Privacy policy

1. introduction

This website is operated by: FKF Hotel Wernigerode GmbH.

It is very important to us to handle our website visitors' data confidentially and to protect it in the best possible way. For this reason, we make every effort to meet the requirements of the GDPR.

Below we explain how we process your data on our website. We use language that is as clear and transparent as possible so that you really understand what happens to your data.

2. general information

Processing of personal data and other terms

Data protection applies to the processing of personal data. Personal data means all data with which you can be personally identified. This is, for example, the IP address of the device (PC, laptop, smartphone, etc.) you are currently using. Such data is processed when 'something happens to it'. Here, for example, the IP is transmitted from the browser to our provider and automatically stored there. This is then a processing (according to Art. 4 No. 2 GDPR) of personal data (according to Art. 4 No. 1 GDPR).

These and other legal definitions can be found in Art. 4 GDPR.

  • Applicable regulations/laws: GDPR, BDSG and TDDDG

The scope of data protection is regulated by law. In this case, these are the GDPR (General Data Protection Regulation) as a European regulation and the BDSG (Federal Data Protection Act) as a national law.

In addition, the TDDDG supplements the provisions of the GDPR as far as the use of cookies is concerned.

The person responsible

The controller within the meaning of the GDPR is responsible for data processing on this website. This is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.

You can reach the person responsible at:

FKF Hotel Wernigerode GmbH

HKK Hotel Wernigerode ****
Pfarrstraße 41
38855 Wernigerode

datenschutz@hkk-wr.de

How data is generally processed on this website

As we have already established, some data (e.g. IP address) is collected automatically. This data is mainly required for the technical provision of the website. If we also use personal data or collect other data, we will inform you of this or ask for your consent.

You provide us with other personal data deliberately. You will find detailed information on this below.

Your rights

The GDPR provides you with comprehensive rights. These include, for example, free information about the origin, recipient and purpose of your stored personal data. You can also request the rectification, blocking or erasure of this data or lodge a complaint with the competent data protection supervisory authority. You can revoke your consent at any time.

The details of these rights and how to exercise them can be found in the last section of this privacy policy.

Data protection - Our view

Data protection is more than just a chore for us! Personal data has great value and careful handling of this data should be a matter of course in our digitalized world. As a website visitor, you should also be able to decide for yourself what "happens" to your data, when and by whom. That is why we are committed to complying with all legal regulations, only collect the data we need and, of course, treat it confidentially.

Forwarding and deletion

The transfer and deletion of data are also important and sensitive issues. We would therefore like to briefly inform you in advance about our general approach to this.

Data will only be passed on on the basis of a legal basis and only if this is unavoidable. This may be the case in particular if it is a so-called processor and an order processing contract has been concluded in accordance with Art. 28 GDPR.

We delete your data when the purpose and legal basis for processing no longer apply and the deletion does not conflict with any other legal obligations. Art. 17 GDPR also provides an overview of this.

For further information, please refer to this privacy policy and contact the controller if you have any specific questions.

Hosting

This website is hosted externally. The personal data collected on this website is stored on the host's servers. This includes the automatically collected and stored log files (see below for more details), as well as all other data provided by website visitors.

External hosting is used for the purpose of secure, fast and reliable provision of our website and in this context serves to fulfill the contract with our potential and existing customers.

The legal basis for the processing is Art. 6 para. 1 lit. a, b and f GDPR, as well as § 25 para. 1 TDDDG, insofar as consent includes the storage of cookies or access to information in the terminal device of the website visitor or user within the meaning of the TDDDG.

Our hoster only processes data that is necessary to fulfill its performance obligations and acts as our processor, i.e. it is subject to our instructions. We have concluded a corresponding contract for order processing with our hoster.

We use the following hoster:

Hetzner

Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany.

info@hetzner.com

https://www.hetzner.com/de/rechtliches/datenschutz.

Legal basis

The processing of personal data always requires a legal basis. The GDPR provides the following options in Art. 6 para. 1 sentence 1:

  1. The data subject has given their consent to the processing of their personal data for one or more specific purposes;
  2. processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
  3. the processing is necessary for compliance with a legal obligation to which the controller is subject;
  4. processing is necessary in order to protect the vital interests of the data subject or of another natural person;
  5. processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
  6. processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

In the following sections, we will provide you with the specific legal basis for the respective processing.

3. what happens on our website

When you visit our website, we process your personal data.

