Privacy Policy

1. An overview of data protection

General information

The fol­lo­wing infor­ma­ti­on will provide you with an easy to navi­ga­te over­view of what will happen with your per­so­nal data when you visit this website. The term “per­so­nal data” com­pri­ses all data that can be used to per­so­nal­ly iden­ti­fy you. For detail­ed infor­ma­ti­on about the subject matter of data pro­tec­tion, please consult our Data Pro­tec­tion Decla­ra­ti­on, which we have included beneath this copy.

Data recording on this website

Who is the responsible party for the recording of data on this website (i.e., the “controller”)?

The data on this website is pro­ces­sed by the ope­ra­tor of the website, whose contact infor­ma­ti­on is available under section “Infor­ma­ti­on about the respon­si­ble party (refer­red to as the “con­trol­ler” in the GDPR)” in this Privacy Policy.

How do we record your data?

We collect your data as a result of your sharing of your data with us. This may, for ins­tance be infor­ma­ti­on you enter into our contact form.

Other data shall be recor­ded by our IT systems auto­ma­ti­cal­ly or after you consent to its recor­ding during your website visit. This data com­pri­ses pri­ma­ri­ly tech­ni­cal infor­ma­ti­on (e.g., web browser, ope­ra­ting system, or time the site was acces­sed). This infor­ma­ti­on is recor­ded auto­ma­ti­cal­ly when you access this website.

What are the purposes we use your data for?

A portion of the infor­ma­ti­on is gene­ra­ted to gua­ran­tee the error free pro­vi­si­on of the website. Other data may be used to analyze your user pat­terns. If con­tracts can be con­cluded or initia­ted via the website, the trans­mit­ted data will also be pro­ces­sed for con­tract offers, orders or other order enqui­ries.

What rights do you have as far as your information is concerned?

You have the right to receive infor­ma­ti­on about the source, reci­pi­ents, and pur­po­ses of your archi­ved per­so­nal data at any time without having to pay a fee for such dis­clo­sures. You also have the right to demand that your data are rec­ti­fied or era­di­ca­ted. If you have con­sen­ted to data pro­ces­sing, you have the option to revoke this consent at any time, which shall affect all future data pro­ces­sing. Moreo­ver, you have the right to demand that the pro­ces­sing of your data be rest­ric­ted under certain cir­cum­s­tances. Fur­ther­mo­re, you have the right to log a com­plaint with the com­pe­tent super­vi­sing agency.

Please do not hesi­ta­te to contact us at any time if you have ques­ti­ons about this or any other data pro­tec­tion related issues.

Analysis tools and tools provided by third parties

There is a pos­si­bi­li­ty that your brow­sing pat­terns will be sta­tis­ti­cal­ly ana­ly­zed when your visit this website. Such ana­ly­ses are per­for­med pri­ma­ri­ly with what we refer to as ana­ly­sis pro­grams.

For detail­ed infor­ma­ti­on about these ana­ly­sis pro­grams please consult our Data Pro­tec­tion Decla­ra­ti­on below.

2. Hosting

We are hosting the content of our website at the fol­lo­wing pro­vi­der:

Raidboxes

The pro­vi­der is the Raid­bo­xes GmbH, Hafenstr. 32, 48153 Münster, Germany (her­ein­af­ter refer­red to as: Raid­bo­xes). When­ever you visit our website, Raid­bo­xes will record a variety of log­files, inclu­ding your IP addres­ses.

For details, please refer to the Data Privacy Policy of Raid­bo­xes: https://raidboxes.io/legal/privacy/.

We use Raid­bo­xes on the basis of Art. 6(1)(f) GDPR. We have a legi­ti­ma­te inte­rest in making the depic­tion of our website as depen­da­ble as pos­si­ble. If you have been asked for your respec­ti­ve consent, pro­ces­sing shall occur exclu­si­ve­ly on the basis of Art. 6 (1)(a) GDPR and § 25(1) TDDDG, if the consent com­pri­ses the archi­ving of cookies or access to infor­ma­ti­on on the user’s device (e.g., device finger prin­ting) as defined in the TDDDG. Such consent may be revoked at any time.

FastPixel

We use the Fast­Pi­xel service to acce­le­ra­te this website. The pro­vi­der is Faster Web Solu­ti­ons SRL, Str. Tran­sil­va­niei nr. 2, Camera 5, Bl. 5, Ap. 19, Sector 1, 010798 Bucha­rest, Romania (her­ein­af­ter „Fast­Pi­xel“).

Fast­Pi­xel opti­mi­ses the content of this website – in par­ti­cu­lar images, fonts and CSS and Java­Script files – and deli­vers it via its own content deli­very network (CDN). In doing so, Fast­Pi­xel pro­ces­ses tech­ni­cal data of website visi­tors, in par­ti­cu­lar the IP address, browser and device infor­ma­ti­on as well as the date and time of access. This data is pro­ces­sed in order to provide and safe­guard the service, to dia­gno­se errors and to count page views.

Fast­Pi­xel is used on the basis of Art. 6(1)(f) GDPR. We have a legi­ti­ma­te inte­rest in pro­vi­ding this website quickly and relia­bly. Where consent has been reques­ted, the pro­ces­sing takes place exclu­si­ve­ly on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as that consent covers the storage of cookies or access to infor­ma­ti­on in the user’s end device within the meaning of the TDDDG. Consent can be revoked at any time.

The pro­vi­der is based in Romania and the­r­e­fo­re within the Euro­pean Union. Insofar as Fast­Pi­xel engages further pro­ces­sors – inclu­ding in third count­ries – in order to provide the service, the data trans­fer is safe­guard­ed by appro­pria­te gua­ran­tees such as the stan­dard con­trac­tu­al clauses of the EU Com­mis­si­on.

