Skip to main contentSkip to footer
All companies
Terms of ServiceAnalyzed 2026-08-30

at.bahn.de

68score
Risk level
Medium Risk

Weighted across nine legal categories. Lower is worse.

Executive summary

This document is a comprehensive GDPR-compliant privacy policy rather than a full Terms of Service agreement. While it excels in data transparency, user rights, and security commitments, it omits critical consumer protections regarding account management, payment terms, liability, and dispute resolution that would typically reside in a separate contract.

Category breakdown

7 of the nine categories are not addressed by this document, so they are left out rather than scored.

Data Privacy

Data collection, usage, and protection

88

The policy demonstrates strong GDPR compliance with granular lawful bases, explicit user rights, clear retention limits, robust security commitments, and straightforward opt-out mechanisms for marketing and tracking.

Key findings

  • Specific purpose-limited collection with clear legal bases
  • GDPR rights honored (access, delete, portability, objection)
  • Security commitments and breach/processor safeguards detailed
  • Explicit consent withdrawal and marketing opt-out paths

Evidence from the document

Sie können Auskunft darüber verlangen, welche Daten über Sie gespeichert sind. Sie können Berichtigung, Löschung und Einschränkung der Verarbeitung (Sperrung) Ihrer personenbezogenen Daten verlangen...
Dieser werblichen Verwendung Ihrer Daten können Sie jederzeit mit Wirkung für die Zukunft widersprechen.
Eine Übermittlung an Drittstaaten außerhalb der EU/des EWR oder an eine internationale Organisation findet nicht statt, es sei denn, es liegen angemessene Garantien vor.

Recommendations

  • Ensure cookie banners provide true granular opt-outs without dark patterns and clarify exact retention schedules for different data categories.

Modification of Terms

How agreements can be changed

45

The policy allows unilateral updates based on functional or legal changes but lacks advance notice periods, prospective-only application guarantees, or user rejection/refund rights.

Key findings

  • Updates permitted at company discretion
  • Recommendation to check regularly implies passive acceptance
  • No version archive or material change notification window

Evidence from the document

Wir passen den Datenschutzhinweis an veränderte Funktionalitäten oder geänderte Rechtslagen an. Daher empfehlen wir, den Datenschutzhinweis in regelmäßigen Abständen zur Kenntnis zu nehmen.
Stand: Juli 2026

Recommendations

  • Implement a 14-30 day advance notice for material changes, apply changes prospectively, and provide a dated changelog with account notification options.
Read the source documentSee the full interactive report

Ex-TerCo provides automated analysis of legal documents for informational purposes. This is not legal advice. Terms can change at any time.