Privacy Policy
As of: August 2026
We are pleased that you are visiting our website and thank you for your interest in MIRA KODA UG (haftungsbeschränkt). Protecting your personal data is important to us. Below we inform you in detail about the processing of your data in accordance with the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
1. Controller
MIRA KODA UG (haftungsbeschränkt)
Äußere Bayreuther Straße 57-59
90409 Nürnberg, Deutschland
Klaus Felmet
E-Mail: [email protected]
Website: www.mirakoda.com
Please note that we have not appointed a data protection officer, as neither the requirements of Article 37 GDPR nor the threshold of Section 38(1) BDSG apply to us. For data protection matters, please contact us directly at the e-mail address above.
2. Hosting
Hetzner Online GmbH
Industriestr. 25, 91710 Gunzenhausen, Deutschland
Hetzner processes the technically necessary server data on our behalf (for example IP addresses, timestamps, pages accessed) as a processor in accordance with Article 28 GDPR. Processing takes place exclusively on servers within the European Union. The legal basis is Article 6(1)(f) GDPR (legitimate interest in the secure and stable operation of the website).
3. Contact form
If you send us an enquiry via the contact form on our website, we collect the following data.
- ✦ Name
- ✦ E-mail address
- ✦ Content of your message
- ✦ Telephone number (optional, if you would like to be contacted by telephone)
This data is processed in order to handle your enquiry and to contact you. The legal basis is Article 6(1)(b) GDPR (pre-contractual measures) and, for general enquiries, Article 6(1)(f) GDPR (legitimate interest). The data is not passed on to third parties, apart from our technical service providers (Hetzner, see above), and is deleted after 6 months at the latest if no contract is concluded.
4. Customer portal
Registered customers can access travel documents, files and photographs through our customer portal. Within the portal we process the following data.
- ✦ Login data (e-mail address and password in encrypted form)
- ✦ Uploaded travel documents and photographs
- ✦ Communication relating to your booking
The legal basis is Article 6(1)(b) GDPR (performance of a contract). The data is stored in the portal for 1 year after the end of the trip and is deleted thereafter, unless statutory retention obligations prevent this.
Your uploaded photographs are used for marketing purposes exclusively on the basis of separate, express consent pursuant to Article 6(1)(a) GDPR. Without your consent we do not use your photographs for promotional purposes.
5. Travel photo book ("Haptic Koda")
On request we create an individual physical photo book from the travel photographs you provide. For its production we pass the image data you have voluntarily provided to a specialised photo book and printing service provider. That provider processes the data exclusively on our behalf for the purpose of creating and printing the photo book, on the basis of a processing agreement pursuant to Article 28 GDPR. The legal basis for the processing is Article 6(1)(b) GDPR. The data is not passed on for any other purpose.
6. Website analytics
We use Umami Analytics, privacy-friendly and cookie-free analytics software that we operate ourselves on our own infrastructure (Hetzner, Germany). Umami does not collect any personal data and does not use cookies. Only anonymised, aggregated usage statistics are recorded (for example the number of page views and the type of device used). Identification of individual persons is neither possible nor intended. Since no personal reference exists, the GDPR does not apply to this processing. As a precaution, we rely on Article 6(1)(f) GDPR (legitimate interest in optimising the website).
We do not use any tracking cookies, any third-party analytics cookies or any re-targeting on this website.
7. Cookies
Our website does not use tracking or analytics cookies. Only technically necessary session cookies may be used, which are required for the operation of the customer portal. These cookies are deleted when the browser is closed and do not require consent under Section 25(2) of the German Telecommunications Digital Services Data Protection Act (TDDDG).
8. E-mail communication
If you contact us by e-mail, we process your e-mail address and the content of your message. We use Google Workspace (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) as our e-mail service. Google processes data on our behalf on the basis of EU standard contractual clauses pursuant to Article 46(2)(c) GDPR. The legal basis for processing e-mails is Article 6(1)(b) or (f) GDPR.
9. Payment processing
We use an external payment service provider to handle the down payment and the balance payment. That provider processes the data required for payment processing (including name, payment amount, bank details or card details) on our behalf or as an independent controller, depending on the provider selected. The legal basis is Article 6(1)(b) GDPR (performance of a contract).
We are currently selecting a suitable payment service provider. As soon as the decision has been taken, we will add the name, the registered office and, where applicable, the certification of the provider at this point.
10. Referrals by sales partners
MIRA KODA works with selected sales partners who make travellers aware of our services. If a sales partner sends us your contact details as a referral, this only happens if you have previously given the sales partner your express consent to that disclosure. We process the data received in this way (name, contact details, date of the referral) for the purpose of contacting you and preparing an individual travel proposal. The legal basis is Article 6(1)(b) GDPR (pre-contractual measures taken at your request) together with the consent you gave to the sales partner. If the referral does not lead to a booking, we delete the data no later than 12 months after receiving it.
11. Insolvency protection
In order to protect your payments in the event of our insolvency pursuant to Section 651r of the German Civil Code (BGB), we transmit your booking-related data (name, booking number, travel price, payment status) to our customer money protection provider, R+V Allgemeine Versicherung AG. The legal basis is Article 6(1)(c) GDPR (legal obligation under Section 651r BGB) in conjunction with Article 6(1)(b) GDPR.
12. Disclosure of data to third parties
We only disclose your personal data in the following cases.
