Privacy Policy
The security and protection of your data is a top priority for us, NEST Mobility GmbH (hereinafter “NOX” or “we”). Therefore, we operate our website in accordance with applicable legal provisions regarding the protection of personal data and data security, in particular the provisions of the General Data Protection Regulation (EU) 2016/679 (GDPR), the Federal Data Protection Act (BDSG), and the Act on Data Protection and the Protection of Privacy in Telecommunications and Digital Services (TDDDG).
In this context, we would like to inform you about what data we collect, process, and use when you use our website, for what purpose and on what legal basis this is done in each case, and to whom we may disclose this data.
1. Scope of Application, Data Controller
This Privacy Policy applies to the website accessible at the domain
(“Website”).
The data controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws and regulations is
NEST Mobility GmbH
Rudi-Dutschke-Straße 23
10969 Berlin
Germany
Email: info@noxmobility.com
2. General Information
Legal Basis for Data Processing
If you have data processing, we process your personal data on the basis of Article 6(1)(a) of the GDPR or Article 9(2)(a) of the GDPR, provided that special categories of data as defined in Article 9(1) of the GDPR are processed. In the event of explicit consent to the transfer of personal data to third countries, data processing is also carried out on the basis of Article 49(1)(a) of the GDPR. If you have consented to the storage of cookies or to access to information on your device (e.g., via device fingerprinting), data processing is additionally based on Section 25(1) of the German Telemedia Act (TDDDG). You may revoke your consent at any time. If your data is necessary for the performance of a contract or for the implementation of pre-contractual measures, we process your data on the basis of Article 6(1)(b) of the GDPR. Furthermore, we process your data if it is necessary to comply with a legal obligation on the basis of Article 6(1)(c) of the GDPR. Data processing may also be based on our legitimate interest pursuant to Article 6(1)(f) of the GDPR. The applicable legal bases in each individual case are described in the following sections of this Privacy Policy.
Recipients of Personal Data
As part of our business operations, we collaborate with various external parties. These include, for example:
(IT) service providers
Financial institutions and payment service providers
Sales partners
Customer service providers (internal/external)
Security companies
(Travel) insurers
Other partners involved in our business operations (e.g., auditors, banks, insurance companies, attorneys, and regulatory authorities)
In some cases, this also requires the transfer of personal data to these external parties. We only disclose personal data to external parties if this is necessary for the performance of a contract, if we are legally obligated to do so (e.g., disclosure of data to tax authorities), if we have a legitimate interest in the disclosure pursuant to Article 6(1)(f) of the GDPR, or if another legal basis permits the disclosure of data. Service providers and partner companies must provide guarantees that they implement appropriate technical and organizational measures to ensure that processing complies with legal requirements and that the rights of data subjects are protected. When using data processors, we disclose our customers’ personal data only on the basis of a valid data processing agreement. In the case of joint processing, a joint processing agreement is concluded.
We disclose personal data to public authorities and institutions (e.g., police, public prosecutors, supervisory authorities) when there is a corresponding obligation or authorization to do so.
Data Transfers Abroad
In connection with the processing activities described in this Privacy Policy, personal data may be transferred to a third country (in particular, the United States). A third country is a country outside the European Union (EU) and outside the European Economic Area (EEA). In this case, we take appropriate measures to ensure that the level of data protection applicable in the EU/EEA is not compromised by the recipient or the recipient country. Appropriate measures may include, for example:
An adequacy decision by the European Commission
Standard data protection clauses (available at https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc/standard-contractual-clauses-international-transfers_en)
Additional safeguards (e.g., pseudonymization)
Withdrawal of Consent
Many data processing operations are only possible with your explicit consent. You may withdraw any consent you have already given at any time. The lawfulness of the data processing carried out prior to the withdrawal remains unaffected by the withdrawal.
3. Collection of General Information When Visiting Our Website
If you use our website purely for informational purposes (i.e., without actively transmitting data to us on your own initiative, such as through inquiries via email, contact forms, or other means of data transmission), we collect only the data that is technically necessary to enable you to use our website and to ensure the stability and security of the IT systems we use. The legal basis for this is Article 6(1)(f) of the GDPR. This general data and information is stored in the server’s log files. The following data is processed:
Browser type and version
Operating system used
Referrer URL
The subpages accessed on our website by a connecting system
Date and time of access to the website
An Internet Protocol (IP) address
The user’s Internet service provider.
