Privacy Policy
Information on the processing of personal data pursuant to Art. 13 and 14 GDPR
Applies to the website secretmission.at
and to our on-site events.
Version of 31 August 2026 · replaces the version of 30 August 2026
This translation is provided for your convenience. The German version is the legally binding one.
1. What do we do?
Secret Mission Eventline DKS OG (Sapphogasse 20/3, 1100 Wien, Austria) organises immersive live experiences in Vienna and, for this purpose, operates the website secretmission.at together with the associated booking, account and assistant services (hereinafter “we”).
The protection of your personal data is very important to us. In this privacy policy we inform you transparently and in plain language about which data we collect and how we handle it.
2. What do we inform you about?
- who is responsible for the data processing;
- which data are collected;
- for what purpose these data are collected;
- on what legal basis we collect these data;
- to whom we disclose these data and whether they are transferred to a third country;
- how long we retain the data;
- how you can object to data processing;
- which rights you have and how you can exercise them.
3. Definitions
What are personal data?
Personal data are any information relating to an identified or identifiable natural person. This includes, for example, name, address, date of birth, e-mail address or telephone number, as well as the IP address. Data about personal preferences such as leisure activities or memberships are also personal data.
What are special categories of personal data?
Special categories of personal data (Art. 9 GDPR) are:
- data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership;
- genetic data and biometric data for the purpose of uniquely identifying a person;
- data concerning health and data concerning a person’s sex life or sexual orientation.
Where necessary and where you disclose such data to us yourself – for example health-related limitations before an event – we may process such data. In this case, their processing is subject to stricter confidentiality and takes place exclusively on the basis of your explicit consent pursuant to Art. 9(2)(a) GDPR.
What is the processing of personal data?
Processing means any handling of personal data, irrespective of the means and procedures used, in particular the collection, storage, retention, use, alteration, disclosure, archiving, erasure or destruction of personal data.
What is the disclosure of personal data?
This is the transmission of personal data or making them accessible, for example by publication or by disclosure to a third party.
4. Controller and contact
The controller within the meaning of Art. 4(7) GDPR is:
Secret Mission Eventline DKS OG
Sapphogasse 20/3, 1100 Wien, Austria
Commercial register: FN 67176 3m, Handelsgericht Wien (Commercial Court of Vienna) · VAT ID: ATU83282127
Authorised representatives: Alexander Datzer, Clemens Kaufmann, Michael Schabereiter
Telephone: +43 670 1984 234
General e-mail: info@secretmission.at
Data protection e-mail: datenschutz@secretmission.at
Data protection officer
We are not obliged to appoint a data protection officer pursuant to Art. 37 GDPR and have not appointed one. The contact person for all data protection matters is Michael Schabereiter, who can be reached at datenschutz@secretmission.at or at the postal address stated above.
5. Data security
We store your data securely and take all appropriate technical and organisational measures to protect your data against loss, unauthorised access, misuse or alteration.
Our contractual partners and staff who have access to your data are obliged to comply with the provisions of data protection law. In some cases, within the scope of processing on our behalf, it is necessary for us to forward your enquiries to companies affiliated with us. In these cases, too, your data are treated confidentially.
Transmission between your browser and our servers is encrypted throughout via TLS (HTTPS) at the highest encryption level supported by your browser. Access to our administration systems is restricted to a defined group of persons and secured by multi-factor authentication and a role and permissions concept.
6. Your rights
Right of access (Art. 15 GDPR)
You may at any time request information about the data we have stored about you. We ask you to send your request for access together with credible proof of identity to datenschutz@secretmission.at.
The information is provided in writing or in another form, where appropriate also electronically. If you so request, we may also provide the information orally, provided that you prove your identity in another form. If you submit the request for access electronically, we will provide the information in a commonly used electronic format, unless you specify otherwise.
The information is generally provided free of charge. If further copies are requested, a reasonable fee may be charged. The right to obtain a copy of the processed data must not adversely affect the rights and freedoms of others. In the case of manifestly unfounded or excessive requests, we reserve the right to refuse to provide the information within the statutory limits or to charge a reasonable fee for it.
Your request is processed within the statutory period of one month. We may extend this period by two further months where necessary, taking into account the complexity and number of requests. You will be informed of any such extension within one month of submitting your request for access, together with the reasons for the delay.
Erasure and rectification (Art. 16, 17 GDPR)
You may at any time request the erasure or rectification or completion of your data, provided that no statutory retention obligations or other statutory grounds permitting processing prevent this.
Please note that exercising your rights may, under certain circumstances, conflict with contractual agreements and may have corresponding effects on the performance of the contract (e.g. early termination of the contract or cost consequences).
Restriction of processing (Art. 18 GDPR)
You also have the right to request restriction of processing if you contest the accuracy of the data, the processing is unlawful, the data are no longer needed, or you have objected to the processing.
If the processing of data is restricted, they may only be stored. Any further processing may only take place with your consent, for the establishment, exercise or defence of legal claims, for the protection of the rights of another person or for reasons of important public interest. You will be informed before the restriction is lifted.
Right to data portability (Art. 20 GDPR)
You have the right to receive the personal data concerning you which you have provided to us in a structured, commonly used and machine-readable format and to transmit those data to another controller without hindrance from us, where the processing is based on consent pursuant to Art. 6(1)(a) or Art. 9(2)(a) GDPR or on a contract pursuant to Art. 6(1)(b) GDPR and the processing is carried out by automated means. You also have the right to have the personal data transmitted directly from us to another controller, where technically feasible.
Right to object pursuant to Art. 21 GDPR
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on our legitimate interests (Art. 6(1)(f) GDPR). We will then no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
Where your personal data are processed for direct marketing purposes, you have the right to object to such processing at any time and without giving reasons. Following such an objection, we will no longer use your data for direct marketing.
An informal message to datenschutz@secretmission.at is sufficient for your objection.
