of Wienecke XI. Hotel Hannover GmbH
1. General information on data protection
We are pleased that you are visiting our website and appreciate your interest in our hotel. The protection of your personal data is important to us.
This Privacy Policy provides information about the nature, scope and purposes of the processing of your personal data. It covers both processing activities carried out when you visit and use our website and those carried out in connection with our business services and operations.
Personal data is processed in accordance with the applicable data protection legislation, in particular the General Data Protection Regulation (GDPR), as well as any supplementary applicable national data protection legislation.
The controller responsible for the processing of personal data is Wienecke XI. Hotel Hannover GmbH – hereinafter also referred to as “we” or “us”.
This Privacy Policy also informs you about your rights.
Controller
The controller responsible for the processing of personal data within the meaning of Art. 4 No. 7 GDPR is:
Wienecke XI. Hotel Hannover GmbH
Hildesheimer Straße 380
30519 Hannover
Phone: +49 511 12 611-0
Email: reservierung@wienecke.de
Authorised management: Andreas Wienecke
Data Protection Officer
The controller’s Data Protection Officer is:
SHIELD GmbH
Ohlrattweg 5
25497 Prisdorf
Germany
Phone: +49 4101 80 50 600
Email: info@shield-datenschutz.de
Authorised management: Martin Vogel, Martin Dalecki
RIGHT TO OBJECT TO DATA PROCESSING IN PARTICULAR CASES AND TO DIRECT MARKETING
WHERE THE PROCESSING OF YOUR PERSONAL DATA IS BASED ON ART. 6 PARA. 1 LIT. E OR F GDPR, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING AT ANY TIME ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION. THIS ALSO APPLIES TO PROFILING BASED ON THOSE PROVISIONS (ART. 21 PARA. 1 S. 1 GDPR). THE RELEVANT LEGAL BASIS FOR THE PROCESSING CAN BE FOUND IN THE CORRESPONDING INFORMATION IN THIS PRIVACY POLICY.
WHERE YOU OBJECT, WE WILL NO LONGER PROCESS THE PERSONAL DATA AFFECTED BY YOUR OBJECTION. THIS DOES NOT APPLY WHERE WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR WHERE THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS (ART. 21 PARA. 1 S. 2 GDPR).
WHERE YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR SUCH MARKETING. THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING (ART. 21 PARA. 2 GDPR).
WHERE YOU OBJECT TO PROCESSING FOR DIRECT MARKETING PURPOSES, YOUR PERSONAL DATA WILL NO LONGER BE PROCESSED FOR SUCH PURPOSES (ART. 21 PARA. 3 GDPR).
Definitions
The terms used in this Privacy Policy generally have the meanings assigned to them in the General Data Protection Regulation (GDPR). To ensure that the information is provided in a transparent, intelligible and easily accessible manner, we explain the key terms below (Art. 12 Para. 1 S. 1 GDPR).
In this Privacy Policy, we use the following terms in particular:
Personal data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly. This may occur in particular by reference to an identifier such as a name, an identification number, location data or an online identifier. Identification may also be possible by reference to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person (Art. 4 No. 1 GDPR).
A data subject is the identified or identifiable natural person to whom the personal data relates (Art. 4 No. 1 GDPR).
Processing means any operation or set of operations performed on personal data, whether or not by automated means. This includes in particular the collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of personal data (Art. 4 No. 2 GDPR).
Restriction of processing means the marking of stored personal data with the aim of limiting its processing in the future (Art. 4 No. 3 GDPR).
Profiling means any form of automated processing of personal data in which such data is used to evaluate certain personal aspects relating to a natural person. This applies in particular to the analysis or prediction of aspects concerning that person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements (Art. 4 No. 4 GDPR).
Pseudonymisation means the processing of personal data in such a manner that the data can no longer be attributed to a specific data subject without the use of additional information. This requires the additional information to be kept separately and to be subject to technical and organisational measures which ensure that the personal data cannot be attributed to an identified or identifiable natural person (Art. 4 No. 5 GDPR).
A filing system means any structured collection of personal data which is accessible according to specific criteria. It is irrelevant whether the collection is maintained centrally, on a decentralised basis or according to functional or geographical criteria (Art. 4 No. 6 GDPR).
A controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing personal data. Where the purposes and means of processing are determined by Union law or the law of a Member State, the controller or the specific criteria for its nomination may also be provided for by Union law or the law of a Member State (Art. 4 No. 7 GDPR).
A processor is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller (Art. 4 No. 8 GDPR).
A recipient is a natural or legal person, public authority, agency or other body to which personal data is disclosed, regardless of whether or not it is a third party.
Public authorities which may receive personal data in the context of a particular inquiry in accordance with Union law or the law of a Member State are not regarded as recipients. The processing of such data by those public authorities must comply with the applicable data protection rules according to the purposes of the processing (Art. 4 No. 9 GDPR).
A third party is a natural or legal person, public authority, agency or other body other than the data subject, the controller, the processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data (Art. 4 No. 10 GDPR).
Consent means any freely given, specific, informed and unambiguous indication of the data subject’s wishes. It is given by a statement or another clear affirmative action by which the data subject signifies agreement to the processing of personal data relating to them (Art. 4 No. 11 GDPR).
A personal data breach is a breach of security which accidentally or unlawfully leads to the destruction, loss, alteration, unauthorised disclosure of or access to personal data transmitted, stored or otherwise processed (Art. 4 No. 12 GDPR).
Genetic data means personal data relating to the inherited or acquired genetic characteristics of a natural person which provides unique information about that person’s physiology or health. Such data may result in particular from the analysis of a biological sample from the person concerned (Art. 4 No. 13 GDPR).
Biometric data means personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person which allows or confirms the unique identification of that person. This includes, for example, facial images or fingerprint data (Art. 4 No. 14 GDPR).
Data concerning health means personal data relating to the physical or mental health of a natural person. This includes the provision of healthcare services where the data reveals information about the health status of the person concerned (Art. 4 No. 15 GDPR).
A supervisory authority is an independent public data protection authority established by a Member State pursuant to Art. 51 GDPR (Art. 4 No. 21 GDPR).
Legal bases for the processing of personal data
We process personal data only where there is a legal basis for doing so. Depending on the purpose and circumstances of the processing, the following legal bases may apply in particular:
- Consent: You have consented to the processing of your personal data for one or more specific purposes (Art. 6 Para. 1 lit. a GDPR).
- Contract and pre-contractual measures: The processing is necessary for the performance of a contract to which you are a party or in order to take pre-contractual measures at your request (Art. 6 Para. 1 lit. b GDPR).
- Legal obligation: The processing is necessary for compliance with a legal obligation to which we are subject (Art. 6 Para. 1 lit. c GDPR).
- Vital interests: The processing is necessary to protect your vital interests or those of another natural person (Art. 6 Para. 1 lit. d GDPR).
- Public interest: The processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in us (Art. 6 Para. 1 lit. e GDPR).
- Legitimate interests: The processing is necessary for the purposes of our legitimate interests or those of a third party, except where your interests, fundamental rights and freedoms requiring the protection of personal data override those interests (Art. 6 Para. 1 lit. f GDPR).
Special categories of personal data are generally subject to a prohibition on processing (Art. 9 Para. 1 GDPR). Such data is processed only where a legal basis under Art. 6 Para. 1 GDPR applies and at least one of the conditions set out in Art. 9 Para. 2 GDPR is also met.
The applicable legal basis and, where relevant, the applicable exception to the prohibition on processing are specified in the information relating to the respective processing activity (Art. 13 Para. 1 lit. c and Art. 14 Para. 1 lit. c GDPR).
Retention periods and erasure of personal data
We retain personal data only for as long as this is necessary for the respective purposes of processing or for as long as statutory retention obligations or other legal grounds require continued storage (Art. 5 Para. 1 lit. e and Art. 6 Para. 1 lit. c GDPR).
Where the purpose of the processing no longer applies and there is no statutory retention obligation or other legal basis for continued storage, the personal data will be erased in accordance with the applicable legal requirements (Art. 17 Para. 1 lit. a GDPR).
Where personal data must continue to be stored due to statutory retention obligations or for the establishment, exercise or defence of legal claims, it will be processed only for those purposes and erased once the relevant reason for retention no longer applies (Art. 17 Para. 3 lit. b and e GDPR).
Where possible, the specific retention period or the criteria used to determine it are stated in the information relating to the respective processing activity (Art. 13 Para. 2 lit. a and Art. 14 Para. 2 lit. a GDPR).
Cooperation with processors and other recipients
In the course of our processing activities, we may disclose personal data to processors, other controllers and other recipients, transfer personal data to them or otherwise grant them access to it. We do so only where the disclosure is necessary for the respective purpose and an appropriate legal basis applies (Art. 6 Para. 1 GDPR).
Where external service providers process personal data exclusively on our behalf and in accordance with our instructions, we engage them as processors (Art. 4 No. 8 GDPR). We engage only processors that provide sufficient guarantees that appropriate technical and organisational measures will be implemented. The processing is governed by a contract or another legal act that meets the applicable statutory requirements (Art. 28 Para. 1 and 3 GDPR).
Where we jointly determine the purposes and means of processing with another party, we are joint controllers. In such cases, we determine in an arrangement which party is responsible for fulfilling the respective data protection obligations. The essence of this arrangement is made available to the data subjects (Art. 26 Para. 1 and 2 GDPR).
The respective recipients or categories of recipients and the applicable legal basis are specified in the information relating to the relevant processing activity (Art. 13 Para. 1 lit. c and e and Art. 14 Para. 1 lit. c and e GDPR).
Where personal data is transferred to recipients outside the European Union or the European Economic Area, we also comply with the statutory requirements governing transfers to third countries (Art. 44 et seq. GDPR).
General information on transfers to third countries
Where we transfer personal data to recipients in countries outside the European Economic Area (EEA) or to international organisations, or enable such recipients to access personal data, we comply with the specific statutory requirements governing transfers to third countries.
Such a transfer takes place only where the general requirements for processing personal data are met and an additional transfer mechanism under Art. 44 et seq. GDPR applies (Art. 6 Para. 1 and Art. 44 GDPR).
Adequacy decision
A transfer may take place where the European Commission has determined that the third country concerned, a territory or one or more specified sectors within that third country, or the international organisation concerned, ensures an adequate level of data protection. In such cases, no additional authorisation or safeguards under Art. 46 GDPR are required (Art. 45 GDPR).
Appropriate safeguards
Where no adequacy decision exists, a transfer may take place if appropriate safeguards are provided to protect the personal data and enforceable rights and effective legal remedies are available to data subjects (Art. 46 Para. 1 GDPR).
Appropriate safeguards may include in particular:
- Standard contractual clauses adopted by the European Commission (Art. 46 Para. 2 lit. c GDPR)
- Binding corporate rules (Art. 46 Para. 2 lit. b and Art. 47 GDPR)
- Approved codes of conduct or certification mechanisms together with binding and enforceable commitments by the recipient of the data (Art. 46 Para. 2 lit. e and f GDPR)
- Other contractual or administrative arrangements, where the applicable statutory requirements are met and any required authorisations have been obtained (Art. 46 Para. 2 and 3 GDPR)
Where necessary, we assess whether the transfer mechanism used ensures an adequate level of protection, taking into account the laws and practices of the recipient country. Where required, we implement additional contractual, technical or organisational safeguards.
Derogations for specific situations
Where neither an adequacy decision nor appropriate safeguards are available, a transfer may take place only in specific exceptional circumstances. This may apply, for example, where you have expressly consented to the transfer after having been informed of the possible risks, where the transfer is necessary for the performance of a contract or where it is required for the establishment, exercise or defence of legal claims (Art. 49 Para. 1 GDPR).
Derogations under Art. 49 GDPR are relied upon only where the applicable statutory requirements are met.
Further information on specific transfers
Whether personal data is transferred to a third country or an international organisation in connection with a specific processing activity, and the legal basis for that transfer, will be stated in the information relating to the relevant processing activity. Where required, we will provide information in particular about:
- The recipient or category of recipients
- The third country or international organisation concerned
- The existence of an adequacy decision
- The appropriate safeguards used
- The means of obtaining or accessing a copy of those safeguards
This information is provided in accordance with the applicable statutory information requirements (Art. 13 Para. 1 lit. f and Art. 14 Para. 1 lit. f GDPR).
Where a transfer is based on appropriate safeguards, you may use the contact details provided in the section entitled “Controller” to request further information and a copy of the relevant safeguards. Content may be appropriately redacted where necessary to protect trade secrets, confidential information and the rights and freedoms of other persons (Art. 15 Para. 2 GDPR).
Security of processing
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the respective risk. These measures are intended in particular to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access (Art. 5 Para. 1 lit. f, Art. 25 Para. 1 and Art. 32 Para. 1 and 2 GDPR).