For further infor­ma­ti­on on how your data is handled, please see FastPixel’s privacy policy: https://fastpixel.io/privacy/.

External Hosting

This website is hosted extern­al­ly. The per­so­nal data coll­ec­ted on this website is stored on the servers of the host or hosts. This may pri­ma­ri­ly involve IP addres­ses, contact requests, meta and com­mu­ni­ca­ti­on data, con­tract data, contact details, names, website acces­ses and other data gene­ra­ted via a website.

The exter­nal hosting takes place for the purpose of ful­fil­ling our con­tract with our poten­ti­al and exis­ting cus­to­mers (Art. 6(1)(b) GDPR) and in the inte­rest of a secure, fast and effi­ci­ent pro­vi­si­on of our online service by a pro­fes­sio­nal pro­vi­der (Art. 6(1)(f) GDPR). Where consent has been reques­ted, the pro­ces­sing takes place exclu­si­ve­ly on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as that consent covers the storage of cookies or access to infor­ma­ti­on in the user’s end device (e.g. device fin­ger­prin­ting) within the meaning of the TDDDG. Consent can be revoked at any time.

Our host or hosts will only process your data to the extent neces­sa­ry to fulfil their per­for­mance obli­ga­ti­ons and will follow our ins­truc­tions with regard to this data.

We use the fol­lo­wing host:

Johan­nes Hüsch
Markt­str. 100
76829 Landau

3. General information and mandatory information

Data protection

The ope­ra­tors of this website and its pages take the pro­tec­tion of your per­so­nal data very serious­ly. Hence, we handle your per­so­nal data as con­fi­den­ti­al infor­ma­ti­on and in com­pli­ance with the sta­tu­to­ry data pro­tec­tion regu­la­ti­ons and this Data Pro­tec­tion Decla­ra­ti­on.

When­ever you use this website, a variety of per­so­nal infor­ma­ti­on will be coll­ec­ted. Per­so­nal data com­pri­ses data that can be used to per­so­nal­ly iden­ti­fy you. This Data Pro­tec­tion Decla­ra­ti­on explains which data we collect as well as the pur­po­ses we use this data for. It also explains how, and for which purpose the infor­ma­ti­on is coll­ec­ted.

We here­wi­th advise you that the trans­mis­si­on of data via the Inter­net (i.e., through e‑mail com­mu­ni­ca­ti­ons) may be prone to secu­ri­ty gaps. It is not pos­si­ble to com­ple­te­ly protect data against third-party access.

Information about the responsible party (referred to as the “controller” in the GDPR)

The data pro­ces­sing con­trol­ler on this website is:

Gebr. Engel­horn GmbH
Ernst-Naujoks-Straße 2
69181 Leimen

Telefon: +49 (0) 6224 7070
E‑Mail: info@hotel-engelhorn.de

Phone: [Tele­fon­num­mer der ver­ant­wort­li­chen Stelle]
E‑mail: [E‑Mail-Adresse der ver­ant­wort­li­chen Stelle]

The con­trol­ler is the natural person or legal entity that single-han­dedly or jointly with others makes decis­i­ons as to the pur­po­ses of and resour­ces for the pro­ces­sing of per­so­nal data (e.g., names, e‑mail addres­ses, etc.).

Storage duration

Unless a more spe­ci­fic storage period has been spe­ci­fied in this privacy policy, your per­so­nal data will remain with us until the purpose for which it was coll­ec­ted no longer applies. If you assert a jus­ti­fied request for dele­ti­on or revoke your consent to data pro­ces­sing, your data will be deleted, unless we have other legally per­mis­si­ble reasons for storing your per­so­nal data (e.g., tax or com­mer­cial law reten­ti­on periods); in the latter case, the dele­ti­on will take place after these reasons cease to apply.

General information on the legal basis for the data processing on this website

If you have con­sen­ted to data pro­ces­sing, we process your per­so­nal data on the basis of Art. 6(1)(a) GDPR or Art. 9 (2)(a) GDPR, if special cate­go­ries of data are pro­ces­sed accor­ding to Art. 9 (1) DSGVO. In the case of expli­cit consent to the trans­fer of per­so­nal data to third count­ries, the data pro­ces­sing is also based on Art. 49 (1)(a) GDPR. If you have con­sen­ted to the storage of cookies or to the access to infor­ma­ti­on in your end device (e.g., via device fin­ger­prin­ting), the data pro­ces­sing is addi­tio­nal­ly based on § 25 (1) TDDDG. The consent can be revoked at any time. If your data is requi­red for the ful­fill­ment of a con­tract or for the imple­men­ta­ti­on of pre-con­trac­tu­al mea­su­res, we process your data on the basis of Art. 6(1)(b) GDPR. Fur­ther­mo­re, if your data is requi­red for the ful­fill­ment of a legal obli­ga­ti­on, we process it on the basis of Art. 6(1)© GDPR. Fur­ther­mo­re, the data pro­ces­sing may be carried out on the basis of our legi­ti­ma­te inte­rest accor­ding to Art. 6(1)(f) GDPR. Infor­ma­ti­on on the rele­vant legal basis in each indi­vi­du­al case is pro­vi­ded in the fol­lo­wing para­graphs of this privacy policy.

Designation of a data protection officer

We have appoin­ted a data pro­tec­tion officer.

