Privacy policy
Updated: 3 Oct 2026
1. Controller
CASTAN Golfreisen Reiseveranstaltungsgesellschaft mbH
Papenreye 22
22453 Hamburg, Germany
Phone: +49 40 696 38 33 70 · Email: info@castangolfreisen.de
2. General
We process personal data only within the framework of the applicable legal provisions, in particular the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the German Telecommunications Digital Services Data Protection Act (TDDDG). This policy informs you about which data we process when you visit this website and when you make enquiries.
3. Hosting and server log files
When you access the website, our hosting provider automatically processes information transmitted by your browser (IP address, date and time, page accessed, referrer, browser type and version, operating system). This data is stored in server log files and used to ensure trouble-free operation and to defend against attacks. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in security and stability). Log files are usually deleted after 14 days. Within the website we store only pseudonymised, hashed IP addresses for security reasons (spam and abuse protection).
4. Enquiry and contact forms
If you contact us via the forms (contact, quote request, hotel enquiry, group enquiry), we process the data you enter (name, email address, phone number, travel wishes, message) to handle your enquiry and prepare an offer. The legal basis is Art. 6 (1) (b) GDPR (pre-contractual measures) and Art. 6 (1) (f) GDPR. The data is stored in our administration system and transmitted by email to our staff. We delete enquiries once they have been dealt with and no statutory retention obligations apply; if a contract is concluded, the commercial and tax law retention periods (6 or 10 years) apply.
5. Communication by email, phone and WhatsApp
If you contact us by email or phone, we process your details to handle your request (Art. 6 (1) (b) and (f) GDPR). If you contact us via WhatsApp, data is transmitted to WhatsApp Ireland Ltd.; WhatsApp’s privacy notices apply in addition. Please do not send us sensitive data via WhatsApp.
6. Cookies and consent management
We use technically necessary cookies (session and security cookies, storage of your cookie settings, language). The legal basis is § 25 (2) TDDDG and Art. 6 (1) (f) GDPR. All further categories (statistics, marketing, external media) are only activated with your consent (§ 25 (1) TDDDG, Art. 6 (1) (a) GDPR). Your consent is stored in a cookie and can be changed or withdrawn at any time via “Cookie settings” in the footer. Details can be found in our cookie policy.
7. Google Maps
On some pages we embed maps from Google Maps (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). The map is only loaded once you actively confirm this or have accepted the “External media” category. When loading, your IP address and possibly further data are transmitted to Google, including to the USA (basis: EU-U.S. Data Privacy Framework and standard contractual clauses). The legal basis is your consent, Art. 6 (1) (a) GDPR. Further information: policies.google.com/privacy.
8. Statistics and marketing tools
If we use analytics or marketing services (e.g. Google Analytics, Google Tag Manager, Meta Pixel), this is done exclusively after your consent via the cookie banner. The services active in each case and their providers are listed in the cookie policy. Without consent, no such scripts are loaded.
9. Fonts and external content
Fonts are loaded locally from our server; no connection to Google Fonts or other font providers is established. Videos on this website are also served from our server.
10. Data processing when booking a trip
If a travel contract is concluded, we process the data required for its performance (travellers, dates of birth, passport data where required, payment data, special requests) and transmit it to service providers (hotels, golf clubs, airlines, transfer companies, insurers), including in third countries outside the EU (e.g. Turkey, Morocco), insofar as this is necessary for the performance of the contract (Art. 6 (1) (b), Art. 49 (1) (b) GDPR).
11. Recipients and processors
We use service providers for hosting, email dispatch and IT maintenance who are contractually bound to comply with data protection (Art. 28 GDPR). Data is not passed on to third parties for advertising purposes.
12. Storage period
We store personal data only for as long as is necessary for the stated purposes or as required by statutory retention obligations. The data is then deleted or anonymised.
13. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and the right to object to processing based on Art. 6 (1) (f) GDPR (Art. 21). You may withdraw consent at any time with effect for the future. You also have the right to lodge a complaint with a supervisory authority; the competent authority is the Hamburg Commissioner for Data Protection and Freedom of Information, Ludwig-Erhard-Str. 22, 20459 Hamburg, Germany.
14. Data security
This website is delivered encrypted via TLS. Our administration system is protected by access controls, two-factor authentication, logging and regular backups.
15. Changes
We adapt this privacy policy when the legal situation or our processing changes. The version published on this page applies.
The German version of this privacy policy is authoritative.