Privacy policy

The following information provides you with an overview of how your personal data is processed when you visit the website of our Mercure Parkhotel in Mönchengladbach. The website is operated by us, Ospidea Hotel Management GmbH (hereinafter referred to as “Ospidea”, “we”, “us”, or “our”).

In addition, this Privacy Policy provides information about further processing activities involving personal data, for example when you contact us, book a stay and become our guest, or visit our social media profiles.

In accordance with Article 13 of the General Data Protection Regulation (GDPR) and, where data has not been collected directly from you, Article 14 GDPR, we inform you about how your personal data is processed. Among other things, we explain which data we process, for what purposes, and what rights you have in relation to such processing.

This Privacy Policy is organised into the following sections:

Table of Contents:

  1. General Information
  2. Rights of Data Subjects
  3. Data Processing When Visiting Our Website
  4. Social Media Presence
  5. Communication with Us
  6. Guest Management
  7. Additional Information

1. General Information

1.1. Data Controller and Data Protection Officer

The controller responsible for the processing of personal data within the meaning of Article 4(7) GDPR is:

Ospidea Hotel Management GmbH
Murnaustraße 12
65189 Wiesbaden

Phone: + +49 611 26 24 37 0
Fax: + +49 611 26 24 37 99
Email: info@ospidea.com

Further information about the controller can be found in the legal notice (Imprint) of this website. If you have any questions regarding data protection, please contact our external Data Protection Officer:

Tengelmann Audit GmbH
External Data Protection Officer (Datenschutzbeauftragter)
An der Pönt 45
40885 Ratingen

Email: datenschutz(at)t-audit.de

1.2. Legal Bases and Principles of Processing

We process personal data in compliance with all applicable legal requirements. Depending on the specific circumstances, processing may be based on one or more of the following legal grounds:

  • Article 6(1)(a) GDPR: Consent of the data subject
  • Article 9(2)(a) GDPR: Explicit consent for processing special categories of personal data pursuant to Article 9(1) GDPR
  • Article 6(1)(b) GDPR: Performance of a contract with the data subject or implementation of pre-contractual measures at the request of the data subject
  • Article 6(1)(c) GDPR: Compliance with a legal obligation
  • Article 6(1)(d) GDPR: Protection of vital interests
  • Article 6(1)(e) GDPR: Performance of a task carried out in the public interest or in the exercise of official authority
  • Article 6(1)(f) GDPR: Legitimate interests pursued by the controller or by a third party, unless such interests are overridden by the interests or fundamental rights and freedoms of the data subject requiring protection of personal data
  • Article 49(1)(a) GDPR: Explicit consent to the transfer of personal data to third countries

Where processing is based on your consent, you may withdraw your consent at any time without giving reasons. Withdrawal of consent shall not affect the lawfulness of processing carried out prior to the withdrawal. The withdrawal will only take effect for future processing activities.

The legal basis applicable in each individual case is specified in the relevant sections of this Privacy Policy.

We generally retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected and processed.

Where and to the extent that your personal data is no longer required for these purposes, we will retain it only for as long as you or we may assert legal claims against the other party.

In addition, we retain your personal data where and for as long as we are required to do so by law. Such statutory retention and documentation obligations may arise, for example, under the German Commercial Code (Handelsgesetzbuch, HGB) or the German Fiscal Code (Abgabenordnung, AO).

As part of our business operations, we cooperate with various external parties and service providers. In certain cases, this requires the transfer of personal data to such third parties.

We disclose personal data to external parties only where:

  • such disclosure is necessary for the performance of a contract;
  • we are legally obliged to disclose the data (e.g. to tax authorities);
  • we have a legitimate interest in the disclosure pursuant to Article 6(1)(f) GDPR; or
  • another legal basis permits the disclosure.

Where we engage data processors, personal data is disclosed only after a Data Processing Agreement (DPA) has been concluded in accordance with applicable data protection legislation.

In cases of joint processing, an agreement on joint controllership pursuant to Article 26 GDPR will be concluded.

2. Rights of Data Subjects

Where we process your personal data as the controller, you have the following rights in relation to the processing of your personal data, which you may exercise at any time:

Right of Access, Rectification and Erasure
Subject to the applicable legal provisions, you have the right to obtain, free of charge and at any time, information about your personal data being processed by us (Article 15 GDPR), including the information set out in Article 15(1)(a) to (h) GDPR.