We use SSL or TLS encryption to protect this data in the best possible way against unauthorized access by third parties. You can recognize this encrypted connection by the https:// or lock symbol in the address bar of your browser.

Below you can find out what data is collected when you visit our website, for what purpose this is done and on what legal basis.

Data collection when accessing the website

When you visit the website, information is automatically stored in so-called server log files. This is the following information:

  • Browser type and browser version
  • Operating system used
  • Referrer URL
  • Host name of the accessing computer
  • Time of the server request
  • IP address

This data is required temporarily in order to be able to display our website to you permanently and without any problems. In particular, this data is used for the following purposes:

  • System security of the website
  • System stability of the website
  • Troubleshooting on the website
  • Establishing a connection to the website
  • Presentation of the website

Data processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR and is based on our legitimate interest in the processing of this data, in particular our interest in the functionality of the website and its security.

Where possible, this data is stored in pseudonymized form and deleted once the respective purpose has been achieved.

If the server log files make it possible to identify the data subject, the data is stored for a maximum period of 14 days. An exception is made if a security-relevant event occurs. In this case, the server log files are stored until the security-relevant event has been resolved and finally clarified.

Otherwise, no merging with other data takes place.

Cookies

General information

This website uses so-called cookies. This is a data record, information that is stored in the browser of your end device and is related to our website.

The use of cookies can make it easier for visitors to navigate the website.

In our cookie consent tool you will find all information about the cookies that we use on our website (if applicable, after your consent).

Rejecting cookies

You can manage all cookies that are not technically necessary directly via our cookie consent tool.

You can prevent cookies from being set by adjusting your browser settings.

Here you will find the corresponding links to frequently used browsers:

Mozilla Firefox: https://support.mozilla.org/de/kb/cookies-und-website-daten-in-firefox-loschen?redirectslug=Cookies+l%C3%B6schen&redirectlocale=en

Google Chrome: https://support.google.com/chrome/answer/95647?co=GENIE.Platform%3DDesktop&hl=de

Microsoft Edge: https://support.microsoft.com/de-de/windows/l%C3%B6schen-und-verwalten-von-cookies-168dab11-0753-043d-7c16-ede5947fc64d

Safari: https://support.apple.com/de-de/guide/mdm/mdmf7d5714d4/web and https://support.apple.com/de-de/guide/safari/sfri11471/mac

If you use a different browser, we recommend that you enter the name of your browser and "Delete and manage cookies" in a search engine and follow the official link to your browser.

Alternatively, you can also manage your cookie settings at www.aboutads.info/choices/
or www.youronlinechoices.com.

However, we must point out that a comprehensive blocking/deletion of cookies can lead to impairments in the use of the website.

Technically necessary cookies

We use technically necessary cookies on this website to ensure that our website functions correctly and in accordance with the applicable laws. They help to make the website user-friendly. Some functions of our website cannot be displayed without the use of cookies.

The legal basis for this is Art. 6 para. 1 lit. b, c and/or f GDPR, depending on the individual case.

Technically not necessary cookies

We also use cookies on our website that are not technically necessary. These cookies are used, among other things, to analyze the surfing behavior of the website visitor or to offer functions of the website that are not technically necessary.

The legal basis for this is your consent pursuant to Art. 6 para. 1 lit. a GDPR.

Technically unnecessary cookies are only set with your consent, which you can revoke at any time in the cookie consent tool.

Data processing through user input

Own data collection

We offer the following (service) on our website: Booking of hotel rooms.

We collect the following data for this purpose:

Name

E-mail address

Address

Phone number

Date of birth

Payment data

The legal basis for this data processing is Art. 6 para. 1 lit. b GDPR.

The data will be deleted as soon as the respective purpose no longer applies and it is possible in accordance with the legal requirements.

Contact us

1st e-mail

When you contact us by email, we process your email address and any other data contained in the email. This data is stored on the mail server and in some cases on the respective end devices. Depending on the request, the legal basis for this is regularly Art. 6 para. 1 lit. f GDPR or Art. 6 para. 1 lit. b GDPR. The data will be deleted as soon as the respective purpose no longer applies and it is possible in accordance with the legal requirements.

2. telephone

If you contact us by telephone, the call data may be stored in pseudonymized form on the respective end device and with the telecommunications provider used. Personal data collected during the telephone call will only be processed in order to process your request. Depending on the request, the legal basis for this is regularly Art. 6 para. 1 lit. f GDPR or Art. 6 para. 1 lit. b GDPR. The data will be deleted as soon as the respective purpose no longer applies and it is possible in accordance with the legal requirements.

