthorised access, use, alteration or disclosure. However, the security of your data also depends on you. For example, if we have provided you with a password to access certain services or if you have chosen a password yourself, you are responsible for keeping this password confidential. The personal data we collect from you may, in certain cases, be transferred to and stored at a destination outside the European Economic Area (EEA). Such data may also be processed by companies operating outside the EEA that work for us or for one of our suppliers. We implement appropriate safeguards to ensure that your personal data remains adequately protected and is processed in accordance with this privacy notice. These safeguards include, in particular, appropriate contractual provisions, such as standard contractual clauses approved by the European Commission, as well as suitable security measures.

Security Feature for WebsiteIntegrated Forms: Google reCAPTCHA (Location: USA)

To protect our contact forms, this website uses the reCAPTCHA service provided by Google Inc. (“Google”). The reCAPTCHA function is a security feature designed to protect our website against hacking attacks and spam. We use the Google reCAPTCHA service to determine whether an entry in our contact or newsletter forms is made by a human or an automated program. The service is only activated when a form is accessed. In doing so, Google checks the following data to determine whether you are a human or a bot:

  1. IP address of the device used,

  2. the website or form you visit on which the CAPTCHA is embedded,

  3. date and duration of the visit,

  4. identification data of the browser and operating system used,

  5. Google account information, if you are logged in to Google,

  6. mouse movements within the reCAPTCHA areas and tasks requiring image selection.

Processing is carried out on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in protecting its web services from abusive automated spying and from spam. Further information on Google’s data protection policies can be found at: 
https://www.google.de/intl/de/privacy 
https://business.safety.google/privacy/

Data Retention

Your personal data will be deleted as soon as it is no longer required for the purposes stated above. However, in certain cases, we may be required to continue storing your data until the expiry of statutory retention obligations and periods imposed by legislators or supervisory authorities, which may arise from the German Commercial Code (HGB), the Fiscal Code (AO) and the Anti‑Money Laundering Act (GwG) and which generally range from six to ten years. In addition, we may retain your data until the expiry of statutory limitation periods (generally three years; in individual cases up to 30 years), where this is necessary for the establishment, exercise or defence of legal claims. After expiry of these periods, the corresponding data will be routinely deleted. Where data is required beyond this period for analytical, historical or other legitimate business purposes, we take appropriate measures to anonymise such data.

Cookies, Personal Privacy Settings and ThirdParty Providers

Cookies are small data files that allow a website to collect and store a range of data on your desktop computer, laptop or mobile device. Cookies help us provide important features and functionality on our websites and mobile apps. Further information on the cookies and similar technologies we use can be found in our Cookie Notice (Cookie Notice at tui.com).

The legal basis for the setting and reading of cookies and the use of similar technologies, or for storing information on and accessing information from the end user’s device, is generally your consent (within the meaning of Art. 4(11) GDPR) pursuant to Art. 5(3) of the ePrivacy Directive (implemented in Germany by Section 25(1) of the German Telecommunications‑Telemedia Data Protection Act – TDDDG) in conjunction with Art. 6(1)(a) GDPR.

Where cookies are strictly necessary to provide a function expressly requested by you (“necessary cookies”), processing is carried out pursuant to Art. 5(3) of the ePrivacy Directive (implemented in Germany by Section 25(2) no. 2 of the TDDDG).

Any further processing of personal data is carried out in accordance with Art. 6(1) GDPR. Where cookies are used for the processing activities described in this privacy notice, the principles set out in the Cookie Notice apply. There, you can also view which cookies are used.

Information on how you can individually configure your cookie preferences and further data processing when visiting our website can be found under Cookie Settings.

Below you will find a list of service providers and third‑party providers that we use in connection with the storage and data protection‑compliant processing of cookies and other technologies on this website.

Our Service Providers and ThirdParty Providers

ADITION (Location: European Union)

On this website, data (anonymised IP address) is collected and stored for marketing and optimisation purposes using ADITION ad‑serving technology provided by ADITION technologies AG (www.adition.com). Pseudonymised user profiles may be created from this data. Cookies may be used for this purpose.

The data collected using ADITION ad‑serving technology is not used by ADITION to personally identify visitors to this website. You may object to the collection and storage of data at any time with effect for the future. An opt‑out function is available at www.adition.com/datenschutz/. You may also object to data collection and storage with future effect via http://www.performance-advertising.de/opt-out/.

Further information is available at: 
https://www.adition.com/datenschutz/

AdsWizz

We use AdsWizz, a service provided by AdsWizz Inc., 487A S El Camino Real, San Mateo, CA 94402, United States of America, for marketing purposes. AdsWizz is used to deliver interest‑based digital advertising and to analyse advertising effectiveness.

Processed data includes online identifiers (such as IP address, device characteristics, device identifiers, probabilistic identifiers, browsing and interaction data, as well as a generated “Listener ID”) and location data (with GPS precision). The Listener ID, which constitutes personal data, is set on the user’s end device when consuming digital audio content (e.g. via digital offerings of radio stations).

Data processing, in particular the setting of certain cookies, is generally carried out on the basis of your consent pursuant to Art. 6(1)(a) GDPR. You may withdraw your consent at any time without affecting the lawfulness of processing carried out on the basis of that consent prior to its withdrawal. AdsWizz is assigned to the “Marketing” category.

Further information is available at: https://www.adswizz.com/privacy-policy/

AdUp Technology (Location: European Union)

Tracking by Ad‑Up Technology, an advertising service provided by Axel Springer Teaser Ad GmbH (Axel‑Springer‑Straße 65, 10969 Berlin), is integrated on our websites. By collecting pseudonymised data, Ad‑Up is able to display interest‑based advertising on websites for a period booked by TUI.

Ad‑Up uses cookies to enable so‑called conversion tracking for advertisers, which measures the effectiveness of advertisements and keywords. In this context, information about the existence of a booking, your browser settings, the time of access and the exit page is transmitted to Ad‑Up.

The legal basis for this data transfer is your consent pursuant to Art. 6(1)(a) GDPR for the purpose of measuring the effectiveness of advertising campaigns and using the evaluations to optimise the promotion of our own offers. Ad‑Up Technology is assigned to the “Marketing” consent category.

Further information on data protection can be found at: 
https://www.adup-tech.com/datenschutz/

Via the “Activate Opt‑Out Cookie” button available at 
https://d.adup-tech.com/optin-optout.html 
you may also set an opt‑out cookie in your browser, thereby deactivating Ad‑Up in your browser and not only for this website.