Withdrawal of consent (Art. 7(3) GDPR)
If you have given consent to the processing of your data, you may withdraw it at any time with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.
Right to lodge a complaint (Art. 77 GDPR)
You have the right to lodge a complaint with a data protection supervisory authority about our processing of your personal data. The supervisory authority competent for us is:
Austrian Data Protection Authority (Datenschutzbehörde)
Barichgasse 40–42, 1030 Wien, Austria
Telephone: +43 1 52 152-0 · E-mail: dsb@dsb.gv.at
Web: www.dsb.gv.at
7. General principles
Which data do we process and where do they come from?
We primarily process personal data that you provide to us or that we collect when operating our website. Under certain circumstances, we may also receive personal data about you from third parties.
These may include the following categories:
- personal master data (name, address, date of birth);
- contact data (telephone number, e-mail address);
- contract and booking data (mission, date, number of participants, voucher codes);
- financial and payment data (billing address, payment method, payment status);
- online identifiers (cookie ID, IP address, device and browser data);
- communication data (messages to our support, chat histories with our assistant).
These data may originate from the following sources:
- information from publicly accessible sources (e.g. media, internet);
- information from public registers (e.g. commercial register, land register, Ediktsdatei [Austrian insolvency and court notice database]);
- information in connection with official or court proceedings;
- information concerning your professional functions and activities (e.g. professional networks);
- information about you in correspondence and meetings with third parties;
- credit reports (insofar as we conduct personal business with you);
- information about you provided to us by people around you – for example when a booking is made for a group or a voucher is purchased for you;
- data in connection with the use of the website.
Under what conditions do we process your data?
We process your data in accordance with the applicable data protection laws, in particular the GDPR and the Austrian Data Protection Act (DSG). Processing takes place in each case for the purposes set out in this privacy policy. In doing so, we pay attention to transparency and proportionality.
The processing of your data is lawful where a legal basis under the GDPR applies. Possible legal bases are in particular:
- your consent (Art. 6(1)(a) GDPR);
- the performance of a contract or of pre-contractual measures (Art. 6(1)(b) GDPR);
- compliance with legal obligations to which we are subject (Art. 6(1)(c) GDPR);
- the protection of vital interests of the data subject or of another natural person (Art. 6(1)(d) GDPR);
- our legitimate interests, unless your interests override them (Art. 6(1)(f) GDPR).
For the storage of information on your terminal device and access to it, § 165(3) of the Austrian Telecommunications Act 2021 (TKG 2021) additionally applies: we only use cookies and comparable technologies that are not technically necessary with your consent.
Under certain circumstances it is necessary for you to provide us with certain personal data so that contractual obligations can be fulfilled. Without such data, we are normally unable to perform a contract. As a rule, the website likewise cannot be used if certain information required to ensure data traffic, such as your IP address, is not disclosed.
In which cases do we disclose your data to third parties?
a) Principle
Under certain circumstances we depend on using the services of third parties or of affiliated companies and commissioning them to process your data (so-called processors). Categories of recipients are in particular:
- accounting, fiduciary and tax advisory services;
- consulting firms (legal advice, tax);
- IT service providers (web hosting, support, cloud services, website design);
- booking and payment service providers;
- providers of tracking, conversion and advertising services;
- insurers (in the event of damage).
We have concluded contracts pursuant to Art. 28 GDPR with all processors. We ensure that these third parties comply with data protection requirements and treat your personal data confidentially. Under certain circumstances we are also obliged to disclose your personal data to authorities.
b) Disclosure to partners and cooperating companies
We sometimes work with various companies and partners who place their offers on our website. It is recognisable to you that these are third-party offers (marked as “advertising”). If you take up such an offer, we transmit your personal data to the relevant partner (e.g. name, position, communication). These partners are independently responsible for the personal data they receive. After the data have been transmitted, the privacy provisions of the respective partner apply.
c) Transfers abroad
In the course of processing on our behalf, your personal data may be transferred to companies outside the European Economic Area (EEA) – in particular to the United States. These companies are bound to data protection to the same extent as we are.
If the level of data protection does not correspond to that of the EEA, we carry out a prior risk assessment and ensure contractually that the same protection as in the EEA is guaranteed – generally by means of the Standard Contractual Clauses of the EU Commission (Implementing Decision (EU) 2021/914) together with supplementary measures. Where a recipient falls under the EU-US Data Privacy Framework, we additionally base the transfer on the EU Commission’s adequacy decision of 10 July 2023. Should our risk assessment be negative, we take additional technical measures to protect your data. You can request a copy of the respective safeguards at datenschutz@secretmission.at.
d) How long do we retain your data?
We store personal data only for as long as is necessary to fulfil the respective purposes. We store contract data for longer because we are required to do so by statutory provisions: under § 132 of the Austrian Federal Fiscal Code (BAO) and § 212 of the Austrian Commercial Code (UGB), we must retain business correspondence, concluded contracts and accounting records for seven years, and correspondingly longer in the case of pending proceedings. Insofar as we no longer need such data to provide the services, further processing is restricted and we use them only for accounting and tax purposes. An overview of the specific periods can be found in section 10.
8. Individual processing operations
8.1 Provision of the website and creation of log files
If you merely visit our website, i.e. do not register or otherwise provide information, only the data that your browser automatically transmits to our server are collected. These data are technically necessary for operating the website.
The following are processed in particular: name of the internet service provider, IP address, technical information such as browser, operating system or screen resolution, date and time of access, file retrieved, and the referrer URL. These data are not merged with other data sources.
PURPOSE — functionality of the website, error analysis and security of our information technology systems, defence against attacks.
LEGAL BASIS — legitimate interest (Art. 6(1)(f) GDPR) in secure and stable operation.
RETENTION PERIOD — access logs are automatically deleted after 14 days at the latest, unless they are needed to investigate a specific security incident.