3. contact form

We offer a contact form. This is used to contact our company.

In this form, we usually process your first and last name, your telephone number, your e-mail address, a postal address and the content of the message. The data is stored on our web server and forwarded internally to the relevant e-mail addresses.

The legal basis for data processing is Art. 6 para. 1 lit. f GDPR, as we have a legitimate interest in responding to your request and in an uncomplicated way of contacting you. If the contact is aimed at the conclusion of a contract, the additional legal basis for the processing is Art. 6 para. 1 lit. b GDPR.

We delete this data no later than 3 months after receipt, unless it is required for a contractual relationship that has arisen.

For contacting us in the course of online applications, we bind the contact form of

Gravity Forms

Rocketgenius Inc, 1620 Centerville Turnpike STE 102, Virginia Beach, VA 23464, USA.
https://www.gravityforms.com/privacy/.

on our website.

4. chat

LiveChat

We use the live chat service LiveChat. This service is provided byT ext S.A., ul. Zwycięska 47, 53-033 Wrocław, Poland. LiveChat enables us to communicate with the website visitor in real time, answer questions and provide support.

The data processed in this context includes names, email addresses, IP addresses and the content of chat messages. This data is used to respond to inquiries, to improve our customer service and to analyze the use of our live chat.

LiveChat stores the data on servers worldwide and can set cookies for data collection and storage. These cookies are only set with consent. This consent can be revoked at any time in our cookie consent tool. The legal basis for the use of cookies is Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG, insofar as this consent includes access to information in the user's terminal device or the storage of cookies within the meaning of the TDDDG.

We have a legitimate interest in using this tool to optimize our customer service, which is covered by Art. 6 para. 1 lit. f GDPR.

The data will be deleted as soon as it is no longer required for the purpose for which it was collected. Mandatory statutory provisions on retention periods remain unaffected.

The EU Commission's Standard Contractual Clauses (SCC) apply to data transfers to the USA. Further information:

https://www.livechat.com/legal/privacy-policy/.

Cookie Consent Tool

Borlabs Cookie

We use the Borlabs Cookie consent management tool from Borlabs GmbH, Rübenkamp 32, 22305 Hamburg, Germany, to ensure that only those cookies are set on our website for which there is a legal basis.

This service is used to obtain the website visitor's consent to the storage of certain cookies in their browser or the use of certain technologies and to document them in accordance with data protection regulations.

When this website is accessed, the consent given by the website visitor or the revocation of consent is stored as a Borlabs cookie in the website visitor's browser without forwarding this data to the Borlabs cookie provider.

The data collected will be stored until the website visitor requests us to delete it or deletes Borlabs cookies himself or until the purpose for storing the data no longer applies. The mandatory statutory retention periods remain unaffected by this.

The legal basis is Art. 6 para. 1 lit. c GDPR. Borlabs Cookies is used to obtain the legally required consent for the use of cookies.

Further details:

https://de.borlabs.io/kb/welche-daten-speichert-borlabs-cookie/.

Analysis and tracking tools

YouTube

We embed YouTube videos on this website. YouTube is an online video platform. This service is offered by Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

As soon as you start a video on our website, a connection to the YouTube servers is established. After starting a video, YouTube can set cookies on the website visitor's end device in order to save settings and preferences and subsequently display personalized advertising. The information obtained from this is also used for video statistics, to improve user-friendliness and to prevent attempted fraud.

The legal basis for the processing is Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG, insofar as this consent includes access to information in the user's terminal device or the storage of cookies within the meaning of the TDDDG. This consent can be revoked at any time.

Further information:

https://policies.google.com/privacy?hl=de.

WP Statistics

We use WP Statistics on this website. WP Statistic is a web analysis service. This service is provided by Veronalabs, Tatari 64, 10134, Tallinn, Estonia.

With the help of WP Statistics, we can analyze the use of our website. For this purpose, log files and actions of the website visitor on the page are recorded. The IP address recorded in the process is shortened so that it can no longer be directly assigned to a user. The data collected is stored exclusively on our server.

The legal basis for the processing is Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in analyzing user behavior on our website in order to optimize our website and our advertising.

Social media plugins

Facebook

Elements of the social network Facebook are integrated on this website. This service is offered by Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland.

If the social media element is activated, a direct connection is established between the website visitor and the Facebook servers and their IP address is transmitted to Facebook. If the website visitor has a user account, the visit to this website can be assigned to the corresponding user account.