Furthermore, you may have the right to request the rectification of inaccurate personal data (Article 16 GDPR) or the erasure of your personal data (Article 17 GDPR).

The right to erasure may be restricted in the circumstances set out in Article 17(3) GDPR, for example where the processing is necessary for the establishment, exercise or defence of legal claims.

Right to Restriction of Processing
You have the right to request the restriction (or blocking) of the processing of your personal data (Article 18 GDPR).

The right to restriction of processing applies in the cases specified in Article 18(1)(a) to (d) GDPR.

Where the processing of your personal data has been restricted, such data may, apart from being stored, only be processed:

  • with your consent;
  • for the establishment, exercise or defence of legal claims;
  • for the protection of the rights of another natural or legal person; or
  • for reasons of important public interest of the European Union or a Member State.

Right to Data Portability

You have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format, provided that:

  • you have supplied the data to us;
  • the processing is carried out by automated means; and
  • the processing is based on your consent or on the performance of a contract with you.

This right is granted pursuant to Article 20 GDPR.

Right to Object to Processing
Where we process your personal data on the basis of legitimate interests pursuant to Article 6(1)(f) GDPR (including any profiling based on those interests), you have the right to object at any time to such processing on grounds relating to your particular situation (Article 21 GDPR).

In such cases, we will no longer process your personal data for those purposes unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or unless the processing serves the establishment, exercise or defence of legal claims.

Please note that the collection of data required for the provision of the website and the storage of log files are essential for the operation of the website and therefore cannot be objected to.

Notwithstanding the above, you have the right to object at any time, without giving reasons, to the processing of your personal data for direct marketing purposes. This also applies to any profiling insofar as it is related to such direct marketing.

Right to Withdraw Consent
Where the processing of personal data is based on your consent, you have the right to withdraw your consent at any time without providing any reason, in accordance with Article 7(3) GDPR.

The withdrawal of consent shall only take effect for the future. It does not affect the lawfulness of any processing carried out on the basis of your consent prior to its withdrawal.

Right to Lodge a Complaint with a Supervisory Authority
If you believe that the processing of your personal data infringes applicable data protection laws, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement, in accordance with Article 77 GDPR.

This right is without prejudice to any other administrative or judicial remedy available to you.

To exercise your rights, please contact us using the contact details provided in the sections relating to the Data Controller and the Data Protection Officer.

When exercising your rights as a data subject, we will also process personal data as necessary for the purpose of handling and responding to your request.

Such processing is carried out either:

  • to comply with a legal obligation pursuant to Article 6(1)(c) GDPR; or
  • on the basis of our legitimate interest pursuant to Article 6(1)(f) GDPR in ensuring compliance with applicable data protection requirements and facilitating the effective exercise of data subject rights.

3. 3. Data Processing When Visiting Our Website

3.1. General Information

When you visit our website, personal data may be processed. This section provides an overview of which data is processed, for what purposes, and on which legal basis.

For security reasons and to protect the transmission of confidential content, such as enquiries or bookings that you send to us as the website operator, this website uses SSL and/or TLS encryption. You can recognise an encrypted connection by the change of the browser address from “http://” to “https://” and by the padlock symbol displayed in your browser’s address bar.

Where SSL or TLS encryption is enabled, the data you transmit to us cannot generally be read by third parties. However, please note that despite all technical and organisational measures taken, security vulnerabilities may exist in electronic data transmission (e.g. via the Internet or email). Complete protection of data against access by third parties cannot be guaranteed.

When accessing our website, our servers may access information stored on your device, such as your IP address, and may also store information on your device, for example through cookies or similar technologies. To the extent that such access or storage is strictly necessary for the technically error-free and secure provision of our website and related services, this is carried out on the basis of Section 25 (2) of the German Telecommunications Digital Services Data Protection Act (TDDDG). In all other cases, such access or storage takes place only on the basis of your consent pursuant to Section 25 (1) TDDDG.

Where the retrieval or storage of information is associated with the processing of personal data, such processing is generally carried out on the basis of an appropriate legal basis pursuant to Article 6(1) GDPR.

For example, we use various technologies, including cookies, that are strictly necessary for the operation of certain functions of our website. Through these technologies, we may collect and process data such as your IP address, the date and time of your visit, device and browser information, and information regarding your use of our website. This processing serves the optimised presentation, functionality, and secure provision of our website and its content. These purposes also constitute our legitimate interest pursuant to Article 6(1)(f) GDPR and therefore provide the legal basis for the processing of such data.