The measures implemented are reviewed regularly and adapted where necessary to reflect technological developments or changes in risk (Art. 32 Para. 1 lit. d GDPR).
Despite these measures, internet-based data transmissions may generally be subject to security risks, meaning that complete protection cannot be guaranteed. Where we offer suitable alternative means of communication, you may also provide us with personal data by those means, for example by telephone or post.
2. Your rights
As a data subject, you have the rights set out below, subject to the applicable statutory requirements. We will facilitate the exercise of your rights. You may contact us using the contact details provided in the section entitled “Controller” (Art. 12 Para. 2 GDPR).
Right of access
You have the right to obtain confirmation from us as to whether or not we process personal data concerning you. Where this is the case, you have the right to access that personal data and to receive the information prescribed by law.
This information includes, in particular, the purposes of the processing, the categories of personal data concerned, the recipients or categories of recipients, the envisaged retention period or the criteria used to determine that period, the source of the data where it was not collected directly from you, and information about any automated decision-making, including profiling. Where personal data is transferred to a third country or an international organisation, you may also request information about the appropriate safeguards relating to the transfer (Art. 15 Para. 1 and 2 GDPR).
You also have the right to receive a copy of the personal data undergoing processing. The term “data copy” means a faithful and intelligible reproduction of the personal data processed (Art. 15 Para. 3 S. 1 GDPR).
The right generally relates to the personal data itself and does not automatically include the provision of complete records or documents. Extracts from documents, complete documents or extracts from databases must, however, be provided where this is essential to enable you to understand the personal data processed and to exercise your rights under the GDPR effectively (Art. 15 Para. 3 S. 1 GDPR).
The first copy is generally provided free of charge. For any further copies requested by you, we may charge a reasonable fee based on administrative costs (Art. 15 Para. 3 S. 2 GDPR). The right to receive a copy must not adversely affect the rights and freedoms of others (Art. 15 Para. 4 GDPR).
Right to rectification
You have the right to obtain from us without undue delay the rectification of inaccurate personal data concerning you. Taking into account the purposes of the processing, you also have the right to have incomplete personal data completed. This may include providing a supplementary statement (Art. 16 GDPR).
Right to erasure
You have the right to obtain from us the erasure of your personal data without undue delay where one of the following grounds applies:
- The personal data is no longer necessary for the purposes for which it was collected or otherwise processed.
- You withdraw your consent and there is no other legal basis for the processing.
- You object to the processing and there are no overriding legitimate grounds for the processing.
- You object to the processing of your personal data for direct marketing purposes.
- The personal data has been unlawfully processed.
- The personal data must be erased to comply with a legal obligation under Union law or the law of a Member State.
- The personal data was collected in relation to the offer of information society services under the conditions set out in Art. 8 Para. 1 GDPR (Art. 17 Para. 1 GDPR).
The right to erasure does not apply to the extent that processing is necessary:
- For exercising the right of freedom of expression and information
- For compliance with a legal obligation requiring processing
- For the performance of a task carried out in the public interest or in the exercise of official authority
- For reasons of public interest in the area of public health
- For archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, where erasure is likely to render impossible or seriously impair the achievement of those purposes
- For the establishment, exercise or defence of legal claims (Art. 17 Para. 3 GDPR)
Right to restriction of processing
You have the right to obtain restriction of processing from us where one of the following conditions applies:
- You contest the accuracy of the personal data. In this case, processing is restricted for the period required for us to verify the accuracy of the data.
- The processing is unlawful and you oppose the erasure of the personal data and request the restriction of its use instead.
- We no longer require the personal data for the purposes of the processing, but you require it for the establishment, exercise or defence of legal claims.
- You have objected to the processing. The restriction applies while it is being determined whether our legitimate grounds override your grounds (Art. 18 Para. 1 GDPR).
Where processing has been restricted, the personal data concerned may, with the exception of storage, be processed only with your consent, for the establishment, exercise or defence of legal claims, for the protection of the rights of another natural or legal person, or for reasons of important public interest. We will inform you before the restriction of processing is lifted (Art. 18 Para. 2 and 3 GDPR).
Right to notification of recipients
Where we have rectified or erased personal data or restricted its processing, we will generally communicate this to each recipient to whom the personal data has been disclosed. This does not apply where such communication proves impossible or involves disproportionate effort. At your request, we will inform you about those recipients (Art. 19 GDPR).
Right to data portability
You have the right to receive personal data which you have provided to us in a structured, commonly used and machine-readable format. You also have the right to transmit that data to another controller without hindrance from us.
This right applies where the processing is based on your consent or on a contract and is carried out by automated means (Art. 20 Para. 1 GDPR).
Where technically feasible, you may request that we transmit the personal data directly to another controller (Art. 20 Para. 2 GDPR).
The right to data portability does not apply to processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority. The exercise of this right must not adversely affect the rights and freedoms of others (Art. 20 Para. 3 and 4 GDPR).
Right to object
You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data where the processing is based on the performance of a task carried out in the public interest, the exercise of official authority or legitimate interests. This also applies to profiling based on those provisions (Art. 6 Para. 1 lit. e or f GDPR and Art. 21 Para. 1 S. 1 GDPR).
Following an objection, we will no longer process the personal data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or unless the processing is required for the establishment, exercise or defence of legal claims (Art. 21 Para. 1 S. 2 GDPR).
Where your personal data is processed for direct marketing purposes, you may object to that processing at any time. This also applies to profiling to the extent that it is related to such direct marketing. Following your objection, your personal data will no longer be processed for direct marketing purposes (Art. 21 Para. 2 and 3 GDPR).
Right to withdraw consent
You have the right to withdraw consent at any time with effect for the future. The withdrawal of consent does not affect the lawfulness of processing carried out on the basis of your consent before its withdrawal. It must be as easy to withdraw consent as it was to give it (Art. 7 Para. 3 GDPR).
Rights relating to automated individual decision-making
We do not make decisions that are based solely on automated processing of personal data, including profiling, and that produce legal effects concerning you or similarly significantly affect you.
You generally have the right not to be subject to such a decision based solely on automated processing, including profiling (Art. 22 Para. 1 GDPR).
This right does not apply where the decision:
- Is necessary for entering into or performing a contract between you and us
- Is authorised by Union law or the law of a Member State which also lays down suitable measures to safeguard your rights, freedoms and legitimate interests
- Is based on your explicit consent (Art. 22 Para. 2 GDPR)
In the cases referred to in Art. 22 Para. 2 lit. a and c GDPR, we will implement suitable measures to safeguard your rights, freedoms and legitimate interests. These include, at a minimum, the right to obtain human intervention, to express your point of view and to contest the decision (Art. 22 Para. 3 GDPR).
Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority where you consider that the processing of your personal data infringes the GDPR. You may, in particular, contact a supervisory authority in the Member State of your habitual residence, your place of work or the place of the alleged infringement (Art. 77 Para. 1 GDPR).
An overview of the data protection supervisory authorities is available here:
https://www.bfdi.bund.de/DE/Service/Anschriften/anschriften_table.html (in German)
The data protection supervisory authority responsible for us is:
The State Data Protection Commissioner of Lower Saxony
P.O. Box 221
30002 Hannover
or:
Prinzenstraße 5
30159 Hannover
Phone: +49 511 120-4500
Email: poststelle@lfd.niedersachsen.de
3. Data processing when visiting our website
Website encryption
For security reasons and to protect the transmission of confidential content, our website uses TLS encryption. This applies in particular to enquiries and other information that you submit to us via our website (Art. 5 Para. 1 lit. f and Art. 32 Para. 1 lit. a GDPR).
You can generally recognise an encrypted connection by the fact that the internet address displayed in your browser’s address bar begins with “https://”. Depending on the browser used, the encrypted connection may also be indicated by a padlock, security or connection icon.
When TLS encryption is enabled, the data transmitted between your browser and our server is encrypted. This helps protect the data against unauthorised interception or alteration during transmission. However, complete protection against all security risks cannot be guaranteed.
Collection of access data and server log files
Whenever you access our website, your browser or the terminal equipment you use automatically transmits certain data to our website server. This data may be temporarily stored in server log files.
Depending on the technical configuration, the following data in particular may be collected:
- IP address of the terminal equipment accessing the website
- Date and time of access
- Page or file accessed
- Volume of data transferred
- Notification indicating whether the retrieval was successful or unsuccessful
- Website from which access was made, known as the referrer URL
- Browser used, including its type and version
- Operating system used
- Other comparable technical data used to provide the website and ensure its security and stability
This data is processed in particular for the following purposes:
- Providing and displaying our website correctly from a technical perspective
- Ensuring the stability and security of our information technology systems
- Identifying, isolating and resolving technical faults
- Identifying and preventing attacks and other forms of unauthorised or improper access
- Investigating security-related incidents
- Establishing, exercising or defending legal claims
- Providing necessary information to the competent authorities, where the applicable statutory requirements are met
Where accessing our website involves access to information already stored in your terminal equipment, such access takes place only to the extent strictly necessary to provide the website that you have expressly requested (Section 25 Para. 2 No. 2 TDDDG).
The subsequent processing of personal access data is carried out for the purposes of our legitimate interests in operating a secure, stable and technically reliable website and protecting our information technology systems (Art. 6 Para. 1 lit. f GDPR).
The server log files are not used to evaluate individual website visitors or to create user profiles. They are not combined with data from other sources unless such processing is described separately in this Privacy Policy.
Recipients of the data may include hosting, IT and IT security service providers engaged by us. Where these service providers process personal data exclusively on our behalf, they are engaged under a data processing agreement that complies with the applicable statutory requirements (Art. 28 GDPR).
Server log files are retained only for as long as necessary for the stated purposes of processing. The relevant considerations include, in particular, the requirements of technical website provision, system security and the investigation of potential security-related incidents.
Where the purpose of processing no longer applies and there is no statutory retention obligation or other legal basis for continued storage, the data will be erased. Where there are specific indications of a security-related incident, the relevant data may be retained until the incident has been fully investigated, evidence has been preserved or any legal claims have been established, exercised or defended (Art. 5 Para. 1 lit. e and Art. 17 Para. 1 lit. a and Para. 3 lit. e GDPR).
Cookies
Our website uses cookies. Cookies are small text files or comparable data records that can be stored on or read from your terminal equipment when you visit a website. Terminal equipment includes, for example, computers, notebooks, tablets and smartphones.
Cookies may contain a unique identifier known as a cookie ID. Such an identifier allows a particular browser to be recognised for the duration of the cookie’s validity. This may be necessary, for example, to maintain a session, store selected settings or provide certain website functions.
Depending on their specific configuration, cookies may serve the following purposes in particular:
- Providing our website securely and from a technical perspective
- Storing your settings and preferences
- Recording the status of your consent choices
- Providing convenience and additional functions
- Analysing the use of our website
- Measuring the reach and effectiveness of our services
- Displaying and measuring the success of personalised advertising
Not all of these purposes are necessarily pursued on our website. Details of the cookies and comparable technologies actually used can be found in the consent management tool and in the information about the respective services provided in this Privacy Policy.
First-party cookies and third-party cookies
First-party cookies are set through the domain that you access directly. They may be read again when you subsequently visit the same domain.
Third-party cookies originate from a domain other than the one you are visiting directly. They may be set, for example, through embedded content or services provided by other providers. Such cookies may allow the respective provider to recognise a browser when other websites incorporating the same service are visited.
The distinction between first-party and third-party cookies does not in itself indicate how long a cookie is stored, the purpose for which it is used or whether consent is required for its use.
Session cookies and persistent cookies
Session cookies are stored for the duration of a browser session and are generally deleted automatically when the session ends. They may be used, for example, to assign multiple page views to the same session.
Persistent cookies remain stored on your terminal equipment after the end of a browser session. They are removed when their specified validity period expires or when they are deleted manually. The respective retention period may vary depending on the cookie.
Legal bases
The storage of information on your terminal equipment or access to information already stored there is governed by Section 25 TDDDG.
Where a cookie or comparable technology is strictly necessary to provide a digital service expressly requested by you, no consent is required (Section 25 Para. 2 No. 2 TDDDG).
We generally use all other cookies and comparable technologies only with your consent (Section 25 Para. 1 TDDDG).
Where personal data is processed in connection with cookies, the subsequent processing is also governed by the GDPR. Processing requiring consent is carried out on the basis of your consent (Art. 6 Para. 1 lit. a and Art. 7 GDPR). Depending on its purpose, processing in connection with strictly necessary cookies may be required for the performance of a contract or to take pre-contractual measures, for compliance with a legal obligation or for the purposes of legitimate interests (Art. 6 Para. 1 lit. b, c or f GDPR).