The legal basis for the processing is Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. Consent can be revoked at any time.

If personal data is collected on this website with the help of Facebook and forwarded to Meta, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Habour, Dublin 2, Ireland are jointly responsible for data processing in accordance with Art. 26 GDPR. This joint responsibility is limited exclusively to the collection and transfer of data to Facebook. There is an agreement on joint processing for this purpose:

https://www.facebook.com/legal/controller_addendum.

We are responsible for providing data protection information when using the Facebook tool and for the secure integration of the tool on the corresponding website in accordance with data protection law. Facebook, on the other hand, is responsible for the data security of its products. This means that data subjects' rights with regard to the data processed by Facebook must be asserted directly with Facebook.

The EU Commission's Standard Contractual Clauses (SCC) apply to data transfers to the USA.

Further information:

 https://www.facebook.com/legal/EU_data_transfer_addendum

https://de-de.facebook.com/help/566994660333381

https://www.facebook.com/policy.php

https://de-de.facebook.com/privacy/explanation.

Instagram

Elements of the social network Instagram are integrated on this website. This service is offered by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

If the social media element is activated, a direct connection is established between the website visitor and the Instagram servers and their IP address is transmitted to Instagram. If the website visitor has a user account, the visit to this website can be assigned to the corresponding user account. As the website operator, we have no knowledge of the content of the transmitted data.

The legal basis for the processing is Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. Consent can be revoked at any time.

If personal data is collected on this website with the help of Facebook or Instagram and forwarded to Meta, the website operator and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Habour, Dublin 2, Ireland are jointly responsible for data processing in accordance with Art. 26 GDPR. This joint responsibility is limited exclusively to the collection and transfer of data to Facebook and Instagram. There is an agreement on joint processing for this purpose:

https://www.facebook.com/legal/controller_addendum.

The website operator is responsible for providing data protection information when using the Instagram tool and for the secure integration of the tool on the corresponding website in accordance with data protection law. Facebook and Instagram, on the other hand, are responsible for the data security of their products. This means that data subjects' rights with regard to data processed by Facebook or Instagram must be asserted directly with Facebook or Instagram.

The EU Commission's Standard Contractual Clauses (SCC) apply to data transfers to the USA.

https://www.facebook.com/legal/EU_data_transfer_addendum

https://de-de.facebook.com/help/566994660333381

https://www.facebook.com/policy.php

https://instagram.com/about/legal/privacy/.

Social media profiles

In addition to our website, we are also present with our company on social networks. Here we want to present our company and create the opportunity to get in touch with us.

We also use the opportunity to place advertisements and job advertisements on social media.

In the following, we provide information about which data we and the respective social network process when you visit and interact with our profile.

LinkedIn

We operate a LinkedIn profile on https://www.linkedin.com/. This social network is operated by LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA.

1. interaction with our company profile

When you visit our LinkedIn profile and interact with us via it, we process personal data.
personal data. On the one hand, the data made publicly available on the profile. On the other hand, we also process the personal data contained in posts, comments or direct messages to us. Through interactions such as liking or sharing, we can see the user profile with the public information.

The legal basis for this processing is Art. 6 para. 1 lit. f GDPR. It is in our legitimate interest to provide relevant and interesting content and to enable the use and functionality of our LinkedIn profile

Insofar as an inquiry is related to the fulfillment of a contract or is necessary for the implementation of pre-contractual measures, our processing is based on Art. 6 para. 1 lit. b GDPR.

2. page insights

LinkedIn provides us with aggregated statistics and insights (called Page Insights) that tell us how people interact with our Company Page. Among other things, we receive information about the number of profiles that view, comment on or otherwise interact with our posts, as well as aggregated demographic and other information that helps us learn about the interaction with our page or LinkedIn profile. Pages Insights provided to us by LinkedIn consist of aggregated data, and LinkedIn does not provide us with any personally identifiable information about members in relation to Page Insights. We also have no way of linking Page Insights to individual members.

When placing ads, LinkedIn provides us with information about the types of people who see our ads and about the success of our ads. Personal data is only passed on to us if this person has consented to such processing. We also receive information from LinkedIn that allows us to understand which of our ads led to a purchase being made or an action being taken.

The purpose of processing this data is to analyze our reach and to adapt our content and advertisements to user interests. By evaluating this data, we can recognize how our content, our profile and our advertising are consumed. This enables us to create target group-specific content and place advertisements in order to better market our company and our services.