This data is analyzed exclusively for statistical purposes. No personal identification takes place. Rather, this information is technically necessary to correctly deliver the content of our website, to ensure the long-term functionality of our information technology systems and the technology of our website, and, in the event of a cyberattack, to provide law enforcement authorities with the information necessary for criminal prosecution.
The data stored in the server’s log files is stored separately from any personal data provided by a data subject.
4. Data Security
We take appropriate technical and organizational measures to ensure that the data collected in connection with the use of the services we offer is protected against loss, unauthorized alteration, or unauthorized access by third parties. Our security measures are continuously reviewed and adapted in line with technological developments.
For security reasons and to protect the transmission of confidential content—such as the data you send to us as the website operator—our website uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the browser’s address bar changes from “http://” to “https://” and by the lock icon in your browser’s address bar. When you enable SSL or TLS encryption, the data you transmit to us cannot be read by third parties.
5. Cookies
To optimize the functionality and user-friendliness of the website, we use so-called cookies. Cookies do not harm your computer and do not contain viruses. Cookies help us make our website more user-friendly, effective, and secure. Cookies are small text files that are stored on your computer and saved by your browser.
The cookies we use include both session cookies and persistent cookies. Session cookies are automatically deleted when you end your session and close your browser. Persistent cookies are stored beyond the duration of your session until their expiration date or until they are deleted. Most of the cookies used on our website are set by us (so-called “first-party cookies”). However, we also work with third-party providers (e.g., for analytics and marketing purposes) who also set cookies when you use the website (so-called “third-party cookies”). You can use our cookie consent tool to determine whether the cookies are set by us or whether a third-party provider is listed as the provider.
Cookies that are technically necessary to enable electronic communication or to provide specific functions you have requested are processed by us in accordance with Article 6(1)(f) of the GDPR. Our legitimate interest lies in ensuring and optimizing the functionality and user-friendliness of the website. If additional cookies (e.g., to analyze your browsing behavior) are stored, they are addressed separately in this Privacy Policy.
We will we will inform you separately within this Privacy Policy and will use this personal data only with your prior consent (Art. 6(1)(a) GDPR or § 25(1) TDDDG).
You can change the cookie settings you selected during your first visit to the website at any time via the “Cookie Policy,” which you can find in the bottom-right corner of the page menu.
You can also configure your browser to notify you when cookies are used, allowing you to decide on a case-by-case basis whether to accept or reject a cookie. Alternatively, your browser can be configured to automatically accept cookies under certain conditions, to always reject them, or to automatically delete cookies when you close your browser. You can also manage the cookies of many companies and features used for advertising on an individual basis. To do so, use the appropriate user tools available at https://www.aboutads.info/choices or http://www.youronlinechoices.com/uk/your-ad-choices. Disabling cookies may limit the functionality of this website. In addition, most browsers offer a so-called “do-not-track” feature, which allows you to indicate that you do not want to be “tracked” by websites. When this feature is enabled, the browser informs advertising networks, websites, and applications that you do not wish to be tracked for the purpose of behavioral advertising.
6. Newsletter
We periodically inform our customers and business partners about our offers and news via a newsletter. You can subscribe to our newsletter on this website. If you wish to do so, we will need your email address. This data is processed solely for the purpose of properly delivering the newsletter. The legal basis for this is Art. 6(1)(a) GDPR or § 25(1) TDDDG.
We use the so-called double opt-in procedure for registration. This means that a confirmation email will be sent to the email address you provided for the newsletter. In this confirmation email, we ask you to confirm your subscription to our newsletter. If you confirm by clicking the link contained in the confirmation email, we will store your email address and any other information you may have provided until you unsubscribe from the newsletter. When you click the link in the confirmation email, we also store the IP address from which the access occurred and the time of access to prevent potential misuse.