- ✦ Where this is necessary in order to carry out a travel booking (for example to hotels, airlines or local partners), on the legal basis of Article 6(1)(b) GDPR
- ✦ Where we are legally obliged to do so
- ✦ Where you have given your express consent
In connection with flight bookings we also collect emergency contact details at the Customer's request, that is the name and contact details of a person designated by the travellers, and pass these on to the respective airline insofar as this is a prerequisite for the flight booking. In doing so, the Customer warrants, in accordance with the MIRA KODA General Travel Terms and Conditions, that they are entitled to pass on this data and have informed the designated person of the transfer. The legal basis for processing the data of the designated contact person is Article 6(1)(f) GDPR (legitimate interest in the safe operation of the flight and in functioning emergency communication), since that person is not a party to the travel contract themselves. We base the collection of this data in connection with your booking on Article 6(1)(b) GDPR (performance of the contract with you).
Further recipients relating to individual processing purposes, in particular our photo book printing service provider, the payment service provider, our customer money protection provider and sales partners, are described separately in the relevant sections of this policy.
In the context of travel bookings, a transfer of data to third countries outside the EEA is often necessary, for example to hotels, tour operators or other service providers on site. For some of our destination countries an adequacy decision of the EU Commission pursuant to Article 45 GDPR exists, for example for Argentina, which means that a recognised level of data protection applies there. For destination countries without such a decision, for example certain destinations in Africa, South America or the Indian Ocean, we base the transfer on the derogation in Article 49(1)(b) GDPR, since the transfer is necessary for the performance of the travel contract concluded with you and takes place at your express request. We will inform you separately during the booking process if a transfer to a country without an adequacy decision takes place.
13. Special categories of personal data
Where this is necessary in order to carry out your trip, we process special categories of personal data pursuant to Article 9 GDPR in individual cases, in particular health data such as information on allergies, intolerances or mobility restrictions. We collect and process this data exclusively if you provide it to us voluntarily and have expressly consented to the processing beforehand. The legal basis is Article 9(2)(a) GDPR. The data is used exclusively to ensure that your travel arrangements are suitable for you and, where necessary, is passed on to the service providers concerned, for example hotels or airlines.
14. Retention periods
We store your personal data only for as long as this is necessary for the respective purposes or for as long as statutory retention obligations require.
- ✦ Contact enquiries that do not lead to a contract are kept for 6 months.
- ✦ Customer data in the CRM is kept for 3 years after the end of the contract.
- ✦ Booking records and invoices are kept for 10 years (Section 147 of the German Fiscal Code, AO, and Section 257 of the German Commercial Code, HGB).
- ✦ Customer portal content is kept for 1 year after the end of the trip.
- ✦ Newsletter consent records are kept for 3 years after you unsubscribe.
- ✦ Referral data from sales partners that does not lead to a booking is kept for 12 months after receipt.
15. Newsletter
You have the option of subscribing to our newsletter. In doing so we collect the following data.
- ✦ E-mail address
- ✦ Time of registration and confirmation (double opt-in) and the associated IP address
- ✦ Language preference and the page from which you subscribed
- ✦ Time of unsubscription (in the event of withdrawal)
The legal basis is your express consent pursuant to Article 6(1)(a) GDPR. You can unsubscribe from the newsletter at any time. Every e-mail contains an unsubscribe link. Withdrawal does not affect the lawfulness of the processing carried out up to that point.
We retain the consent records as evidence for 3 years after you unsubscribe. The newsletter is sent using our own infrastructure (Hetzner, Germany).
16. Obligation to provide data
Providing certain personal data is necessary in order to conclude and perform a travel contract with you, for example your name, contact details, payment details and, for flight bookings, the additional information required by the respective airline. If you do not provide this data, we cannot conclude or perform the desired travel contract at all or in full. Other information, for example in the contact form or for the newsletter, is voluntary. In these cases, not providing it has no disadvantages other than the loss of the respective function, for example being contacted or receiving the newsletter.
17. Automated decision-making
We do not use automated decision-making, including profiling, within the meaning of Article 22 GDPR.
18. Your rights as a data subject
Under the GDPR you have the following rights in relation to us.
- ✦ Right of access (Article 15 GDPR). You may request information about the data stored about you.
- ✦ Right to rectification (Article 16 GDPR). You may request the correction of inaccurate data.
- ✦ Right to erasure (Article 17 GDPR). Under certain conditions you may request the deletion of your data.
- ✦ Right to restriction of processing (Article 18 GDPR).
- ✦ Right to data portability (Article 20 GDPR).
- ✦ Right to object (Article 21 GDPR). You may object at any time to the processing of your data based on Article 6(1)(f) GDPR.
- ✦ Right to withdraw consent (Article 7(3) GDPR). You may withdraw consent you have given at any time with effect for the future.
To exercise your rights, please contact us at [email protected]
19. Right to lodge a complaint with the supervisory authority
You have the right to lodge a complaint with the competent data protection supervisory authority. For MIRA KODA UG this is the following authority.
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach
Telefon: +49 (0)981 53-1300
Website: www.lda.bayern.de
20. Data security
Our website transmits data exclusively in encrypted form via the HTTPS protocol (TLS). We take appropriate technical and organisational measures pursuant to Article 32 GDPR to protect your data against unauthorised access, loss or misuse.
21. Currency of this privacy policy
We reserve the right to amend this privacy policy if our website or the legal framework changes. The current version is always available on this page. This version is dated August 2026.