Adobe Analytics (Location: European Union)

Adobe Analytics is a web analytics solution used to measure user behaviour on our websites in order to improve the customer experience and to monitor website performance and stability. User tracking is carried out via a cookie stored in the browser, the so‑called AMCV cookie (Adobe Marketing Cloud Visitor), which is valid for two years unless removed by the browser before expiry.

All data within Adobe Analytics is linked to this cookie value, allowing us to track different sessions a visitor has had on our websites, what they searched for, what they may have purchased and which errors occurred. In addition, we can determine the visitor’s approximate location based on the IP address and device type used to access the website.

The following data points are shared with Adobe Analytics via server‑to‑server tracking in order to better understand and analyse customer logins and behaviour: customer account ID.

Adobe Customer Journey Analytics (CJA) – Location: European Union

We use Adobe Customer Journey Analytics (CJA), provided by Adobe Systems Software Ireland Limited, Dublin, to analyse user behaviour and improve our digital offerings. The Adobe Experience Cloud Identity Service (ECID) is used, which creates a pseudonymous visitor identifier. Processing is carried out using Adobe Analytics cookies, with the IP address truncated or anonymised.

Processing is carried out exclusively on the basis of your consent pursuant to Art. 6(1)(a) GDPR, which is obtained via our cookie banner. You may withdraw your consent at any time with effect for the future via the cookie settings or object to the processing (opt‑out). No analysis takes place without consent.

Adobe Target (Location: European Union)

Adobe Target is a tool for A/B testing and optimisation, enabling us to carry out client‑side experiments on our website. It is used to test new ideas with a subset of website visitors before rolling them out to all visitors. It is also used to provide personalised experiences based on a user’s browsing behaviour and to deliver important functions and/or messages (e.g. refund request forms or banners relating to the COVID‑19 situation) as quickly as possible.

Adobe Experience Cloud Identity Service (Location: European Union)

The Adobe Experience Cloud Identity Service (ID service) provides a universal, persistent ID that identifies visitors across all Experience Cloud solutions. It is responsible for linking all Adobe‑related data with a single anonymous ID recorded via the AMCV cookie.

On our websites where Adobe Analytics and Adobe Target are used, data from both solutions is combined so that we can analyse all activities delivered via Adobe Target in Adobe Analytics.

Further information on data protection is available from the service provider at: 
https://www.adobe.com/de/privacy.html

Amazon Ad Tag

The controller uses the Amazon Advertising Tag provided by Amazon Europe Core S.à r.l., 38 avenue John F. Kennedy, L‑1855 Luxembourg (“Amazon”) on the website. This enables the controller to track conversions, retarget website visitors and obtain additional information about Amazon users who view the controller’s advertisements. The Amazon Ad Tag, a small JavaScript code snippet, places a cookie in your web browser or uses a pixel to collect data relating to visits to our website, including URL, referrer URL, IP address, device and browser characteristics, timestamps and page views. Amazon does not share personal data with us; instead, it provides aggregated reports on website audiences and advertising performance. You may consent to the use of the Amazon Ad Tag and withdraw your consent at any time via the following link: https://www.amazon.de/adprefs

Awin Tracking (Location: European Union)

Using the tracking service of Awin AG, Eichhornstr. 3, 10785 Berlin, cookies are stored in your browser when you visit websites or other online offerings of the Awin partner programme. In this context, we attribute the success of an advertising medium so that the corresponding billing via the network can be carried out. Awin does not establish a direct personal reference, but processes data that may be considered personal data. Only the following information is documented:

  1. the advertiser’s partner programme,

  2. the publisher,

  3. the time of the user’s action (click or view).

From this information, an individual numerical sequence is generated which cannot be assigned to an individual user. The legal basis for processing is your consent given at the start of website use pursuant to Art. 6(1)(a) GDPR. Awin tracking is assigned to the “Marketing” category. If you do not wish cookies to be stored in your browser, you also have the option of preventing this by configuring the appropriate settings in your browser. Cookies can be disabled in your respective browser under Tools / Internet Options. You may also restrict this setting to specific websites or configure your browser to notify you whenever a cookie is sent. Information on data protection provided by the service provider, as well as an additional option to object directly to the service provider using so‑called opt‑out cookies, can be found here: 
https://www.awin.com/de/rechtliches/cookieoptout

Bing / Microsoft (Location: European Union)

Bing (Redmond, WA 98052‑6399, USA) is an internet search engine operated by the third‑party provider Microsoft, which displays search queries in various categories (images, videos, news, maps). TUI.com uses the option of placing advertisements on Bing that correspond to your search queries. If you click on such an advertisement, Microsoft collects data about you and your interactions with Bing for billing purposes. The data collected depends on the context of your interactions with Microsoft. Microsoft also receives data about you from third‑party providers.

Further information about Bing, Microsoft’s data protection practices and opt‑out options for interest‑based advertising can be found at: 
https://privacy.microsoft.com/de-de/privacystatement

Botify

PageWorkers is a solution provided by Botify, 12 rue d’Amsterdam, 75009 Paris, France (www.botify.com), which enables search engine optimisation (SEO) teams to test and implement optimisations for search engine crawlers.

PageWorkers applies optimisations via an embedded JavaScript tag on the website. When an optimised webpage is requested, PageWorkers sends a secure HTTP request to retrieve page details, including the URL and all page links.

PageWorkers may process data, in particular IP addresses of website visitors (which are considered personal data in some countries). This processing is carried out solely for the limited purpose of delivering the JavaScript tag to the website visitor, as required for the effective provision of the services subscribed to by TUI from Botify.

Botify does not further store or process the IP addresses of website visitors. Further information on data protection by the third‑party provider Botify can be found, for example, at: 
https://www.botify.com/privacy-and-terms

Braze (Location: European Union)

We use the services of Braze, Inc., 318 West 39th Street, 5th Floor, New York, NY 10018, for newsletter marketing and push notifications.

Processing is carried out on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR in optimising our newsletter content and app push notifications. For this purpose, Braze processes user data such as email address, push tokens, interaction data and IP address in order to manage the sending of newsletters and push notifications and to analyse user interactions.

Further information on data processing by Braze can be found in Braze’s privacy policy: 
https://www.braze.com/company/legal/privacy/

Criteo (Location: European Union)

Our websites use cookies and advertising IDs from Criteo SA, 32 Rue Blanche, F‑75009 Paris, for advertising purposes. This enables us to display advertisements for our products on partner websites, apps and emails to users who have shown an interest in our products.

You can opt out of this interest‑based advertising at: 
https://optout.networkadvertising.org/?c=1https://www.youronlinechoices.com/

Further details on these linking capabilities can be found in Criteo’s privacy policy at: 
https://www.criteo.com/de/privacy/

The legal basis is your consent given at the start of website use pursuant to Art. 6(1)(a) GDPR. Criteo is assigned to the “Marketing” category.