The personal data collected as part of the newsletter service will not be disclosed to third parties. You may cancel your subscription to our newsletter at any time, effective immediately. To revoke your consent to the subscription, you can click the corresponding link included in every newsletter. You can also unsubscribe from the newsletter at any time by sending an email to the email address listed at the beginning of this privacy policy.
Newsletter Tracking
Our newsletters contain so-called tracking pixels. A tracking pixel is a miniature graphic embedded in emails sent in HTML format to enable log file recording and analysis. This allows for a statistical evaluation of the success or failure of online marketing campaigns. Using the embedded tracking pixel, NOX can determine whether and when you opened an email and which links in the email you clicked on. We store and analyze the personal data collected via the tracking pixels contained in the newsletters to optimize the distribution of the newsletter and to tailor the content of future newsletters even better to the interests of the data subject. This personal data is not shared with third parties. The legal basis for this is Article 6(1)(a) and (f) of the GDPR.
You have the right to withdraw your consent at any time by sending an email to info@noxmobility.com. Once you withdraw your consent, your personal data will be deleted. If you unsubscribe from the newsletter, NOX automatically interprets this as a withdrawal of your consent and will also delete your data.
7. Contact Form
You can contact us via the contact form on our website. The data you must provide to us includes your name, your email address, and the message containing your contact request. This personal data is processed for the purpose of responding to and handling your contact request. The legal basis for this is Article 6(1)(b) of the GDPR. This personal data is not disclosed to third parties.
8. Retention Period
We store your personal data only for as long as is necessary to fulfill the purpose for which it was collected. The retention period for the collected personal data depends on the purpose for which we process the data. Unless an explicit retention period is specified below, your personal data will be deleted or blocked as soon as the purpose or legal basis for storage no longer applies.
However, data may be retained beyond the specified period in the event of a (potential) legal dispute with you or other legal proceedings, or if retention is required by legal provisions to which we, as the data controller, are subject. When the retention period prescribed by law expires, the personal data will be blocked or deleted, unless further storage by us is necessary and there is a legal basis for doing so.
9. Automated Decision-Making
We do not use automated decision-making or profiling.
10. Booking, Execution, and Processing of Train Trips
NOX offers overnight train travel for long-distance travelers via its website. As part of the booking process, we collect, store, and process the following categories of personal data:
Email address
Last name and first name
Itinerary details
Payment information
Travel details (departure and destination)
Agreement to the applicable terms and conditions
Seat reservation information
Baggage details
If you also provide data for other traveling companions as part of a booking (e.g., names for additional reserved seats), we process this data solely for the purpose of carrying out and handling the booked transportation service for the individuals in question. The legal basis for this is Article 6(1)(b) of the GDPR. You are responsible for ensuring that the fellow travelers whose information you provide have been informed about the processing of their data in accordance with this Privacy Policy and, where necessary, have given their consent. If you provide data for minor fellow travelers, please ensure that you are authorized to do so as a legal guardian or with the consent of the legal guardian.
In addition, you have the option to provide a phone number so we can contact you in the event of delays or changes to the itinerary (optional).
This data is processed for the purpose of booking, carrying out, and handling the transportation services, as well as for communicating with you in connection with the booked trip (e.g., booking confirmation, travel information).
The legal basis for this is Article 6(1)(b) of the GDPR (performance of a contract or implementation of pre-contractual measures).
Passenger Rights
If your trip is affected by a delay, cancellation, or missed connection, we will also process your travel and booking data (in particular, your name, contact information, itinerary details, and payment information) to handle any claims for alternative travel arrangements, refunds, or compensation under Regulation (EU) 2021/782 on the rights and obligations of rail passengers. The legal basis for this is Article 6(1)(c) of the GDPR in conjunction with the relevant provisions of Regulation (EU) 2021/782.
Customer Account
You can make a booking either as a guest, without creating a user account, or with a registered user account. In the password-protected area of your customer account, you can conveniently manage your bookings and save your information for future trips.
To create a customer account, the following required information is collected:
Email address (for all other countries)
Password (of your choice).
The legal basis is Article 6(1)(a) of the GDPR.
In addition, you can also provide a cell phone number in your customer account so that we can contact you in the event of a delay or a change to your trip itinerary (optional).
