We, Flix SE, including our subsidiaries (hereinafter jointly referred to as “FlixBus”, “we” or “us”), would like to hereby inform you about data protection at FlixBus.
Data protection regulations for the protection of persons affected by data processing (we refer to you as a “data subject” hereinafter, as well as “customer”, “user” or “you”,) arise in particular from the EU General Data Protection Regulation (Regulation EU 2016/679, hereinafter referred to as “GDPR”). Insofar as we decide on the purposes and means of data processing either alone or jointly with others, this primarily includes the obligation to inform you transparently about the type, scope, purpose, duration and legal basis of the processing (see Art. 13 and Art. 14 GDPR).
You can find further legal information here:
For job applicants:
1. General Information
1.1 Definition of Terms
- “personal data” means any information relating to an identified or identifiable natural person (“data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person (Art. 4(1) GDPR). Identifiability can also be provided by linking such information or other additional knowledge. This does not depend on the occurrence, form or physical embodiment of the information (photos, video or audio recordings may also contain personal data).
- “processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means (i.e., technology‑supported). This includes in particular the collection (i.e., the procurement), recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of personal data as well as the change of definition of a target or purpose that was originally used as a basis for data processing (Art. 4(2) GDPR).
- “controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data (Art. 4(7) GDPR).
- “processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller, in particular in accordance with its instructions (Art. 4(8) GDPR).
- “third party” means a natural or legal person, public authority, agency or other body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorized to process personal data; this also includes other legal entities belonging to the group (Art. 4(10) GDPR).
- “consent” of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her (Art. 4(11) GDPR).
1.2 Name and Address of the Controller
The person responsible for the processing of your personal data (Art. 4(7) GDPR) is:
Friedenheimer Brücke 16
Telephone: +49 (0)30 300 137 300
Further information about our company can be found in the Legal Notice.
1.3 Contact Details of the Data Protection Officer
Our company data protection officer is available to you at any time to answer all your questions and as a contact person on the subject of data protection.
Her contact details are:
Friedenheimer Brücke 16
For general questions about FlixBus, please contact firstname.lastname@example.org.
1.4 Legal Basis for Data Processing
The processing of personal data is permitted if at least one of the legal bases listed below is complied with:
- Art. 6 para. 1(a) GDPR: the data subject has given consent to the processing of his or her personal data for one or more specific purposes;
- Art. 6 para. 1(b) GDPR: processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
- Art. 6 para. 1(c) GDPR: processing is necessary for compliance with a legal obligation to which the controller is subject (e.g., a statutory retention obligation);
- Art. 6 para. 1(d) GDPR: processing is necessary in order to protect the vital interests of the data subject or of another natural person;
- Art. 6 para. 1(e) GDPR: processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller; or
- Art. 6 para. 1(f) GDPR: processing is necessary to safeguard the legitimate interests pursued by the controller or by a third party, unless the opposing interests or rights of the data subject prevail (in particular where the data subject is a child).
For processing carried out by us, we specify the applicable legal basis under Clause 2. Processing can also be based on more than one legal basis.
1.5 Categories of Recipients
Under certain conditions, we transmit your personal data to our subsidiaries or personal data from our subsidiaries is transferred to us, to the extent permissible.
As with any major company, we also use external domestic and foreign service providers to handle our business transactions and work with partner companies at home and abroad. These include, for example:
- carriers (you can find an overview of the current carriers here),
- (IT) service providers,
- financial institutions and payment service providers,
- sales partners,
- customer service providers (internal/external),
- store operators,
- security companies,
- (travel) insurers,
- other partners engaged for our business operations (e.g., auditors, banks, insurance companies, lawyers, supervisory authorities, other parties participating in company acquisitions).
The service providers and partner companies must provide guarantees that suitable technical and organizational measures are implemented by them in such a way that the processing meets legal requirements and the rights of the data subjects are safeguarded.
We transmit personal data to public entities and institutions (e.g., law enforcement, district or state attorneys’ offices, supervisory authorities) if there is a corresponding obligation/authorization.
For processing carried out by us, we specify the categories of the data recipients under Clause 2.
1.6 Requirements for the Transfer of Personal Data to Third Countries
As part of our business relationships, your personal data may be shared with or disclosed to third parties who may also be located outside the European Economic Area (EEA), i.e., in third countries.
Insofar as it is necessary, we will inform you in the relevant sections of Clause 2 about the respective details of the transfer to third countries in connection with the processing carried out by us.