Timo Weber-Engel­horn
Ernst-Naujoks-Straße 2
69181 Leimen

Telefon: +49 6224 7070
E‑Mail: datenschutzbeauftragter@hotel-engelhorn.de

Phone: [Tele­fon­num­mer des Daten­schutz­be­auf­trag­ten]
E‑mail: [E‑Mail-Adresse des Daten­schutz­be­auf­trag­ten]

Recipients of personal data

In the scope of our busi­ness acti­vi­ties, we coöpe­ra­te with various exter­nal parties. In some cases, this also requi­res the trans­fer of per­so­nal data to these exter­nal parties. We only dis­c­lo­se per­so­nal data to exter­nal parties if this is requi­red as part of the ful­fill­ment of a con­tract, if we are legally obli­ga­ted to do so (e.g., dis­clo­sure of data to tax aut­ho­ri­ties), if we have a legi­ti­ma­te inte­rest in the dis­clo­sure pur­su­ant to Art. 6 (1)(f) GDPR, or if another legal basis permits the dis­clo­sure of this data. When using pro­ces­sors, we only dis­c­lo­se per­so­nal data of our cus­to­mers on the basis of a valid con­tract on data pro­ces­sing. In the case of joint pro­ces­sing, a joint pro­ces­sing agree­ment is con­cluded.

Revocation of your consent to the processing of data

A wide range of data pro­ces­sing tran­sac­tions are pos­si­ble only subject to your express consent. You can also revoke at any time any consent you have already given us. This shall be without pre­ju­di­ce to the lawful­ness of any data coll­ec­tion that occur­red prior to your revo­ca­ti­on.

Right to object to the collection of data in special cases; right to object to direct advertising (Art. 21 GDPR)

IN THE EVENT THAT DATA ARE PROCESSED ON THE BASIS OF ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT TO AT ANY TIME OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA BASED ON GROUNDS ARISING FROM YOUR UNIQUE SITUATION. THIS ALSO APPLIES TO ANY PROFILING BASED ON THESE PROVISIONS. TO DETERMINE THE LEGAL BASIS, ON WHICH ANY PROCESSING OF DATA IS BASED, PLEASE CONSULT THIS DATA PROTECTION DECLARATION. IF YOU LOG AN OBJECTION, WE WILL NO LONGER PROCESS YOUR AFFECTED PERSONAL DATA, UNLESS WE ARE IN A POSITION TO PRESENT COMPELLING PROTECTION WORTHY GROUNDS FOR THE PROCESSING OF YOUR DATA, THAT OUTWEIGH YOUR INTERESTS, RIGHTS AND FREEDOMS OR IF THE PURPOSE OF THE PROCESSING IS THE CLAIMING, EXERCISING OR DEFENCE OF LEGAL ENTITLEMENTS (OBJECTION PURSUANT TO ART. 21(1) GDPR).

IF YOUR PERSONAL DATA IS BEING PROCESSED IN ORDER TO ENGAGE IN DIRECT ADVERTISING, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR AFFECTED PERSONAL DATA FOR THE PURPOSES OF SUCH ADVERTISING AT ANY TIME. THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS AFFILIATED WITH SUCH DIRECT ADVERTISING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR DIRECT ADVERTISING PURPOSES (OBJECTION PURSUANT TO ART. 21(2) GDPR).

Right to log a complaint with the competent supervisory agency

In the event of vio­la­ti­ons of the GDPR, data sub­jects are entit­led to log a com­plaint with a super­vi­so­ry agency, in par­ti­cu­lar in the member state where they usually main­tain their domic­i­le, place of work or at the place where the alleged vio­la­ti­on occur­red. The right to log a com­plaint is in effect regard­less of any other admi­nis­tra­ti­ve or court pro­cee­dings available as legal recour­ses.

Right to data portability

You have the right to have data that we process auto­ma­ti­cal­ly on the basis of your consent or in ful­fill­ment of a con­tract handed over to you or to a third party in a common, machine-rea­da­ble format. If you should demand the direct trans­fer of the data to another con­trol­ler, this will be done only if it is tech­ni­cal­ly fea­si­ble.

Information about, rectification and eradication of data

Within the scope of the appli­ca­ble sta­tu­to­ry pro­vi­si­ons, you have the right to demand infor­ma­ti­on about your archi­ved per­so­nal data, their source and reci­pi­ents as well as the purpose of the pro­ces­sing of your data at any time. You may also have a right to have your data rec­ti­fied or era­di­ca­ted. If you have ques­ti­ons about this subject matter or any other ques­ti­ons about per­so­nal data, please do not hesi­ta­te to contact us at any time.

Right to demand processing restrictions

You have the right to demand the impo­si­ti­on of rest­ric­tions as far as the pro­ces­sing of your per­so­nal data is con­cer­ned. To do so, you may contact us at any time. The right to demand rest­ric­tion of pro­ces­sing applies in the fol­lo­wing cases:

  • In the event that you should dispute the cor­rect­ness of your data archi­ved by us, we will usually need some time to verify this claim. During the time that this inves­ti­ga­ti­on is ongoing, you have the right to demand that we rest­rict the pro­ces­sing of your per­so­nal data.
  • If the pro­ces­sing of your per­so­nal data was/is con­duc­ted in an unlawful manner, you have the option to demand the rest­ric­tion of the pro­ces­sing of your data instead of deman­ding the era­di­ca­ti­on of this data.
  • If we do not need your per­so­nal data any longer and you need it to exer­cise, defend or claim legal entit­le­ments, you have the right to demand the rest­ric­tion of the pro­ces­sing of your per­so­nal data instead of its era­di­ca­ti­on.
  • If you have raised an objec­tion pur­su­ant to Art. 21(1) GDPR, your rights and our rights will have to be weighed against each other. As long as it has not been deter­mi­ned whose inte­rests prevail, you have the right to demand a rest­ric­tion of the pro­ces­sing of your per­so­nal data.