When you create an account, a “persistent” cookie containing a session ID is stored on your device to ensure that you do not have to log in again during subsequent visits to our website. This feature is not available to you if you have disabled the storage of such cookies in your browser settings.
The legal basis is Article 6(1)(f) of the GDPR.
You can delete your customer account at any time via the account settings.
Payment Processing
Payment processing for bookings is handled by the payment service providers SumUp and PayPal. For more information about these service providers and the associated data processing, please see Section 13 of this Privacy Policy.
Product Recommendations
To the extent permitted, we may use the email address provided in connection with the booking or transportation service to periodically send you offers via email for similar products from our product range, such as those you have already purchased.
We use external customer service providers as data processors to send product recommendations.
You will receive these product recommendations from us regardless of whether you have subscribed to a newsletter or consented to marketing communications via email. In this way, we aim to provide you with information about products from our selection that may interest you based on your most recent purchases with us.
The legal basis is Article 6(1)(f) of the GDPR in conjunction with Section 7(3) of the UWG; our legitimate interest lies in informing you about our offerings and drawing your attention to specific products.
You may object to the use of your email address for this purpose at any time by clicking the unsubscribe link in the product recommendation or by sending a message to info@noxmobility.com.
11. Social Media Presence
To provide information about us and to communicate with users, we maintain accounts on social media platforms. These may include accounts belonging to our company, individual business units, and media brands, as well as the pages of our corporate influencers.
In this context, various user data may be processed by the operators of these social networks, including outside the European Union and, in particular, in the United States. This data may include, in particular, master data (e.g., names, addresses), contact data (e.g., email, phone numbers), content data (e.g., entries in online forms), usage data (e.g., websites visited, interest in content, access times), and meta/communication data (e.g., device information, IP addresses).
The operators of social networks generally also process user data for market research and advertising purposes. The usage behavior and interests of users stored in cookies on their computers may be used by the operators to display interest-based advertising both within and outside the networks. Therefore, for a detailed description of data processing and the rights of data subjects, please refer to the privacy policies of the respective networks.
We process data in connection with the operation of our social media presences based on our legitimate business interest pursuant to Art. 6(1)(f) of the GDPR for the efficient handling of contact requests and inquiries, for communication with you, for tailoring our offerings to your needs, for providing product information, and for customer service.
Pages may be operated on the following social networks:
Instagram: Social network; Service provider: Instagram Inc., 1601 Willow Road, Menlo Park, CA 94025, USA (parent company: Meta Platforms, Inc., 1 Hacker Way, Menlo Park, CA 94025, USA, or, if you are based in the EU, Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland);
Website: https://www.instagram.com
Privacy Policy: https://instagram.com/about/legal/privacy
Facebook: Social network; Service provider: Meta Platforms, Inc., 1 Hacker Way, Menlo Park, CA 94025, USA, or, if you are based in the EU, Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. We are jointly responsible with Facebook Ireland Ltd. for the collection of data from visitors to our Facebook pages. Facebook and we are each independently responsible for the further processing of the data. This data may include content data (e.g., entries in online forms), usage data (e.g., interest in content, access times), and meta/communication data (e.g., device information, IP addresses). Facebook also processes this information to provide it to us in the form of analytics via “Page Insights.” This provides us with insights into how people interact with our pages and what content is of interest to them. To this end, we have entered into a data protection agreement with Facebook, in which Facebook specifies the security measures it uses to protect this data and confirms that it complies with the rights of data subjects (e.g., right of access, right to erasure). You can view the agreement here: https://www.facebook.com/legal/terms/page_controller_addendum. Further information can be found in the “Page Insights Information”: https://www.facebook.com/legal/terms/information_about_page_insights_data Website: https://www.facebook.com; Privacy Policy: https://www.facebook.com/about/privacy.
LinkedIn: Social network; Service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; Website: https://www.linkedin.com; Privacy Policy: https://www.linkedin.com/legal/privacy-policy; Opt-out option: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
X (formerly Twitter): Social network; Service provider: Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2 D02 AX07, Ireland; Parent company: Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA; Privacy Policy: https://twitter.com/privacy, (Settings for personalization and data: https://twitter.com/personalization.
