GDPR Compliance
Last updated: August 14, 2026
General Data Protection Regulation Compliance
impanunstr is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR). This page outlines how we comply with GDPR requirements when processing your personal information.
Data Controller
For the purposes of GDPR, impanunstr acts as the data controller for the personal information we collect and process. We are responsible for ensuring that your data is processed lawfully, fairly, and transparently.
Legal Basis for Processing
We process your personal data under the following legal bases:
- Contractual necessity: to fulfill our obligations under travel service contracts
- Legitimate interests: to improve our services and communicate about travel offerings
- Legal obligation: to comply with applicable laws and regulations
- Consent: where you have provided explicit consent for specific processing activities
Your Rights Under GDPR
As a data subject, you have the following rights:
Right to Access
You have the right to request access to your personal data and receive information about how we process it.
Right to Rectification
You can request that we correct any inaccurate or incomplete personal data we hold about you.
Right to Erasure
Under certain circumstances, you have the right to request deletion of your personal data.
Right to Restriction of Processing
You can request that we restrict the processing of your personal data in specific situations.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used format and transmit it to another controller.
Right to Object
You can object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision Making
You have the right not to be subject to decisions based solely on automated processing that produces legal effects.
Data Protection Measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data
- Regular security assessments
- Access controls and authentication
- Staff training on data protection
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected individuals without undue delay.
International Data Transfers
When we transfer your personal data outside the European Economic Area, we ensure appropriate safeguards are in place, such as standard contractual clauses or adequacy decisions.
Exercising Your Rights
To exercise any of your rights under GDPR, please contact us at [email protected]. We will respond to your request within one month, though this period may be extended by two further months where necessary.
Complaints
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) or your local supervisory authority.