If you have rest­ric­ted the pro­ces­sing of your per­so­nal data, these data – with the excep­ti­on of their archi­ving – may be pro­ces­sed only subject to your consent or to claim, exer­cise or defend legal entit­le­ments or to protect the rights of other natural persons or legal enti­ties or for important public inte­rest reasons cited by the Euro­pean Union or a member state of the EU.

SSL and/or TLS encryption

For secu­ri­ty reasons and to protect the trans­mis­si­on of con­fi­den­ti­al content, such as purcha­se orders or inqui­ries you submit to us as the website ope­ra­tor, this website uses either an SSL or a TLS encryp­ti­on program. You can reco­gni­ze an encrypt­ed con­nec­tion by che­cking whether the address line of the browser swit­ches from “http://” to “https://” and also by the appearance of the lock icon in the browser line.

If the SSL or TLS encryp­ti­on is acti­va­ted, data you trans­mit to us cannot be read by third parties.

Rejection of unsolicited e‑mails

We here­wi­th object to the use of contact infor­ma­ti­on published in con­junc­tion with the man­da­to­ry infor­ma­ti­on to be pro­vi­ded in our Site Notice to send us pro­mo­tio­nal and infor­ma­ti­on mate­ri­al that we have not express­ly reques­ted. The ope­ra­tors of this website and its pages reserve the express right to take legal action in the event of the unso­li­ci­ted sending of pro­mo­tio­nal infor­ma­ti­on, for ins­tance via SPAM mes­sa­ges.

4. Recording of data on this website

Cookies

Our web­sites and pages use what the indus­try refers to as “cookies.” Cookies are small data packa­ges that do not cause any damage to your device. They are either stored tem­po­r­a­ri­ly for the dura­ti­on of a session (session cookies) or they are per­ma­nent­ly archi­ved on your device (per­ma­nent cookies). Session cookies are auto­ma­ti­cal­ly deleted once you ter­mi­na­te your visit. Per­ma­nent cookies remain archi­ved on your device until you actively delete them, or they are auto­ma­ti­cal­ly era­di­ca­ted by your web browser.

Cookies can be issued by us (first-party cookies) or by third-party com­pa­nies (so-called third-party cookies). Third-party cookies enable the inte­gra­ti­on of certain ser­vices of third-party com­pa­nies into web­sites (e.g., cookies for hand­ling payment ser­vices).

Cookies have a variety of func­tions. Many cookies are tech­ni­cal­ly essen­ti­al since certain website func­tions would not work in the absence of these cookies (e.g., the shop­ping cart func­tion or the display of videos). Other cookies may be used to analyze user beha­vi­or or for pro­mo­tio­nal pur­po­ses.

Cookies, which are requi­red for the per­for­mance of elec­tro­nic com­mu­ni­ca­ti­on tran­sac­tions, for the pro­vi­si­on of certain func­tions you want to use (e.g., for the shop­ping cart func­tion) or those that are neces­sa­ry for the opti­miza­ti­on (requi­red cookies) of the website (e.g., cookies that provide mea­sura­ble insights into the web audi­ence), shall be stored on the basis of Art. 6(1)(f) GDPR, unless a dif­fe­rent legal basis is cited. The ope­ra­tor of the website has a legi­ti­ma­te inte­rest in the storage of requi­red cookies to ensure the tech­ni­cal­ly error-free and opti­mi­zed pro­vi­si­on of the operator’s ser­vices. If your consent to the storage of the cookies and similar reco­gni­ti­on tech­no­lo­gies has been reques­ted, the pro­ces­sing occurs exclu­si­ve­ly on the basis of the consent obtai­ned (Art. 6(1)(a) GDPR and § 25 (1) TDDDG); this consent may be revoked at any time.

You have the option to set up your browser in such a manner that you will be noti­fied any time cookies are placed and to permit the accep­tance of cookies only in spe­ci­fic cases. You may also exclude the accep­tance of cookies in certain cases or in general or acti­va­te the delete-func­tion for the auto­ma­tic era­di­ca­ti­on of cookies when the browser closes. If cookies are deac­ti­va­ted, the func­tions of this website may be limited.

If other cookies and ser­vices are used on this website, you can find this infor­ma­ti­on in this privacy policy.

Overview of the cookies in use

The table below lists all cookies and ser­vices used on this website – each with its name, pro­vi­der, purpose and storage period. This allows you to see at any time what is stored on this website and for what purpose.

Your personal consent

Below you will find the consent ID stored for your browser and the history of the consent decis­i­ons you have made on this website.

Consent with Borlabs Cookie

Our website uses the Borlabs consent tech­no­lo­gy to obtain your consent to the storage of certain cookies in your browser or for the use of certain tech­no­lo­gies and for their data privacy pro­tec­tion com­pli­ant docu­men­ta­ti­on. The pro­vi­der of this tech­no­lo­gy is Borlabs GmbH, Ham­bur­ger Str. 11, 22083 Hamburg, Germany (her­ein­af­ter refer­red to as Borlabs).

When­ever you visit our website, a Borlabs cookie will be stored in your browser, which archi­ves any decla­ra­ti­ons or revo­ca­ti­ons of consent you have entered. These data are not shared with the pro­vi­der of the Borlabs tech­no­lo­gy.

The recor­ded data shall remain archi­ved until you ask us to era­di­ca­te them, delete the Borlabs cookie on your own or the purpose of storing the data no longer exists. This shall be without pre­ju­di­ce to any reten­ti­on obli­ga­ti­ons man­da­ted by law. To review the details of Borlabs’ data pro­ces­sing poli­ci­es, please visit https://de.borlabs.io/kb/welche-daten-speichert-borlabs-cookie/

We use the Borlabs cookie consent tech­no­lo­gy to obtain the decla­ra­ti­ons of consent man­da­ted by law for the use of cookies. The legal basis for the use of such cookies is Art. 6(1)© GDPR.