Facebook – Conversion API

https://developers.facebook.com/docs/marketing-api/conversions-api/ We use server‑to‑server tracking by generating and storing a unique identifier when you click on a tracking link or are shown an advertisement. If you subsequently perform an action such as visiting a website or making a purchase, the unique identifier is matched. This enables us to measure the effectiveness of our advertising campaigns. The following data points are shared with our partner Facebook via server‑to‑server tracking in order to improve our marketing tracking and capabilities:

  1. pseudonymised email address,

  2. pseudonymised first name,

  3. pseudonymised last name,

  4. IP address,

  5. pseudonymised Tealium cookie ID,

  6. Facebook browser ID (“fbp”),

  7. Facebook click ID (“fbc”, advertising ID),

  8. details of conversion events (e.g. hotel ID).

Facebook / Meta (Location: USA)

The social media teams for digital marketing work with the third‑party provider Facebook/Meta to carry out advertising campaigns, both for brands and paid activities, on Facebook’s social networks, including Facebook and Instagram. Facebook event tracking enables marketing teams to measure and optimise the effectiveness of their campaigns and to adjust spending and targeting accordingly.

Facebook Pixel / Meta (Storage: USA)

Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland. We act as joint controllers together with Meta with regard to the processing of your personal data on our online services via the Facebook Pixel. The essential contents of the joint controllership agreement can be accessed at any time via the following link: 
https://www.facebook.com/legal/controller_addendum In particular, this agreement regulates which security measures Meta must observe 
(https://www.facebook.com/legal/terms/data_security_terms) 
and how data subject rights can be exercised vis‑à‑vis Meta. Meta processes your personal data on the basis of your consent via the Facebook Pixel in order to create campaign reports, track conversions, click events and provide targeted advertising outside our websites (retargeting). Processing is based on HTTP headers (including IP address, device and browser characteristics, URL, referrer URL), pixel‑specific data (including pixel ID and Facebook cookie), click behaviour, optional values (e.g. conversions, page type) and form field names (such as “email”, “address” or “quantity” when purchasing a product or service). We do not receive personal data about you from Meta, but only anonymised campaign reports regarding website audiences and advertisement performance. You can object to receiving interest‑based advertising from Facebook by adjusting your advertising preferences on Facebook’s website. Further information can be found at: 
https://www.facebook.com/policy

Google Ads (Location: European Union)

Google Ads is a pay‑per‑click advertising system in which we place bids indicating how much we are willing to pay for each click on our advertisements displayed in Google search results and the wider advertising network.

Tracking enables the marketing team to measure and optimise campaign effectiveness and to adjust budgets and target groups accordingly.

Further information on how Google processes personal data can be found at: 
https://business.safety.google/privacy/

Google Ads – Marketing Enhanced Conversion API

https://support.google.com/google-ads/answer/9888656?hl=de

We use server‑to‑server tracking by generating and storing a unique identifier when you click on a tracking link or when an advertisement is displayed to you. If you subsequently perform an action, such as visiting a website or making a purchase, the unique identifier is matched. This allows us to measure the effectiveness of our advertising campaigns.

The following data points are shared with our partner Google for Google Ads via server‑to‑server tracking in order to improve our marketing tracking and capabilities: pseudonymised email address, IP address, pseudonymised Tealium cookie ID, Google Click ID (“gclid”, advertising ID), and details of the conversion event (e.g. hotel ID).

Search Ads 360

We use Google Search Ads 360, a service provided by Google Ireland Limited, for the efficient management and optimisation of digital advertising campaigns. The integration is performed server‑side, whereby certain event data (e.g. completed purchases or contact enquiries) is transmitted to Google in order to measure and improve the effectiveness of our campaigns.

Data processing is carried out on the basis of your consent pursuant to Art. 6(1)(a) GDPR, provided that you have given such consent via our cookie banner or privacy settings.

The following data points are shared with our partner Google for Google Search Ads 360 via server‑to‑server tracking to improve our marketing tracking and capabilities: pseudonymised email address, IP address, pseudonymised Tealium cookie ID, and details of the conversion event (e.g. hotel ID).

Google Analytics (Location: European Union)

For the purpose of designing our website in line with user needs, measuring reach, analysing general user behaviour on the website and optimising business operations, we use Google Analytics, a web analytics service provided by the third‑party provider Google Ireland Limited (a company incorporated and operated under Irish law, registration number 368047, with registered office at Gordon House, Barrow Street, Dublin 4, Ireland).

Google Analytics uses so‑called “cookies”. The information generated by these cookies about your use of our website (including your IP address) is transmitted to and stored on Google servers. TUI has activated IP anonymisation on this website. As a result, your IP address is truncated by Google within member states of the European Union or in other contracting states to the Agreement on the European Economic Area before any further processing. IP anonymisation does not, however, render your usage behaviour anonymous, as attribution may still occur, for example via the cookies used.

Google Analytics is used under joint responsibility of Google and the website operator. An agreement on data processing has been concluded with Google for this purpose, which currently assigns full responsibility for the respective processing activities to both parties. Google combines your usage data with other data collected by Google and uses the resulting profiles to display personalised advertising and provide analytics.

For the website operator, Google will use this information to evaluate your use of the website, compile reports on website activities and provide additional services related to website and internet usage.

The data processed by Google includes device settings and device data, precise usage times of individual elements of this website and thus your usage behaviour. Further information on Google’s data usage, settings and objection options can be found on Google’s websites:

https://policies.google.com/technologies/partner-sites?hl=de 
(“How Google uses data when you use our partners’ sites or apps”)

https://policies.google.com/technologies/ads 
(“Technologies and Principles – Advertising”)

https://adssettings.google.com/authenticated?hl=de 
(“Ad Settings”)

https://business.safety.google/privacy/ 
(“Processing of personal data”)

The IP address transmitted by your browser as part of Google Analytics is not combined with other Google data. You may prevent the storage of cookies by adjusting your browser settings; however, please note that in this case you may not be able to use all functions of this website in full.

You may also prevent the collection of data generated by cookies and related to your use of the website (including your IP address) by Google and the processing of this data by Google by downloading and installing the browser add‑on available at the following link: 
https://tools.google.com/dlpage/gaoptout?hl=de

Please note that use of the browser add‑on is limited to the respective browser and device and must not be disabled or deleted after installation in order for Google Analytics deactivation to remain effective.