OBJECTION — Storing the log files is strictly necessary for operation; an objection is not possible in this respect.
8.2 Cookies and similar technologies
Cookies are small text files that are stored on your terminal device by your browser. They do not cause any damage. In addition, we use your browser’s local storage (localStorage and sessionStorage). We use storage that is technically necessary or triggered by you yourself without separate consent; beyond that, with your consent we use cookies for audience measurement (Microsoft Clarity and Google Analytics 4, see 8.14) and, for marketing purposes, the Meta Pixel, the TikTok Pixel and the Snapchat Pixel (see 8.14).
| NAME | TYPE | PURPOSE | DURATION |
|---|---|---|---|
sm_sprache | Cookie, necessary | Remembers the selected language of the website | 1 year |
sm_harlan_koeder | Cookie, necessary | Remembers that the assistant’s speech bubble was dismissed | Session |
| Assistant history | localStorage / sessionStorage | Keeps the ongoing conversation with “Agent Harlan” in the browser | Until you end the conversation or clear your browser storage |
| Session cookie | Cookie, necessary | Login and security (CSRF protection) in the customer account | Session |
_ga | Cookie, statistics | Distinguishes visitors for Google Analytics 4 (see 8.14) | 2 years |
_ga_<Kennung> | Cookie, statistics | Records the session state for Google Analytics 4 | 2 years |
_fbp | Cookie, marketing | Attributes page views and bookings to the Meta Pixel (see 8.14) | 3 months |
_fbc | Cookie, marketing | Records the ad interaction (fbclid) for the Meta Pixel’s conversion measurement | 3 months |
_clck | Cookie, statistics | Recognises returning visits for Microsoft Clarity (see 8.14) | 1 year |
_clsk | Cookie, statistics | Groups the page views of a session for Microsoft Clarity | 1 day |
_ttp | Cookie, marketing | Attributes page views and events to the TikTok Pixel (see 8.14) | 13 months |
_tt_enable_cookie | Cookie, marketing | Records that the TikTok Pixel may set cookies | 13 months |
_scid | Cookie, marketing | Attributes page views and events to the Snapchat Pixel (see 8.14) | 13 months |
_sctr | Cookie, marketing | Records the ad interaction for the Snapchat Pixel’s conversion measurement | 13 months |
You can configure your browser so that it informs you about cookies being set and you allow this only in individual cases, or so that cookies are generally rejected and deleted when the browser is closed. If cookies are deactivated, the functionality of our website may be limited.
LEGAL BASIS — for technically necessary storage, § 165(3) TKG 2021 in conjunction with our legitimate interest (Art. 6(1)(f) GDPR); for all other storage, your consent (Art. 6(1)(a) GDPR).
8.3 Contact and support enquiries
You can contact us via our contact and enquiry forms, by e-mail, telephone or WhatsApp. Enquiries from the forms are created as tickets in our own administration system (“SMOC”, operated on our infrastructure in the EU) and processed there.
The data you provide are processed – usually name, e-mail address, where applicable telephone number, company name and the content of your message – together with the time of transmission.
PURPOSE — handling and answering your enquiry, documenting the course of the enquiry.
LEGAL BASIS — contract or pre-contractual measures (Art. 6(1)(b) GDPR), otherwise legitimate interest in communicating with prospective customers (Art. 6(1)(f) GDPR).
RETENTION PERIOD — until the enquiry has been finally dealt with; thereafter deleted, unless retention obligations under commercial or tax law apply. We delete pure prospect enquiries without conclusion of a contract after 24 months at the latest.
For communication via WhatsApp, WhatsApp Ireland Ltd. is involved jointly with us. Please note that metadata of your message are transmitted to the operator in the process. Use e-mail or telephone if you wish to avoid this.
8.4 Booking and contract processing
When you make a booking, we collect: surname and first name, e-mail address and telephone number, billing address, booking details (date, mission, number of participants) and payment information.
PURPOSE — carrying out and processing your booking, sending booking confirmations and reminders, managing cancellations and rebookings, invoicing.
LEGAL BASIS — performance of a contract or of pre-contractual measures (Art. 6(1)(b) GDPR); for the retention of records, legal obligation (Art. 6(1)(c) GDPR).
RETENTION PERIOD — seven years from the end of the calendar year in which the service was provided (§ 132 BAO, § 212 UGB).
Bokun (booking platform)
We use Bokun, a booking platform of Bokun ehf., Borgartún 27, 105 Reykjavík, Iceland (a company of the Tripadvisor group), to manage and process online bookings. Since August 2026, no Bokun booking window has been embedded on our website: date selection and checkout run entirely on secretmission.at. Bokun works behind the scenes as the booking system – the exchange takes place between our servers and Bokun, not in your browser. Consequently, no script from widgets.bokun.io is loaded any more, your IP address is no longer transmitted to Bokun when you visit our pages, and Bokun no longer sets any cookies in your browser. We continue to transmit your booking data to Bokun so that the date, capacity and booking confirmation can be managed there.
The following are processed: surname, first name, address and contact details, booking details (chosen experience, date, time, number of participants), payment information (directly from the integrated payment service provider) and communication data (booking confirmations, reminders, cancellations).
LEGAL BASIS — performance of a contract or of pre-contractual measures (Art. 6(1)(b) GDPR).
RECIPIENT / THIRD COUNTRY — Bokun ehf. as processor; as Bokun belongs to the Tripadvisor group, data may also be processed outside the EEA. Protection is ensured by Standard Contractual Clauses.
PRIVACY POLICY — bokun.io/privacy-policy
8.5 Payment processing
Payments are processed via the payment methods offered during the booking process – including credit and debit card, eps bank transfer, Klarna, Apple Pay and Google Pay. You enter the payment data (in particular the card number) directly with the respective payment service provider; complete card data are neither collected nor stored by us. We only receive information on whether and in what amount a payment was successful, as well as the details required for invoicing.