The European Commission certifies that some third countries have data protection that is comparable to the EEA standard by means of so-called adequacy decisions (a list of these countries and a copy of the adequacy decisions can be downloaded from: http://ec.europa.eu/justice/data-protection/international-transfers/adequacy/index_en.html).
However, in other third countries to which personal data may be transferred, there may not be a consistently high level of data protection due to a lack of legal provisions. If this is the case, we ensure that data protection is adequately guaranteed.
This is possible, for example, via binding company regulations (referred to as “binding corporate rules”), standard contractual clauses of the European Commission for the protection of personal data, certificates and recognized codes of conduct.
Insofar as it is necessary for your booking and the associated provision and processing of transport services, the transmission of personal data required for this to third countries is permitted in accordance with Art. 49 para. 1(b) GDPR.
Please contact our data protection officer if you would like more detailed information on this topic.
1.7 Storage Duration and Data Erasure
The storage period of the personal data collected depends on the purpose for which we process the data. The data will be stored for as long as this is necessary to achieve the intended purpose.
In the case of processing carried out by us, we specify how long we will store the data in Clause 2. If no explicit storage period is specified below, your personal data will be erased or blocked as soon as the purpose or legal basis for the storage no longer applies.
However, storage may be extended beyond the specified time in the event of a(n) (imminent) legal dispute with you or if other legal proceedings are initiated or if storage is stipulated by statutory provisions to which we as the controller are subject. If the storage period prescribed by statutory provisions expires, the personal data will be blocked or erased unless further storage by us is required by law.
1.8 Automated Decision-Making (Including Profiling)
We do not intend to use any personal data collected from you for any processes involving automated decision-making (including profiling). If we wish to implement these procedures, we will inform you of this separately in accordance with statutory provisions.
1.9 No Obligation to Provide Personal Data
We do not fundamentally make the conclusion of contracts with us dependent on your providing us with personal data beforehand. In principle, there is also no statutory or contractual obligation to provide us with your personal data; however, we may only be able to provide certain offers to a limited extent or may not be able to provide them at all if you do not provide the data required for this.
1.10 Statutory Obligation to Transmit Certain Data
Under certain circumstances, we may be subject to a special statutory or legal obligation to provide personal data to third parties, in particular to public entities.
1.11 Data Security
We use suitable technical and organizational measures to collect your data, taking into consideration the latest technology, the implementation costs, and the nature, scope, context and purpose of the processing, as well as the existing risks of a data breach (including the probability and effect of such an event), in order to protect the data subject against accidental or intentional manipulation, partial or complete loss or destruction or against unauthorized access by third parties (e.g., we use TLS encryption for our websites). Our security measures are continuously being improved to take into account technological developments.
We will be happy to provide you with further information about this upon request. Please contact our data protection officer or our CISO (chief information security officer) in this regard.
His contact details are:
Friedenheimer Brücke 16
1.12 Your Rights
You may assert your rights as a data subject regarding your personal data at any time, in particular by contacting us using the contact details provided in Clause 1.2. Data subjects have the following rights under the GDPR:
Right to Information
You can request information in accordance with Art. 15 GDPR about your personal data processed by us. In your request for information, you should clarify your concern to make it easier for us to compile the necessary data. Upon request, we will provide you with a copy of the data that are the subject of the processing. Please note that your right to information may be limited under certain circumstances in accordance with statutory provisions.
Right to Rectification
If the information relating to you is not or is no longer correct, you may request a correction in accordance with Art. 16 GDPR. If your data is incomplete, you may request completion.
Right to Erasure
You may request the erasure of your personal data in accordance with the provisions of Art. 17 GDPR. Your right to erasure depends, among other things, on whether the data relating to you are still required by us to perform our statutory duties.
Right to Restriction of Processing
In accordance with the provisions of Art. 18 GDPR, you have the right to request restriction of the processing of the data relating to you.
Right to Data Portability
In accordance with the provisions of Art. 20 GDPR, you have the right to receive the data that you have provided to us in a structured, commonly-used and machine-readable format or to request its transmission to another controller.
Right to Object
In accordance with Art. 21 para. 1 GDPR, you have the right to object to the processing of your data at any time for reasons relating to your particular situation. You can object to receiving advertising at any time with effect for the future, in accordance with Art. 21 para. 2 GDPR (objection to advertising in the case of direct marketing).