Google’s privacy policy is available at: 
https://www.google.com/intl/de/policies/privacy/

Google Remarketing (Location: European Union)

To generate interest‑based online advertising, we use remarketing with Google Analytics and Google Signals. Our advertisements are displayed on websites by third‑party providers, including Google. We and third‑party providers, including Google, use first‑party cookies (e.g. Google Analytics cookies) in combination with third‑party cookies (e.g. DoubleClick cookies) to target, optimise and display advertisements based on users’ previous visits to our website.

We use Google Analytics reports on performance by demographic characteristics and interests. We use data obtained from Google’s interest‑based advertising and visitor data from third‑party providers (e.g. age, gender, interests, cross‑device activity) within Google Analytics for marketing purposes and to continuously improve our offerings.

The legal basis is your consent pursuant to Art. 6(1)(a) GDPR. Google Remarketing is assigned to the “Marketing” category.

You may also object to the use of Google Remarketing directly with the service provider by preventing the setting of cookies by Google and/or DoubleClick or by using Google’s opt‑out options.

More information about Google advertising can be found at: 
https://www.google.com/policies/privacy/ads/

You may also configure and disable Google Remarketing via the following website: 
https://adssettings.google.com/authenticated?hl=de

Further information on how Google processes personal data can be found at: 
https://business.safety.google/privacy/

Google Floodlight / DoubleClick (Location: European Union)

DoubleClick is a subsidiary of the third‑party provider Google Inc. With the product Floodlight, a DoubleClick Manager function is provided which enables TUI to record conversions, i.e. activities of website visitors after they have seen or clicked on one of our advertisements, use this information in reports and define target audiences. Users are included in lists based on specific actions performed on a website, which are then available for targeting in subsequent campaigns. The legal basis for this processing is your consent given at the start of website use pursuant to Art. 6(1)(a) GDPR.

You may additionally object to the use of personalised advertising via DoubleClick Floodlight across websites at any time directly with the service provider via the following link: 
https://policies.google.com/privacy?hl=de Further information on how Google processes personal data can be found at: 
https://business.safety.google/privacy/

Google Maps (Location: European Union and USA) On our website, we use the Google Maps (API) map service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”) to display our location. When you access a sub‑page on which Google Maps is integrated, our website transmits information, including your IP address, to Google in the United States, where it is stored on Google servers. If you have a Google user account and are logged in at the time you visit our website, this data is directly associated with your account. Even if you do not have a Google user account or are not logged in, Google creates a usage profile for you. This takes place regardless of whether Google provides a user account that you are logged into or whether no user account exists. Our transfer of data to Google is based on our legitimate interest in providing the Google Maps functionality on our website. Both we and Google are considered joint controllers with regard to the Google Maps service pursuant to Art. 26 GDPR. Each party independently determines the purposes and means of processing personal data and fulfils the requirements of the GDPR. The allocation of processing‑related responsibilities can be found in the Google Maps Controller‑Controller Data Protection Terms: 
https://privacy.google.com/intl/de/businesses/mapscontrollerterms/ You can prevent the assignment of the data transmitted by us to your Google user account by logging out of Google before visiting our website. To completely prevent the transfer of data to Google, you must disable JavaScript in your browser. In this case, the map display can no longer be used. Further information on Google and the use of Google Maps can be found here:

  1. Google Terms of Service: 
    https://www.google.de/intl/de/policies/terms/regional.html

  2. Google Maps Terms of Service: 
    https://www.google.com/intl/de_US/help/terms_maps/

  3. Google Privacy Policy: 
    https://www.google.de/intl/de/policies/privacy/

  4. Google Maps Controller‑Controller Data Protection Terms: 
    https://privacy.google.com/intl/de/businesses/mapscontrollerterms/

  5. Processing of personal data: 
    https://business.safety.google/privacy/

iAdvize (Location: Europe)

We use the “iAdvize” chat function provided by iAdvize SAS, Bat B Le Berlingot, 9 rue Nina Simone, CS 14021, F‑44040 Nantes Cedex 1, France (“iAdvize”) on our website. iAdvize is a SaaS solution that enables us to optimise our online customer service. Our aim is to increase customer satisfaction and optimise our website offerings. We use iAdvize to provide additional support via chat and other contact options. A small window allows you to initiate contact. Data required for the iAdvize service is stored on your device via cookies. Data is only stored on iAdvize servers once you initiate a communication process with one of our advisors. The advisor receives information about your visit to our website and standard web data (e.g. browser identifier and operating system) in order to assist you as quickly as possible. Data is collected solely for the purpose of user support. The collection and processing of your data is carried out exclusively on the basis of your consent. You may update your consent for the services mentioned above at any time by re‑opening the cookie banner or via the cookie settings. iAdvize will only collect, process and use the data for the purposes specified by us and will not pass the data on to third parties, such as advertising networks. The data is deleted as soon as it is no longer required for the processing purposes.

Kayak (Location: Switzerland)

Kayak Europe GmbH, Fraumünsterstr. 16, CH‑8001 Zurich, operates a travel search engine as its main product for flights, hotels, rental cars and package holidays. Kayak collects the following personal data: platform information, booking information, account information, trips, customer support data and promotional information. Detailed information on the types of data processed can be found at: 
https://www.kayak.de/privacy#cookies

TUI uses the option of placing advertisements on Kayak that correspond to your search queries. If you follow such an advertisement, Kayak collects data about you and your interactions with Kayak. The legal basis is your consent given at the start of website use pursuant to Art. 6(1)(a) GDPR.

Further information on data protection and an additional opt‑out option directly with the service provider can be found at: 
https://www.kayak.de/privacy#cookies

Pinterest (Location: European Union)

Using Pinterest’s conversion tracking technology provided by Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland, we are able to display relevant advertisements, create campaign performance reports, build remarketing lists and form interest‑based target groups and lookalikes (so‑called statistical twins).

For this purpose, a Pinterest conversion tracking pixel is integrated on our pages, which informs Pinterest that you have visited our website and which areas of our offerings you are interested in. For example, if you have shown interest in one of our products on our website, you may be shown an advertisement for our products on Pinterest.

The following data points are shared with our partner Pinterest via a pixel and server‑to‑server tracking to improve our marketing tracking and capabilities: pseudonymised email address, IP address, pseudonymised Tealium cookie ID, Pinterest click ID (“_epik”, advertising ID) and details of conversion events (e.g. hotel ID).

Pinterest Tag HTTP Data

Log data that is generated for technical reasons when using the Pinterest Tag via HTTPS, including IP address, type and version of the internet browser, operating system used, accessed page, referring page (referrer URL), and date and time of access.

Pinterest Tag EndDevice Data

Data generated by Pinterest and assigned to your device, such as device type, operating system or a unique device identifier.