LEGAL BASIS — performance of a contract (Art. 6(1)(b) GDPR); for the retention of records, legal obligation (Art. 6(1)(c) GDPR).
RECIPIENT — the respective payment service provider as an independent controller; its privacy provisions apply. For purchase on account or payment in instalments, the provider may carry out a credit check.
8.6 Customer account “Agentenakte” (Agent File)
You can create a personal customer account on our website. In it you can see your bookings, vouchers, letters of safe conduct (“Geleitbriefe”) and your rank. For login we process your e-mail address, your name and a password in encrypted form (hash) – or, if you log in via a sign-in service, the identifier transmitted by that service.
For login we additionally offer Google Sign-In (Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland) and Apple Sign-In (Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland). If you use this option, we receive your e-mail address, your name and a unique user identifier from the respective provider. The sign-in service thereby learns that you have logged in with us. The use of such a service is voluntary – you can equally register with your e-mail address and a password.
PURPOSE — provision of the account, allocation of your bookings and vouchers, authentication.
LEGAL BASIS — performance of a contract (Art. 6(1)(b) GDPR); for login via an external service, your consent (Art. 6(1)(a) GDPR).
RETENTION PERIOD — until you delete the account. We delete accounts without a login for more than 36 months after prior notice. Booking records are not affected by the deletion of the account and continue to be retained in accordance with the statutory periods.
DELETION — at any time via the account settings or informally to datenschutz@secretmission.at.
8.7 AI assistant “Agent Harlan”
A text-based assistant is available on our website that answers questions about missions, prices, dates and vouchers. The assistant only opens when you click on it; no content is transmitted without your input.
When you send a question, the text of your message, together with the previous conversation history and the selected language, is transmitted to our service at assistent.secretmission.at. This service runs on the infrastructure of Cloudflare, Inc. and forwards the request to a language model of Anthropic PBC, 548 Market St, San Francisco, CA 94104, USA, for a reply. To limit misuse, we additionally process a truncated form of your IP address.
Please do not enter any sensitive data in the chat – in particular no health data, payment data, passwords or information about third parties. For personal matters you can reach us by telephone or via WhatsApp from Monday to Friday, 9:00 a.m. to 5:30 p.m.; the route to a human is available in every reply window.
PURPOSE — automated answering of questions about our offering, improvement of our information service.
LEGAL BASIS — legitimate interest in providing information quickly (Art. 6(1)(f) GDPR); by sending your message you also consent to the transmission of the message text (Art. 6(1)(a) GDPR).
THIRD COUNTRY — USA. The transfer is safeguarded by Standard Contractual Clauses of the EU Commission. The provider is contractually prohibited from using the content to train its models.
RETENTION PERIOD — The conversation history is kept in your browser’s storage and is deleted as soon as you start a new conversation or clear your browser storage. The provider retains requests for abuse monitoring for a maximum of 30 days.
OBJECTION — Do not use the assistant; you can obtain all information equally by telephone, by e-mail or via our FAQ page.
8.8 Newsletter
You can subscribe to our newsletter via our website. For this we need your e-mail address and your declaration that you agree to receive the newsletter.
Registration takes place using the double opt-in procedure: after registering, you receive an e-mail with a confirmation link. Only after your confirmation do we add you to the mailing list. As proof of registration, we log the time of registration and confirmation as well as the IP address used.
You can unsubscribe at any time – via the unsubscribe link at the end of every newsletter e-mail or informally to datenschutz@secretmission.at. Your data in connection with sending the newsletter are deleted immediately if you unsubscribe; we retain the registration logs as proof for up to three years. The lawfulness of processing carried out before the withdrawal remains unaffected.
LEGAL BASIS — your consent (Art. 6(1)(a) GDPR, § 174 TKG 2021); for logging, legitimate interest in being able to provide proof (Art. 6(1)(f) GDPR).
PERFORMANCE MEASUREMENT — We analyse whether an e-mail was opened and which links were clicked in order to improve our content. You can prevent this by deactivating the loading of external images in your e-mail program.
8.9 Push notifications
If you expressly allow it in your browser, we send you notifications about your bookings (such as date reminders). For this purpose an anonymous device or browser identifier is stored. You can withdraw the permission at any time in the settings of your browser or your account; the identifier is then deleted.
LEGAL BASIS — your consent (Art. 6(1)(a) GDPR).
8.10 Video content (YouTube)
On some pages we embed videos. We load these using the two-click method: at first you only see a still image delivered by ourselves. Only when you click on it is a connection established to youtube-nocookie.com (Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland) and your IP address as well as information about your browser and device transmitted to Google. As long as you do not start a video, no transmission to Google takes place.
LEGAL BASIS — your consent by clicking on the video (Art. 6(1)(a) GDPR).
THIRD COUNTRY — USA (Google LLC); safeguarded by the EU-US Data Privacy Framework and Standard Contractual Clauses.
MORE INFORMATION — policies.google.com/privacy
Where possible, we deliver trailers and our own productions directly from our own servers. In these cases no connection to third parties is established. We also load our fonts from our own server; no connection to Google Fonts takes place.
8.11 Participation in the event
When you participate in an event, the following data may additionally arise:
- signatures on liability waivers and declarations of consent;
- health-related information (allergies, health limitations) – exclusively on the basis of your explicit consent pursuant to Art. 9(2)(a) GDPR and only insofar as this is necessary for your safety during the experience;
- proof of age for minors together with the declaration of consent of their parents or legal guardians;
- in exceptional cases, information about an incident on site (accident, property damage) for settlement with our insurer.
LEGAL BASIS — performance of a contract (Art. 6(1)(b) GDPR); for health information, explicit consent (Art. 9(2)(a) GDPR); for claims settlement, legitimate interest (Art. 6(1)(f) GDPR).