Server log files

The pro­vi­der of this website and its pages auto­ma­ti­cal­ly coll­ects and stores infor­ma­ti­on in so-called server log files, which your browser com­mu­ni­ca­tes to us auto­ma­ti­cal­ly. The infor­ma­ti­on com­pri­ses:

  • The type and version of browser used
  • The used ope­ra­ting system
  • Refer­rer URL
  • The host­na­me of the acces­sing com­pu­ter
  • The time of the server inquiry
  • The IP address

This data is not merged with other data sources.

This data is recor­ded on the basis of Art. 6(1)(f) GDPR. The ope­ra­tor of the website has a legi­ti­ma­te inte­rest in the tech­ni­cal­ly error free depic­tion and the opti­miza­ti­on of the operator’s website. In order to achieve this, server log files must be recor­ded.

Contact form

If you submit inqui­ries to us via our contact form, the infor­ma­ti­on pro­vi­ded in the contact form as well as any contact infor­ma­ti­on pro­vi­ded therein will be stored by us in order to handle your inquiry and in the event that we have further ques­ti­ons. We will not share this infor­ma­ti­on without your consent.

The pro­ces­sing of these data is based on Art. 6(1)(b) GDPR, if your request is related to the exe­cu­ti­on of a con­tract or if it is neces­sa­ry to carry out pre-con­trac­tu­al mea­su­res. In all other cases the pro­ces­sing is based on our legi­ti­ma­te inte­rest in the effec­ti­ve pro­ces­sing of the requests addres­sed to us (Art. 6(1)(f) GDPR) or on your agree­ment (Art. 6(1)(a) GDPR) if this has been reques­ted; the consent can be revoked at any time.

The infor­ma­ti­on you have entered into the contact form shall remain with us until you ask us to era­di­ca­te the data, revoke your consent to the archi­ving of data or if the purpose for which the infor­ma­ti­on is being archi­ved no longer exists (e.g., after we have con­cluded our respon­se to your inquiry). This shall be without pre­ju­di­ce to any man­da­to­ry legal pro­vi­si­ons, in par­ti­cu­lar reten­ti­on periods.

Request by e‑mail, telephone, or fax

If you contact us by e‑mail, tele­pho­ne or fax, your request, inclu­ding all resul­ting per­so­nal data (name, request) will be stored and pro­ces­sed by us for the purpose of pro­ces­sing your request. We do not pass these data on without your consent.

These data are pro­ces­sed on the basis of Art. 6(1)(b) GDPR if your inquiry is related to the ful­fill­ment of a con­tract or is requi­red for the per­for­mance of pre-con­trac­tu­al mea­su­res. In all other cases, the data are pro­ces­sed on the basis of our legi­ti­ma­te inte­rest in the effec­ti­ve hand­ling of inqui­ries sub­mit­ted to us (Art. 6(1)(f) GDPR) or on the basis of your consent (Art. 6(1)(a) GDPR) if it has been obtai­ned; the consent can be revoked at any time.

The data sent by you to us via contact requests remain with us until you request us to delete, revoke your consent to the storage or the purpose for the data storage lapses (e.g. after com­ple­ti­on of your request). Man­da­to­ry sta­tu­to­ry pro­vi­si­ons – in par­ti­cu­lar sta­tu­to­ry reten­ti­on periods – remain unaf­fec­ted.

5. Analysis tools and advertising

Google Tag Manager

We use the Google Tag Manager. The pro­vi­der is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland

The Google Tag Manager is a tool that allows us to inte­gra­te track­ing or sta­tis­ti­cal tools and other tech­no­lo­gies on our website. The Google Tag Manager itself does not create any user pro­files, does not store cookies, and does not carry out any inde­pen­dent ana­ly­ses. It only manages and runs the tools inte­gra­ted via it. However, the Google Tag Manager does collect your IP address, which may also be trans­fer­red to Google’s parent company in the United States.

The Google Tag Manager is used on the basis of Art. 6(1)(f) GDPR. The website ope­ra­tor has a legi­ti­ma­te inte­rest in the quick and uncom­pli­ca­ted inte­gra­ti­on and admi­nis­tra­ti­on of various tools on his website. If appro­pria­te consent has been obtai­ned, the pro­ces­sing is carried out exclu­si­ve­ly on the basis of Art. 6(1)(a) GDPR and § 25 (1) TDDDG, insofar the consent includes the storage of cookies or the access to infor­ma­ti­on in the user’s end device (e.g., device fin­ger­prin­ting) within the meaning of the TDDDG. This consent can be revoked at any time.

The company is cer­ti­fied in accordance with the “EU-US Data Privacy Frame­work” (DPF). The DPF is an agree­ment between the Euro­pean Union and the US, which is inten­ded to ensure com­pli­ance with Euro­pean data pro­tec­tion stan­dards for data pro­ces­sing in the US. Every company cer­ti­fied under the DPF is obliged to comply with these data pro­tec­tion stan­dards. For more infor­ma­ti­on, please contact the pro­vi­der under the fol­lo­wing link: https://www.dataprivacyframework.gov/participant/5780.

Google Analytics

This website uses func­tions of the web ana­ly­sis service Google Ana­ly­tics. The pro­vi­der of this service is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Ana­ly­tics enables the website ope­ra­tor to analyze the beha­vi­or pat­terns of website visi­tors. To that end, the website ope­ra­tor recei­ves a variety of user data, such as pages acces­sed, time spent on the page, the uti­li­zed ope­ra­ting system and the user’s origin. This data is assi­gned to the respec­ti­ve end device of the user. An assign­ment to a user-ID does not take place.

