Privacy Notice for Navklar
Version of 29 September 2026 — English translation for convenience; the German version is binding.
This notice explains how we process personal data of travel agencies that sign up for or use Navklar, and of their staff (Art. 13 GDPR). How the data of an agency's customers is processed is explained in that agency's own privacy notice; for that data we act only as a processor (Data Processing Agreement).
1. Controller
Donau Ventures Private Limited, [Anschrift der Donau Ventures Private Limited / address — placeholder]
Email: [Kontakt-E-Mail / contact email — placeholder]
Representative in the European Union (Art. 27 GDPR): Manigrama [Rechtsform und Anschrift / legal form and address — placeholder]
2. What we process and why
- Sign-up and review: name, email address, details of the agency (name, address, country, website, size, booking systems used, logo), the accepted versions of these texts and the history of the sign-up. Purpose: reviewing the sign-up and setting up the agency. Legal basis: Art. 6(1)(b) GDPR (steps prior to a contract).
- Accounts and use: name, username or email address, role, encrypted password, sign-in times and a log of important actions (such as changes to settings). Purpose: running the Platform, security and accountability. Legal basis: Art. 6(1)(b) and (f) GDPR (contract; legitimate interest in secure operation).
- Emails: confirmation, receipt and notification emails to the address given. Legal basis: Art. 6(1)(b) GDPR.
- News (only if chosen at sign-up): email address. Legal basis: Art. 6(1)(a) GDPR (consent), which can be withdrawn at any time.
- Technically necessary data: IP address and time of access (to prevent misuse, for example by limiting sign-in attempts). Legal basis: Art. 6(1)(f) GDPR.
3. Cookies
We set only technically necessary cookies: a session cookie after sign-in and a cookie for the chosen language. The light or dark theme is stored in the browser only. There are no analytics or advertising cookies; no consent is needed for these (§ 25(2) TDDDG).
4. Recipients
- Hosting: Hostinger International Ltd (Lithuania, EU), data centre in Frankfurt am Main, Germany
- Sending emails through the email service we use [provider — placeholder].
- Within our company, only the people who run the Platform and review sign-ups.
Transfers to countries outside the EU / EEA take place only where Art. 44 et seq. GDPR are met (for example an adequacy decision or standard contractual clauses).
5. How long we keep data
- Rejected or unfinished sign-ups: unconfirmed ones are deleted after 30 days, rejected or abandoned ones after 6 months, unless we must keep them.
- Accounts and logs: for as long as the Platform is used; afterwards after [period — placeholder].
- Records we must keep under commercial or tax law: up to 10 years.
6. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object (Art. 21 GDPR), and the right to withdraw consent at any time with effect for the future. Write to us at [Kontakt-E-Mail / contact email — placeholder].
You can also complain to a data protection supervisory authority, for example [Zuständige Datenschutz-Aufsichtsbehörde / competent supervisory authority — placeholder].
7. Whether you must provide data
Without the sign-up details we cannot set up the agency. We make no automated decisions within the meaning of Art. 22 GDPR; a person decides on every sign-up.