The processing is based on our legitimate interest pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR.

When processing personal data in the course of the so-called Page Insights, the processing is carried out in joint responsibility with LinkedIn in accordance with Art. 26 para. 1 GDPR.

We have concluded a corresponding agreement with LinkedIn for this purpose, which can be viewed here(https://legal.linkedin.com/pages-joint-controller-addendum).

The contact details of LinkedIn are:

LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland.

For LinkedIn, you can contact the data protection officer at the following link:

https://www.linkedin.com/help/linkedin/ask/TSO-DPO.

Processing by LinkedIn

In connection with your visit to our company profile, LinkedIn may also process additional personal data. In this case, the processing is carried out under the sole responsibility of LinkedIn and without our knowledge. You can find more information from LinkedIn on this at:

https://de.linkedin.com/legal/privacy-policy.

Facebook

We operate a Facebook fan page on https://www.facebook.com. This social network is operated by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

Interaction with our company profile

When you visit our Facebook profile and interact with us via it, we process personal data. On the one hand, the data made publicly available on the profile. On the other hand, we also process the personal data contained in posts, comments or direct messages to us. Through interactions such as liking or sharing, we can see the user profile with the public information.

The legal basis for this processing is Art. 6 para. 1 lit. f GDPR. It is in our legitimate interest to provide relevant and interesting content and to enable the use and functionality of our Facebook profile.

Insofar as an inquiry is related to the fulfillment of a contract or is necessary for the implementation of pre-contractual measures, our processing is based on Art. 6 para. 1 lit. b GDPR.

Page Insights

As explained in the Meta Privacy Policy under "How do we use your information?" (Meta also collects and uses information to provide analytics services, known as Page Insights, for site operators. This also applies to our Facebook page.

Page insights are summarized statistics that are created based on certain interactions of visitors with pages and the content associated with them (e.g. viewing a page or a video, subscribing to a page, marking a page with "Like" or "No longer like", etc.) and are logged by the meta servers.

In connection with the Page Insights, Meta provides us with summarized statistics and insights that give us information about how people interact with our company website. We do not have access to any personal data, only to the summarized Page Insights. With the help of Page Insights, we can view anonymous statistics, e.g. the reach of our account, page views, likes, etc.. These also contain evaluations according to age, gender and location of the users (as specified by them in their respective Facebook profiles). To evaluate the reach, we can make settings or set appropriate filters with regard to the selection of a time period, the viewing of a specific post and demographic groupings. This data is anonymized. It is not possible for us to draw conclusions about specific individuals.

The purpose of processing this data is to analyze our reach and adapt our content and advertisements to user interests so that visitors can derive the greatest possible benefit from them. By evaluating this data, we can recognize how our content, our profile and our advertising are consumed. This enables us to create target group-specific content and place advertisements to better market our company and our services.

The processing is based on our legitimate interest pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR.

When processing personal data in the course of the so-called Page Insights, we are jointly responsible with Facebook in accordance with Art. 26 para. 1 GDPR.

We have concluded a corresponding agreement with Facebook for this purpose, which can be viewed here (https://www.facebook.com/legal/terms/page_controller_addendum).

The contact details for Facebook are:

Online contact: https://www.facebook.com/help/contact/1650115808681298

Postal: Meta Platforms Ireland Limited, ATTN: Privacy Operations, Merrion Road, Dublin 4, D04 X2K5, Ireland.

For Facebook, you can contact the data protection officer at the following link:

https://www.facebook.com/help/contact/540977946302970.

Further information about the Page Insights:

https://de-de.facebook.com/legal/terms/page_cntroller_addendum

Processing of personal data and cookies by Meta

When you access a Facebook page, the IP address assigned to your end device is transmitted to Facebook. According to Facebook, this IP address is anonymized (for "German" IP addresses). Facebook also stores information about the end devices of its users (e.g. as part of the "login notification" function); Facebook may thus be able to assign IP addresses to individual users. If you are currently logged in to Facebook as a user, a cookie with your Facebook ID is stored on your device. This enables Facebook to track that you have visited this page and how you have used it. Facebook buttons integrated into websites enable Facebook to record your visits to these websites and assign them to your Facebook profile. This data can be used to tailor content or advertising to you.

Information on how personal data can be managed or deleted can be found in Facebook's Privacy Center:

https://www.facebook.com/privacy/center/.