Fur­ther­mo­re, Google Ana­ly­tics allows us to record your mouse and scroll move­ments and clicks, among other things. Google Ana­ly­tics uses various mode­ling approa­ches to augment the coll­ec­ted data sets and uses machine lear­ning tech­no­lo­gies in data ana­ly­sis.

Google Ana­ly­tics uses tech­no­lo­gies that make the reco­gni­ti­on of the user for the purpose of ana­ly­zing the user beha­vi­or pat­terns (e.g., cookies or device fin­ger­prin­ting). The website use infor­ma­ti­on recor­ded by Google is, as a rule trans­fer­red to a Google server in the United States, where it is stored.

The use of these ser­vices occurs on the basis of your consent pur­su­ant to Art. 6(1)(a) GDPR and § 25(1) TDDDG. You may revoke your consent at any time.

Data trans­mis­si­on to the US is based on the Stan­dard Con­trac­tu­al Clauses (SCC) of the Euro­pean Com­mis­si­on. Details can be found here: https://business.safety.google/adscontrollerterms/sccs/.

The company is cer­ti­fied in accordance with the “EU-US Data Privacy Frame­work” (DPF). The DPF is an agree­ment between the Euro­pean Union and the US, which is inten­ded to ensure com­pli­ance with Euro­pean data pro­tec­tion stan­dards for data pro­ces­sing in the US. Every company cer­ti­fied under the DPF is obliged to comply with these data pro­tec­tion stan­dards. For more infor­ma­ti­on, please contact the pro­vi­der under the fol­lo­wing link: https://www.dataprivacyframework.gov/participant/5780.

IP anonymization

Google Ana­ly­tics IP anony­miza­ti­on is active. As a result, your IP address will be abbre­via­ted by Google within the member states of the Euro­pean Union or in other states that have rati­fied the Con­ven­ti­on on the Euro­pean Eco­no­mic Area prior to its trans­mis­si­on to the United States. The full IP address will be trans­mit­ted to one of Google’s servers in the United States and abbre­via­ted there only in excep­tio­nal cases. On behalf of the ope­ra­tor of this website, Google shall use this infor­ma­ti­on to analyze your use of this website to gene­ra­te reports on website acti­vi­ties and to render other ser­vices to the ope­ra­tor of this website that are related to the use of the website and the Inter­net. The IP address trans­mit­ted in con­junc­tion with Google Ana­ly­tics from your browser shall not be merged with other data in Google’s pos­ses­si­on.

Browser plug-in

You can prevent the recor­ding and pro­ces­sing of your data by Google by down­loa­ding and instal­ling the browser plugin available under the fol­lo­wing link: https://tools.google.com/dlpage/gaoptout?hl=en.

For more infor­ma­ti­on about the hand­ling of user data by Google Ana­ly­tics, please consult Google’s Data Privacy Decla­ra­ti­on at: https://support.google.com/analytics/answer/6004245?hl=en.

Google Ads

The website ope­ra­tor uses Google Ads. Google Ads is an online pro­mo­tio­nal program of Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Ads enables us to display ads in the Google search engine or on third-party web­sites, if the user enters certain search terms into Google (keyword tar­ge­ting). It is also pos­si­ble to place tar­ge­ted ads based on the user data Google has in its pos­ses­si­on (e.g., loca­ti­on data and inte­rests; target group tar­ge­ting). As the website ope­ra­tor, we can analyze these data quan­ti­ta­tively, for ins­tance by ana­ly­zing which search terms resul­ted in the display of our ads and how many ads led to respec­ti­ve clicks.

The use of these ser­vices occurs on the basis of your consent pur­su­ant to Art. 6(1)(a) GDPR and § 25(1) TDDDG. You may revoke your consent at any time.

Data trans­mis­si­on to the US is based on the Stan­dard Con­trac­tu­al Clauses (SCC) of the Euro­pean Com­mis­si­on. Details can be found here: https://policies.google.com/privacy/frameworks and https://business.safety.google/controllerterms/.

The company is cer­ti­fied in accordance with the “EU-US Data Privacy Frame­work” (DPF). The DPF is an agree­ment between the Euro­pean Union and the US, which is inten­ded to ensure com­pli­ance with Euro­pean data pro­tec­tion stan­dards for data pro­ces­sing in the US. Every company cer­ti­fied under the DPF is obliged to comply with these data pro­tec­tion stan­dards. For more infor­ma­ti­on, please contact the pro­vi­der under the fol­lo­wing link: https://www.dataprivacyframework.gov/participant/5780.

6. Newsletter

Newsletter data

If you would like to receive the news­let­ter offered on the website, we require an e‑mail address from you as well as infor­ma­ti­on that allows us to verify that you are the owner of the e‑mail address pro­vi­ded and that you agree to receive the news­let­ter. Further data is not coll­ec­ted or only on a vol­un­t­a­ry basis. For the hand­ling of the news­let­ter, we use news­let­ter service pro­vi­ders, which are descri­bed below.

Brevo

This website uses Brevo for the sending of news­let­ters. The pro­vi­der is Brevo GmbH (form­er­ly Sen­din­blue GmbH), Köpe­ni­cker Straße 126, 10179 Berlin, Germany.

Brevo ser­vices can, among other things, be used to orga­ni­ze and analyze the sending of news­let­ters. The data you enter for the purpose of sub­scrib­ing to the news­let­ter are archi­ved on servers of Brevo GmbH in Germany.