TikTok: Social network; Service provider: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland, and TikTok Information Technologies UK Limited, Kaleidoscope, 4 Lindsey Street, London, United Kingdom, EC1A 9HP; Website: https://www.tiktok.com; Privacy Policy: https://www.tiktok.com/de/privacy-policy.
YouTube: Social network and video platform; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://www.youtube.com/; Privacy Policy: https://policies.google.com/privacy.
12. Social Media Plugins
Our website may also use so-called social media plugins. We may use plugins from the following providers: Facebook, X (formerly Twitter), LinkedIn, Instagram, TikTok.
We do not use direct social media plugins on our website; instead, we use a privacy-friendly alternative in which the social media buttons are integrated solely as links to the pages of the external service providers. With this solution, you can decide for yourself whether and when data is transmitted to the operators of the respective social networks. Therefore, when you visit our website, no data is automatically transmitted to the social networks listed above. Only when you actively click on the respective button will you be redirected to the social network’s website, and your browser will establish a connection to the servers of that social network. Your data may then be processed by the operator.
For more information on the purpose and scope of data processing by the plugin provider, please refer to the respective privacy policies of these providers. There you will also find further information regarding your rights in this regard and settings options for protecting your privacy.
13. Service Providers and Third-Party Tools Used
In order to offer and continuously improve our services, we rely on the services of the following third-party providers, through which personal data may also be processed. We have carefully selected these third-party providers in accordance with the provisions of applicable data protection laws.
A. Analytics, Tag Management, and Cookie Consent
Google Analytics
The website uses “Google Analytics 4” (“Google Analytics”), a web analytics service provided by Google LLC. The data controller for users in the EU/EEA and Switzerland is Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”). The legal basis for the use of Google Analytics and the processing of data is Art. 6(1)(a) GDPR or § 25(1) TDDDG (consent). We use Google Analytics to analyze the use of our website and to continuously improve individual features, offerings, and the user experience. By statistically evaluating user behavior, we can improve our offerings and make them more interesting for you as a user.
Google Analytics uses its own cookies for these purposes. When users click on pages on our website, the following data may be processed:
browser type/version,
operating system used,
Referrer URL (the previously visited page),
Hostname of the accessing computer (IP address), and
time of the server request.
This data is generally transmitted to a Google server in the United States and processed there.
To ensure that Google processes the transmitted data only in accordance with our instructions and in compliance with applicable data protection laws, we have entered into a Data Processing Agreement (DPA) with Google pursuant to Article 28(3) of the GDPR.
Google is certified under the EU-U.S. Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards when processing data in the United States. Every company certified under the DPF commits to complying with these data protection standards. For more information, please visit the provider’s website at the following link: https://www.dataprivacyframework.gov/participant/5780.
Please note that we have extended the Google Analytics tracking code on this website to include “anonymizeIp()” to ensure that IP addresses are collected anonymously (so-called IP masking). Only in exceptional cases is the full IP address transmitted to a Google server in the U.S. and truncated there. On our behalf, Google will use this information to compile reports on activity on our website and to provide other services related to website and internet usage. Google may also disclose this information to third parties if required by law or if such third parties process the information on Google’s behalf. The IP address transmitted by your browser as part of Google Analytics is not combined with other data held by Google. With regard to data sharing, we have configured the settings so that Google cannot access your data to improve its own products and services. You can prevent the use of cookies by adjusting your browser settings accordingly; however, please note that in this case, you may not be able to use all features of this website to their full extent.
You can prevent Google from collecting the data generated by the cookie and related to your use of the website (including your IP address), as well as from processing this data, by downloading and installing the browser plugin available at the following link (http://tools.google.com/dlpage/gaoptout?hl=de).
You may also revoke your consent at any time, in whole or in part, with future effect by changing your cookie settings.
For more information on the Terms of Service and privacy policy, please visit www.google.com/analytics/terms/de.html or https://www.google.de/intl/de/policies/.
You can disable the use of your Google Account activity and information by checking a box under “Ad Settings” at https://adssettings.google.com/anonymous?hl=de.
Google Tag Manager
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Purpose: Management and deployment of tags/scripts integrated into the website.