RETENTION PERIOD — We delete health information no later than 30 days after the event. We retain liability declarations until the warranty and limitation periods have expired (generally three years).
8.12 Photo and video recordings during our experiences
We film and photograph during our missions ourselves. Our team regularly records the proceedings – this is part of the production and not an exception. Participants are recognisable in the recordings. You yourself are not permitted to film or take photographs during the experience for dramaturgical reasons (see Terms of Participation); the recordings are made exclusively by us.
a) Recordings during the experience
Image and sound recordings of you are processed in the context of the booked experience.
PURPOSE — documentation of the proceedings, quality assurance of our production, training of our performers, and traceability in the event of an incident.
LEGAL BASIS — legitimate interest in documenting and further developing our production (Art. 6(1)(f) GDPR).
RETENTION PERIOD — We delete raw footage without an intended use after 24 months at the latest.
b) Publication for advertising purposes
We also use recordings in which you are recognisable for our online presence and our advertising – in particular on our website, in our profiles on Instagram, Facebook, TikTok, LinkedIn and YouTube, in newsletters and in press and advertising material. Publication takes place exclusively on the basis of your prior, separate consent, which may be withdrawn at any time (Art. 6(1)(a) GDPR in conjunction with § 78 of the Austrian Copyright Act (UrhG), right to one’s own image). We obtain this consent in writing before the start of the experience together with the liability waiver; it is voluntary and not a condition for your participation.
If you do not give your consent, you participate quite normally – we then do not publish any recordings in which you are recognisable. If you book as a group, we need the consent of each participant individually; consent given by the person making the booking is not sufficient for this.
RECIPIENTS — the operators of the platforms mentioned as well as commissioned agencies and editorial offices. Once published on a platform, the recordings are accessible worldwide and may also be processed by the platform operator outside the EEA.
RETENTION PERIOD — until you withdraw your consent.
c) Withdrawal
You can withdraw your consent at any time and without giving reasons with effect for the future – informally by e-mail to datenschutz@secretmission.at. The lawfulness of publication carried out up to that point remains unaffected.
Following a withdrawal, we will immediately remove the recordings concerned from all channels that we operate ourselves. Please note: we have no access to material that has already been printed, to copies made by third parties, or to caches of search engines and social networks – we therefore cannot guarantee complete removal from the internet.
8.13 Our social media profiles
We maintain publicly accessible profiles on Instagram and Facebook (Meta Platforms Ireland Ltd., Merrion Road, Dublin 4, Ireland), TikTok (TikTok Technology Ltd., Dublin, Ireland), LinkedIn (LinkedIn Ireland Unlimited Company, Dublin, Ireland) and YouTube (Google Ireland Ltd.). On our website we merely link to these profiles – no content from the networks is embedded, and no data are transmitted to them when you simply visit our website.
If you visit one of our profiles or interact with us there, the respective operator processes your data under its own responsibility; we have no influence on the type and scope. We see the content you publish there (comments, messages, reactions) as well as aggregated, non-personal statistics on reach. We are jointly responsible with the respective operator for the processing in connection with these page statistics (Art. 26 GDPR); you can exercise your rights against both.
PURPOSE — public presentation, communication with prospective customers and guests.
LEGAL BASIS — legitimate interest in effective public relations (Art. 6(1)(f) GDPR).
NOTE — For confidential matters, please do not use a network’s direct messages but datenschutz@secretmission.at.
8.14 Audience measurement and advertising
We advertise via Google Ads (Google Ireland Ltd.), Meta (Meta Platforms Ireland Ltd.), TikTok and Snapchat to draw attention to our experiences. To measure how our website is used and which advertising leads to a booking, we use – exclusively with your prior consent via the consent banner – Google Analytics 4 and the Meta Pixel, as well as Microsoft Clarity to improve our website and the TikTok Pixel and the Snapchat Pixel to measure the success of our advertising on these two networks. These services are delivered via Google Tag Manager.
Google Tag Manager
Google Tag Manager is a tool of Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) with which we manage the measurement services mentioned above. Tag Manager itself is not a measurement service: it does not set cookies, does not store identifiers and does not analyse your behaviour. It alone decides which measurement service may be loaded – and that is precisely why it runs on every page.
Before you have responded in the consent banner, Google Consent Mode v2 in Tag Manager is set to “denied”. In this state no measurement service is loaded, no cookie is set and no data flow to Google, Meta, TikTok or Snapchat. Only your consent unlocks the category to which you have consented; if you withdraw it, “denied” applies again. When Tag Manager itself is retrieved, your IP address is transmitted to Google – as with any retrieval of a file from the web.
PURPOSE — management and consent-dependent delivery of the measurement services used.
LEGAL BASIS — our legitimate interest in technically sound control of these services that respects your consent (Art. 6(1)(f) GDPR). The services themselves run exclusively on the basis of your consent (Art. 6(1)(a) GDPR).
COOKIES — none.
THIRD COUNTRY — Transfers to the USA may occur. Google LLC is certified under the EU-US Data Privacy Framework; Standard Contractual Clauses are also in place.
Google Analytics 4
Google Analytics 4 is a web analytics service of Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). We use it to understand how our website is used: which pages are viewed, how visitors found us, how long they stay and at which point in the booking process they drop off.
The following are recorded: the pages viewed and the order in which they were viewed, the referring page and, where applicable, the identifier of the ad through which you came to us, information about browser, operating system and device, the approximate location based on the IP address, and a randomly assigned identifier stored in a cookie. The IP address is truncated by Google before it is stored and is not merged with other data.
If you complete a booking, we additionally transmit the transaction itself: a transaction number, the amount, the currency and the experience booked. We do not transmit your name, e-mail address, telephone number or address to Google. The transaction number cannot be attributed to a person without our own systems; it serves to avoid counting the same purchase twice.
PURPOSE — audience measurement, understanding the use of our website, measuring the success of our advertising through to a completed booking.