In addition, our website uses optional cookies and external services provided by the service providers described below. These technologies are only activated on the basis of your consent pursuant to Section 25 (1) TDDDG. Any personal data collected through such technologies is processed on the basis of your consent pursuant to Article 6(1)(a) GDPR and, where applicable, Article 49(1)(a) GDPR, if you consent to the transfer of data to a third country.

If you wish to review or modify your cookie preferences, including withdrawing your consent, you may do so at any time using the “Change Cookie Settings” option available on this website.

Further information regarding our hosting services as well as the cookies, external services and other technologies used on our website can be found in the following sections.

3.2. Hosting

Each time our website is accessed, certain information is automatically transmitted to and temporarily stored on our web server by our hosting provider for technical reasons.

Server Log Files

When you access our website, information is automatically collected and stored in so-called server log files, which your browser automatically transmits to us. This information may include, in particular:

  • Browser type and browser version
  • Operating system used
  • Referrer URL
  • Host name of the accessing device
  • Subpages of our website accessed via the requesting system
  • Date and time of the server request
  • Internet service provider of the requesting system
  • IP address
  • Other similar data and information used for security purposes in the event of attacks on our information technology systems

This data is not merged with other data sources.

The collection and processing of the above-mentioned data is carried out on the basis of Article 6(1)(f) GDPR. We have a legitimate interest in ensuring the technically error-free operation, presentation, and optimisation of our website, which requires the collection of server log files. Furthermore, we have a legitimate interest in detecting, preventing, investigating, and defending against cyberattacks and other security-related incidents affecting our information technology systems.

Borlabs Cookie Consent

Our website uses the Borlabs Cookie Consent Platform to obtain, manage, and document your consent to the storage of certain cookies on your device and the use of specific technologies in a manner compliant with applicable data protection laws. This service is provided by Borlabs GmbH, Hamburg, Germany (“Borlabs”).
When you visit our website, a Borlabs cookie is stored on your device in order to record and document the consents you have given, as well as any withdrawal of consent.
Further information, including details regarding the retention period of Borlabs cookies, can be found in the Cookie Settings available in the footer of our website.
Additional information about the data processing carried out by Borlabs Cookie is available at:
https://de.borlabs.io/kb/welche-daten-speichert-borlabs-cookie/

The use of the Borlabs Cookie Consent Platform serves the purpose of obtaining and documenting the legally required consents for the use of cookies and similar technologies.
The legal basis for this processing is Article 6(1)(c) GDPR, insofar as the processing is necessary to comply with a legal obligation, and alternatively our legitimate interest pursuant to Article 6(1)(f) GDPR in implementing and demonstrating compliance with applicable data protection requirements.

3.3. Google Tag Manager

With your consent, we use Google Tag Manager, a service provided by Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

According to Google, Google Tag Manager itself does not create user profiles, store cookies, or perform independent analyses. The data processed through Google Tag Manager may include your IP address, browser and device information, as well as information regarding your interaction with our website. While Google Tag Manager itself does not set cookies, it may trigger other services that do.

The purpose of the processing is to facilitate the integration and management of website tags and tracking codes used to analyse user interactions with our website. Google Tag Manager may also transfer the collected data to Google’s parent company in the United States. The data may subsequently be shared within the Google group of companies, with processing being carried out primarily by Google LLC in the United States.

The legal basis for this processing is your consent pursuant to Article 6(1)(a) GDPR. You may withdraw your consent at any time with future effect by accessing the cookie settings within this Privacy Policy and adjusting your preferences accordingly. The withdrawal of consent shall not affect the lawfulness of any processing carried out on the basis of consent before its withdrawal.

For data protection purposes, the United States is generally considered a third country, meaning that its data protection laws may differ from those applicable within the European Union and may not provide a level of protection equivalent to that guaranteed within the EU. However, the European Commission has adopted an adequacy decision for the EU-U.S. Data Privacy Framework (DPF) for organisations that have been appropriately certified. Google’s U.S. parent company has obtained such certification. Further information is available at the following external link:

https://www.dataprivacyframework.gov/participant/5780

Where personal data is processed outside the EU/EEA, Google also relies, among other safeguards, on the European Commission’s Standard Contractual Clauses (SCCs) to ensure an adequate level of data protection.