Right to Appeal
If you are of the opinion that we have not complied with the provisions of the data protection regulations when processing your data, you may file a complaint with a data protection supervisory authority about the processing of your personal data, such as the data protection supervisory authority to whom we are responsible:
Bavarian State Office for Data Protection Supervision, Promenade 18, 91522 Ansbach
Right to Withdraw Consent
You can withdraw your consent to the processing of your data at any time with future effect. This also applies to declarations of consent that were issued before the GDPR came into force, i.e., before 05/25/2018.
2. Special Information
2.1 Visiting our Websites
Information about FlixBus and the services we offer can be found in particular at https://global.flixbus.com / https://www.flixtrain.com/ including the associated subpages (hereinafter referred to jointly as the “website” or “websites”). When you visit our websites, your personal data is processed.
2.1.1 Provision of Websites
When the websites are used for information purposes, we collect, store and process the following categories of personal data:
Log data: when you visit our websites, a log data record (referred to as “server log files”) is saved on our web server. This consists of:
- the page from which the page was requested (referred to as referrer URL),
- the name and URL of the requested page,
- the date and time of the access request (in the server’s time zone),
- the version of the web browser used,
- the IP address of the requesting computer,
- the amount of data transferred,
- the operating system,
- the message indicating whether the call was successful (access status/Http status code),
- the GMT time zone difference.
We use IT service providers for hosting our websites and for statistical evaluations of the log data.
The processing of the log data serves statistical purposes and improves the quality of our websites, in particular the stability and security of the connection.
The legal basis is Art. 6 para. 1(f) GDPR. Our legitimate interest is to be able to make the websites duly available to you.
2.1.2 Contact Forms
When using contact forms, the data thus transmitted are processed (e.g., title, last name and first name, address, company, email address and time of transmission, reason for the inquiry).
The processing of contact form data takes place in order to process inquiries, and, depending on the basis and the reason for your inquiry, either on the legal basis of Art. 6 para. 1(b) GDPR, if it concerns a contract-related inquiry or in other cases on the legal basis of Art. 6 para. 1(f) GDPR; our legitimate interest is to process contact inquiries.
We use customer service providers for job processing to answer inquiries made via our contact forms.
In addition, we store the contact form data as well as the respective IP address in order to comply with our obligations to provide evidence, to ensure compliance with and documentation of legal obligations, in order to be able to clarify any possible misuse of your personal data and to ensure the security of our systems.
The legal basis is Art. 6 para. 1(c) or (f) GDPR.
2.1.3 Booking, Provision and Processing of Transport Services
When booking tickets for transport services, we collect, store and process the following categories of personal data:
- email address,
- last name and first name,
- connection data,
- payment data,
- date of birth (for transport services where children have a special price),
- consent to the respective terms and conditions,
- advance seat reservation information,
- baggage details,
- language of the booking domain,
- booking channel (web or app).
You also have the option of providing a contact telephone number in case of delays or changes in the itinerary of your trip (optional).
These data are processed for the booking, provision and processing of transport services, including customer service, as well as for the fulfillment of legal obligations.
The legal basis is Art. 6 para. 1(b), (c) GDPR.
We also use some of these data for product recommendations, see Clause 2.1.4, for the newsletter, see Clause 2.1.5, and for the customer account, see Clause 2.1.6.
When booking tickets for international transport services, the following categories of personal data are also collected depending on the place of departure and arrival:
- gender information,
- identity document, passport or ID number.
These data are processed for the booking, provision and processing of transport services, including customer service, as well as for the fulfillment of legal obligations.
We pass on the above-mentioned data to the respective carrier or carriers, as well as to public entities if there is a corresponding obligation/authorization.
The legal basis is Art. 6 para. 1(b) or (c) GDPR.
The necessary payment data will be transmitted to a payment service provider for the secure processing of the payments initiated by you.
Our payment service providers are:
|Payment service providers
Simon Carmiggeltstraat 6-50, 1011 DJ, Netherlands
|PayU Bilgi Teknolojileri A.S.
Otakcilar Cad. No: 78, Flat Ofis D-Blok 34050, Eyup - ISTANBUL
|Paymill Plus GmbH
St.-Martin-Straße 63, 81669 Múnich
|PayPal (Europe) S.à r.l. et Cie, S.C.A.
22-24 Boulevard Royal 2449 Luxembourg
The legal basis is Art. 6 para. 1(b) or (f) GDPR.
For certain bookings, we also use the technologies and services of Distribusion Technologies GmbH as processors (Wattstrasse 10, 13355 Berlin, telephone: +49-30-3465507-50, email: email@example.com).