LEGAL BASIS — your consent (Art. 6(1)(a) GDPR) in conjunction with § 165(3) TKG 2021.
COOKIES — _ga and
_ga_<Kennung> (each with a lifetime of 2 years), listed in the overview in 8.2.
RETENTION PERIOD — The cookies expire automatically after the stated period. We delete the analytics data in Google Analytics after 14 months; aggregated reports without personal reference remain beyond that.
THIRD COUNTRY — Transfers to the USA may occur. Google LLC is certified under the EU-US Data Privacy Framework; Standard Contractual Clauses are also in place. A data processing agreement pursuant to Art. 28 GDPR has been concluded with Google.
WITHDRAWAL — You can withdraw your consent at any time with effect for the future, most easily via secretmission.at/cookies/. From the time of withdrawal, Google Analytics is no longer loaded. The lawfulness of processing carried out up to that point remains unaffected.
Meta Pixel
The Meta Pixel is an advertising and analytics tool of Meta Platforms Ireland Limited (Merrion Road, Dublin 4, D04 X2K5, Ireland). With it we measure how many people visit our website and book there after seeing an ad on Facebook or Instagram. Meta and we are joint controllers pursuant to Art. 26 GDPR for processing in connection with these advertising functions; the allocation of obligations is governed by the joint controller agreement provided by Meta. Meta is solely responsible for further processing by Meta, in particular for building audiences and delivering advertising.
The following are recorded: the viewing of our pages, the address viewed and the referring page, information about browser, operating system and device, your IP address and an identifier stored in a cookie. If you come via a Meta ad, its identifier (fbclid) is also processed. For a completed booking we additionally transmit the amount, currency and a transaction number.
We do not transmit names, addresses, e-mail addresses, telephone numbers or your entries in our forms to Meta; Meta itself may match the data with Meta accounts if you are logged in there.
The pixel is only loaded after you have consented to the “Marketing” category in the consent banner. Without your consent, no script is requested from Meta and no cookie is set. The pixel is not active in the checkout at /checkout/; there we measure only the path to completion, not reach.
PURPOSE — measuring the success of our advertising on Facebook and Instagram (reach, page views and bookings after ad interaction) and optimising ad delivery.
LEGAL BASIS — your consent (Art. 6(1)(a) GDPR) in conjunction with § 165(3) TKG 2021.
COOKIES — _fbp (lifetime 3 months) and
_fbc (lifetime 3 months), listed in the overview in 8.2.
RETENTION PERIOD — The cookies expire automatically after the stated periods. Meta’s deletion periods apply to the data in its systems.
THIRD COUNTRY — Transfers to the USA may occur. Meta Platforms, Inc. is certified under the EU-US Data Privacy Framework; Standard Contractual Clauses are also in place.
WITHDRAWAL — You can withdraw your consent at any time with effect for the future, most easily via secretmission.at/cookies/. From the time of withdrawal, the pixel is no longer loaded. The lawfulness of processing carried out up to that point remains unaffected.
Microsoft Clarity
Microsoft Clarity is a web analytics service of Microsoft Ireland Operations Limited (One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland). Clarity helps us understand how our website is used: it records page views and their order, clicks, mouse movements and scrolling behaviour, screen size, device type, browser and operating system, the approximate location based on the truncated IP address, and the referring page. From this, aggregated analyses are produced – such as heatmaps showing which areas of a page are clicked – as well as replays of individual sessions.
Clarity does not record your entries in form fields in plain text: text entries are masked in the browser itself. Neither your details in contact and booking forms nor payment data or login credentials are visible to us in the recordings.
Clarity is only loaded after you have consented to the “Statistics” category in the consent banner. Without your consent, no script is requested from Microsoft and no cookie is set. We do not use Clarity on the booking platform or the knowledge platform.
PURPOSE — understanding how our website is used; identifying usability and display problems; improving structure, content and loading behaviour.
LEGAL BASIS — your consent (Art. 6(1)(a) GDPR) in conjunction with § 165(3) TKG 2021.
COOKIES — _clck (lifetime 1 year) and
_clsk (lifetime 1 day), listed in the overview in 8.2.
RETENTION PERIOD — The cookies expire automatically after the stated periods. We delete analyses and session recordings as soon as they are no longer needed for improving the website; beyond that, Microsoft’s deletion periods apply.
THIRD COUNTRY — Transfers to the USA may occur. Microsoft Corporation is certified under the EU-US Data Privacy Framework; Standard Contractual Clauses are also in place. A data processing agreement pursuant to Art. 28 GDPR has been concluded with Microsoft.
WITHDRAWAL — You can withdraw your consent at any time with effect for the future, most easily via secretmission.at/cookies/. From the time of withdrawal, Clarity is no longer loaded; cookies already set expire or can be deleted in your browser. The lawfulness of processing carried out up to that point remains unaffected.
TikTok Pixel
The TikTok Pixel is an advertising and analytics tool of TikTok Technology Limited (10 Earlsfort Terrace, Dublin 2, D02 T380, Ireland) and TikTok Information Technologies UK Limited (Kaleidoscope, 4 Lindsey Street, London, EC1A 9HP, United Kingdom). TikTok and we are joint controllers pursuant to Art. 26 GDPR for processing in connection with these advertising functions; the allocation of obligations is governed by the TikTok Business Products (Data) Terms. TikTok is solely responsible for further processing of the data by TikTok, in particular for building audiences and delivering advertising.
The following are recorded: the viewing of our pages, the address viewed and the referring page, information about browser, operating system and device, your truncated IP address and an identifier stored in a cookie. If you come via a TikTok ad, its identifier (ttclid) is also processed. This allows us to measure how many people land on our website after seeing an ad. We do not transmit names, addresses, e-mail addresses, telephone numbers or your entries in our forms to TikTok; TikTok itself may match the data with TikTok accounts if you are logged in there.