Pinterest Tag Measurement Data

Device‑related raw data collected and analysed via the Pinterest Tag when using our website, in particular information about completed purchases, shopping carts, search behaviour and individual page views. This data does not allow us to directly identify you personally.

Pinterest Tag Reporting Data

Aggregated report data generated from device‑related raw data, including information on the effectiveness of advertisements and the assignment of users to target groups for Pinterest advertising. Pinterest may generate additional data from this information for its own purposes or for third‑party purposes. After consent is given, data is automatically provided by the user’s browser.

The recipient of the data is Pinterest Europe Limited, Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland. Provision of the above data is neither legally nor contractually required and is not necessary for the conclusion of a contract. There is no obligation to provide the data. If the data is not provided, we are unable to perform advertising analysis and optimisation using Pinterest.

No automated decision‑making takes place. We have no knowledge of any automated decision‑making processes used by Pinterest for advertisement delivery.

Further information is available at: https://policy.pinterest.com/privacy-policy

Qualtrics (Location: Dublin)

We use “Qualtrics” on our websites. This software is operated by Qualtrics Ireland Limited, Costello House, 1 Clarendon Row, Dublin 2, D02 TA43, Ireland.

This software allows us to anonymously survey users about our products and to capture anonymous feedback directly within our products. For this purpose, a cookie is set in the user’s browser. We use the anonymous feedback data to optimise our products and services with the aim of providing an excellent customer experience.

Qualtrics does not process any personal data. Cookies expire in accordance with standard browser settings (usually 13 months). Data is otherwise deleted as soon as it is no longer required for processing purposes.

The legal basis for the use of Qualtrics is consent. Consent is voluntary and can be withdrawn at any time with effect for the future; the lawfulness of processing carried out prior to withdrawal remains unaffected.

Quantum Metric

We use a web analytics tool provided by Quantum Metric Inc., 10807 New Allegiance Drive, Suite 155, Colorado Springs, CO 80921, USA, to analyse the use of the website and identify areas for improvement.

Quantum Metric uses cookies to identify a visitor’s browser and track user behaviour. Mouse clicks, mouse movements and sessions are recorded anonymously in order to improve the website, analyse errors and create heatmaps and behavioural reports.

Use of this analytics tool is based on your consent pursuant to Art. 6(1)(a) GDPR. Consent is voluntary and may be withdrawn at any time with effect for the future.

You may change your selection via the cookie settings. Quantum Metric is assigned to the “Statistics” category. Alternatively, you can opt out directly with Quantum Metric and find further information on data protection at: 
https://www.quantummetric.com/legal/privacy-policy

RTB House

We use the services of RTB House GmbH, Kurfürstendamm 226, 10719 Berlin, Germany, an advertising technology company, to conduct personalised advertising campaigns on our behalf. You may opt out of this interest‑based advertising at: 
https://optout.rtbhouse.com/

Further details on these data processing and linking activities can be found in the provider’s privacy policy at: 
https://www.rtbhouse.com/privacy-center

The legal basis for processing is your consent given at the start of website use pursuant to Art. 6(1)(a) GDPR. RTB House GmbH is assigned to the “Marketing” category.

Ryanair

If you wish to book a trip with Ryanair online, it is necessary to interact with Ryanair’s website in order to complete your booking. Please note that the cookie settings you have selected on tui.com do not automatically apply to the Ryanair website and vice versa. Tui.com and Ryanair exchange only the data necessary to complete the booking; no additional data is shared.

Further information on data protection and cookies at Ryanair can be found in Ryanair’s privacy and cookie policy.

Skyscanner (Location: United Kingdom)

Skyscanner Ltd., Floor 6, The Avenue, 1 Bedford Avenue, London, WC1B 3AU, operates a travel search engine as its primary product for flights, hotels and car rentals. Skyscanner collects the following personal data: platform information, booking information, customer support information and promotional information.

Skyscanner’s privacy and cookie policies can be found at: 
https://www.skyscanner.de/medien/datenschutzrichtlinie

https://www.skyscanner.de/medien/cookie-richtlinien

TUI uses the option of placing advertisements on Skyscanner that correspond to your search queries. If you follow such an advertisement, Skyscanner collects data about you and your interactions with Skyscanner and TUI. The data collected is stored for as long as it is necessary for evaluation and billing purposes, for audit purposes and to comply with statutory retention obligations.

The legal basis for this processing is your consent given at the start of website use pursuant to Art. 6(1)(a) GDPR.

Tealium (Location: United Kingdom)

Tealium is a tag management system used to implement scripts and tracking pixels on our websites and mobile apps. It helps us transmit data to other tools and third‑party providers used by us, but does not store any data itself. It sets cookies that allow us to identify you as an anonymised individual user. Thanks to this cookie, for example, you only need to select your cookie preferences during your first visit and not again on every subsequent page.

Tealium Collect

Tealium Collect is a function of the Tealium tag management system. Data may be transmitted to servers in Germany, where it can be pre‑processed and subsequently forwarded to other tools and third‑party providers listed in this privacy notice (e.g. Meta Platforms Ireland Limited, Google Ireland Limited, Pinterest Europe Limited, Microsoft Ireland Operations Limited).

Using this tool, we may create a customer profile based on the collected data. These functions are only used if you have consented to the relevant category of a tool or partner during your website visit (cookie notice). Tealium Collect does not store any data itself.

The Trade Desk

We use cookies, device IDs and similar tracking technologies from The Trade Desk on our website. The service is used to analyse user behaviour on our website and to deliver advertising.

The Trade Desk Pixel is a product of The UK Trade Desk Ltd., 10th Floor, 1 Bartholomew Close, London EC1A 7BL, United Kingdom (“The Trade Desk”). The platform collects and processes pseudonymised data, i.e. data that does not directly identify individuals, relating to users, devices and advertisements, as well as where advertisements are displayed.

The processed data includes cookie ID, mobile device ID, IP address, interest information, web browser and device information, information about which advertisements have already been shown to you, timestamps and website URLs.

Please also refer to The Trade Desk’s privacy policy at: 
https://www.thetradedesk.com/de/privacy

Information on cookies can be found at: 
https://www.thetradedesk.com/legal/cookie-notice

Information on opting out of data processing by The Trade Desk is also provided there.

The United Kingdom is subject to an adequacy decision by the European Commission pursuant to Art. 45 GDPR and therefore provides an adequate level of protection for personal data. However, The Trade Desk is affiliated with other companies within the same corporate group (in particular The Trade Desk Inc., 42 N. Chestnut St., Ventura, CA 93001, USA) located in the United States and uses these as processors. As a result, a transfer of your personal data to the United States cannot be ruled out.