Legal basis: Art. 6(1)(f) GDPR; the analytics and marketing tags delivered via Tag Manager are loaded only after consent is given (Art. 6(1)(a) GDPR, § 25(1) TDDDG).
This website uses Google Tag Manager. Google Tag Manager is a software solution provided by Google Inc. that allows companies to manage website tags via a user interface. For the European region, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all Google services. The legal basis for the use of Google Tag Manager is Article 6(1)(f) of the GDPR. Our legitimate interest lies in optimizing our website. Google Tag Manager merely implements tags. This means that no cookies are used and no personal data is collected. Google Tag Manager triggers other tags, which may in turn collect data. We hereby draw your attention to this separately. However, Google Tag Manager does not access this data. If the user has disabled tracking at the domain or cookie level, this setting remains in effect for all tracking tags implemented via Google Tag Manager.
PostHog (EU Cloud)
Provider: PostHog Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA, with data processing via the EU Cloud instance.
Purpose: Product analysis to evaluate website usage and related functions.
Legal basis: Art. 6(1)(a) GDPR, § 25(1) TDDDG (consent).
Iubenda
Provider: Iubenda S.r.l., Via San Gregorio 34, 20124 Milan, Italy.
Purpose: Management of cookie consents (consent management).
Legal basis: Art. 6(1)(c) GDPR in conjunction with § 25(2) TDDDG (duty to provide evidence of consent), Art. 6(1)(f) GDPR.
B. Marketing and Advertising
Google Ads
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Purpose: Measuring the effectiveness of search ads (conversion tracking) and measuring reach.
Legal basis: Article 6(1)(a) of the GDPR, Section 25(1) of the TDDDG (consent).
Meta Ads (Meta Pixel)
Provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
Purpose: Campaign measurement for advertisements on Facebook and Instagram.
Legal basis: Art. 6(1)(a) GDPR, § 25(1) TDDDG (consent).
Brevo
Provider: Sendinblue SAS (Brevo), 7 Rue de Madrid, 75008 Paris, France.
Purpose: CRM and marketing automation (including email, WhatsApp, and SMS communication) as well as sending transaction-related emails (e.g., booking confirmations).
Data processed: Name, email address, phone number (if applicable), interaction data.
Legal basis: Art. 6(1)(b) GDPR (transaction-related communication), Art. 6(1)(a) GDPR or § 25(1) TDDDG (marketing communication, where consent is required).
HubSpot
Provider: HubSpot Ireland Limited, One Dockland Central, Guild Street, Dublin 1, Ireland.
Purpose: Management of business contacts (B2B CRM), particularly in the context of partnerships and business inquiries.
Legal basis: Article 6(1)(b) and (f) of the GDPR.
C. Customer Account, Booking, and Payment Processing
Registration via Email
Purpose: Creation and management of a user account on the website using an email address and password.
Legal basis: Art. 6(1)(b) of the GDPR.
Google SSO
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Purpose: Alternative login option for the user account using an existing Google account (Single Sign-On).
Legal basis: Art. 6(1)(b) of the GDPR.
Firebase
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Purpose: Technical infrastructure for the booking platform (including authentication and data storage).
Legal basis: Art. 6(1)(b) and (f) of the GDPR; any transfers to third countries based on standard contractual clauses.
SumUp
Provider: SumUp Payments Limited, Level 5, Watchmaker Court, 33 St John’s Lane, London EC1M 4DB, United Kingdom (SumUp Financial Technologies Ireland Ltd. for EU customers).
Purpose: Payment processing for train travel bookings.
Data Processed: Payment information, booking references.
Legal basis: Art. 6(1)(b) of the GDPR.
PayPal
Provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg.
Purpose: Payment processing for train travel bookings, integrated via SumUp.
Data processed: Payment information, booking references.
Legal basis: Art. 6(1)(b) of the GDPR.
If you choose to pay using the online payment service provider PayPal, your contact information will be transmitted to PayPal. PayPal is a service provided by PayPal (Europe) S.à r.l. & Cie. S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg.
The personal data transmitted to PayPal typically includes first name, last name, IP address, email address, a unique transaction number, or other data required for payment processing.