The cookies and technologies used, their providers, purposes, legal bases and retention periods are described in more detail in the consent management tool or in the information relating to the respective service.
Managing your consent
Where consent is required, you can use the consent management tool provided on our website to decide which cookies and comparable technologies you wish to accept. You may withdraw or change your consent there at any time with effect for the future (Art. 7 Para. 3 GDPR).
Browser settings
You can configure your browser to notify you when cookies are set, permit cookies only in individual cases, reject certain cookies or delete cookies automatically when the browser is closed. You can also remove cookies that have already been stored through your browser settings.
Disabling or deleting cookies may result in certain functions of our website being unavailable or available only to a limited extent. Managing cookies through your browser does not replace giving or withdrawing consent through the consent management tool provided on our website.
Data transmission via forms
We provide forms on our website through which you can submit personal data to us. The personal data processed in this context is determined by the respective input form and any supplementary information provided for that form.
We process the data you submit in order to handle your request, communicate with you and provide the content or services offered through the relevant form. The specific purpose of the processing is determined by the respective form.
Information marked as mandatory is required so that we can handle your request or provide the requested service. Without this information, we may be unable to process the form. The provision of any additional information is voluntary (Art. 13 Para. 2 lit. e GDPR).
Where the transmission of data relates to a contract to which you are a party or to pre-contractual measures taken at your request, the processing is based on Art. 6 Para. 1 lit. b GDPR.
In other cases, the processing is carried out for the purposes of our legitimate interests in handling submitted requests appropriately and efficiently and in maintaining our business contacts (Art. 6 Para. 1 lit. f GDPR).
Where the processing is necessary for compliance with a legal obligation, it is based on Art. 6 Para. 1 lit. c GDPR. Where we obtain your consent for a specific processing activity, the processing is based on Art. 6 Para. 1 lit. a and Art. 7 GDPR.
When a form is submitted, additional technical access data may be processed. This may include, in particular, the IP address of the terminal equipment used and the date and time of submission. This data is processed where necessary for the technical transmission of the form, the security of our information technology systems or the detection and prevention of misuse (Art. 6 Para. 1 lit. f GDPR). Further information is available in the section entitled “Collection of access data and server log files”.
Form data is generally transmitted in encrypted form. Further information is available in the section entitled “Website encryption”.
Within our organisation, access to your personal data is restricted to those persons and departments that require it to handle your request.
Recipients may also include hosting, IT, communications and other service providers engaged by us. Where these service providers process personal data exclusively on our behalf, they are engaged under a data processing agreement that complies with the applicable statutory requirements (Art. 28 GDPR).
Personal data is disclosed to other recipients only where an appropriate legal basis applies and the disclosure is necessary for the respective purpose. The relevant recipients or categories of recipients will be specified, where required, in connection with the respective form or elsewhere in this Privacy Policy (Art. 13 Para. 1 lit. e GDPR).
We retain personal data submitted through forms only for as long as necessary to handle your request and fulfil the respective purposes of processing. Where the purpose of processing no longer applies and there is no statutory retention obligation or other legal basis for continued storage, the data will be erased (Art. 5 Para. 1 lit. e and Art. 17 Para. 1 lit. a GDPR).
Where the data is required for a contractual relationship, compliance with statutory retention obligations or the establishment, exercise or defence of legal claims, it may be retained for a correspondingly longer period. It will be erased once the respective reason for retention no longer applies (Art. 6 Para. 1 lit. b and c and Art. 17 Para. 3 lit. b and e GDPR).
Contact by email or telephone
Where you contact us by email or telephone, we process the personal data you provide in order to handle your enquiry and communicate with you. This may include, in particular, your contact details and identification data, the content of your enquiry, any documents submitted, and the date and time of contact.
Where your enquiry relates to a contract to which you are a party or to pre-contractual measures taken at your request, the processing is based on Art. 6 Para. 1 lit. b GDPR.
In other cases, the processing is carried out for the purposes of our legitimate interests in handling enquiries addressed to us appropriately and efficiently and in maintaining our business contacts (Art. 6 Para. 1 lit. f GDPR).
Where the processing is necessary for compliance with a legal obligation, it is based on Art. 6 Para. 1 lit. c GDPR. Where we obtain your consent for a specific processing activity, the processing is based on Art. 6 Para. 1 lit. a GDPR.
Within our organisation, access to your personal data is restricted to those persons and departments that require it to handle your enquiry. Recipients may also include IT, telecommunications and communications service providers engaged by us. Personal data is disclosed to other recipients only where an appropriate legal basis applies and the disclosure is necessary for the respective purpose (Art. 6 Para. 1 GDPR).
We retain the personal data processed in connection with your contact only for as long as necessary to handle your enquiry and for any subsequent communication. Where the purpose of processing no longer applies and there is no statutory retention obligation or other legal basis for continued storage, the data will be erased (Art. 5 Para. 1 lit. e and Art. 17 Para. 1 lit. a GDPR).
Where the data is required for a contractual relationship, compliance with statutory retention obligations or the establishment, exercise or defence of legal claims, it may be retained for a correspondingly longer period. It will be erased once the respective reason for retention no longer applies (Art. 6 Para. 1 lit. b and c and Art. 17 Para. 3 lit. b and e GDPR).
Links to external websites
Our website may contain links to websites operated by other providers. When you follow an external link, you leave our website and are redirected to the website of the relevant provider.
We have no control over the content, availability or data protection practices of external websites. The respective operator is generally responsible for the processing of personal data that takes place when you access and use an external website (Art. 4 No. 7 GDPR).
Please refer to the privacy information provided on the external website for details of the nature, scope and purposes of the processing of personal data carried out there, as well as your rights (Art. 12 to 14 GDPR).
This information applies only to external links. Where content or services provided by third parties are embedded directly into our website, we provide separate information about this in this Privacy Policy.
CookieScript
We use 'CookieScript' on our website. The provider is Objectis, UAB, Laisvės st. 60, LT-05120 Vilnius, Lithuania (hereinafter referred to as 'CookieScript').
CookieScript is a consent management technology which enables us to inform you about the use of cookies and comparable technologies on our website, obtain, manage and document consent, and control the use of services requiring consent in accordance with your selection. When you access our website, CookieScript may display an overview of the cookies and comparable technologies used, structured by categories. You can specify there which categories or services you wish to allow.
When you make a selection or change your consent, an anonymous randomly generated key, your consent decision, your IP address in anonymised form, the date and time of your consent decision, the page on which consent was given or withdrawn, and browser information may be processed in particular. These data are processed in order to store your consent decision, recognise your selection during later visits to the website, demonstrate consent and withdrawals, and control the use of cookies and comparable technologies in accordance with your selection.
To store your consent decision, CookieScript may store a technically necessary first-party cookie named 'CookieScriptConsent' in your browser. This cookie stores, in particular, the anonymous key and the respective consent status in encrypted form.
The processing of consent data is carried out for the fulfilment of our legal obligation to obtain and be able to demonstrate consent for the use of certain cookies and comparable technologies, on the basis of Art. 6 Para. 1 lit. c GDPR. Where the processing additionally serves the legally compliant, user-friendly and technically reliable management of your consent decision, it is carried out on the basis of our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR. The storage and access of the technically necessary CookieScript cookie are carried out on the basis of Section 25 Para. 2 No. 2 TDDDG, as this cookie is necessary to store the consent decision you have made and to provide the website in accordance with your selection.
The consent data processed by CookieScript are stored for as long as this is necessary for documenting your consent decision and demonstrating consent. You can withdraw or change your consent at any time with effect for the future by reopening the cookie settings on our website. Statutory retention and documentation obligations remain unaffected.
Objectis, UAB has its registered office in Lithuania and therefore within the European Union. Where CookieScript transfers personal data to third countries or has them processed by sub-processors in third countries, this is carried out in accordance with the data protection requirements of Art. 44 et seq. GDPR, in particular on the basis of appropriate safeguards such as standard contractual clauses within the meaning of Art. 46 GDPR.
CookieScript processes personal data of visitors to our website as a processor within the meaning of Art. 4 No. 8 GDPR, insofar as this processing is carried out on our behalf for the provision and operation of the consent management technology. We have concluded a data processing agreement with CookieScript within the meaning of Art. 28 Para. 3 GDPR. In this agreement, CookieScript undertakes in particular to process personal data only in accordance with our instructions and for the provision of the agreed services, to implement appropriate technical and organisational protective measures, and to use sub-processors only in accordance with the contractual provisions.
Further information on data processing by CookieScript can be found at https://cookie-script.com/legal/privacy-policy. Further information on CookieScript’s Data Processing Agreement can be found at https://cookie-script.com/legal/data-processing-agreement
Google Tag Manager
We use 'Google Tag Manager' on our website. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter referred to as 'Google').
Google Tag Manager is a tag management system which enables us to centrally integrate and manage services, scripts, analytics, marketing and other website functions. Google Tag Manager is used in particular to control and trigger so-called tags. The services integrated via Google Tag Manager may themselves process personal data, set cookies or use comparable technologies. Which data are processed in this context depends on the respective integrated services and their configuration. We provide separate information on these services in this Privacy Policy.
When Google Tag Manager is used, technical data may be processed, including in particular the IP address, date and time of access, browser and device information, referrer URL, page accessed and further technical information that may be required for the provision and execution of the tag management system. According to Google, Google may process this information in connection with its services.
Personal data may also be stored and processed in the USA, a third country for which there is no adequacy decision by the European Commission. However, Google bases the transfer of data to the USA on the EU-U.S. Data Privacy Framework of the European Commission. Where Google transfers personal data to further third countries or has them processed there, Google states that it additionally bases such transfers on appropriate safeguards, in particular standard contractual clauses within the meaning of Art. 46 GDPR.
The use of Google Tag Manager is generally based on our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR in being able to manage services, scripts and website functions technically efficiently, securely and centrally. Where services requiring consent are loaded or controlled via Google Tag Manager, or where information is stored on or accessed from the end device when Google Tag Manager is used, the use is carried out only on the basis of your consent pursuant to Art. 6 Para. 1 lit. a GDPR and Section 25 Para. 1 TDDDG. Consent is voluntary and can be withdrawn at any time with effect for the future.
The technical data processed in connection with the use of Google Tag Manager are stored for as long as this is necessary for the provision, control and technical management of the integrated services. Further retention periods may arise from the respective services integrated via Google Tag Manager, about which we provide separate information in this Privacy Policy.
Further information on data processing by Google can be found at https://policies.google.com/privacy?hl=en
Links to open the interactive map on Google Maps
We provide links on our website to access an interactive map on 'Google Maps'. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter referred to as 'Google').
The Google Maps links provided on our website are external links. As long as you do not click on these links, no connection to Google servers is established via these links and no data are transmitted to Google merely by providing the links on our website.
If you click on a Google Maps link, you leave our website and are redirected to a Google page or Google service. From that point onwards, Google processes personal data under its own responsibility. In this context, your IP address, date and time of access, the Google Maps page accessed, location data insofar as you allow these or they are technically processed, browser and device information, operating system, referrer URL, usage and interaction data as well as further technical access data may be processed in particular. Google may also use cookies or comparable technologies in this context.
The link to Google Maps serves to provide you with our locations, directions and information about the surrounding area in a user-friendly manner and to enable you to use the interactive map functions of Google Maps voluntarily.
The processing in connection with the provision of the external link on our website is carried out on the basis of our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR in providing you with an easy way to find our locations and user-friendly directions. Further data processing after clicking on the link is carried out by Google under its own responsibility. We have no influence over this data processing.
Personal data may also be stored and processed by Google in the USA, a third country for which there is no adequacy decision by the European Commission.
However, Google bases the transfer of data to the USA on the EU-U.S. Data Privacy Framework of the European Commission. Where Google transfers personal data to further third countries or has them processed there, Google states that it additionally bases such transfers on appropriate safeguards, in particular standard contractual clauses within the meaning of Art. 46 GDPR.
Further information on data processing by Google can be found at https://policies.google.com/privacy?hl=en. Further information on the Google Maps Terms of Service can be found at https://www.google.com/intl/en-en/help/terms_maps/
DialogShift Chat AI and Phone AI
We use 'DialogShift' for AI-supported communication with guests and prospective guests. The provider is DialogShift GmbH, Torstraße 201, 10115 Berlin, Germany (hereinafter referred to as 'DialogShift').
DialogShift provides a platform for AI-supported guest communication in the hospitality sector. In particular, we use Chat AI for communication via our website and Phone AI as an AI-supported telephone assistant. Depending on the configuration, DialogShift can be used to answer general questions, process booking and offer enquiries, provide information about our hotel and services, record callback requests, support or carry out booking processes, and forward enquiries to our employees or the relevant departments.