TikTok

We use the TikTok Pixel on our website. The TikTok Pixel is an advertiser tool provided by TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland, and TikTok Information Technologies UK Limited, WeWork, 125 Kingsway, London, WC2B 6NH, United Kingdom (together “TikTok”).

The TikTok Pixel is a JavaScript code snippet that enables us to understand and track the activities of visitors on our website. The TikTok Pixel collects and processes information about visitors to our website or about the devices they use. Data collected via the TikTok Pixel is used for targeting our advertisements, improving ad delivery and for personalised advertising.

For this purpose, the data collected on our website via the TikTok Pixel is transmitted to TikTok. Some of this data consists of information stored on your device. In addition, cookies are used by the TikTok Pixel to store information on your device. Such storage of information or access to information already stored on your device occurs only with your consent.

We also use the TikTok Events API (https://ads.tiktok.com/help/article/events-api). We use server‑to‑server tracking via the TikTok Events API, whereby a unique identifier is generated and stored when you click on a tracking link. This enables us to measure the effectiveness of our advertising campaigns.

The following data points are shared with our partner TikTok via server‑to‑server tracking: pseudonymised email address, IP address, pseudonymised Tealium cookie ID, TikTok Click ID (advertising ID), and details of conversion events (e.g. hotel ID).

Further information on how TikTok processes personal data, including the legal basis relied upon by TikTok and the options for exercising your rights, can be found in TikTok’s privacy policy at: 
https://www.tiktok.com/legal/privacy-policy?lang=de-DE

Xandr Universal Pixel

Xandr Inc., 28 West 23rd Street, 4th Floor, New York, NY 10010, USA (“Xandr”), provides advertising technology that enables websites, apps, smart TVs, audio and other internet‑connected devices to generate revenue by displaying advertising to users, and enables marketers and advertisers to display advertising to individuals (“end users”, “consumers” or “you”) who may be interested in their products or services.

The platform is designed to use information about internet users that does not identify them in the “real world”. Xandr has contractual provisions in place that prohibit customers of the platform from directly linking platform cookies with personal information that could directly identify an individual.

Opt‑out link: 
https://monetize.xandr.com/privacy-center/opt_out

Cookie list (EN): 
https://about.ads.microsoft.com/en-us/solutions/xandr/digital-platform-cookie-policy

Data Transfers to Third Countries

According to its own statements, Facebook/Meta has implemented additional security measures, in addition to concluding the applicable EU standard contractual clauses, to achieve an adequate level of protection for your data. These measures include, in particular:

  1. IT security: Facebook/Meta has established a comprehensive IT security programme to secure data stored in systems, platforms and products.

  2. Encryption: Data in transit is encrypted so that it cannot be read.

  3. Policies and procedures: Policies and processes are in place to review the legality of government access requests through an expert team and, where applicable, to refuse disclosure (see the “Government Requests for User Data” section in the Transparency Center).

  4. Transparency reporting: Meta publishes information on government requests in its Transparency Report (including information under the U.S. Foreign Intelligence Surveillance Act (FISA), where legally permissible).

  5. Data centres: Information on Meta’s data centres can be found at: 
    https://sustainability.fb.com/data-centers/

Google reCAPTCHA also uses Google’s global IT infrastructure to detect automated bot activity. Exclusive data localisation within the European Economic Area is not possible for this feature. The function is activated only when you access the forms integrated on our website. We explicitly inform you about the use of reCAPTCHA and a possible data transfer outside the European Economic Area. You may therefore decide whether to use the form or instead contact customer service.

Links to Other Websites

Our websites and mobile apps may contain links to websites of other organisations that have their own privacy notices. Please ensure that you carefully read the terms of use and privacy notice before submitting personal data to websites of other organisations, as we accept no responsibility or liability for such websites.

Social Media Features and Messaging Services

Our websites and mobile apps may contain social media features provided by services such as Facebook, Twitter, Pinterest or Instagram, each of which has its own privacy notice. We use plugins from Facebook, Twitter, Pinterest and Instagram on our websites. If you do not want social networks to collect data about you via active plugins, you can select the browser setting “block third‑party cookies”. In this case, the browser will not send cookies to the servers of third‑party providers for embedded content. Please note, however, that in addition to plugins, other cross‑site features may no longer function properly when this setting is enabled. When these plugins are activated, your browser establishes a direct connection to the servers of the respective social network as soon as you access a page of our website. The content of the plugin is transmitted directly to your browser by the social network and integrated into the website. As a result, the social network receives information that you have accessed the relevant page of our website. If you are logged in to the respective social network, the visit may be assigned to your user account. If you interact with the plugins, for example by clicking the Facebook “Like” button or posting a comment, the corresponding information is transmitted directly from your browser to the social network and stored there. Even if you are not logged in to a social network, websites with active social plugins may transmit data to the networks. An active plugin sets a cookie with a unique identifier each time the website is accessed. Because your browser sends this cookie unprompted with every connection to the network server, the network could theoretically create a profile of which websites the user associated with that identifier has visited. It would also be possible to associate this identifier with an individual at a later stage, for example when logging in to the social network. The purpose and scope of data collection, as well as the further processing and use of the data by the social networks, and your rights and options for protecting your privacy, can be found in the respective privacy notices of the social networks. The corresponding links are provided below.

Integration of Facebook Plugins

Our website includes social plugins (“plugins”) of the social network Facebook, operated by Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland (“Meta”). Information on the purpose and scope of data collection, further processing and use of data by Meta, as well as your rights and settings options for protecting your privacy, can be found in Meta’s privacy notice: 
https://www.facebook.com/privacy/center/

Integration of Twitter Plugins

Our website includes social plugins (“plugins”) of the social network Twitter, operated by Twitter Inc., 795 Folsom St., Suite 600, San Francisco, CA 94107, USA (“Twitter”). Information on the purpose and scope of data collection, further processing and use of data by Twitter, as well as your rights and settings options for protecting your privacy, can be found in Twitter’s privacy notice: 
https://twitter.com/privacy

Integration of Pinterest Plugins

This website also integrates plugins of the social network Pinterest Inc., 635 High Street, Palo Alto, CA 94301, USA (“Pinterest”). You can recognise the Pinterest plugin by the “Pin it” button on our website. If you click the Pinterest “Pin it” button while you are logged into your Pinterest account, you can link content from our pages to your Pinterest profile. This allows Pinterest to associate your visit to our pages with your Pinterest user account.