The pixel is only loaded after you have consented to the “Marketing” category in the consent banner. Without your consent, no script is requested from TikTok and no cookie is set. This applies to all pages of secretmission.at, including the booking process at /buchung/: until August 2026 it was located on a separate subdomain without its own consent banner, and it was moved to the main domain precisely for this reason — since then, one consent applies to everything. We do not use the pixel on the knowledge platform.
PURPOSE — measuring the success of our TikTok advertising (reach, page views after ad interaction) and optimising ad delivery.
LEGAL BASIS — your consent (Art. 6(1)(a) GDPR) in conjunction with § 165(3) TKG 2021.
COOKIES — _ttp and
_tt_enable_cookie (each with a lifetime of 13 months), listed in the overview in 8.2.
RETENTION PERIOD — The cookies expire automatically after the stated periods. TikTok’s deletion periods apply to the data in its systems.
THIRD COUNTRY — Transfers outside the EEA may occur, including to the USA, the United Kingdom and Singapore. They are based on Standard Contractual Clauses of the EU Commission together with supplementary safeguards; for the United Kingdom there is an adequacy decision of the EU Commission.
WITHDRAWAL — You can withdraw your consent at any time with effect for the future, most easily via secretmission.at/cookies/. From the time of withdrawal, the pixel is no longer loaded on any page, including the booking process; cookies already set expire or can be deleted in your browser. The lawfulness of processing carried out up to that point remains unaffected. In your TikTok account you can additionally object to personalised advertising under “Settings and privacy”.
Snapchat Pixel
The Snapchat Pixel is an advertising and analytics tool of Snap B.V. (Keizersgracht 165, 1016 DP Amsterdam, Netherlands), which is responsible for users from the European Economic Area, and of Snap Group Limited (77 Shaftesbury Avenue, London W1D 5DU, United Kingdom). Snap and we are joint controllers pursuant to Art. 26 GDPR for processing in connection with these advertising functions; the allocation of obligations is governed by the Snap Business Tools Terms. Snap is solely responsible for further processing of the data by Snap, in particular for building audiences and delivering advertising.
The following are recorded: the viewing of our pages, the address viewed and the referring page, information about browser, operating system and device, your truncated IP address and an identifier stored in a cookie. If you come via a Snapchat ad, its identifier (ScCid) is also processed. This allows us to measure how many people land on our website after seeing an ad. We do not transmit names, addresses, e-mail addresses, telephone numbers or your entries in our forms to Snap; Snap itself may match the data with Snapchat accounts if you are logged in there.
The pixel is only loaded after you have consented to the “Marketing” category in the consent banner. Without your consent, no script is requested from Snap and no cookie is set. This applies to all pages of secretmission.at, including the booking process at /buchung/ – there it depends on the same consent as everywhere else. We do not use the pixel on the knowledge platform.
PURPOSE — measuring the success of our Snapchat advertising (reach, page views after ad interaction) and optimising ad delivery.
LEGAL BASIS — your consent (Art. 6(1)(a) GDPR) in conjunction with § 165(3) TKG 2021.
COOKIES — _scid and _sctr
(each with a lifetime of 13 months), listed in the overview in 8.2.
RETENTION PERIOD — The cookies expire automatically after the stated periods. Snap’s deletion periods apply to the data in its systems.
THIRD COUNTRY — Transfers outside the EEA may occur, including to the USA and the United Kingdom. They are based on Standard Contractual Clauses of the EU Commission together with supplementary safeguards; for the United Kingdom there is an adequacy decision of the EU Commission.
WITHDRAWAL — You can withdraw your consent at any time with effect for the future, most easily via secretmission.at/cookies/. From the time of withdrawal, the pixel is no longer loaded on any page, including the booking process; cookies already set expire or can be deleted in your browser. The lawfulness of processing carried out up to that point remains unaffected. In your Snapchat account you can additionally object to personalised advertising under “Settings” → “Ad Preferences”.
Tracking pixels
Tracking pixels – also known as web beacons – are small, usually invisible images that are retrieved automatically when you visit a website or open an e-mail. They can be used to record the same information as in log files. We currently use tracking pixels only to measure the performance of our newsletter (see 8.8). To prevent processing by means of tracking pixels in general, you can install suitable browser extensions and block external graphics in your e-mail program.
8.15 Hosting, content delivery and e-mail dispatch
We operate our websites and our administration system on rented servers within the European Union. Upstream, we use Cloudflare (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, or Cloudflare Germany GmbH) as a content delivery network, DNS provider and protection against attacks. In doing so, connection data including your IP address are processed in order to deliver content quickly and to fend off overload attacks (DDoS).
For sending system and booking e-mails and for storing files, we use services of Amazon Web Services (Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, 1855 Luxembourg), in particular Amazon Simple Email Service and Amazon S3.
LEGAL BASIS — legitimate interest in secure, fast and reliable operation (Art. 6(1)(f) GDPR); in the context of bookings, additionally performance of a contract (Art. 6(1)(b) GDPR).
THIRD COUNTRY — Transfers to the USA may occur; these are safeguarded by Standard Contractual Clauses and – insofar as the provider is certified – by the EU-US Data Privacy Framework. Data processing agreements pursuant to Art. 28 GDPR have been concluded with both providers.
8.16 Customer relationship management (CRM)
To maintain relationships with customers and prospective customers, in addition to our own system we partly use HubSpot (HubSpot Ireland Ltd., 1 Sir John Rogerson's Quay, Dublin 2, Ireland). Contact details, enquiry history and communication history are stored there in order to allocate and answer enquiries.
LEGAL BASIS — pre-contractual measures and performance of a contract (Art. 6(1)(b) GDPR) as well as legitimate interest in orderly customer management (Art. 6(1)(f) GDPR).
THIRD COUNTRY — Transfers to the USA are safeguarded by Standard Contractual Clauses.