This transfer is necessary to process your payment using the payment method you have selected, in particular to verify your identity and to process, allocate, and post your payment. The legal basis is Article 6(1)(b) of the GDPR.
Please note, however, that personal data may be and, in some cases, is also transferred by PayPal to service providers, subcontractors, or other affiliated companies to the extent that this is necessary to fulfill the contractual obligations arising from your payment order or to process the personal data on their behalf.
Depending on the payment method selected via PayPal—e.g., invoice or direct debit—the personal data transmitted to PayPal will be forwarded by PayPal to credit reporting agencies. This transfer serves to verify your identity and creditworthiness in connection with the payment order you have placed. For information on which credit reporting agencies are involved and what data PayPal generally collects, processes, stores, and discloses, please refer to PayPal’s Privacy Policy at https://www.paypal.com/de/webapps/mpp/ua/privacy-full.
OpenFiskal
Provider: OpenFiskal GmbH, Germany.
Purpose: Technical security device (TSE) for the legally compliant recording of payment transactions.
Legal basis: Art. 6(1)(c) GDPR (statutory record-keeping obligations).
NetSuite (Oracle)
Provider: Oracle NetSuite, Oracle Corporation, 2300 Oracle Way, Austin, TX 78741, USA.
Purpose: Inventory management/ERP system, specifically invoicing.
Data Processed: Invoice data, posting and payment references.
Legal basis: Art. 6(1)(b) and (c) of the GDPR; transfers to third countries based on standard contractual clauses.
Apple Wallet
Provider: Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland.
Purpose: Provision of tickets to be added to the digital wallet after booking is complete.
Legal basis: Art. 6(1)(b) of the GDPR.
Google Wallet
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Purpose: To provide tickets for addition to the digital wallet (Google Wallet) after booking is complete.
Legal basis: Art. 6(1)(b) of the GDPR.
D. Customer Service
Zendesk (Ticketing)
Provider: Zendesk International Ltd., 55 Charlemont Place, Saint Kevin’s, Dublin, D02 F985, Ireland.
Purpose: Omnichannel customer support (including email, WhatsApp, Instagram, and Facebook) in connection with handling customer inquiries.
Data processed: Contact information, content of the inquiry, communication history.
Legal basis: Art. 6(1)(b) and (f) of the GDPR; any transfers to third countries based on standard contractual clauses.
Zendesk (AI chat widget)
Provider: Zendesk International Ltd., 55 Charlemont Place, Saint Kevin’s, Dublin, D02 F985, Ireland.
Purpose: Provision of an (AI-powered) chat widget on the website to respond to user inquiries.
Legal basis: Art. 6(1)(b) and (f) of the GDPR; any transfers to third countries are based on standard contractual clauses.
E. Content Management and Localization
Contentful
Provider: Contentful GmbH, Lagerstraße 36, 20357 Hamburg, Germany.
Purpose: Content management system for managing website content.
Legal basis: Art. 6(1)(f) of the GDPR.
Crowdin
Provider: Crowdin LLC, 700 N. Colorado Blvd, Suite 439, Denver, CO 80206, USA.
Purpose: Localization/translation of website content into various languages.
Legal basis: Art. 6(1)(f) GDPR; transfer to a third country based on standard contractual clauses.
F. Hosting, Infrastructure, and Operational Monitoring
Hetzner
Provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany.
Purpose: Hosting of the technical infrastructure within the European Union.
Legal basis: Art. 6(1)(b) and (f) of the GDPR.
Neon
Provider: Neon Inc., 209 Kearny Street, San Francisco, CA 94108, USA, with database hosting in the European Union.
Purpose: Database hosting for the website’s technical systems.
Legal basis: Art. 6(1)(b) and (f) of the GDPR; any transfers to third countries are based on standard contractual clauses.
Sentry
Provider: Functional Software, Inc. (Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA.
Purpose: Error and operational monitoring of the website and its technical systems.
Data processed: Technical log data regarding errors and performance; personal data is anonymized to the extent possible prior to transmission (PII anonymization).
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in stability and security); transfer to third countries based on standard contractual clauses.
The providers listed above may change as we continue to develop our services; the providers currently in use are continuously updated in this Privacy Policy.