We would like to point out that we have no knowledge of the content of the data transmitted or how it is used by Pinterest. Further information can be found in Pinterest’s privacy policy at: 
http://about.pinterest.com/de/privacy

Integration of Instagram Plugins

This website also integrates plugins of the social network Instagram Inc., 1601 Willow Road, Menlo Park, CA 94025, USA (“Instagram”). You can recognise the Instagram plugin by the “Instagram” button on our website. If you click the “Instagram” button while you are logged into your Instagram account, you can link content from our pages to your Instagram profile.

This allows Instagram to associate your visit to our pages with your Instagram user account. We would like to point out that we have no knowledge of the content of the data transmitted or how it is used by Instagram. Further information can be found in Instagram’s privacy policy at: 
http://instagram.com/about/legal/privacy/

Integration of Happy Contest Competitions / Quizzes

Our competitions and quizzes are integrated into our services via an iFrame (a website within our website) using the services of Happy Contests GmbH, Maximilianstraße 14, 86150 Augsburg, Germany (“Happy Contests”). Happy Contests is engaged as a processor pursuant to Art. 28 GDPR.

Further information on data processing by Happy Contests and on settings to protect your privacy can be found at: 
https://www.happy-contests.de/datenschutz/

The privacy policy of Happy Contests GmbH is available at: 
https://www.happy-contests.de/datenschutz/

Amazon API Gateway (Location: European Union)

Amazon API Gateway, a cookie‑like technology (execute-api.eu-central-1.amazonaws), is a fully managed service that simplifies the creation, publication, maintenance, monitoring and securing of APIs for developers at any scale. APIs act as a “front door” for applications to access data, business logic or functionality from backend services.

With API Gateway, RESTful APIs and WebSocket APIs can be created, enabling applications to communicate bidirectionally in real time. API Gateway supports containerised and serverless workloads as well as web applications.

Further information on this service can be found at: 
https://aws.amazon.com/de/api-gateway/

Amazon CloudFront (Location: European Union)

Amazon CloudFront is a web service, using cookie‑like technology (cloudfront.net), that accelerates the delivery of static and dynamic web content such as HTML, CSS, JavaScript and image files to users. CloudFront distributes content via a global network of data centres known as edge locations. When a user requests content, the request is routed to the edge location with the lowest latency, ensuring optimal performance.

Further information on this service can be found at: 
https://docs.aws.amazon.com/de_de/AmazonCloudFront/latest/DeveloperGuide/Introduction.html

Datatrans (Location: Switzerland)

Datatrans is a service provider used for secure payment processing and optimisation processes in online commerce and is based in Switzerland. Further information on this service can be found at: 
https://www.datatrans.ch/de

production-beone.com (Location: European Union)

production-beone.com is an internal TUI content API and provides image data for TUI.com.

tui-tas.com & cdn.tui-tas.com (Location: European Union)

This technically necessary cookie‑like technology is required for the technical provision of seat reservations and seat‑related components during the booking process.

The cookie‑like tracking technologies mentioned above are purely technical components of the website that are integrated to ensure the provision of necessary technical services during the booking process. These technically required cookies are categorised as Necessary Cookies and Functions.

Necessary cookies are required for the website to function and cannot be disabled in your systems. We require these cookies to ensure that the service you request functions properly, that you can navigate our website and use its features, such as completing forms. These cookies cannot be disabled.

Push Notifications

You can subscribe to receive our push notifications. To send push notifications, we use the delivery service “Accengage”, operated by Accengage SAS, 31 Rue du 4 Septembre, 75002 Paris, France.

You will regularly receive information about special offers, deals, products and suitable offers from TUI Deutschland GmbH via our push notifications. To subscribe, you must confirm your browser’s request to receive notifications. This process is documented and stored by Accengage, including the time of subscription as well as your browser ID or device ID. Collection of this data is necessary to enable us to verify processes in the event of misuse and thereby ensure our legal protection.

In order to display push notifications, Accengage processes your browser ID and, in the case of mobile access, your device ID on our behalf. By subscribing to our push notifications, you consent to receiving them. The legal basis for processing your data after subscribing to push notifications is Art. 6(1)(a) GDPR, provided you have given your consent. Accengage and TUI also analyse push notifications for statistical purposes. Accengage can determine whether and when our push notifications are displayed and clicked. You may withdraw your consent to the storage and use of your personal data, to the receipt of push notifications and to the statistical analysis described above at any time with effect for the future. To withdraw your consent, you can adjust the relevant settings for receiving push notifications in your browser. If you use our push notifications on a desktop PC with the Windows operating system, you can also unsubscribe by right‑clicking on the respective push notification and using the settings displayed. Your data will be deleted as soon as it is no longer necessary to achieve the purpose for which it was collected. Accordingly, your data will only be stored for as long as your subscription to our push notifications remains active.

Access to and Updating of Your Personal Data; Complaints

You have the right to request a copy of the personal data that we store about you, although you should usually also be able to view and update the data associated with your customer account and bookings online. You may nevertheless contact us and request a copy of any other personal data stored about you. Please provide details that help us identify and locate your personal data. Where we are able to provide access, this will be done free of charge unless additional copies are requested. In such cases, we may charge a reasonable fee based on administrative costs. We aim to ensure that the personal data we hold about you is accurate and up to date. If any information we store about you is incorrect, please let us know. You may also request the correction or deletion of your personal data, object to the processing of your personal data and, where technically feasible, request that personal data you have provided to us be transferred to another organisation. We will update or delete your data unless we are required to retain it for legitimate business or legal purposes. You may also contact us if you would like to complain about how we collect, store and use your personal data. Our aim is to address your concerns as effectively as possible. Pursuant to Art. 77 GDPR in conjunction with Section 19 of the German Federal Data Protection Act (BDSG), you have the right to lodge a complaint with a supervisory authority. The supervisory authority responsible for TUI Deutschland GmbH is:

  1. State Commissioner for Data Protection and Freedom of Information of Lower Saxony

Prinzenstraße 5, 30159 Hanover Phone: +49 511 120‑4500 Email: poststelle@lfd.niedersachsen.de If you are not satisfied with our response, you may also contact your local data protection authority at: 
https://www.lfd.niedersachsen.de/startseite/ Please note that we may ask you to verify your identity before processing your request or complaint. We may also request additional information to ensure that you are authorised to submit the request or complaint, for example if you contact us on behalf of another person.

For questions, requests or comments relating to data protection, please contact the Data Protection Officer of TUI Deutschland GmbH by email at: Datenschutz@tui.de. Legal Basis for the Processing of Personal Data We collect and use your personal data only if at least one of the following conditions applies:

  1. you have given your consent;

  2. it is necessary in order to contact you or to take steps at your request prior to entering into a contract;

  3. it is necessary to comply with a legal obligation.