Further information on Google’s privacy practices can be found at:

https://policies.google.com/privacy

Information regarding the cookies used by Google can be found at:

https://policies.google.com/technologies/cookies.

3.4. Google Analytics

Subject to your consent, this website uses Google Analytics 4, a web analytics service provided by Google LLC, California, USA. For users located in the European Union (EU) and the European Economic Area (EEA), the service is provided by Google Ireland Limited, Google Building, Gordon House, 4 Barrow Street, Dublin, D04 E5W5, Ireland (“Google”).

Google Analytics enables the website operator to analyse the behaviour of website visitors. In this context, the website operator receives various usage data, including, for example, page views, time spent on the website, operating systems used, and the visitor’s country or region of origin. This information may be aggregated into a unique user identifier and assigned to the respective device used by the website visitor.

In addition, Google Analytics may record user interactions such as mouse movements, scrolling behaviour and clicks. Google Analytics also uses various modelling techniques to supplement collected datasets and employs machine learning technologies for data analysis. Furthermore, Google Analytics uses technologies that enable the recognition of users for the purpose of analysing user behaviour (e.g. cookies or device fingerprinting). Information collected by Google regarding the use of this website is generally transmitted to and stored on servers located in the United States.

We have enabled IP anonymisation by default for Google Analytics. As a result, your IP address will be truncated by Google within Member States of the European Union or in other states party to the Agreement on the European Economic Area before transmission. Only in exceptional cases will the full IP address be transferred to a Google server in the United States and shortened there.

Google will process this information on our behalf for the purpose of evaluating your use of the website, compiling reports on website activity, and providing us with additional services related to website usage and internet usage. The reports provided by Google Analytics help us analyse the performance of our website and the effectiveness of our marketing activities.

Data collected through Google Analytics may be shared within the Google group of companies. Consequently, data processing is carried out primarily by Google LLC in the United States.

Please note that, from a data protection perspective, the United States is considered a third country where data protection laws may differ from those applicable in the European Union and where the level of data protection may not be equivalent to that guaranteed within the EU. Transfers of personal data to the United States are based, among other safeguards, on the European Commission’s Standard Contractual Clauses (SCCs). Further information is available at:

https://business.safety.google/adscontrollerterms/sccs/

In addition, Google LLC is certified under the EU-U.S. Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards when personal data is processed in the United States. Companies certified under the DPF commit to complying with these standards. Further information is available at:

https://www.dataprivacyframework.gov/participant/5780

The standard data retention period configured for Google Analytics is 14 months. Data that has reached the end of the retention period is automatically deleted once per month.

The use of Google Analytics is based on your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TDDDG. You may withdraw your consent at any time with future effect by accessing the cookie settings available in this Privacy Policy and adjusting your preferences accordingly. The withdrawal of consent shall not affect the lawfulness of any processing carried out before the withdrawal.

In addition to refusing consent, you may prevent the storage of cookies from the outset by configuring your browser software accordingly. Please note, however, that if you configure your browser to reject all cookies, certain functionalities of this and other websites may be limited.

Further information on how Google processes user data in connection with Google Analytics can be found in Google’s Privacy Policy:

https://support.google.com/analytics/answer/6004245

Information regarding the cookies used by Google can be found at:

https://policies.google.com/technologies/cookies/

3.5. Google Maps

This website uses Google Maps, a mapping service provided by Google LLC, California, USA. For users in the European Union (EU) and the European Economic Area (EEA), the service is provided by Google Ireland Limited, Google Building, Gordon House, 4 Barrow Street, Dublin, D04 E5W5, Ireland (“Google”).

Google Maps enables us to display interactive maps directly on our website and allows you to conveniently use map functionalities and easily locate the places referenced on our website.

When using Google Maps, additional Google services, such as Google Fonts, may also be used in order to ensure the optimal presentation and functionality of the mapping service. As part of this process, your browser may load the required web fonts into its cache to display text and fonts correctly.

The use of Google Maps, and therefore the processing of personal data by Google Maps, is only possible if you have provided your consent via the cookie settings on this website. Processing is based on Article 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as your consent includes the storage of cookies or access to information stored on your device (e.g. device fingerprinting) within the meaning of the TDDDG. You may withdraw your consent at any time with future effect by accessing the cookie settings in this Privacy Policy and adjusting your preferences accordingly. The withdrawal of consent shall not affect the lawfulness of processing carried out on the basis of consent prior to its withdrawal.