If you use the chat function, the messages entered by you and the information contained therein are processed in particular. Depending on the content of your enquiry, this may include your name, email address, telephone number, stay and booking data, information about requested services, arrival and departure dates, number of guests, special requests and other information provided by you in the course of the communication. Technical data such as your IP address, the date and time of access and session and connection information required to provide the chat function may also be processed.
If you communicate with our Phone AI by telephone, your speech is technically processed so that the AI telephone assistant can recognise, process and respond to your enquiry. In this context, your telephone number, the date and time of the call, the content of the conversation and telephone transcripts generated from it may be processed in particular. Depending on the subject of the conversation, your name, contact details, booking and stay data, information about requested rooms or services, travel period, number of guests, callback requests and other information provided by you during the conversation may also be processed. DialogShift's current privacy information does not indicate that permanent storage of complete audio recordings of telephone calls forms part of its standard processing.
Phone AI uses artificial intelligence methods to process and respond to your enquiry automatically. For this purpose, the content of the conversation is processed in text form and evaluated using AI models in order to generate an appropriate response or carry out the action requested by you. Speech synthesis technologies are used to generate the spoken response. Depending on the configuration, Phone AI may also retrieve availability and booking information, process booking enquiries, record callback requests, send booking links by SMS or WhatsApp, or forward calls to the relevant department. Where a call is forwarded, our employees may be provided with a summary of the conversation up to that point.
Where activated in our specific configuration, the content of conversations may also be analysed automatically in order to assess quality and satisfaction in connection with the respective conversation. According to DialogShift, no permanent guest or user profiles are created for this purpose and information is not combined across different communication processes to create a profile.
The processing serves to process and respond to your enquiries, provide an accessible communication channel, support bookings and reservations, process offer and callback enquiries, forward enquiries to the relevant employees, improve our availability and service quality, and reduce the workload of our employees in connection with frequently recurring guest enquiries.
Where your communication relates to the initiation or performance of a contract, in particular in the case of booking, reservation, offer or service enquiries, the processing is carried out on the basis of Art. 6 Para. 1 lit. b GDPR. In the case of general information and service enquiries, the processing is carried out on the basis of our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR in providing guests and prospective guests with fast, reliable and efficient communication, ensuring our availability and efficiently processing frequently recurring enquiries.
Where the DialogShift chat function on our website is loaded or activated only after you have given your consent, the processing required for this purpose is carried out on the basis of your consent pursuant to Art. 6 Para. 1 lit. a GDPR. Where information is stored on or accessed from your end device when the chat function is loaded or activated, this is carried out on the basis of Section 25 Para. 1 TDDDG. Consent is voluntary and can be withdrawn or changed at any time with effect for the future via the settings of our consent banner.
Where, after you have activated the chat function, technically necessary information is stored on or accessed from your end device, for example in order to maintain an ongoing chat session, assign the conversation history during use or provide the chat function expressly requested by you, this is carried out on the basis of Section 25 Para. 2 No. 2 TDDDG.
The aforementioned provisions of the TDDDG concerning access to information on your end device do not apply to the telephone use of Phone AI merely because you call the telephone assistant.
DialogShift uses various technical service providers and AI models to process guest enquiries. According to DialogShift, these include AI services provided by OpenAI, Google and other providers, services provided by ElevenLabs for speech synthesis and sipgate for technical telephony services. DialogShift states that the relevant guest data are processed exclusively on servers within the European Union. According to DialogShift, guest data are not used by the AI providers involved to train their AI models.
Personal data arising from guest communication, including chat histories and telephone transcripts, are automatically and irreversibly deleted after 90 days according to DialogShift. Irrespective of this, data transferred to our own systems or connected hotel, booking or management systems in connection with a booking, reservation, enquiry or other service may continue to be processed and stored there in accordance with the retention periods applicable to the respective processing activity.
DialogShift processes personal data of guests and prospective guests in connection with Chat AI and Phone AI as a processor within the meaning of Art. 4 No. 8 GDPR, insofar as the processing is carried out on our behalf for the provision of the communication services. We have concluded a data processing agreement with DialogShift within the meaning of Art. 28 Para. 3 GDPR. Under this agreement, DialogShift undertakes in particular to process personal data only in accordance with our documented instructions and for the provision of the agreed services, to implement appropriate technical and organisational protective measures, and to engage further processors in accordance with the contractual provisions.
Further information on data processing by DialogShift can be found at https://www.dialogshift.com/en/data-privacy. Further information on DialogShift Phone AI can be found at https://www.dialogshift.com/en/phone-ai
Sitebrunch
We use 'Sitebrunch' on our website. The provider is sitebrunch GmbH, Eifflerstraße 43, c/o betahaus, 22769 Hamburg, Germany (hereinafter referred to as 'Sitebrunch').
Sitebrunch is a tool for data-minimised usage analysis in connection with the testing and improvement of the digital accessibility of our website. With Sitebrunch, we can understand how visitors use certain page areas, functions, buttons or links on our website. This serves in particular to identify possible usability obstacles, usage problems and barriers, to improve user guidance and to make our website more accessible and easier to use.
When Sitebrunch is used, technical access data such as the IP address, date and time of access, page or subpage accessed, referrer URL, browser and device information, operating system as well as usage and interaction data may be processed in particular. This may include, in particular, clicks on certain buttons or links, subpages accessed, time spent on pages, navigation paths and technical events in connection with the use of our website.
According to the information available to us, an identification number is created when the website is accessed, which may be linked for a limited period to the IP address used during the visit. The IP address itself is not stored for longer than is technically necessary. The identification number enables individual usage processes to be traced in pseudonymised form for a limited period in order to identify typical usage obstacles and barriers. Your visitor behaviour is not tracked beyond our website, used for interest-based advertising or disclosed for advertising purposes.
Sitebrunch is used exclusively to evaluate the use of our website with regard to digital accessibility and usability. The processing is carried out on the basis of our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR in making our website more accessible, more user-friendly and technically easier to use, identifying usage obstacles and continuously improving the accessibility of our online offering.
Where Sitebrunch is used without cookies or comparable technologies, no information is stored on the end device and no information is accessed from the end device within the meaning of the TDDDG. Where cookies are set, information is stored on or accessed from the end device or comparable technologies are used when Sitebrunch is used, this is carried out only on the basis of consent pursuant to Art. 6 Para. 1 lit. a GDPR and Section 25 Para. 1 TDDDG, unless the access is technically necessary. Consent is voluntary and can be withdrawn at any time with effect for the future.
The data processed in connection with Sitebrunch are stored for as long as this is necessary for data-minimised usage analysis, testing and improving digital accessibility, identifying usability obstacles and technically optimising our website. The data are then deleted or anonymised unless statutory retention obligations exist or further storage is required for the establishment, exercise or defence of legal claims.
Further information on data processing by Sitebrunch can be found at https://www.sitebrunch.com/en/privacy-policy
3DVista
We provide a link on our website to an externally hosted virtual tour made available using the '3DVista' service. The provider is 3DVISTA ESPAÑA S.L., Avenida Fernando de los Ríos 50, 18006 Granada, Spain (hereinafter referred to as '3DVista').
3DVista is a platform for creating and providing virtual 360-degree and 3D tours. Via the link provided by us, you can access an externally hosted virtual tour and view, for example, rooms, guest rooms, event areas or other areas of our hotel.
The virtual tour is not embedded directly into our website. Therefore, merely accessing our website does not establish a connection to 3DVista's servers and no personal data are transmitted to 3DVista via our website. Only when you click the relevant link do you leave our website and your browser accesses the externally provided virtual tour.
When the external tour is accessed, your end device may establish a direct connection to the servers used to provide the virtual tour. In this context, your IP address, the date and time of access, the tour accessed or file requested, referrer information, browser and device information, operating system, technical connection data and information relating to your use of and interaction with the virtual tour may be processed in particular.
As part of its cloud and hosting services, 3DVista also offers functions for statistically analysing the use of virtual tours. Depending on the specific configuration, this may include analysing the number and duration of visits, content and areas accessed and interactions within the tour. 3DVista also states that cookies may be used in connection with its services. The specific technologies used when you access the external tour depend on the configuration of the respective external service.
The external link is provided on the basis of our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR in providing guests and prospective guests with an illustrative and user-friendly presentation of our premises and services.
As this is an external link and the service is not embedded into our website, merely displaying the link on our website does not allow 3DVista to access information on your end device. Only when you click the link and access the external tour may cookies or comparable technologies be used there or information be stored on or accessed from your end device.
Further information on data processing by 3DVista can be found at https://www.3dvista.com/en/privacy_policy/
ShortPixel
We use 'ShortPixel' on our website. The provider is ID SCOUT SRL, Str. Transilvaniei nr. 2, Camera 5, Bl. 5, Ap. 19, Sector 1, 010798 Bucharest, Romania (hereinafter referred to as 'ShortPixel').
ShortPixel is a service for image optimisation and the technical delivery of optimised media content. Depending on the configuration used, ShortPixel can compress images and other static content on our website, convert them into modern file formats, provide them in a size suitable for the screen size of the respective end device and deliver them via a content delivery network. In this context, content may be loaded in particular via technical ShortPixel domains such as 'shortpixel.ai'.
When such content is accessed, a connection to ShortPixel servers may be established. In this context, your IP address, date and time of access, the file or URL accessed, browser and device information, operating system, referrer URL, technical request data, CDN traffic data, server logs as well as security and performance data may be processed in particular. Where images or other media files are optimised via ShortPixel, the image, file and metadata required for this purpose may also be processed.
The processing serves the optimised, fast and stable provision of images and other static content, the improvement of loading times, the reduction of data volume, the technical adaptation to the respective end device, error analysis, prevention of misuse and the security and performance of our website.
ID SCOUT SRL has its registered office in Romania and therefore within the European Union. Due to the technical functioning of a content delivery network, the possible use of globally distributed server locations and the use of sub-processors, however, it cannot be ruled out that personal data may also be processed outside the European Union or the European Economic Area. Where ShortPixel transfers personal data to third countries or has them processed there, this is carried out in accordance with the data protection requirements of Art. 44 et seq. GDPR, in particular on the basis of appropriate safeguards such as standard contractual clauses within the meaning of Art. 46 GDPR.
The processing is carried out on the basis of our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR in providing our website securely, stably, performantly and in a user-friendly manner, optimising loading times, detecting and resolving technical errors and delivering content efficiently. Where technically necessary cookies are set or information is stored on or accessed from the end device when using ShortPixel, this is carried out on the basis of Art. 6 Para. 1 lit. f GDPR and Section 25 Para. 2 No. 2 TDDDG. Where non-technically necessary cookies or comparable technologies are used, this is done only on the basis of consent pursuant to Art. 6 Para. 1 lit. a GDPR and Section 25 Para. 1 TDDDG.
The technical data processed in connection with the provision and optimisation of images and other static content are stored for as long as this is necessary for the provision, optimisation, security, error analysis, prevention of misuse and technical improvement of our website. The data are then deleted or anonymised unless statutory retention obligations exist or further storage is required for the establishment, exercise or defence of legal claims.
ShortPixel processes personal data of visitors to our website as a processor within the meaning of Art. 4 No. 8 GDPR, insofar as this processing is carried out on our behalf for the provision, optimisation and delivery of images and other static content. We have concluded a data processing agreement with ShortPixel within the meaning of Art. 28 Para. 3 GDPR. In this agreement, ShortPixel undertakes in particular to process personal data only in accordance with our instructions and for the provision of the agreed services, to implement appropriate technical and organisational protective measures, and to use sub-processors only in accordance with the contractual provisions.
Further information on data processing by ShortPixel can be found at https://shortpixel.com/privacy. Further information on ShortPixel’s Data Processing Agreement can be found at https://shortpixel.com/knowledge-base/article/shortpixel-dpa-data-processing-agreement/
Booking system Hotelpartner
We use 'HotelPartner' for online room reservations on our website. The provider is Hotelpartner Deutschland GmbH, Steinstraße 27, 20095 Hamburg, Germany (hereinafter referred to as 'HotelPartner').
HotelPartner provides a web booking engine or internet booking engine through which you can request or book rooms and further services online. The booking route may be embedded on our website or opened via a corresponding link or button in a new browser window or a new view. HotelPartner can be used to display availability, room categories, prices, additional services and booking information, and to technically receive and process reservations.
When you make a room reservation or submit a booking enquiry via the booking system, the data required to process the booking are processed. This may include, in particular, title, first name, surname, email address, telephone number, address, business address, period of stay, arrival and departure date, number of guests, booked room category, rate, booked additional services, payment and billing data, communication data, booking number, special requests or comments as well as further information voluntarily provided by you during the booking process. In addition, technical access data such as the IP address, date and time of access, browser and device information, referrer URL, pages or functions accessed and server logs may be processed.