9. Recipients at a glance
The following overview summarises the external parties to which data may flow.
| SERVICE | PROVIDER & SEAT | PURPOSE | LEGAL BASIS | THIRD COUNTRY |
|---|---|---|---|---|
| Bokun | Bokun ehf., Iceland (Tripadvisor group) | Booking system in the background (dates, capacities, booking confirmations); not embedded in the website | Art. 6 (1) b | yes, SCC |
| Cloudflare | Cloudflare, Inc., USA / Cloudflare Germany GmbH | CDN, DNS, attack defence, operation of the assistant | Art. 6 (1) f | yes, SCC |
| Anthropic | Anthropic PBC, USA | Language model for the assistant “Agent Harlan” | Art. 6 (1) a / f | yes, SCC |
| Amazon Web Services | AWS EMEA SARL, Luxembourg | E-mail dispatch (SES), file storage (S3) | Art. 6 (1) b / f | yes, SCC |
| HubSpot | HubSpot Ireland Ltd., Ireland | Customer and prospect management | Art. 6 (1) b / f | yes, SCC |
| Google Ireland Ltd., Ireland | Videos (only after click), sign-in service, advertising, audience measurement (Google Analytics 4), management of measurement services (Tag Manager) | Art. 6 (1) a / f | yes, DPF/SCC | |
| Microsoft | Microsoft Ireland Operations Ltd., Ireland | Audience measurement and session analysis (Clarity) | Art. 6 (1) a | yes, DPF/SCC |
| Apple | Apple Distribution International Ltd., Ireland | Sign-in service for the customer account | Art. 6 (1) a | no |
| Meta | Meta Platforms Ireland Ltd., Ireland | Social media profiles, WhatsApp contact, advertising and performance measurement (Meta Pixel) | Art. 6 (1) a / f | yes, DPF/SCC |
| TikTok | TikTok Technology Ltd., Ireland / TikTok Information Technologies UK Ltd. | Advertising and performance measurement (TikTok Pixel) | Art. 6 (1) a | yes, SCC |
| Snap | Snap B.V., Netherlands / Snap Group Ltd., United Kingdom | Advertising and performance measurement (Snapchat Pixel) | Art. 6 (1) a | yes, SCC |
| Payment service providers | depending on the payment method chosen | Payment processing | Art. 6 (1) b | case by case |
| Tax advisors | Austria | Accounting, fulfilment of tax obligations | Art. 6 (1) c | no |
| Insurance | Austria | Settlement of claims | Art. 6 (1) f | no |
SCC = Standard Contractual Clauses of the EU Commission · DPF = EU-US Data Privacy Framework
10. Retention periods at a glance
| TYPE OF DATA | DURATION | BASIS |
|---|---|---|
| Access logs (log files) | 14 days | Operational security |
| Audience measurement (Google Analytics 4) | Cookies: 2 years · Analytics data: 14 months | Consent |
| Audience measurement (Clarity) | Cookies: 1 year or 1 day | Consent |
| Advertising measurement (Meta Pixel) | Cookies: 3 months | Consent |
| Advertising measurement (TikTok Pixel) | Cookies: 13 months | Consent |
| Advertising measurement (Snapchat Pixel) | Cookies: 13 months | Consent |
| Booking and invoice data | 7 years from year end | § 132 BAO, § 212 UGB |
| Business correspondence | 7 years from year end | § 132 BAO |
| Enquiries without conclusion of a contract | max. 24 months | Necessity |
| Customer account | until deletion, at the latest after 36 months without login | Necessity |
| Newsletter subscription | until withdrawal | Consent |
| Newsletter registration log | 3 years after unsubscribing | Obligation to provide proof |
| Health information for the event | 30 days after the event | Consent |
| Liability waivers and declarations of consent | 3 years | Limitation periods |
| Raw footage of recordings during experiences | max. 24 months | Necessity |
| Published marketing recordings | until withdrawal | Consent |
| Chat history with the assistant | Session (in the browser), max. 30 days at the provider | Abuse monitoring |
11. No automated decision-making
We do not use your personal data for a decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR). No profiling to evaluate personal aspects takes place.
The AI assistant “Agent Harlan” provides information only and does not make decisions about bookings, prices or claims. If a payment method carries out an automated credit check, this is done under the sole responsibility of the respective payment service provider; you will receive the relevant information during the payment process.
12. Special notes on minors
Our offerings are generally aimed at adults. For participants under the age of 16, the consent of their parents or legal guardians is required; this also applies to consent to data processing pursuant to § 4(4) DSG. We process data of minors only to the extent necessary for performing the contract. Should we become aware that data of minors have been transmitted to us without the required consent, we will delete them without delay.
13. Video surveillance at locations
We do not operate any video surveillance of our own.
Insofar as video surveillance is used for security reasons at locations we use, it is operated by the respective location operator. The operator is solely responsible for it; the systems are signposted on site in accordance with the statutory requirements (§§ 12 et seq. DSG), and you will also receive the associated data protection information there. We have no influence on the type, scope and retention period of these recordings and no access to them.
Video surveillance must be distinguished from the photo and video recordings that we make ourselves during our experiences. We inform you about these in section 8.12.
14. Does our privacy policy always stay the same?
We may amend this privacy policy at any time, for example if we use new services or the legal situation changes. The version available at the time of your visit applies. The current version is published at secretmission.at/datenschutz. No separate notification is given; in the case of material changes affecting a consent, we will obtain it anew.
Secret Mission Eventline DKS OG · Sapphogasse 20/3, 1100 Wien,
Austria · FN 67176 3m (Handelsgericht Wien) · VAT ID ATU83282127
Data protection questions: datenschutz@secretmission.at
· Version of 31 August 2026
Privacy Policy, Version of 31 August 2026 · Legal notice · Cookie settings · Right of withdrawal