Privacy Policy
1) Who is responsible?
Great to have you here! We’re glad you stopped by our website. To help you feel safe, we want to be completely open about what happens with your data.
The party responsible for all data protection matters is:
22places Media S.L.
Calle Geraneo 3, 2G
35660 Corralejo, Las Palmas, Spain
Email: hey@22places.de
2) What happens when you simply visit our site?
Even if you don’t send us a message, your browser automatically transmits some information to our server. These are called “server log files.” This is technically necessary to keep the site running smoothly and securely (legal basis: Art. 6(1)(f) GDPR).
This includes, for example:
- Which page you visit
- Date and time of access
- The amount of data transmitted
- Which site you came from
- Which browser and operating system you’re using
- Your IP address (which we anonymize)
We store these log files for a maximum of 14 days and then delete them automatically.
Security comes first: our site uses SSL/TLS encryption. You can recognize this by the “https://” and the padlock icon in your browser’s address bar. Your data is transmitted in encrypted form.
3) Why you won’t find an annoying cookie banner on our site
You may have already noticed: there’s no pop-up asking for your cookie consent. That’s because we only use technically necessary cookies.
These are small helpers that, for example, keep the site running securely or make sure our newsletter offer isn’t shown to you again every time right after you’ve just dismissed it. We don’t load any third-party tracking scripts or advertising cookies — which means we don’t need your explicit consent, and you get a more relaxed reading experience.
4) Get in touch: The contact form
If you send us a message (e.g. via the contact form or email), we store your details in order to handle your inquiry. We use your data exclusively for this purpose.
The legal basis is our legitimate interest in responding to you (Art. 6(1)(f) GDPR), or the preparation of a contract (Art. 6(1)(b) GDPR) if the inquiry relates to a potential collaboration. Once your request has been resolved, we delete the data — at the latest after three years, unless statutory retention obligations (e.g. under tax law) require otherwise.
5) Mail from us: The newsletter
If you’d like to receive tips from us, you can subscribe to our newsletter. All we need is your email address. Any additional information is optional.
We use a double opt-in process: after signing up, you’ll receive an email with a confirmation link. You’ll only be added to our mailing list once you click that link — this ensures no one else can sign you up without your knowledge (legal basis: Art. 6(1)(a) GDPR).
So that we can prove you actually signed up if needed, we log the time of your registration and confirmation as well as the IP address used. We store this data for as long as you remain subscribed to the newsletter.
ActiveCampaign: We use ActiveCampaign (ActiveCampaign LLC, Chicago, USA) to send our newsletter. Your data is transferred to the USA as part of this process. We have entered into a data processing agreement with ActiveCampaign. The company is certified under the EU-US Data Privacy Framework — the European Commission has issued an adequacy decision confirming that it provides a level of data protection comparable to that of the EU (Art. 45 GDPR). That said, you should be aware that US authorities may in principle have access to data stored with US-based providers.
You can unsubscribe at any time with a single click via the link at the bottom of every email. After that, we’ll delete your data from our mailing list.
6) Recommendations & Affiliate Links
We partly fund our work through affiliate links. If you book or buy something through one of these links, we receive a small commission — the price you pay stays exactly the same.
As soon as you click one of these links, you’ll be redirected to the partner’s website. Cookies may be set there so the provider knows you came from us. In the process, your IP address, browser and device information, and a tracking ID are typically transferred to the respective partner. You can find out exactly what data is processed in that provider’s privacy policy.
We work with the following partners: 12GoAsia, Amazon, Awin, Bergfreunde, Booking.com, Check24, Camper Oase, Direct Ferries, FinanceAds, Finance Quality, Foto Koch, GetYourGuide, Globetrotter, Hellotickets, Impact, Jrailpass, Manawa, Nomad, Partnerize, Rakuten, Saily, Sportevents365, Tiqets, Tradedoubler, Viator.
7) Web analytics: So we know what you enjoy
We want to know which articles are popular so we can keep improving our content. For this, we use the privacy-friendly analytics tool Matomo.
We host this on our own servers. Your IP address is truncated before analysis, so there’s no way for us to identify you personally. All data stays with us (legal basis: Art. 6(1)(f) GDPR). We store the anonymized statistical data for a maximum of 24 months.
8) VG Wort
We use the VG Wort measurement procedure to determine the likelihood that texts are being copied. This helps us receive fair compensation for our written content. No personal data about you is stored in this process.
9) Your rights (Important!)
You have control over your data at all times. Specifically, you have the following rights:
- Access (Art. 15 GDPR): You have the right to know what data we hold about you.
- Rectification (Art. 16 GDPR): If something is incorrect, we’ll correct it.
- Erasure (Art. 17 GDPR): We’ll delete your data when it’s no longer needed.
- Restriction of processing (Art. 18 GDPR): You can request that we limit how we process your data.
- Data portability (Art. 20 GDPR): You can receive your data in a commonly used format.
- Right to object (Art. 21 GDPR): You can object to the use of your data (especially for advertising purposes) at any time.
- Withdrawal of consent (Art. 7(3) GDPR): You can withdraw any consent you’ve given at any time, with effect for the future.
Just send us a quick email at hey@22places.de.
If you believe we’re not handling your data properly, you also have the right to lodge a complaint with a data protection authority. The authority responsible for us is the Spanish data protection authority:
Agencia Española de Protección de Datos (AEPD)
C/ Jorge Juan, 6
28001 Madrid, Spain
www.aepd.es
You may also contact the data protection authority in your country of residence.
10) How long do we store your data?
We only store your data for as long as necessary for the respective purpose or as required by law (e.g. up to ten years for accounting records). You’ll find the specific retention periods listed under each individual section above. Once there’s no longer a reason to retain the data, it will be deleted or anonymized.
Last updated: May 2026