By using Google Maps, Google receives information that the relevant page or subpage of our website has been accessed, together with your IP address. This occurs regardless of whether Google provides a user account through which you are logged in or whether no user account exists. If you are logged into your Google account, your data may be directly associated with your account. If you do not wish such association to occur, you must log out of your Google account before activating Google Maps.

Google stores your data as usage profiles and uses them for advertising, market research and/or the tailored design of its websites. Such analysis may be carried out, in particular, to provide interest-based advertising, including for users who are not logged in. You have the right to object to the creation of such user profiles; to exercise this right, you must contact Google directly.

Personal data collected through Google Maps may be transferred to the United States. For data protection purposes, the United States is generally considered a third country, meaning that its data protection legislation may differ from that of the European Union and may not provide a level of protection equivalent to that guaranteed within the EU. However, the European Commission has adopted an adequacy decision under the EU-U.S. Data Privacy Framework (DPF) for organisations that have been appropriately certified. Google’s U.S. parent company has obtained such certification. Further information is available at:

https://www.dataprivacyframework.gov/participant/5780

In addition, Google relies on appropriate safeguards, including the European Commission’s Standard Contractual Clauses (SCCs), to ensure an adequate level of data protection. Further details are available at:

https://business.safety.google/adscontrollerterms/sccs/

Further information regarding the purpose and scope of data collection and processing by Google Maps, as well as information about your rights and available privacy settings, can be found in Google’s Privacy Policy:

https://www.google.com/policies/privacy/

4. Social Media Presence

We maintain active profiles on various social media networks and platforms relating to our hotel in order to communicate with guests and prospective guests and, for example, to provide information about career opportunities, services, and other activities.

Please note that we are not responsible for the independent processing of personal data carried out by the operators of the respective platforms. Details of such processing can be found in the applicable terms of use and privacy policies of the respective platform operators. We also draw your attention to the fact that personal data processed when visiting social media platforms may be transferred to so-called third countries (countries outside the European Union and the European Economic Area) where different data protection laws may apply and the level of protection may not be equivalent to that provided within the European Union. Further information can be found in the privacy policies of the respective platform operators.

When visiting one of our hotel profiles, you are under no obligation to actively provide us with personal data. We may process only personal data that you have made publicly available (e.g. your name as displayed in your user profile) and that is directly related to activities on our hotel profile (e.g. comments, posts, likes, tags, or similar interactions), or data that you voluntarily provide to us when communicating with us.

Depending on the individual case, the purposes for which we process personal data may include market research and promotional activities, effective communication with users, and responding to user enquiries. These purposes constitute our legitimate interest and therefore provide the legal basis for processing pursuant to Article 6(1)(f) GDPR.

Where communication with you via a social media platform is necessary for the performance of a contract with you or for the implementation of pre-contractual measures, the processing is also based on Article 6(1)(b) GDPR.

Where data analysis activities are initiated by the operators of the respective social networks or platforms, such processing may be based on different legal grounds determined by those operators (for example, consent pursuant to Article 6(1)(a) GDPR).

The platform operators also use cookies and similar technologies, primarily to identify registered users and generally to analyse user behaviour. We do not have direct access to the information collected through such cookies and technologies. However, such information may form the basis of statistical reports and analytical data that the platform operators make available to us. Further information can be found in the privacy notices of the respective platform operators.

Please note that communications with us via social media platforms are processed through the infrastructure of the respective platform operators, over whose security measures we have only limited control. If you wish to provide us with more detailed or confidential information, we therefore recommend contacting us directly through our own communication channels.

The platform operators may also provide us with aggregated statistical information, either with or without a personal reference, which we use to evaluate user behaviour in relation to our hotel profile and/or our activities on the respective platform. Such information may include, for example, the number of followers, views, likes, demographic information (such as users’ countries of residence), or professional information (such as business sectors or areas of responsibility). We have no or only limited influence over the collection, preparation, and provision of such data. The analysis of this information helps us assess the effectiveness of our activities and improve our presence on the respective platforms. This also constitutes our legitimate interest pursuant to Article 6(1)(f) GDPR.