The processing serves the technical provision of the online booking route, the checking of availability, the processing and confirmation of your booking or booking enquiry, communication with you, the preparation and performance of your stay, the billing of booked services and the documentation of booking processes.
The processing is carried out, insofar as it is necessary for the initiation or performance of an accommodation contract, the processing of your booking enquiry, the execution of the reservation or the provision of booked services, on the basis of Art. 6 Para. 1 lit. b GDPR. Where we are legally obliged to retain certain booking, payment, billing or business documents, the processing is carried out on the basis of Art. 6 Para. 1 lit. c GDPR. Where the processing is necessary for the secure, stable and user-friendly provision of the booking route, error analysis, prevention of misuse or the establishment, exercise or defence of legal claims, it is carried out on the basis of our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR. Voluntary information that is not required for the booking is processed on the basis of your consent pursuant to Art. 6 Para. 1 lit. a GDPR, unless another legal basis applies.
Where technically necessary cookies are set or information is stored on or accessed from the end device when using the booking system, this is carried out on the basis of Art. 6 Para. 1 lit. b GDPR or Art. 6 Para. 1 lit. f GDPR and Section 25 Para. 2 No. 2 TDDDG, provided that this is necessary for the provision of the booking route, the execution of the booking process or the storage of technically necessary session information. Where non-technically necessary cookies or comparable technologies are used, this is done only on the basis of consent pursuant to Art. 6 Para. 1 lit. a GDPR and Section 25 Para. 1 TDDDG. Consent is voluntary and can be withdrawn at any time with effect for the future.
The data processed in connection with the online booking are stored for as long as this is necessary for processing your booking or enquiry, performing the stay, billing, complying with statutory retention obligations or the establishment, exercise or defence of legal claims. Booking, payment and billing data may be stored for the statutory retention periods due to commercial and tax law requirements. The data are then deleted or restricted in processing unless further storage is required.
HotelPartner processes personal data of users of our website and booking guests as a processor within the meaning of Art. 4 No. 8 GDPR, insofar as this processing is carried out on our behalf for the provision and operation of the booking system. We have concluded a data processing agreement with HotelPartner within the meaning of Art. 28 Para. 3 GDPR. In this agreement, HotelPartner undertakes in particular to process personal data only in accordance with our instructions and for the provision of the agreed services, to implement appropriate technical and organisational protective measures, and to use sub-processors only in accordance with the contractual provisions.
Further information on data processing by HotelPartner can be found at https://hotelpartner.com/privacy-policy/
Guestline Property Management System
We use 'Guestline' as a Property Management System (PMS) for the management and operation of our hotel business. The provider is Guestline Limited, Armstrong Building, Oakwood Drive, Loughborough University Science & Enterprise Park, Loughborough, LE11 3QF, United Kingdom, a company of The Access Group (hereinafter referred to as 'Guestline').
Guestline is a cloud-based hotel management system which can be used, in particular, to manage reservations, guest profiles, stays, rooms and availability as well as other operational processes within a hotel. The system is used by our employees for internal hotel operations and is not integrated as a separate service into our website.
In connection with the use of Guestline, the following data in particular may be processed: first name and surname, title, address, email address, telephone number, date of birth, booking and reservation numbers, arrival and departure dates, duration of stay, room category, booked rate, number and names of accompanying guests, additional services booked, booking source, communication contents, invoice and billing data, payment status as well as information relating to amendments, cancellations and previous stays. Depending on the use and configuration of the system, preferences, special requests and other information provided by you in connection with your booking or stay may also be stored.
The data processed in Guestline may be collected directly when a reservation is made or during your stay, or may be transferred from other booking and distribution systems used by us. This may include, in particular, bookings made directly with us, via an online booking platform, a travel agency, a tour operator, a booking service or other connected distribution channels.
Guestline supports us in particular with the management of reservations and availability, the preparation and performance of your stay, check-in and check-out, room management, the allocation and provision of booked services, guest communication, invoicing and billing, the documentation of booking and stay processes and the organisation of internal hotel operations. Depending on our specific configuration, further hotel, payment, distribution, communication or administration systems may be connected to Guestline via interfaces.
The processing is carried out on the basis of Art. 6 Para. 1 lit. b GDPR insofar as it is necessary for processing your reservation, preparing and carrying out your stay, providing the services booked by you, communicating with you or billing. Where we are legally obliged to process or retain certain guest, booking, registration, invoice, payment or business records, the processing is carried out on the basis of Art. 6 Para. 1 lit. c GDPR. Where processing is necessary for the efficient organisation of our hotel operations, ensuring consistent booking and guest data, preventing incorrect bookings, maintaining IT and system security or establishing, exercising or defending legal claims, it is carried out on the basis of our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR.
Where you inform us of special requests in connection with a booking or your stay, these may in individual cases allow conclusions to be drawn about special categories of personal data within the meaning of Art. 9 Para. 1 GDPR, for example information relating to health-related requirements, a disability, allergies or particular dietary requirements. We process such data only insofar as this is necessary for the service requested by you and a legal basis pursuant to Art. 9 Para. 2 GDPR applies, or where you have expressly and voluntarily provided us with the relevant information.
Personal data may also be processed in the United Kingdom in connection with the provision of Guestline. The United Kingdom is subject to an adequacy decision of the European Commission pursuant to Art. 45 GDPR, which was renewed in December 2025. Personal data may therefore be transferred to the United Kingdom on this basis. Where Guestline or The Access Group engages further sub-processors for the provision of the service and personal data are transferred to other third countries for which no adequacy decision exists, appropriate safeguards are provided for such transfers in accordance with the contractual data protection provisions, in particular, where required, standard contractual clauses within the meaning of Art. 46 GDPR.
The retention period for data processed in Guestline depends on the respective purpose of the processing and the retention and deletion periods determined by us. We generally retain booking and stay data for as long as this is necessary for the performance and administration of the stay, the handling of subsequent enquiries, billing and compliance with statutory retention and documentation obligations. Where statutory retention obligations under commercial or tax law apply, individual booking, invoice and business data may be retained for the periods prescribed by law. The data are subsequently deleted or anonymised unless there is a further legal basis for their retention.
Guestline processes personal data of guests as a processor within the meaning of Art. 4 No. 8 GDPR insofar as this processing is carried out on our behalf for the provision and operation of the Property Management System. We have agreed contractual data processing provisions for this processing within the meaning of Art. 28 Para. 3 GDPR. Guestline or the relevant company of The Access Group is obliged in particular to process personal data in accordance with our documented instructions, to implement appropriate technical and organisational protective measures and to engage further processors in accordance with the contractual data protection provisions.
Further information on data processing by The Access Group can be found at https://www.theaccessgroup.com/en-gb/privacy-notice/. Further information on the data processing provisions applicable to Access products can be found at https://www.theaccessgroup.com/en-gb/legal-hub/data-processor-terms/
straiv
We use the straiv solution provided by straiv GmbH, Industriestraße 23, 70565 Stuttgart, Germany (hereinafter referred to as 'straiv').
Straiv enables hotels to offer their guests digital information (e.g. digital guest directory, guest messaging) and services (e.g. digital check-in and check-out including registration form) on their own devices throughout all phases of the stay.
Each hotel decides independently which contents and services are provided through straiv.
Personal data are only collected if you provide them voluntarily or if legal regulations require their collection. For certain functions, entering personal data may be necessary to verify your authorisation to use a service. In particular, the following categories of data may be processed:
- Cookie ID, geo-data, room number
- Usage data (e.g. modules used and duration of visit)
- Booking data (e.g. booking number, arrival and departure date)
Not all of the data categories mentioned above are necessarily processed; this depends on the specific configuration and modules used by each hotel. The use of the solution is generally possible without registration. When submitting or requesting a service, you will at least once be asked to give your consent to data processing.
Categories of recipients:
- Public authorities where overriding legal provisions apply
- Other external recipients if you have given your consent or the transfer is permissible due to overriding legitimate interests
- The respective hotel and its authorised employees with system access
Data processing is carried out – depending on the module used – either on the basis of your consent pursuant to Art. 6 Para. 1 lit. a GDPR or on the basis of our legitimate interests pursuant to Art. 6 Para. 1 lit. f GDPR, in particular our interest in efficiently providing digital guest services. You may withdraw your consent at any time with effect for the future.
If, in the course of using straiv, data are transferred to third countries, such transfer is carried out on the basis of appropriate safeguards pursuant to Art. 46 GDPR, in particular the standard contractual clauses.
We have concluded a Data Processing Agreement within the meaning of Art. 28 Para. 3 GDPR with straiv, under which straiv is obliged to protect our guests’ data and not to disclose them to third parties. Straiv implements all necessary technical and organisational measures to ensure the security of your data.
Further information on data processing by straiv can be found in straiv’s Privacy Policy at https://straiv.io/en/legal/privacy/
Our Payment Service Providers
Apple Pay
We offer 'Apple Pay' as an electronic payment method. The provider of the Apple Pay service for users in Germany and the European Economic Area is Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Republic of Ireland (hereinafter referred to as 'Apple').
Apple Pay enables you to make payments using credit, debit or other supported payment cards stored in Apple Wallet on a compatible Apple device. If you select Apple Pay as your payment method, you can choose a payment method stored there and authorise the payment using the authentication methods supported by your Apple device.
In connection with the provision and use of Apple Pay, Apple may process, in particular, information relating to your Apple Account, your end device, payment cards stored in Apple Wallet and their issuers, your use of Apple Pay, your location, and security and fraud prevention information. Depending on the specific transaction, information about the merchant, the payment amount and other transaction information required to process the payment may also be processed.
If you use Apple Pay on our website, the information required to process the payment is transmitted via Apple Pay to us or to the payment service provider or payment processor used by us. This may include, in particular, encrypted payment information, a payment token generated for the respective transaction, billing and, where applicable, delivery information, email address and other information requested by us for the processing of the booking, order or payment. Your actual credit, debit or other card number is not disclosed to us by Apple Pay.
Apple transmits payment information for payments made in apps and on websites in encrypted form. According to Apple, this information is processed technically in such a way that it can only be decrypted by the respective merchant, its development partner or the payment processor involved. Apple states that it does not retain the payment information transmitted in this context in a form that can be linked back to you.
The further processing of the payment takes place with the involvement of the payment service provider used by us, the participating bank, the card issuer, the payment network and, where applicable, other parties required for the selected payment method. Where necessary, we provide additional information about the payment service providers used by us in separate sections of this Privacy Policy.
The processing of personal data received by us in connection with an Apple Pay payment is carried out, insofar as it is necessary for the execution of the payment requested by you and for the performance of a contract concluded with you or for taking steps at your request prior to entering into a contract, on the basis of Art. 6 Para. 1 lit. b GDPR. Where processing is necessary for compliance with statutory retention, documentation, tax or commercial-law obligations, it is carried out on the basis of Art. 6 Para. 1 lit. c GDPR. Where data are processed to ensure secure and reliable payment processing, prevent misuse and fraud or establish, exercise or defend legal claims, this is carried out on the basis of our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR.
Where information is stored on or accessed from the end device as part of the technical provision and use of Apple Pay and this is strictly necessary to provide the payment function expressly selected by you, check the availability of Apple Pay on your end device, authenticate the payment or securely execute the payment transaction, this is carried out on the basis of Section 25 Para. 2 No. 2 TDDDG. Where non-technically necessary cookies or comparable technologies are used beyond this, this is done only on the basis of your consent pursuant to Art. 6 Para. 1 lit. a GDPR and Section 25 Para. 1 TDDDG. Consent is voluntary and can be withdrawn at any time with effect for the future.
Apple processes personal data in connection with your Apple Account, payment methods stored in Apple Wallet, the provision of Apple Pay, eligibility checks, security and fraud prevention and other purposes determined by Apple under its own data protection responsibility. Apple is not our processor in respect of this processing. We have no direct influence over the further processing or retention period of these data by Apple.
Personal data may also be processed by Apple and affiliated companies outside the European Union or the European Economic Area, in particular in the USA. Apple states that personal data collected by Apple or Apple-affiliated companies worldwide may generally also be stored by Apple Inc. in the USA. According to Apple, international transfers of personal data collected in the European Economic Area are governed in particular by the European Commission's standard contractual clauses.
Payment, booking, order and billing data processed by us in connection with the payment are retained for as long as this is necessary for the execution and documentation of the payment, performance of the underlying contract, handling of refunds or payment disputes, compliance with statutory retention and documentation obligations or the establishment, exercise or defence of legal claims. For personal data processed by Apple under its own data protection responsibility, the retention periods determined by Apple apply.