2.1.4 Product Recommendation
To the extent permitted, we may use the email address received in connection with the booking or transport service to send you regular offers by email for products from our range similar to those already purchased.
We use external customer service providers as processors to send product recommendations.
You will receive these product recommendations from us regardless of whether you have subscribed to a newsletter or have consented to marketing communication by email. We wish to provide you in this way with information about products from our range that you might be interested in, based on your recent purchases with us.
The legal basis is Art. 6 para. 1(f) GDPR; our legitimate interest is to inform you about our product range and to suggest certain products to you.
You can object to the use of your email address for this purpose at any time by using the unsubscribe link in the product recommendation or by sending a message to firstname.lastname@example.org.
If you also register for the newsletter via our registration link, we ask you to consent to the processing of your data (email address, first and last names, place of residence) in order to send you our newsletter by email on a regular basis.
As part of your subscription to the newsletter, we also obtain your consent that we may personalize the content of our newsletter according to your needs and interests.
To register for our newsletter, we use the “double opt-in” procedure. This means that after you have registered, we will send an email to the email address you provided, asking you to confirm that you wish to receive the newsletter. If you do not confirm your registration within 24 hours, your information will be blocked and automatically erased after one month.
The newsletter may concern all goods, services, products, offers and promotions provided by the controller (Clause 1.2) and/or by companies affiliated with the controller or by partner companies.
The legal basis is Art. 6 para. 1(a) GDPR.
In addition, we store the IP addresses you use and the registration and confirmation times. The purpose of the procedure is to prove that you are registered and, if necessary, to be able to clarify any possible misuse of your personal data. If we process your personal data for this purpose, this is done on the basis of our legitimate interests in ensuring compliance with and documentation of legal requirements.
The legal basis is Art. 6 para. 1(f) GDPR; our legitimate interest is to be able to prove consent.
You can revoke the use of your email address at any time by using the unsubscribe link in the newsletter or by sending a message to email@example.com. The legality of the data processing operations already carried out remains unaffected by the revocation.
We use external IT service providers who act as processors to distribute the newsletter.
2.1.6 Customer Account
You have the option of creating a personal customer account with us. In the password-protected area of the customer account, you can manage your bookings conveniently and have your data stored for future journeys.
To create a customer account, the following mandatory information is collected:
- email address,
- first and last names,
- password (self-selected).
We use this data to manage your customer account and to create invoices.
In addition, you can also enter a mobile phone number in your customer account so that we can contact you in the event of a delay or a change in the itinerary of your trip (optional).
You may also choose to store the following additional data in your customer account (optional):
- date of birth,
- address (zip code, city and country),
- payment methods.
These data are used to manage your customer account and to issue invoices, and can also be used to send personalized product recommendations (Clause 2.1.4) and – if you have registered for this purpose – to send newsletters (Clause 2.1.5).
The legal basis is Art. 6 para. 1(a), (b) or (f) GDPR.
If you have given your consent, “persistent” cookies are stored on your device with the “remain logged in” function; their purpose is to ensure that you do not have to log in again during subsequent visits to our website. This function is not available to you if you have deactivated the storage of such cookies in your browser settings.
The legal basis is Art. 6 para. 1(f) GDPR.
You can update or delete the customer account – and thus also your stored personal data – at any time in your personal customer account.
The use of technically necessary cookies is based on Art. 6 (1) lit. f GDPR. Our legitimate interest is to provide you with the specific functionalities of our websites, to improve them, and to ensure the security and integrity of our websites.
You can prevent cookies from being saved and to delete cookies already existing by changing your browser settings accordingly. The help function of most browsers tells you how to make these settings. However, if you do not accept cookies, the service features of the Internet offer may be impaired. Therefore, we recommend leaving the cookie function turned on.
Comprehensive information on how this can be accomplished on a number of browsers can be found on the following websites: youronlinechoices, Network Advertising Initiative and/or Digital Advertising Alliance. You can also find information there about how to delete cookies from your computer as well as general information about cookies. We use different types of cookies:
Transient cookies, which are also known as in-memory cookie or "session cookies", are cookies that are deleted after you leave our website and close the browser. E.g. these cookies usually save language settings or the content of the order.
Persistent or permanent cookies remain stored even after the browser is closed. This enables e.g. saving the login status or any search terms that were entered. We use such cookies, among other things, to measure the reach or for marketing purposes. Persistent cookies are automatically deleted after a specified period, which may vary depending on the cookie. However, you can delete these cookies at any time in the security settings of your browser.