Personal data collected directly through our hotel profiles will be deleted from our systems when you request deletion, withdraw your consent, or when the purpose for storing the data no longer applies. Cookies remain stored on your device until you delete them. Mandatory statutory provisions, particularly legal retention obligations, remain unaffected.

The retention period for personal data stored by the operators of social media networks and platforms for their own purposes is beyond our control. For further information on such retention periods, please contact the relevant platform operator directly.

For certain processing activities relating to personal data in connection with our hotel profiles, both we and the respective platform operator may act as joint controllers within the meaning of the GDPR. This may be the case, in particular, where platform operators provide us with individual statistics and analyses relating to our hotel profiles.

In relation to such jointly controlled processing activities, you may generally exercise your rights of access, rectification, erasure, restriction of processing, data portability, and complaint both with us and with the operator of the respective platform.

Please note that, despite any joint controllership arrangements, we do not have full influence over the data processing activities carried out by social media networks and platforms. Our ability to influence such processing depends largely on the policies and operational practices of the respective provider.

Further information on the respective platform operators is provided below.

Meta (Facebook & Instagram)
In addition to us, the operator of the respective social network is also responsible for the processing of personal data in connection with our Facebook pages and Instagram hotel profiles:

Meta Platforms Ireland Limited
Dublin 2
Ireland

Meta’s Data Protection Officer can be contacted via Meta’s online contact form and by post at:

Meta Platforms Ireland Limited
Merrion Road
Dublin 4
Ireland

Further information regarding the scope, nature, and duration of the processing of your personal data can be found in Facebook’s Privacy Policy, Instagram’s Privacy Policy, and Meta’s Terms of Use (external links).

With regard to the processing of personal data in connection with our hotel profiles on Facebook and Instagram, we and Meta act as joint controllers within the meaning of Article 26 GDPR. Further information regarding this joint controllership arrangement can be found in Meta’s Joint Controller Addendum and related information provided by Meta (external links).

Meta Platforms Ireland Limited is part of the U.S.-based Meta Group. As a result, your personal data may be transferred to the United States.

For data protection purposes, the United States is generally classified as a third country, meaning that its data protection laws may differ from those applicable within the European Union and may not provide a level of protection equivalent to that guaranteed by EU law. However, the European Commission has adopted an adequacy decision under the EU-U.S. Data Privacy Framework (DPF) for organisations that have obtained the relevant certification. Meta’s U.S. parent company has been certified under the DPF.

Further information is available at the following external link:

https://www.dataprivacyframework.gov/participant/4452

5. Communication with Us

We provide various means of contacting us (e.g. on this website, on business cards, or in email signatures). In most cases, these contact details are provided to enable current and prospective business partners, guests, and other interested parties to direct their enquiries to us efficiently. If you contact us regarding a vacancy with us or one of our clients, please also refer to the relevant sections below.

When you contact us, for example by email, telephone, or fax, we process the personal data that you voluntarily provide (such as your email address, name, or telephone number) in order to process and respond to your enquiry. Where the chosen communication channel offers additional features (e.g. video calling), you are always free to activate or deactivate such features at your discretion.

Access to the personal data received in the course of communications is restricted to those individuals who require such data for the lawful fulfilment of the respective processing purpose. Personal data obtained through communications with you will only be disclosed to external third parties where this is technically necessary (e.g. telecommunications providers or IT service providers), necessary for the proper handling of your request (e.g. cloud service providers, postal services, or parcel delivery services), or where you have given your consent to such disclosure.

We select and engage external service providers in accordance with our internal data protection standards and applicable legal requirements, including, where necessary, the conclusion of appropriate data processing agreements pursuant to Article 28 GDPR.

The processing of personal data arising from communications with us is based on Article 6(1)(b) GDPR where your enquiry relates to the performance of a contract with you or is necessary in order to take steps prior to entering into a contract.

In all other cases, processing is generally based on our legitimate interest in the efficient handling of enquiries addressed to us pursuant to Article 6(1)(f) GDPR, or on your consent pursuant to Article 6(1)(a) GDPR, where such consent has been requested. Any consent granted may be withdrawn at any time with future effect.

If you are not yourself a contractual partner but, for example, an employee or representative of a current, prospective, or former business partner, personal data may be processed, where necessary, for the initiation, performance, or termination of a business relationship based on our legitimate interests pursuant to Article 6(1)(f) GDPR. Efficient communication for the purpose of conducting our business operations and fulfilling mutual contractual and pre-contractual obligations constitutes both our legitimate interest and, at least in part, the legitimate interest of our business partners.