Further information on the processing of personal data by Apple Pay can be found at https://www.apple.com/legal/privacy/data/en/apple-pay/. Apple's general Privacy Policy can be found at https://www.apple.com/legal/privacy/en-ww/
Computop
We use 'Computop' for the technical processing of electronic payments. The provider is Computop Paygate GmbH, Schwarzenbergstraße 4, 96050 Bamberg, Germany (hereinafter referred to as 'Computop'). Computop is an independent company within the Nexi Group.
Computop provides 'Computop Paygate', a payment platform through which various electronic payment methods can be integrated and payment transactions can be technically processed. In particular, Computop manages the data flows required for the respective payment between us, you, the banks involved, credit card companies, providers of the selected payment method and, where applicable, other service providers involved in payment processing or fraud prevention.
If you select or use a payment method provided via Computop, the personal data required to carry out the payment transaction are transmitted to Computop or collected directly via a payment interface provided by Computop. Depending on the payment method selected and the technical integration, these data may include, in particular, first name and surname, billing and, where applicable, delivery address, email address, telephone number, booking, order or service data, payment amount, currency, payment method, transaction and reference numbers, payment status, data relating to refunds or chargebacks as well as card, account or other payment-method-specific data.
Technical data may also be processed, including in particular the IP address, date and time of access, browser and device information, operating system, technical connection data, information about the payment service used and data required for authentication and the secure execution of the payment transaction. In the case of credit card payments, additional information relating to authentication, the browser and end device used and, where required for the respective transaction, contact, billing or delivery information may be processed as part of 3-D Secure and transmitted to the parties involved in the authentication procedure.
The processing serves the technical execution and management of the payment transaction, the authorisation and authentication of the payment, the transmission of the payment status, the allocation of the payment to your booking, order or other service, the processing of refunds and chargebacks and, where corresponding functions are used, fraud and misuse prevention.
The processing is carried out, insofar as it is necessary for the execution of the payment requested by you and for the performance of a contract concluded with you or for taking steps at your request prior to entering into a contract, on the basis of Art. 6 Para. 1 lit. b GDPR. Where processing is necessary for compliance with statutory retention, documentation or other legal obligations, it is carried out on the basis of Art. 6 Para. 1 lit. c GDPR. Where data are processed to ensure secure and reliable payment processing, prevent misuse and fraud or establish, exercise or defend legal claims, the processing is carried out on the basis of our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR.
The further companies which receive personal data in connection with a payment transaction depend on the payment method selected by you. These may include, in particular, banks, acquirers, credit card organisations, providers of digital payment methods and other payment service providers required for the respective payment method. Where these providers process personal data under their own data protection responsibility, the further processing is governed by their respective privacy policies. Where necessary, we provide additional information about the payment service providers offered by us in separate sections of this Privacy Policy.
According to Computop, no cookies are set as standard on the Hosted Payment Page provided by Computop. Individually customised or differently integrated payment pages may involve different technical processing.
Computop states that payment transactions in the Computop Paygate database and Computop Analytics are regularly deleted after 12 months. According to Computop, payment transactions in the Computop Reporter database are regularly deleted after 24 months. Backups of the databases may subsequently be retained for a further 12 months. Individual data required for billing, traceability of transactions, subsequent actions or reporting may continue to be stored within these periods. Irrespective of this, we retain payment, booking and billing data available to us for as long as this is necessary for the performance of the contract, payment processing, compliance with statutory retention obligations or the establishment, exercise or defence of legal claims.
Computop processes personal data in connection with the technical processing of payment transactions via Computop Paygate as a processor within the meaning of Art. 4 No. 8 GDPR. We have concluded a data processing agreement with Computop within the meaning of Art. 28 Para. 3 GDPR. Under this agreement, Computop undertakes in particular to process personal data only in accordance with our documented instructions and for the provision of the agreed services and to implement appropriate technical and organisational measures to protect personal data. Computop itself confirms this processor role for the connection to Computop Paygate.
Further information on data processing by Computop can be found at https://computop.com/en/data-protection/. Further information on the processing and deletion of transaction data in Computop Paygate can be found at https://support.computop.com/hc/en-gb/articles/360015240800-GDPR-General-Information
Google Pay
We offer 'Google Pay' as an electronic payment method. The provider responsible for processing Google Payments data for users in the European Economic Area is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter referred to as 'Google').
Google Pay enables you to make payments using payment methods stored in your Google Account or Google Wallet. If you select Google Pay as your payment method, a payment interface provided by Google is displayed, allowing you to select a stored payment method and authorise the payment. Google states that Google Pay can store payment methods and other information associated with a Google Account in order to facilitate transactions.
As part of the payment process, Google may process, in particular, information relating to your Google Account, payment methods stored by you, the selected payment method, card issuer or card network, payment and transaction information, billing and, where applicable, delivery address, email address, as well as technical information relating to your end device and your use of Google Pay. Depending on the configuration and payment method, device, account and location information and data used for security, risk assessment and fraud prevention may also be processed. Google's current Payments Privacy Notice expressly covers registration, payment-method and transaction information as well as fraud-risk assessments.
For an online payment via Google Pay, your full actual card number is generally not transmitted to us. Instead, Google Pay provides a payment token or a virtual or otherwise technically protected representation of the selected payment method. This payment token, together with the transaction information required for the respective order, booking or other service, is transmitted to our payment service provider or the payment gateway used by us and processed there for the purpose of completing the payment.
Depending on the specific configuration, Google may also provide us or the payment service provider involved with certain information relating to the selected payment method as well as security and fraud-risk assessments. The further processing of the payment takes place with the involvement of the payment service provider used, participating banks, card organisations or other providers of the selected payment method. Where necessary, we provide additional information about these payment service providers in separate sections of this Privacy Policy. Google itself states that, except where Google or an affiliate is the issuer, Google is not a party to the contractual relationship governing the user's underlying payment method.
The processing of personal data received by us in connection with a Google Pay payment is carried out, insofar as it is necessary for the execution of the payment requested by you and for the performance of a contract concluded with you or for taking steps at your request prior to entering into a contract, on the basis of Art. 6 Para. 1 lit. b GDPR. Where processing is necessary for compliance with statutory retention, documentation, tax or commercial-law obligations, it is carried out on the basis of Art. 6 Para. 1 lit. c GDPR. Where data are processed to ensure secure payment processing, prevent misuse and fraud or establish, exercise or defend legal claims, this is carried out on the basis of our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR.
Where information is stored on or accessed from the end device as part of the technical provision and use of Google Pay and this is strictly necessary to provide the payment function expressly selected by you, authenticate the payment or securely execute the payment transaction, this is carried out on the basis of Section 25 Para. 2 No. 2 TDDDG. Where non-technically necessary cookies or comparable technologies are used beyond this, this is done only on the basis of your consent pursuant to Art. 6 Para. 1 lit. a GDPR and Section 25 Para. 1 TDDDG. Consent is voluntary and can be withdrawn at any time with effect for the future.
Google processes personal data in connection with your Google Account, your Google payments profile, payment methods stored there, the provision of Google Pay, security and fraud prevention and other purposes determined by Google under its own data protection responsibility. Google is therefore not our processor in this respect. We have no direct influence over the further processing or retention period of these data by Google. Google's Payments Privacy Notice confirms, among other things, processing for provision of the service, fraud prevention, risk modelling, analytics and other Google-defined purposes.
Personal data may also be processed by Google and companies within the Google group outside the European Union or the European Economic Area, in particular in the USA. Where personal data are transferred to appropriately certified Google companies in the USA and the relevant processing is covered by their certification, the transfer may be based on the European Commission's adequacy decision concerning the EU-U.S. Data Privacy Framework. For transfers not covered by an adequacy decision, Google states that appropriate safeguards may be used where required, including standard contractual clauses within the meaning of Art. 46 GDPR.
Payment, booking, order and billing data processed by us in connection with the payment are retained for as long as this is necessary for the execution and documentation of the payment, performance of the underlying contract, handling of refunds or payment disputes, compliance with statutory retention and documentation obligations or the establishment, exercise or defence of legal claims. For data processed by Google under its own data protection responsibility, the retention periods determined by Google apply. Google states that Google Payments information may be retained for the duration of use and for an additional period where necessary to comply with legal and regulatory obligations.
Further information on the processing of personal data in connection with Google Payments can be found at https://payments.google.com/payments/apis-secure/get_legal_document?ldl=en-GB&ldo=0&ldt=privacynotice. Google's general Privacy Policy can be found at https://policies.google.com/privacy?hl=en. The current Google Pay/Google Payments Terms of Service can be found at https://payments.google.com/termsOfService?hl=en
Nexi Paygate
We use 'Nexi Paygate' for the processing of credit card payments and, where applicable, further payment methods offered. The provider is Nexi Germany GmbH, Helfmann-Park 7, 65760 Eschborn, Germany (hereinafter referred to as 'Nexi').
Nexi Paygate is a payment service which enables electronic payments to be technically received, authorised and processed. Nexi may be used both for online payments, for example in connection with order, booking or payment processes, and for on-site payments. If you select or use a payment method offered via Nexi, in particular credit card, the data required for payment processing are transmitted to Nexi or collected directly by Nexi.
The data processed may include, in particular, first name, surname, billing address, email address, IP address, order, booking or service data, payment amount, currency, transaction number, payment status, technical access data and further data required for payment processing, payment confirmation, fraud prevention and prevention of misuse. In the case of credit card payments, card-specific payment data such as the cardholder name, credit card number, expiry date and card verification number may also be processed. Depending on the payment method and area of use, these payment data are collected directly in an input form provided by Nexi or an integrated payment service provider, via a payment terminal or via other technical payment infrastructure.
The processing serves the selection and execution of the desired payment method, the technical authorisation of the payment, payment processing, transmission of the payment status, allocation of the payment to your order, booking or other service used, fraud prevention, prevention of misuse and fulfilment of statutory and regulatory requirements in connection with payment services.
The processing is carried out, insofar as it is necessary for the performance of the contract, the processing of your order or booking, the provision of the service used and the processing of the payment method selected by you, on the basis of Art. 6 Para. 1 lit. b GDPR. Where the processing is necessary for compliance with statutory or regulatory obligations, in particular commercial, tax, payment services or anti-money laundering obligations, it is carried out on the basis of Art. 6 Para. 1 lit. c GDPR. Where the processing is necessary for secure and efficient payment processing, prevention of misuse, fraud prevention, technical protection of the payment processes or the establishment, exercise or defence of legal claims, it is carried out on the basis of our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR.
Where technically necessary cookies are set or information is stored on or accessed from the end device when Nexi Paygate is used online, this is carried out on the basis of Art. 6 Para. 1 lit. b GDPR or Art. 6 Para. 1 lit. f GDPR and Section 25 Para. 2 No. 2 TDDDG, provided that this is necessary for the provision of the payment function, the execution of the payment process, fraud prevention or the storage of technically necessary session information. Where non-technically necessary cookies or comparable technologies are used, this is done only on the basis of consent pursuant to Art. 6 Para. 1 lit. a GDPR and Section 25 Para. 1 TDDDG. Consent is voluntary and can be withdrawn at any time with effect for the future.
The data processed in connection with payment processing are stored for as long as this is necessary for the execution and documentation of the payment, the processing of the order, booking or other service, billing, compliance with statutory retention and documentation obligations, fraud prevention or the establishment, exercise or defence of legal claims. The data are then deleted or restricted in processing unless further storage is required.
Nexi may process personal data under its own responsibility in connection with payment processing. Further information on data processing by Nexi can be found at https://www.nexi.de/de/legal-footer/datenschutzerklaerung (in German)
PayPal
We use 'PayPal' for the processing of certain payment methods, in particular for online payments and, where applicable, for on-site payments. The provider is PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg, Luxembourg (hereinafter referred to as 'PayPal').
PayPal is a payment service provider through which various payment methods can be offered and processed. These may include, in particular, payments via a PayPal account, credit card payments, direct debit payments, purchase on account, payment by instalments or further payment methods provided by PayPal. If you select or use a payment method offered via PayPal, the data required for payment processing are transmitted to PayPal or collected directly by PayPal.
The data processed may include, in particular, first name, surname, billing address, delivery address, email address, telephone number, payment data, order, booking or service data, payment amount, currency, transaction number, payment status, IP address, device and browser information, technical access data and further data required for payment processing, payment confirmation, fraud prevention, prevention of misuse, risk assessment, receivables management or compliance with statutory and regulatory obligations. PayPal may also process personal data if you make payments without a PayPal account or via guest payment functions provided by PayPal.
The processing serves the selection and execution of the desired payment method, payment processing, transmission of the payment status, allocation of the payment to your order, booking or other service used, the review and management of payment claims, fraud prevention, prevention of misuse and fulfilment of statutory and regulatory requirements in connection with payment services.