In addition to so-called "first-party cookies", which we set as controllers for data processing, "third-party cookies" are also used, which are offered by other providers.
2.1.8 Machine Learning and Dynamic Adaptation of website/app
We use machine learning to optimise and automate our processes. This involves teaching a system decision-making logic based on use cases, i.e. the system can learn from the past and use algorithms to develop statistical models that can be applied to similar tasks in the future.
For example, we use machine learning in a secured and hashed model to quickly and easily create customised travel offers for you. For this purpose, we use framework data, in particular user ID, the corresponding travel and search history and the IP-address.
Additionally, we use data to automatically adapt our website and app to offer you the best experience possible. For example, we can use your purchase history to offer you additional services (e.g.: adding a seat reservation, purchasing additional luggage etc...) or help you in your user journey (e.g.: if you have an upcoming trip in the near future, we could point you to the real time tracking of your bus).
For this purpose, in addition to the framework data listed above, we also use the purchase history and contacts with Flix via Customer Service. The data is salted and hashed to provide an additional layer of protection
We base this processing on our legitimate interest pursuant to Art. 6 para. 1 (f) GDPR, as we have an economic interest in offering you the most suitable experience. You also benefit from this as you receive a journey offer tailored to your needs rather than a standard recommendation, or we redirect you to services that would benefit your planning, travel and post-travel experience.
If you wish to object to the processing of your data for the purposes of machine learning or dynamic adaptation of website/app, you may do so at any time in accordance with the legal provisions by objecting under this mail “firstname.lastname@example.org”. Please note that you will then only receive standard services.
2.1.9 Fraud Prevention
To prevent fraudulent bookings, we process order-related data, e.g. IP-address, name, e-mail address.
This is lawful under Art. 6 para. 1 (f) GDPR. Our legitimate interest is to prevent being victim to fraud and suffering financial losses.
In individual cases, a decision about cancellation may occur after booking based on automated decision. The logic for this is based on a set of internal algorithms that processes relevant data points and provides us with scores on matches to different fraudulent patterns or compare the data points with thresholds and values typical of fraudulent patterns in order to detect fraudulent bookings. If you wish to contest this decision, express your own point of view or obtain the intervention of a human of the part of the controller, please reach out to email@example.com.
2.2 Customer Service
When you contact our customer service, we collect the personal data that you provide to us on your own initiative. For example, you can send this to us by email, telephone or letter. Your personal data will only be used in order to contact you or for the purpose for which you have provided us with this data, e.g., for processing your inquiries, technical administration or customer administration.
This data (including information on means of communication such as email address, telephone number) is provided on a voluntary basis. We use the data to process your concern, to fulfill legal obligations if necessary, and for administrative purposes.
The legal basis is Art. 6 para. 1(b), (c) or (f) GDPR.
In the case of a telephone inquiry, your data is also processed by telephone applications and in part also via a voice dialogue system in order to support us in the distribution and processing of inquiries.
For our customer service, we use external customer service providers as processors.
2.3 Presence on Social Media Channels
We have a presence on social media (currently: Facebook, Instagram, LinkedIn, Twitter, TikTok). To the extent that we have control over the processing of your data, we ensure that the applicable data protection regulations are complied with.
In addition to us, the following are responsible for the company’s presence within the meaning of the GDPR and other data protection regulations:
Facebook (Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland)
Instagram (Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland)
Twitter (Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland)
LinkedIn (LinkedIn Ireland Unlimited Company, Gardner House Wilton Place, Dublin 2, Ireland)
TikTok (TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland)
We would like to point out that your data may be processed outside the European Union.
The legal basis for the processing of your personal data by us is Art. 6 para. 1(f) GDPR. Our legitimate interest is effective information and communication.
Further information about data protection laws in relation to our corporate presence on social media channels can be found here:
2.4 Report on Speakout@Flix (Whistleblowing portal)
When you contact us via our whistleblowing portal, “Speakout@Flix”, we collect the personal data you provide on your own initiative (e.g. name and email address). You can make a report via the web portal or telephone.
Your personal data will only be used to process your report and for potential internal investigations conducted after your report.
The legal basis is Art. 6 para. 1(a) GDPR.
Your data is provided voluntarily, and you can make all reports anonymously.
According to the Art. 6 para. 1(c) GDPR, we are legally obliged to transfer your data to public authorities if requested.
Our web portal uses an external service provider (Convercent, Inc.) as the processor.