For the purposes described above, we do not generally transfer personal data on a regular basis to third countries (countries outside the European Union or the European Economic Area) or to international organisations. However, depending on the location of the parties involved in the communication at the time of the exchange and the telecommunications services used, transfers of personal data to third countries (such as the United States) cannot be entirely excluded.

The personal data you provide to us in the course of communications will be retained until you request its deletion, withdraw your consent to its storage, or the purpose for which the data was collected no longer applies (for example, after your enquiry has been fully resolved), unless retention is required for legitimate reasons, such as statutory retention obligations pursuant to Article 6(1)(c) GDPR or our legitimate interests pursuant to Article 6(1)(f) GDPR, including the handling of follow-up enquiries or the establishment, exercise, or defence of legal claims.

6. Guest Management

Purposes and Legal Bases of Processing
When we welcome guests to one of our hotels, we naturally process personal data as part of providing our services. The purposes of such processing may include, among others:

  • Booking and administration of hotel stays;
  • Provision of hotel accommodations and related services;
  • Improvement and personalisation of services, including tailoring services to individual preferences;
  • Billing and invoicing;
  • Retention of data in accordance with commercial, tax, and other statutory requirements;
  • Compliance with other legal obligations, such as the collection and remittance of local charges (e.g. visitor taxes, tourism levies, city taxes, accommodation taxes) or obligations under the German Federal Registration Act (Bundesmeldegesetz, BMG);
  • Direct marketing of our own similar products and services;
  • Ensuring the safety and security of our hotels, guests, and employees, as well as the prevention of fraud;
  • Quality assurance and the enhancement of the overall security, efficiency, and effectiveness of our administrative processes and service delivery.

We process our guests’ personal data only where a valid legal basis exists. This is the case where:

  • you have provided your consent to the processing of personal data (Article 6(1)(a) GDPR or Article 9(2)(a) GDPR);
  • the processing is necessary for the performance of a contract with you or for taking steps at your request prior to entering into a contract (Article 6(1)(b) GDPR);
  • the processing is necessary to comply with legal obligations, for example under commercial law, tax law, or the German Federal Registration Act (Article 6(1)(c) GDPR), or is based on our legitimate interest in complying with legal requirements pursuant to Article 6(1)(f) GDPR;
  • the processing is necessary for the performance of a contract with another party, for example where you are travelling as a companion of the contracting guest, based on our legitimate interest pursuant to Article 6(1)(f) GDPR;
  • we have a legitimate interest pursuant to Article 6(1)(f) GDPR in improving our services, making your stay as pleasant as possible, and informing you about our products and services.

Our legitimate interests may also include efficient administration within our corporate group or franchise network, internal controlling, the preparation and evaluation of statistics for the effective management and improvement of business operations, ensuring the safety and security of our hotels, guests, employees, property, and third-party assets, fraud prevention, and the establishment, exercise, or defence of legal claims.

Where we process your personal data on the basis of legitimate interests pursuant to Article 6(1)(f) GDPR (including any profiling), you have the right to object at any time to such processing on grounds relating to your particular situation. Where processing is based on your consent, you may withdraw that consent at any time without providing reasons in accordance with Article 7(3) GDPR. For further information regarding your rights as a data subject, please refer to Section 2 of this Privacy Policy.

Source of Personal Data
We obtain personal data relating to our guests either directly from the guests themselves, for example when they:

  • make a reservation;
  • check in or check out;
  • complete forms;
  • request or use hotel services.

We may also receive personal data about our guests from third parties. This may include our franchise partner, the Accor Group, from whom we may receive booking information (for example where reservations are made through the franchise partner) or information relating to loyalty and rewards programmes.

In addition, we may receive personal data from travel agencies, booking platforms, tour operators, or other travel service providers through which hotel stays are booked, where such information is necessary to manage reservations and provide hotel services.