Data analysis by Brevo

Brevo enables us to analyze our news­let­ter cam­paigns. For ins­tance, it allows us to see whether a news­let­ter message has been opened and, if so, which links may have been clicked. This enables us to deter­mi­ne, which links drew an extra­or­di­na­ry number of clicks.

Moreo­ver, we are also able to see whether once the e‑mail was opened or a link was clicked, any pre­vious­ly defined actions were taken (con­ver­si­on rate). This allows us to deter­mi­ne whether you have made a purcha­se after cli­cking on the news­let­ter.

Brevo also enables us to divide the sub­scri­bers to our news­let­ter into various cate­go­ries (i.e., to “cluster” reci­pi­ents). For ins­tance, news­let­ter reci­pi­ents can be cate­go­ri­zed based on age, gender, or place of resi­dence. This enables us to tailor our news­let­ter more effec­tively to the needs of the respec­ti­ve target groups.

If you do not want to permit an ana­ly­sis by Brevo, you must unsub­scri­be from the news­let­ter. We provide a link for you to do this in every news­let­ter message. Moreo­ver, you can also unsub­scri­be from the news­let­ter right on the website.

For detail­ed infor­ma­ti­on on the func­tions of Brevo please follow this link: https://www.brevo.com/de/newsletter-software/.

Legal basis

The data is pro­ces­sed based on your consent (Art. 6(1)(a) GDPR). You may revoke any consent you have given at any time by unsub­scrib­ing from the news­let­ter. This shall be without pre­ju­di­ce to the lawful­ness of any data pro­ces­sing tran­sac­tions that have taken place prior to your revo­ca­ti­on.

Storage period

The data depo­si­ted with us for the purpose of sub­scrib­ing to the news­let­ter will be stored by us until you unsub­scri­be from the news­let­ter or the news­let­ter service pro­vi­der and deleted from the news­let­ter dis­tri­bu­ti­on list after you unsub­scri­be from the news­let­ter. Data stored for other pur­po­ses with us remain unaf­fec­ted.

After you unsub­scri­be from the news­let­ter dis­tri­bu­ti­on list, your e‑mail address may be stored by us or the news­let­ter service pro­vi­der in a black­list, if such action is neces­sa­ry to prevent future mai­lings. The data from the black­list is used only for this purpose and not merged with other data. This serves both your inte­rest and our inte­rest in com­ply­ing with the legal requi­re­ments when sending news­let­ters (legi­ti­ma­te inte­rest within the meaning of Art. 6(1)(f) GDPR). The storage in the black­list is inde­fi­ni­te. You may object to the storage if your inte­rests out­weigh our legi­ti­ma­te inte­rest.

For more details, please consult the Data Pro­tec­tion Regu­la­ti­ons of Brevo at: https://www.brevo.com/de/datenschutz-uebersicht/ and https://www.brevo.com/de/legal/privacypolicy/.

7. Plug-ins and Tools

Google Maps

This website uses the mapping service Google Maps. The pro­vi­der is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. With the means of this service, we can inte­gra­te map mate­ri­al on our website.

To enable the use of the Google Maps fea­tures, your IP address must be stored. As a rule, this infor­ma­ti­on is trans­fer­red to one of Google’s servers in the United States, where it is archi­ved. The ope­ra­tor of this website has no control over the data trans­fer. In case Google Maps has been acti­va­ted, Google has the option to use Google Fonts for the purpose of the uniform depic­tion of fonts. When you access Google Maps, your browser will load the requi­red web fonts into your browser cache, to cor­rect­ly display text and fonts.

We use Google Maps to present our online content in an appe­al­ing manner and to make the loca­ti­ons dis­c­lo­sed on our website easy to find. This con­sti­tu­tes a legi­ti­ma­te inte­rest as defined in Art. 6(1)(f) GDPR. If appro­pria­te consent has been obtai­ned, the pro­ces­sing is carried out exclu­si­ve­ly on the basis of Art. 6(1)(a) GDPR and § 25 (1) TDDDG, insofar the consent includes the storage of cookies or the access to infor­ma­ti­on in the user’s end device (e.g., device fin­ger­prin­ting) within the meaning of the TDDDG. This consent can be revoked at any time.

Data trans­mis­si­on to the US is based on the Stan­dard Con­trac­tu­al Clauses (SCC) of the Euro­pean Com­mis­si­on. Details can be found here: https://privacy.google.com/businesses/gdprcontrollerterms/ and https://privacy.google.com/businesses/gdprcontrollerterms/sccs/.

For more infor­ma­ti­on on the hand­ling of user data, please review Google’s Data Privacy Decla­ra­ti­on under: https://policies.google.com/privacy?hl=en.

The company is cer­ti­fied in accordance with the “EU-US Data Privacy Frame­work” (DPF). The DPF is an agree­ment between the Euro­pean Union and the US, which is inten­ded to ensure com­pli­ance with Euro­pean data pro­tec­tion stan­dards for data pro­ces­sing in the US. Every company cer­ti­fied under the DPF is obliged to comply with these data pro­tec­tion stan­dards. For more infor­ma­ti­on, please contact the pro­vi­der under the fol­lo­wing link: https://www.dataprivacyframework.gov/participant/5780.

Hotel Spider (booking engine)

This website uses the „Hotel Spider“ booking engine, which you can use to enquire about and book rooms and apart­ments direct­ly online. The pro­vi­der is Tour­is­oft Sàrl, Route de Champ-Colin 18, CH-1260 Nyon, Switz­er­land (her­ein­af­ter „Hotel Spider“).