The processing is carried out, insofar as it is necessary for the performance of the contract, the processing of your order or booking, the provision of the service used and the processing of the payment method selected by you, on the basis of Art. 6 Para. 1 lit. b GDPR. Where the processing is necessary for compliance with statutory or regulatory obligations, in particular commercial, tax, payment services, anti-money laundering or supervisory obligations, it is carried out on the basis of Art. 6 Para. 1 lit. c GDPR. Where the processing is necessary for secure and efficient payment processing, prevention of misuse, fraud prevention, risk assessment or the establishment, exercise or defence of legal claims, it is carried out on the basis of our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR.
Where technically necessary cookies are set or information is stored on or accessed from the end device when PayPal is used online, this is carried out on the basis of Art. 6 Para. 1 lit. b GDPR or Art. 6 Para. 1 lit. f GDPR and Section 25 Para. 2 No. 2 TDDDG, provided that this is necessary for the provision of the payment function, the execution of the payment process, fraud prevention or the storage of technically necessary session information. Where non-technically necessary cookies or comparable technologies are used, this is done only on the basis of consent pursuant to Art. 6 Para. 1 lit. a GDPR and Section 25 Para. 1 TDDDG. Consent is voluntary and can be withdrawn at any time with effect for the future.
The data processed in connection with payment processing are stored for as long as this is necessary for the execution and documentation of the payment, the processing of the order, booking or other service, billing, compliance with statutory retention and documentation obligations, fraud prevention, receivables management or the establishment, exercise or defence of legal claims. The data are then deleted or restricted in processing unless further storage is required.
PayPal processes personal data under its own responsibility in connection with payment processing. Further information on data processing by PayPal can be found at https://www.paypal.com/uk/legalhub/paypal/privacy-full
Wero
We use 'Wero' for the processing of certain payment methods, in particular for online payments and, where applicable, for on-site payments. The provider is EPI Company SE, De Lignestraat 13, 1000 Brussels, Belgium (hereinafter referred to as 'Wero').
Wero is a European payment solution through which payments can be initiated and processed, in particular via participating banks, payment service providers, banking apps or the Wero app. If you select or use a payment method offered via Wero, the data required for payment processing are transmitted to Wero, your bank, the respective payment service provider or other parties involved in the payment processing, or are collected directly by them.
The data processed may include, in particular, first name, surname, payment identifier, telephone number, email address, account information, payment amount, currency, transaction number, payment status, payer and payee information, order, booking or service data, IP address, device and browser information, technical access data and further data required for payment processing, payment confirmation, fraud prevention, prevention of misuse, risk assessment or compliance with statutory and regulatory obligations.
The processing serves the selection and execution of the desired payment method, payment processing, transmission of the payment status, allocation of the payment to your order, booking or other service used, the review and management of payment claims, fraud prevention, prevention of misuse and fulfilment of statutory and regulatory requirements in connection with payment services.
The processing is carried out, insofar as it is necessary for the performance of the contract, the processing of your order or booking, the provision of the service used and the processing of the payment method selected by you, on the basis of Art. 6 Para. 1 lit. b GDPR. Where the processing is necessary for compliance with statutory or regulatory obligations, in particular commercial, tax, payment services, anti-money laundering or supervisory obligations, it is carried out on the basis of Art. 6 Para. 1 lit. c GDPR. Where the processing is necessary for secure and efficient payment processing, prevention of misuse, fraud prevention, risk assessment or the establishment, exercise or defence of legal claims, it is carried out on the basis of our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR.
Where technically necessary cookies are set or information is stored on or accessed from the end device when Wero is used online, this is carried out on the basis of Art. 6 Para. 1 lit. b GDPR or Art. 6 Para. 1 lit. f GDPR and Section 25 Para. 2 No. 2 TDDDG, provided that this is necessary for the provision of the payment function, the execution of the payment process, fraud prevention or the storage of technically necessary session information. Where non-technically necessary cookies or comparable technologies are used, this is done only on the basis of consent pursuant to Art. 6 Para. 1 lit. a GDPR and Section 25 Para. 1 TDDDG. Consent is voluntary and can be withdrawn at any time with effect for the future.
The data processed in connection with payment processing are stored for as long as this is necessary for the execution and documentation of the payment, the processing of the order, booking or other service, billing, compliance with statutory retention and documentation obligations, fraud prevention, receivables management or the establishment, exercise or defence of legal claims. The data are then deleted or restricted in processing unless further storage is required.
Wero or EPI Company SE processes personal data under its own responsibility in connection with payment processing. Further information on data processing by Wero can be found at https://wero-wallet.eu/legal-center
4. Other processing activities
Data protection in relation to applications and the recruitment process
We process applicants’ personal data for the purpose of conducting the recruitment process and deciding whether to establish an employment relationship.
Purposes of processing
The processing is carried out in particular for the following purposes:
- Receiving, reviewing and assessing your application
- Communicating with you, in particular to arrange appointments, clarify queries and exchange documents
- Planning and conducting interviews, selection procedures and selection decisions
- Assessing your suitability for the advertised position or a comparable position
- Preparing and initiating an employment relationship
- Complying with legal obligations
- Establishing, exercising or defending legal claims
- Including you in a talent pool for future vacancies, where you have given us your consent to do so
Categories of personal data
Depending on the nature and scope of your application, we process the following categories of personal data in particular:
- Identification data: First name, surname, title and, where applicable, date of birth
- Contact details: Address, email address and telephone number
- Application data: Covering letter, curriculum vitae, application photograph, certificates, evidence of qualifications, employment history and references
- Information relating to the position sought: Preferred area of work, working hours, salary expectations, availability and earliest possible starting date
- Communication data: Content of messages, emails, telephone calls and conversations, as well as interview notes and appointment arrangements
- Assessment and selection data: Assessments, evaluations and decisions made during the recruitment process
- Other information: Any further information that you voluntarily provide as part of your application
Source of the data
We generally collect your personal data directly from you. This applies in particular to data that you provide as part of your application, during an interview or in subsequent communications (Art. 13 GDPR).
Where you apply through a recruitment portal, recruitment agency or other service provider, we may also receive your data from that organisation. In individual cases, we may also process information obtained from publicly accessible professional sources where this is necessary for the recruitment process and legally permissible (Art. 14 GDPR).
Special categories of personal data
Please provide us only with personal data that is necessary for the recruitment process.
Your application documents may contain special categories of personal data. These include, for example, health data and information concerning a disability, religious beliefs or trade union membership (Art. 9 Para. 1 GDPR).
We process such data only where this is necessary for exercising rights or complying with legal obligations under employment law, social security law or social protection law and the applicable statutory requirements are met (Art. 9 Para. 2 lit. b GDPR and Section 26 Para. 3 S. 1 BDSG).
Where the processing is based on your explicit consent, it will be carried out only for the purposes specified in that consent (Art. 9 Para. 2 lit. a GDPR and Section 26 Para. 2 and Para. 3 S. 2 BDSG). You may withdraw your consent at any time with effect for the future (Art. 7 Para. 3 GDPR).
Legal bases for processing
Depending on the purpose and circumstances, we process your personal data on the following legal bases:
- Conducting the recruitment process: The processing is necessary for deciding whether to establish an employment relationship and for taking pre-contractual measures (Section 26 Para. 1 S. 1 BDSG and Art. 6 Para. 1 lit. b GDPR).
- Compliance with legal obligations: The processing is necessary for compliance with a legal obligation to which we are subject (Art. 6 Para. 1 lit. c GDPR in conjunction with the applicable statutory provision).
- Legitimate interests: The processing is necessary for the purposes of our legitimate interests or those of a third party. These include, in particular, ensuring IT security and establishing, exercising or defending legal claims (Art. 6 Para. 1 lit. f GDPR).
- Consent: The processing is based on your freely given consent. This applies in particular to inclusion in a talent pool or to other processing activities expressly covered by your consent (Art. 6 Para. 1 lit. a and Art. 7 GDPR and Section 26 Para. 2 BDSG).
- Special categories of personal data: Such data is processed only under the conditions set out in Art. 9 Para. 2 GDPR and Section 26 Para. 3 BDSG.
Recipients and categories of recipients
Within our organisation, access to your personal data is restricted to those persons and departments that require it to conduct the recruitment process or comply with legal obligations. These may include in particular:
- Human resources personnel
- Management
- Managers and the relevant departments
- Employees involved in the selection process
- The works council or other employee representative bodies, where their involvement is required or provided for by law
External recipients may include in particular:
- IT, hosting and communications service providers
- Providers of recruitment and human resources management systems
- Recruitment agencies and recruitment consultancies
- Legal and tax advisers
- Courts, authorities and other public bodies
Where external service providers process personal data exclusively on our behalf, they are engaged as processors under a contract that complies with the applicable statutory requirements (Art. 28 GDPR).
Transfers to third countries
Where service providers process your application data outside the European Union or the European Economic Area, the transfer takes place only in compliance with the statutory requirements governing transfers to third countries (Art. 44 et seq. GDPR).
A transfer may be based in particular on an adequacy decision adopted by the European Commission or on appropriate safeguards such as the European Commission’s standard contractual clauses (Art. 45 and Art. 46 GDPR).
Requirement to provide personal data
Providing the personal data required to assess your application and conduct the recruitment process is necessary for us to process your application. Without this data, we may be unable to assess your suitability for the relevant position or conduct the recruitment process (Art. 13 Para. 2 lit. e GDPR).
Retention period and erasure
We retain your personal data only for as long as is necessary to conduct the recruitment process and fulfil the other purposes described above (Art. 5 Para. 1 lit. e GDPR).
Where an employment relationship is established, the application data required for establishing and administering the employment relationship will be transferred to your personnel file. Any further processing will be governed by the data protection and statutory provisions applicable to the employment relationship (Section 26 Para. 1 S. 1 BDSG).
Where no employment relationship is established, we generally erase your application data no later than six months after you receive notification that your application was unsuccessful or after you withdraw your application. The temporary retention of the data serves in particular to establish, exercise or defend potential legal claims (Art. 6 Para. 1 lit. f and Art. 17 Para. 3 lit. e GDPR).
Data may be retained for a longer period where specific legal claims have been asserted or judicial or administrative proceedings are pending. In such cases, we retain the necessary data until the proceedings have been finally concluded or the reason for retention no longer applies.
Where you have consented to the inclusion of your data in a talent pool, we retain your data until you withdraw your consent, but for no longer than twelve months. At the end of this period, the data will be erased unless you consent again to its continued retention (Art. 6 Para. 1 lit. a and Art. 7 GDPR and Section 26 Para. 2 BDSG).
Information on video surveillance in our properties
Video surveillance is a particularly intensive form of processing personal data. Almost everyone feels uncomfortable when they are under video surveillance. This is also referred to as "surveillance pressure". Not being exposed to this pressure is almost one of the basic human needs.
Another human need, however, is the desire for security. Individuals and communities, but also inanimate things such as objects and systems, derive great benefit from an environment that is free of security risks or dangers.
Video surveillance is subject to strict data protection requirements for good reasons. On the other hand, the security interests of the controller must also be fairly assessed. Because often these interests are not limited to the controller alone. Employees, interested parties, suppliers, customers, tenants, guests, visitors, etc. may also have a need for security, which can be satisfied by a moderate and sensible use of video surveillance.
Even if some of the following information is already mentioned elsewhere in this data protection declaration, we would like to list all the information in this section of the text as it can also be found in a detailed information sign for video surveillance (information sheet according to Art. 13 GDPR):
Name and contact details of controller and, if applicable, his representative:
To be found at the bottom of this Data Protection Statement.
Contact details of the data protection officer:
To be found at the bottom of this Data Protection Statement.
Purposes and legal basis of data processing:
Investigation and detection of criminal offences as well as other security-related events.
Art. 6 Para. 1 lit. f EU General Data Protection Regulation.
Legitimate interests pursued:
Safety of employees, suppliers, guests, visitors, etc.
Protection of property, exercise of domiciliary rights.
Duration of storage or criteria for determining the duration:
In our properties, image data is usually deleted after 72 hours at the latest, insofar as the purpose of the storage has also ceased to apply at this time.
In doing so, we follow a recommendation of the independent data protection authorities of the federal and state governments (Data Protection Conference – DSK).
With a storage period of 72 hours, according to the DSK's justification, the supervisor can regularly pursue his security interests, while at the same time the interests of the data subjects worthy of protection remain protected.
If necessary, a special monitoring purpose may justify longer storage. However, this must be adequately justified.
Recipients or categories of recipients of the data (if data transfer takes place):
The data controller will not transfer the personal data to a third country or an international organisation.
Information on the rights of the data subject
See also the section "Rights of the data subject" at the top of this Data Protection Statement. For video surveillance in summary:
The data subject has the right to obtain confirmation from the controller as to whether personal data concerning him or her are being processed; if this is the case, he or she has a right of access to such personal data and to the information specified in Article 15 of the GDPR.