Categories of Personal Data Processed
We may generally process the following categories of personal data relating to our guests:

  • Stay-related information (e.g. room number, business stay, leisure stay);
  • Booking information (e.g. reservation number, arrival and departure dates);
  • Information relating to loyalty and rewards programmes;
  • Contact details (e.g. name, postal address, telephone number, email address);
  • Guest preferences and stay history (e.g. preferred wake-up times, food and beverage preferences);
  • Billing and invoicing information (e.g. billing address);
  • Relevant communication records and correspondence;
  • Payment information (e.g. credit card details);
  • Information required pursuant to Sections 29 and 30 of the German Federal Registration Act (Bundesmeldegesetz, BMG) and, where applicable, supplementary state law provisions, such as date of birth, nationality, passport number, or details of another officially recognised and valid travel document.

Disclosure of Personal Data
As is customary in the course of business operations, we engage external service providers, cooperate with affiliated companies, and may be required to disclose information to public authorities in order to fulfil our contractual and legal obligations.

Personal data is disclosed to third parties only where such disclosure is necessary for the purposes described above, is permitted by law, or where you have provided your prior consent.

Possible recipients of personal data include:

  • Public authorities and governmental bodies where disclosure is required by law;
  • External service providers, for example in the fields of information technology, hospitality systems, or marketing;
  • Franchise partners (in particular, the Accor Group);
  • Travel agencies, booking providers, and other travel-related service providers;
  • Affiliated companies within our corporate group;
  • Auditors, accountants, tax advisers, and legal counsel;
  • Payment service providers.

Depending on the nature of their involvement, recipients may act either as data processors on our behalf within the meaning of Article 4(8) GDPR or as independent (or joint) controllers within the meaning of Article 4(7) GDPR.

We do not intend to transfer personal data to third countries (countries outside the European Union or the European Economic Area) or to international organisations. Should such a transfer become necessary or unavoidable, for example due to the integration of international information technology services, any transfer will take place only in accordance with the requirements of Articles 44 et seq. GDPR to ensure an adequate level of data protection, or in the circumstances provided for under Article 49 GDPR.

For further information regarding the processing and disclosure of personal data by our franchise partner, please refer to the Accor Group’s Privacy Policy available at:

https://all.accor.com/a/en/information/data-protection.html

Retention Period
We process and retain personal data only for as long as is necessary to fulfil the purposes described above and/or to comply with applicable legal obligations. Personal data may also be retained until all mutual contractual and legal claims have been fully settled or until any consent previously granted has been withdrawn.

Legal retention obligations regularly arise from statutory record-keeping and retention requirements, including those under the German Commercial Code (Handelsgesetzbuch, HGB), the German Fiscal Code (Abgabenordnung, AO) and the German Federal Registration Act (Bundesmeldegesetz, BMG). Depending on the applicable legal requirements, retention periods may extend to up to ten years.

In addition, it may be necessary to retain personal data for the duration of any applicable limitation periods during which legal claims may be asserted by or against us, or otherwise pursued, exercised, or defended.

7. Additional Information

7.1 Requirement to Provide Personal Data

The provision of personal data may be required in connection with existing or prospective contractual relationships where such data is necessary for the conclusion or performance of a contract.

In addition, legal obligations may require us to collect and process certain personal data.

As a general rule, the provision of personal data is voluntary. However, please note that, depending on the circumstances of the individual case, we may be unable to provide certain services, carry out specific measures, or enter into or perform a contractual relationship without the relevant personal data.

7.2 Automated Decision-Making

No automated decision-making, including profiling within the meaning of Article 22 GDPR, takes place.

7.3 Objection to Unsolicited Marketing Communications

The use of contact details published as part of our legal notice (imprint) obligations for the purpose of sending unsolicited advertising or informational materials is hereby expressly prohibited.

The operators of this website expressly reserve the right to take legal action in the event of the unsolicited transmission of advertising materials, including but not limited to spam emails.

7.4 Amendments to This Privacy Policy

We reserve the right to modify our security and data protection measures where this becomes necessary due to technological developments.

In such cases, we will update this Privacy Policy accordingly. Changes to our services or developments in applicable laws and regulations may also require amendments to this Privacy Policy.

7.5 Web Application Firewall

We use a Web Application Firewall (WAF) to protect our website against unauthorised access, malicious activities, and cyberattacks.

For this purpose, technical access data, in particular IP addresses, is processed for security and threat prevention purposes. Such data is stored in a shortened or anonymised form on our servers for a period of seven (7) days and is subsequently deleted.

The legal basis for this processing is Article 6(1)(f) GDPR.

Our legitimate interest lies in ensuring the integrity, confidentiality, and availability of our information technology systems and in protecting our website and related services from security threats and unauthorised access.