Example: Customer Account You grant us permission to process your personal data when you register for a customer account.

Example: Provision of Products and Services Requested by You We must process your personal data in order to manage your customer account or booking, to provide you with the products and services you wish to purchase, and to assist you with orders or any potential refunds.

Example: Sharing Personal Data with Authorities In order for you to travel, it may be mandatory (as required by law by authorities at the relevant point of departure and/or destination) to disclose and process your personal data for purposes of immigration, border control, security, counter‑terrorism or other purposes deemed appropriate by the authorities. In addition, processing may be necessary:

  1. to protect vital interests of you or another person;

  2. for reasons of public interest or in the exercise of official authority;

  3. for the purposes of our legitimate interests or those of a third party, provided that your interests or fundamental rights and freedoms do not override such interests.

Processing of Special Categories of Personal Data Where it is necessary for us to process special categories of personal data, for example health data for medical reasons, this shall only take place if one or more of the following additional conditions apply:

  1. you have given your explicit consent;

  2. processing is necessary to protect your vital interests or those of another person and you are physically or legally incapable of giving consent;

  3. processing is necessary for the establishment, exercise or defence of legal claims;

  4. processing is necessary for reasons of substantial public interest.

Your Rights as a Data Subject For TUI Deutschland GmbH, it is important to ensure that our processing activities are fair and transparent. Therefore, in addition to the right to object and subject to the respective legal requirements, data subjects may exercise the following rights:

  1. Right of access, Art. 15 GDPR

  2. Right to rectification, Art. 16 GDPR

  3. Right to erasure (“right to be forgotten”), Art. 17 GDPR

  4. Right to restriction of processing, Art. 18 GDPR

  5. Right to data portability, Art. 20 GDPR

  6. Right to object, Art. 21 GDPR

What Rights Do I Have as a User and Customer? (Access, Erasure, Withdrawal)

  1. As a data subject, you have various rights pursuant to Art. 15 et seq. GDPR.

  2. You may request information at any time about which personal data relating to you is stored.

  3. You may request rectification or erasure, provided this is legally permissible and possible within the scope of an existing contractual relationship.

Example: In an Emergency The safety of our customers is our highest priority. TUI crisis management monitors global events around the clock, intervenes where necessary and provides information via the SMS assistant in the event of a potential crisis or incident. Your insurer, its agents and medical staff may exchange relevant personal data and special categories of personal data with us, for example where we or the aforementioned parties must act on your behalf, in the interests of other customers or in an emergency.

Example: Security Measures We may use personal data to implement security measures or respond to incidents or similar events, including those of a medical or insurance‑related nature.

Example: Personalising Your Travel Experience We may use your personal data to better understand your interests, allowing us to predict which products, services and information may be of particular interest to you. This enables us to tailor our communications and make them more relevant to you.

Further Rights and How to Exercise Them

  1. If you have set up a customer account, for example via the “My TUI” portal, you may delete it yourself or request its deletion.

  2. You may request a restriction of processing or object to the processing of your personal data. Where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out prior to the withdrawal.

  3. You have the right to data portability.

To exercise your rights, please contact us by email at Datenschutz@tui.de. For identification purposes, please provide the following information:

  1. name,

  2. postal address,

  3. email address, and optionally: customer number or booking reference.

For the purpose of processing your request and verifying your identity, we draw your attention to the fact that we process your personal data pursuant to Art. 6(1)(c) GDPR. You will receive a response to your request regarding your data subject rights no later than within the statutory period of four weeks. Before processing your personal data for a new purpose, we will inform you in advance.

Service Chat: Data Protection Information In order to ensure efficient and user‑friendly use for both parties, we process personal data as follows:

  1. we store the conversation and related data for a period of three years;

  2. we enable our employees to view your browser activity on our website in real time (no storage).

Purpose and Legal Basis We collect and process your data when we have received your explicit consent pursuant to Art. 6(1)(a) GDPR.

Purpose: We collect and archive chat records to provide you with the best possible support and to improve our products and services.

Recipients and CrossBorder Transfers

For questions, requests or comments regarding data protection, please contact the Data Protection Officer of TUI Deutschland GmbH at Datenschutz@tui.de. Your data is hosted within the European Union.

Conversational Cookie The cookie (vuID) stored in your browser is technically necessary for the display and provision of the chat service (communication with an agent or chatbot). It is also used to store the selected language, number of pages accessed, browsing time, connection duration, browser type and your URL.

Key Terms

Controller: The controller determines the purposes and means of the processing of personal data.

European Economic Area (EEA): EU Member States plus Norway, Iceland and Liechtenstein.

Online Advertising: Marketing messages that you may see on the internet.

Special Categories of Personal Data: Categories of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership; genetic data; biometric data for the purpose of uniquely identifying a natural person; health data; and data concerning a person’s sex life or sexual orientation.

Caricom API Data: Some or all CARICOM states have concluded an agreement with the United States under which enhanced passenger data required and provided by CARICOM states for border security purposes may be transferred to the U.S. Department of Homeland Security for processing on behalf of those CARICOM states. Please visit the CARICOM website for further information.

U.S. Secure Flight Data: The Transportation Security Administration (TSA) requires you to provide your full name, date of birth and gender for the purpose of processing passenger lists. You may also provide your redress number, if available. Failure to provide this information may result in denial of transport or access to the boarding area. The TSA may share the information you provide with law enforcement or intelligence agencies or with others as set out in its published System of Records Notices. Please visit the TSA website for further information.

Affiliated Companies of the TUI Group

L’tur GmbH 
Robinson Club GmbH 
TUI 4U GmbH 
TUI AG 
TUI Austria Holding GmbH 
TUI Business Service GmbH 
TUI Cruises GmbH 
TUI Customer Operations GmbH 
TUI Deutschland GmbH 
TUI Spain S.L.U. 
TUI Hotel Betriebsgesellschaft mbH 
TUI Magic Life GmbH 
TUI Österreich GmbH 
TUI Service AG 
TUI Suisse Ltd 
TUIfly Vermarktungs GmbH

Amendments to This Privacy Notice

This privacy notice replaces all previous versions. We reserve the right to amend this notice at any time; therefore, please review it regularly on our website(s) for updates. Where changes are significant, we will provide a clearly visible notice on our website(s). In addition, we may send electronic notifications regarding changes to our privacy notices where we consider this appropriate.

Last updated: February 2026

TUI Deutschland GmbH 
Karl‑Wiechert‑Allee 23 
30625 Hanover 
Datenschutz@tui.de