14. Your Rights
To the extent that we process your personal data, you, as a data subject within the meaning of the GDPR, have the following rights:
14.1 Right of Access
You may request confirmation from us as to whether we process personal data about you.
If this is the case, you may request the following information from us:
the purposes for which the personal data is processed;
the categories of personal data being processed;
the recipients or categories of recipients to whom your personal data has been or will be disclosed;
the planned duration of the storage of your personal data or, if specific details cannot be provided, the criteria used to determine the storage period;
the existence of a right to rectification or erasure of the personal data concerning you, a right to restrict processing by the controller, or a right to object to such processing;
the existence of a right to lodge a complaint with a supervisory authority;
all available information regarding the source of the data, if personal data about you is collected not from you but from third parties;
the existence of automated decision-making, including profiling, pursuant to Article 22(1) and (4) of the GDPR.
You have the right to request information regarding whether the personal data concerning you is transferred to a third country or to an international organization. In this context, you may request to be informed about the appropriate safeguards pursuant to Article 46 of the GDPR in connection with the transfer.
14.2 Right to Rectification
You have the right to have your personal data rectified and/or completed if the personal data we process about you is inaccurate or incomplete. If this is the case, we will rectify the data without delay.
14.3 Right to Erasure (Right to Be Forgotten)
Obligation to Erase
You may request that we erase your personal data without undue delay if any of the following grounds apply:
Your personal data is no longer necessary for the purposes for which it was collected or otherwise processed;
if the processing was based on Article 6(1)(a) of the GDPR or Section 25(1) of the TDDDG, you have withdrawn your consent, and there is no other legal basis for the processing;
you object to the processing pursuant to Article 21(1) of the GDPR and there are no overriding legitimate grounds for the processing; or you object to the use of your personal data for marketing purposes pursuant to Article 21(2) of the GDPR.
Your personal data has been processed unlawfully.
The erasure of your personal data is necessary to comply with a legal obligation.
Exceptions
The right to erasure does not apply to the extent that processing is necessary:
to exercise the right to freedom of expression and information;
to comply with a legal obligation or to perform a task carried out in the public interest;
to assert, exercise, or defend legal claims.
14.4 Right to Restriction of Processing
Under the following conditions, you may request that the processing of your personal data be restricted:
if you contest the accuracy of your personal data for a period that allows us to verify its accuracy;
the processing is unlawful, and you oppose the erasure of your personal data and instead request the restriction of its use;
we no longer need your personal data for the purposes of processing, but you need it to assert, exercise, or defend legal claims; or
if you have objected to the processing pursuant to Article 21(1) of the GDPR and it has not yet been determined whether our legitimate grounds as the controller override your grounds as the data subject.
If the processing of your personal data has been restricted, such data—apart from its storage—may be processed only with your consent, or for the purpose of asserting, exercising, or defending legal claims, or to protect the rights of another natural or legal person, or for reasons of an important public interest of the Union or a Member State.
If the restriction on processing has been imposed in accordance with the above conditions, we will notify you before the restriction is lifted.
14.5 Right to Data Portability
You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format, and you have the right to transmit this data to another controller without hindrance from us, provided that the processing is based on Article 6(1)(a) or (b) or Article 9(2) of the GDPR.
14.6 Right to Object
If your personal data is processed on the basis of legitimate interests pursuant to Article 6(1)(f) of the GDPR, you have the right, pursuant to Article 21 of the GDPR, to object to the processing of your personal data, provided there are grounds for doing so that arise from your particular situation. Your personal data will then no longer be processed, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defense of legal claims.
14.7 Right to Withdraw Consent
To the extent that the processing of your personal data is based on your consent pursuant to Article 6(1)(a) of the GDPR or Section 25(1) of the TDDDG, you may withdraw your consent at any time with future effect by sending an email to info@noxmobility.com.
14.8 Right to File a Complaint with a Supervisory Authority
Without prejudice to other legal remedies, you have the right to lodge a complaint with a competent supervisory authority if you believe that the processing of your personal data violates the GDPR.
15. Updates
This Privacy Policy is updated from time to time. The date of the last update is listed below.
As of: August 2026