The data subject has the right to obtain from the controller the rectification without delay of inaccurate personal data concerning him or her and, where applicable, the completion of incomplete personal data (Article 16 GDPR).
The data subject has the right to obtain from the controller the erasure without delay of personal data concerning him or her, where one of the grounds listed in detail in Article 17 of the GDPR applies, e.g. where the data are no longer needed for the purposes pursued (right to erasure).
The data subject has the right to request the controller to restrict processing if one of the conditions listed in Art. 18 GDPR applies, e.g. if the data subject has objected to the processing, for the duration of the controller's review.
The data subject shall have the right to object at any time, on grounds relating to his or her particular situation, to the processing of personal data concerning him or her. The controller shall then no longer process the personal data unless it can demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims (Article 21 GDPR).
Without prejudice to any other administrative or judicial remedy, any data subject shall have the right to lodge a complaint with a supervisory authority if the data subject considers that the processing of personal data relating to him or her infringes the GDPR (Art. 77 GDPR). The data subject may exercise this right before a supervisory authority in the Member State of his or her residence, place of work or the place of the alleged infringement. In Lower Saxony, the competent supervisory authority is:
The State Data Protection Commissioner of Lower Saxony
P.O. Box 221
30002 Hannover
or:
Prinzenstraße 5
30159 Hannover
Phone: +49 511 120-4500
Email: poststelle@lfd.niedersachsen.de
Microsoft 365
We use 'Microsoft 365'. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland (hereinafter referred to as 'Microsoft').
Microsoft 365 is a cloud-based platform for communication, collaboration, calendar management, file storage, document processing and the organisation of business processes. Depending on the functions used by us, we use Microsoft 365 in particular for email communication, calendar and appointment management, online meetings and chats, the collaborative editing and storage of files and documents, and other internal and external communication and organisational processes.
In connection with the use of Microsoft 365, master data, contact details, communication data, email data, content data, file and document contents, appointment and calendar data, meeting and chat contents, contractual and business data, usage data, technical data and metadata may be processed in particular. These may include names, email addresses, telephone numbers, sender and recipient information, subject lines, communication contents, attachments, sending and receipt times, calendar and appointment information, participant data, documents, files, access and editing information, and technical log and connection data.
The personal data processed in each individual case depend on which Microsoft 365 services and functions are used and which information is processed or provided in the course of the respective communication, collaboration or other business activity.
The processing serves in particular internal and external communication, the handling of enquiries, the organisation of appointments and meetings, collaboration within our organisation and with external parties, the creation, editing, storage and management of documents and files, the organisation and documentation of business processes, and the secure and efficient operation of our business processes.
Where the processing is necessary for taking steps at your request prior to entering into a contract or for the performance of a contract with you, it is carried out on the basis of Art. 6 Para. 1 lit. b GDPR. Where the processing is carried out to safeguard our legitimate interests, it is based on Art. 6 Para. 1 lit. f GDPR. Our legitimate interests include, in particular, efficient and secure communication, the structured organisation of our business processes, collaboration within our organisation and with external parties, the documentation of business transactions, the handling of enquiries, and the secure provision and management of business information and documents. Where we are legally obliged to process or retain certain communications, documents or business transactions, the processing is carried out on the basis of Art. 6 Para. 1 lit. c GDPR. Where special categories of personal data within the meaning of Art. 9 Para. 1 GDPR are processed in individual cases, this is done only where an appropriate legal basis pursuant to Art. 9 Para. 2 GDPR applies.
Microsoft has established an EU Data Boundary for Microsoft 365 customers whose tenant sign-up location is in a country of the European Union or the European Free Trade Association. Within the scope of this commitment, customer data and personal data relating to the Microsoft 365 online services covered are generally stored and processed within the European Union or the European Free Trade Association. In certain limited circumstances, however, personal data may continue to be processed outside this data region or transferred there. This may be necessary, in particular, in connection with certain support and security services, technical operational processes, the prevention of cyberattacks, compliance with legal obligations or the involvement of certain sub-processors.
Where personal data are transferred to Microsoft Corporation or other Microsoft companies in the USA covered by the relevant certification and the respective processing is covered by that certification, the transfer may be based on the European Commission's adequacy decision concerning the EU-U.S. Data Privacy Framework. Where personal data are transferred to further third countries or a transfer is not covered by an adequacy decision, Microsoft states that it relies on appropriate safeguards for such transfers, in particular standard contractual clauses within the meaning of Art. 46 GDPR.
The retention period depends on the type of data processed, the respective Microsoft 365 service, the configuration selected by us and the purpose of the processing. We generally delete personal data or restrict their processing when they are no longer required for the respective processing purpose and there are no statutory retention obligations or other legitimate grounds requiring further storage. Certain communications, contractual documents, booking records, invoices or other business documents may in particular be subject to statutory retention periods under commercial and tax law.
Microsoft processes personal data as a processor within the meaning of Art. 4 No. 8 GDPR insofar as this processing is carried out on our behalf for the provision and operation of Microsoft 365. We have concluded a data processing agreement with Microsoft within the meaning of Art. 28 Para. 3 GDPR. Under this agreement, Microsoft undertakes in particular to process personal data in accordance with our documented instructions and for the provision of the agreed services, to implement appropriate technical and organisational protective measures, and to engage sub-processors in accordance with the contractual provisions.
For certain business operations associated with the provision of Microsoft services, Microsoft may process personal data under its own data protection responsibility. This applies in particular to processing activities for which Microsoft itself determines the purposes and means of processing and assumes the obligations of a controller under the applicable contractual data protection provisions.
Further information on data processing by Microsoft can be found at https://www.microsoft.com/en-gb/privacy/privacystatement. Further information on the Microsoft Products and Services Data Protection Addendum can be found at https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA
Our social media profiles
Data processing by social networks and platforms
We maintain publicly accessible profiles and presences on social networks and other platforms. The providers we use are listed below.
When you visit one of our social media profiles, the respective platform operator may process personal data relating to you. This may include, in particular, your IP address, device and browser information, details relating to your user account and information about your interactions with our profile.
Where you are logged into your user account, the platform operator may associate your visit to our social media profile with that account. Personal data may also be collected where you are not logged in or do not have an account with the relevant platform. This information may be collected, for example, through cookies, similar technologies, device identifiers or your IP address.
The platform operators may use the data collected to create usage and interest profiles. On this basis, personalised content and advertising may be displayed to you both within and outside the respective platform. Where you have a user account, personalised content and advertising may also be displayed across different devices.
We cannot fully trace or influence all processing activities carried out by the platform operators. The scope, purposes and legal bases of the processing, as well as the applicable retention periods, are largely determined by the respective provider. Further information is available in the privacy policies linked below.
Purposes and legal bases of our processing
We process personal data that you provide to us through our social media profiles or that becomes available to us in connection with your use of our profiles, in particular for the following purposes:
- Public relations and presentation of our organisation
- Providing information about our services, offers and events
- Communicating with interested parties, customers, guests, applicants and business partners
- Handling enquiries, messages, comments and other interactions
- Maintaining customer and business relationships
- Marketing and promoting our services
- Recruiting and approaching potential applicants
- Analysing the reach and use of our social media profiles
- Moderating our profiles and protecting them against abusive or unlawful content
We generally maintain our social media profiles and carry out the associated processing for the purposes of our legitimate interests in modern public relations, communicating with users, maintaining our business relationships and promoting our services (Art. 6 Para. 1 lit. f GDPR).
Where your contact relates to a contract to which you are a party or to pre-contractual measures taken at your request, the processing is based on Art. 6 Para. 1 lit. b GDPR.
Where we obtain your consent for a particular processing activity, the processing is based on Art. 6 Para. 1 lit. a and Art. 7 GDPR. Where processing is necessary for compliance with a legal obligation, it is based on Art. 6 Para. 1 lit. c GDPR.
The legal bases for processing carried out independently by the platform operators are explained in their respective privacy policies.
Controllers and the exercise of your rights
We are the controller for processing activities for which we determine the purposes and means of processing. This applies in particular to content published by us and to the processing of messages, comments and other interactions addressed directly to us (Art. 4 No. 7 GDPR).
The respective platform operator is generally an independent controller for the processing of personal data carried out for its own purposes in connection with operating the platform, providing user accounts, analysing user behaviour or displaying advertising.
Where we jointly determine the purposes and means of particular processing activities with a platform operator, we and the platform operator are joint controllers. This may apply in particular to the preparation and provision of aggregated usage statistics or so-called insights data. In such cases, the respective responsibilities are determined in an arrangement concerning joint controllership (Art. 26 Para. 1 and 2 GDPR).
Where joint controllership exists, you may generally exercise your rights against either us or the respective platform operator (Art. 26 Para. 3 GDPR). Please note that the platform operator generally has sole or more comprehensive access to the user, device and usage data processed by it. The platform operator can therefore often respond directly to corresponding requests.
Further information about your rights is available in the section entitled “Rights of the data subject” in this Privacy Policy.
Recipients and public visibility
Within our organisation, access to personal data processed through our social media profiles is restricted to those persons and departments that require it for the purposes described above.
Recipients of the data also include the respective platform operators and any service providers engaged by them. Depending on your settings and the nature of your interaction, posts, comments, reactions or other content published by you may be visible to other users or to the public.
Personal data is disclosed to other recipients only where an appropriate legal basis applies and the disclosure is necessary for the respective purpose (Art. 6 Para. 1 GDPR).
Transfers to third countries
Some platform operators or their affiliated companies also process personal data in countries outside the European Union or the European Economic Area.
Where personal data is transferred to a third country, the transfer must be based on one of the mechanisms provided for in Art. 44 et seq. GDPR. These may include an adequacy decision adopted by the European Commission or appropriate safeguards such as the European Commission’s standard contractual clauses (Art. 45 and Art. 46 GDPR).
Further information about international data transfers and the safeguards used is available in the privacy policy of the respective platform operator.
Retention periods and erasure
We retain personal data that we process directly through our social media profiles only for as long as necessary for the purposes described above.
Where the purpose of processing no longer applies and there is no statutory retention obligation or other legal basis for continued storage, the data will be erased. Data may be retained for a longer period where this is necessary for compliance with legal obligations or for the establishment, exercise or defence of legal claims (Art. 5 Para. 1 lit. e and Art. 17 Para. 1 lit. a and Para. 3 lit. b and e GDPR).
Depending on the respective platform, posts, comments and other content published by you may remain publicly visible or visible to other users until you, we or the platform operator delete that content. We generally have no influence over how long the platform operator retains data for its own purposes. Details are available in the respective provider’s privacy policy.
We maintain a profile on Facebook. The provider for users in the European Economic Area is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5 Ireland.
For certain processing activities relating to Page Insights, we and Meta Platforms Ireland Limited may be joint controllers (Art. 26 GDPR).
The Page Controller Addendum is available here: https://www.facebook.com/legal/terms/page_controller_addendum?locale=en_GB
Meta’s English-language Privacy Policy for Facebook and Instagram is available here: https://www.facebook.com/privacy/policy/?locale=en_GB
We maintain a profile on Instagram. The provider for users in the European Economic Area is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
Meta’s English-language Privacy Policy for Facebook and Instagram is available here: https://www.facebook.com/privacy/policy/?locale=en_GB
We maintain a profile on LinkedIn. The provider for users in the European Union, the European Economic Area and Switzerland is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland.
LinkedIn’s English-language Privacy Policy is available here: https://www.linkedin.com/legal/privacy-policy
The supplementary European Regional Privacy Notice is available here: https://www.linkedin.com/legal/privacy/eu
We maintain a profile on XING. The provider is New Work SE, Baumwall 7, 20459 Hamburg, Germany.
XING’s English-language Privacy Policy is available here: https://privacy.xing.com/en/privacy-policy
Tripadvisor
We maintain a profile on Tripadvisor. The controller for processing carried out by Tripadvisor is Tripadvisor LLC, 400 1st Avenue, Needham, MA 02494, USA.
Tripadvisor has appointed the following representative in the European Union Tripadvisor Ireland Limited, c/o Matheson, 70 Sir John Rogerson’s Quay, Dublin 2, D02 R296, Ireland.
Tripadvisor’s English-language Privacy and Cookies Statement is available here: https://tripadvisor.mediaroom.com/uk-privacy-policy
5. Final provisions
Hannover, August 2026
Amendments to this Privacy Policy
We reserve the right to amend this Privacy Policy where this becomes necessary due to changes in the law, regulatory or judicial requirements, technological developments or changes to our services and processing activities.
The current version published on this website applies. The version date of this Privacy Policy can be found in the place and date information provided above.
Where required by law, we will inform you of material amendments to this Privacy Policy in an appropriate manner.