Privacy Policy

This page is being finalised. The full version is currently under review. If you need any of this information in the meantime, please contact us at pickup@interrail-europe.de.

1. Controller

InterRail Europe GmbH, An der Mainkur 9a, 60386 Frankfurt am Main, Germany, represented by its managing directors Igor Maiorov and Birgit Dehner (Amtsgericht Frankfurt am Main, HRB 35828) — see our imprint.
E-mail: pickup@interrail-europe.de
External data protection officer: Dragon Data Solutions GmbH, dsb@dragondata.de

2. What we process, and why

a) The pick-up request you submit

  • company details: company name, street, postal code, city, country, VAT ID;
  • contact details: contact name, phone number, e-mail address, invoice e-mail address;
  • request details: container number(s), planned pick-up date, your remarks, and the calculated storage charges, additional costs and service fee.

We use this to check your entitlement to collect the container, to calculate the charges and to process and invoice your request. Legal basis: Art. 6 (1) (b) GDPR (performance of a contract or pre-contractual measures); where retention is required by tax or commercial law, Art. 6 (1) (c) GDPR.

b) Transport and customs details (Malaszewicze terminal only)

For containers at the Malaszewicze terminal the terminal requires additional information before release: the truck driver's name and phone number, the truck and trailer registration plates, the customs clearance type, the customs reference number and your pick-up reference. We use them to arrange the physical handover at the terminal and to complete the customs formalities. Legal basis: Art. 6 (1) (b) and (c) GDPR; as regards the driver's data, Art. 6 (1) (f) GDPR — our legitimate interest and that of our operational partner in a secure, verifiable handover of the goods. Separate information for drivers is in section 6.

c) IP addresses and security logging

During normal use of the portal your IP address is not stored — neither in access logs nor in the portal database. We keep no web access logs at all: no record of which pages you visited, which browser you use or where you came from. For rate limiting, your address is processed temporarily in the server's memory and is automatically discarded when the relevant time window ends.

Only in the event of repeated incorrect access code entries may your address be recorded in a security log, so that an attempt to guess container access codes does not go unnoticed. This happens only when such an attempt is detected, never during ordinary use. The processing serves to detect and prevent unauthorised access and is based on Art. 6 (1) (f) GDPR. The entry is deleted after seven days, unless longer retention is necessary to investigate a specific security incident. The alert we send ourselves when this happens contains no IP address.

3. Cookies and tracking

This website uses no tracking, no analytics and no advertising cookies, and loads no content from third-party servers. The public request form sets no cookies at all. Our staff area sets a single, strictly necessary cookie to keep an administrator logged in; under § 25 (2) TDDDG that needs no consent. Consequently there is no cookie banner.

4. Who receives your data

  • within InterRail Europe GmbH: the container operations team handling your request;
  • InterRail-Polcont Sp. z o.o., ul. Wilcza 33 lok. 3, 00-544 Warsaw, Poland, a company of the same group, which handles releases at the Malaszewicze terminal. It receives a copy of the request including the transport and customs details and announces the driver to the terminal operator. Because it decides on its own responsibility what it must report and bills us for the storage itself, it acts as an independent data controller, not as a processor on our behalf. It is established in Poland, so the data stays within the EU;
  • you: the contact address you enter receives a copy of your own request;
  • Microsoft Ireland Operations Ltd. as our e-mail provider (Microsoft 365), which processes the request e-mails on our behalf as a processor under Art. 28 GDPR. Microsoft may process data outside the EU; such transfers are safeguarded by the EU-US Data Privacy Framework and EU standard contractual clauses;
  • Hetzner Online GmbH, Germany, which hosts the application and database as a processor under Art. 28 GDPR;
  • public authorities, where we are legally required to disclose data (in particular customs authorities).

We do not sell your data and do not use it for advertising.

5. How long we keep your data

  • Driver and vehicle details: in this portal they are erased from the database as soon as the request has been sent to the people who have to act on it — normally a matter of seconds, and within seven days at the latest if a technical fault delayed that message. They remain in the e-mail correspondence about that pick-up, which is kept like other business correspondence.
  • Requests in this portal: deleted 24 months after they were submitted. The accounting record is not created here.
  • Accounting and correspondence: certain accounting records must be retained for ten years, accounting vouchers for eight years, and commercial and business correspondence generally for six years. Archived e-mails are deleted, or access to them restricted, once that period has run.
  • IP addresses: never stored in our database; see section 2 c for the security log entries.

6. Information for truck drivers

If you are a driver whose name and phone number were entered in this form, we received those details from the company that ordered the container pick-up — not from you. What we do with them, who receives them and what rights you have is set out separately in our Privacy Information for Truck Drivers.

7. Your rights

Where applicable, you have the right to request access to your personal data (Art. 15 GDPR), its rectification (Art. 16) or erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20), and to object to processing based on our legitimate interests (Art. 21). Which of these apply depends on the legal basis of the processing concerned. To exercise them, contact pickup@interrail-europe.de.

You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Postfach 3163, 65021 Wiesbaden, Germany.

8. Is providing the data mandatory?

Providing the requested data is not a statutory requirement, but it is necessary in order to process a pick-up request. Without it we cannot verify your entitlement to the container, calculate the charges or arrange the handover.

9. Automated decision-making

We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR. The charge shown in the form is a non-binding estimate calculated from the stored tariffs; the final amount is determined by us.

10. Security

Traffic to this site is encrypted (HTTPS/TLS) and enforced by HSTS. Access to the staff area requires a password, stored only as an Argon2id hash. The database is reachable only by the application, never from the internet. Container look-ups are rate-limited to prevent guessing of security codes.