When you open and use the booking form, Hotel Spider pro­ces­ses the per­so­nal and booking data you enter into the form (e.g. name, contact details, period of stay and further details of your booking, and payment data where appli­ca­ble). In addi­ti­on, tech­ni­cal data such as your IP address, browser infor­ma­ti­on and the date and time of access are pro­ces­sed in order to provide the service and to avoid incor­rect boo­kings. Tech­ni­cal­ly, the booking engine is loaded from the provider’s servers (inclu­ding wbe-static.hotel-spider.com).

The booking data you enter is pro­ces­sed in order to initia­te and carry out your booking and the­r­e­fo­re on the basis of Art. 6(1)(b) GDPR. Where consent has been reques­ted, the loading of the booking engine as an embedded service takes place exclu­si­ve­ly on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as that consent covers the storage of cookies or access to infor­ma­ti­on in your end device within the meaning of the TDDDG. Consent can be revoked at any time.

Hotel Spider is based in Switz­er­land. An ade­quacy decis­i­on of the EU Com­mis­si­on exists for Switz­er­land, which means that an ade­qua­te level of data pro­tec­tion is ensured there. Insofar as Hotel Spider engages further pro­ces­sors – inclu­ding in third count­ries – in order to provide the service, the data trans­fer is safe­guard­ed by appro­pria­te gua­ran­tees such as the stan­dard con­trac­tu­al clauses of the EU Com­mis­si­on.

For further infor­ma­ti­on on how your data is handled, please see the provider’s privacy policy at https://www.hotel-spider.com/privacy-policy/.

8. eCommerce and payment service providers

Processing of Customer and Contract Data

We collect, process, and use per­so­nal cus­to­mer and con­tract data for the estab­lish­ment, content arran­ge­ment and modi­fi­ca­ti­on of our con­trac­tu­al rela­ti­onships. Data with per­so­nal refe­ren­ces to the use of this website (usage data) will be coll­ec­ted, pro­ces­sed, and used only if this is neces­sa­ry to enable the user to use our ser­vices or requi­red for billing pur­po­ses. The legal basis for these pro­ces­ses is Art. 6(1)(b) GDPR.

The coll­ec­ted cus­to­mer data shall be deleted upon com­ple­ti­on of the order or ter­mi­na­ti­on of the busi­ness rela­ti­onship and upon expi­ra­ti­on of any exis­ting sta­tu­to­ry archi­ving periods. This shall be without pre­ju­di­ce to any sta­tu­to­ry archi­ving periods.

9. Custom Services

Handling applicant data

We offer website visi­tors the oppor­tu­ni­ty to submit job appli­ca­ti­ons to us (e.g., via e‑mail, via postal ser­vices on by sub­mit­ting the online job appli­ca­ti­on form). Below, we will brief you on the scope, purpose and use of the per­so­nal data coll­ec­ted from you in con­junc­tion with the appli­ca­ti­on process. We assure you that the coll­ec­tion, pro­ces­sing, and use of your data will occur in com­pli­ance with the appli­ca­ble data privacy rights and all other sta­tu­to­ry pro­vi­si­ons and that your data will always be treated as strict­ly con­fi­den­ti­al.

Scope and purpose of the collection of data

If you submit a job appli­ca­ti­on to us, we will process any affi­lia­ted per­so­nal data (e.g., contact and com­mu­ni­ca­ti­ons data, appli­ca­ti­on docu­ments, notes taken during job inter­views, etc.), if they are requi­red to make a decis­i­on con­cer­ning the estab­lish­ment or an employ­ment rela­ti­onship. The legal grounds for the afo­re­men­tio­ned are § 26 BDSG accor­ding to German Law (Nego­tia­ti­on of an Employ­ment Rela­ti­onship), Art. 6(1)(b) GDPR (General Con­tract Nego­tia­ti­ons) and – pro­vi­ded you have given us your consent – Art. 6(1)(a) GDPR. You may revoke any consent given at any time. Within our company, your per­so­nal data will only be shared with indi­vi­du­als who are invol­ved in the pro­ces­sing of your job appli­ca­ti­on.

If your job appli­ca­ti­on should result in your recruit­ment, the data you have sub­mit­ted will be archi­ved on the grounds of § 26 BDSG and Art. 6(1)(b) GDPR for the purpose of imple­men­ting the employ­ment rela­ti­onship in our data pro­ces­sing system.

As part of the appli­ca­ti­on process, we may also conduct an inter­net search on you. This pri­ma­ri­ly includes Google sear­ches, Lin­ke­dIn, and Xing. The legal basis for this type of pro­ces­sing is our legi­ti­ma­te inte­rest in obtai­ning an overall impres­si­on of publicly available infor­ma­ti­on about you in accordance with Art. 6 (1) (f) GDPR.

Data Archiving Period

If we are unable to make you a job offer or you reject a job offer or with­draw your appli­ca­ti­on, we reserve the right to retain the data you have sub­mit­ted on the basis of our legi­ti­ma­te inte­rests (Art. 6(1)(f) GDPR) for up to 6 months from the end of the appli­ca­ti­on pro­ce­du­re (rejec­tion or with­dra­wal of the appli­ca­ti­on). After­wards the data will be deleted, and the phy­si­cal appli­ca­ti­on docu­ments will be des­troy­ed. The storage serves in par­ti­cu­lar as evi­dence in the event of a legal dispute. If it is evident that the data will be requi­red after the expiry of the 6‑month period (e.g., due to an impen­ding or pending legal dispute), dele­ti­on will only take place when the purpose for further storage no longer applies.

Longer storage may also take place if you have given your agree­ment (Article 6(1)(a) GDPR) or if sta­tu­to­ry data reten­ti­on requi­re­ments pre­clude the dele­ti­on.