Further information on the handling of data by Facebook can be found here:

http://de-de.facebook.com/about/privacy.

Instagram

We operate an Instagram profile. This social media platform is offered by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

Interaction with our company profile

When you visit our Instagram profile and interact with us, we process personal data. On the one hand, the data made publicly available on the profile. On the other hand, we also process the personal data contained in posts, comments or direct messages to us. Through interactions such as liking or sharing, we can see the user profile with the public information.

The legal basis for this processing is Art. 6 para. 1 lit. f GDPR. It is in our legitimate interest to provide relevant and interesting content and to enable the use and functionality of our Instagram profile.

Insofar as an inquiry is related to the fulfillment of a contract or is necessary for the implementation of pre-contractual measures, our processing is based on Art. 6 para. 1 lit. b GDPR.

Insights

As explained in the Meta Privacy Policy under "How do we use your information?" (https://privacycenter.instagram.com/policy/?entry_point=ig_help_center_data_policy_redirect), Meta also collects and uses information to provide analytics services, known as insights, for site operators. This also applies to our Instagram profile.

The insights are summarized statistics that are created based on certain interactions of visitors with pages and the content associated with them and are logged by the meta servers. This includes the following information, among others

  • How many people see and interact with our products, services or content, such as posts, videos, Instagram pages, listings, stores and advertisements (if the advertisement is shown on meta-products);
  • How people interact with our content, websites, apps and services;
  • Which group of people interact with our content and which group of people use our services.

Meta provides us with summarized reports and insights that tell us how well our content, features, products and services are performing.

We do not have access to personal data, but only to the summarized reports.

To evaluate the reach, we can make settings or set appropriate filters with regard to the selection of a time period, the viewing of a specific post and demographic groupings. This data is anonymized. It is not possible for us to draw conclusions about specific individuals.

The purpose of processing this data is to analyze our reach and adapt our content and advertisements to user interests so that visitors can derive the greatest possible benefit from them. By evaluating this data, we can recognize how our content, our profile and our advertising are consumed. This enables us to create target group-specific content and place advertisements to better market our company and our services.

The processing is based on our legitimate interest pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR.

When processing personal data in the course of so-called insights, the processing is carried out under joint responsibility with Meta in accordance with Art. 26 para. 1 GDPR.

We have concluded a corresponding agreement with Meta, which can be viewed here (https://www.facebook.com/legal/terms/page_controller_addendum.).

Meta's contact details are as follows:

Online contact: https://www.facebook.com/help/contact/1650115808681298

Postal: Meta Platforms Ireland Limited, ATTN: Privacy Operations, Merrion Road, Dublin 4, D04 X2K5, Ireland.

For Instagram, you can contact the data protection officer at the following link:

https://www.facebook.com/help/contact/540977946302970.

Further information about the Insights:

https://de-de.facebook.com/help/pages/insights.

You can find Instagram's full privacy policy here:

https://privacycenter.instagram.com/policy/?entry_point=ig_help_center_data_policy_redirect

Processing of personal data and cookies by Meta

When you access an Instagram page, the IP address assigned to your device is transmitted to Meta. According to Meta, this IP address is anonymized (for "German" IP addresses). Meta also stores information about the end devices of its users (e.g. as part of the "login notification" function); Meta may thus be able to assign IP addresses to individual users. If you are currently logged in to Instagram as a user, a cookie with your Instagram ID is stored on your device. This enables Meta to track that you have visited this page and how you have used it. Meta buttons integrated into websites enable Meta to record your visits to these websites and assign them to your Instagram profile. This data can be used to tailor content or advertising to you.

Further information:

https://privacycenter.instagram.com/policy/?entry_point=ig_help_center_data_policy_redirect.

XingX (formerly Twitter)

We use the short message service "X" (formerly Twitter). This is a service of X Corp, 1355 Market Street, Suite 900, San Francisco, CA 94103 USA. Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2 D02 AX07, Ireland, is responsible for the data processing of persons living outside the United States.

Interactions with our account

In principle, we do not collect and process any data from you when you use our short message service. The data you enter on X, in particular your user name and the content published under your account, will be processed by us on the basis of your consent in accordance with Art. 6 para. 1 lit. a GDPR, insofar as your tweets are re-tweeted, we reply to them or tweets are written that refer to your account. The data freely published and disseminated on X is thus included by us and made accessible to our followers.

Data processed by X

We have no control over the nature and extent of the data processed by X Corp., how it is processed and used, or whether it is disclosed to third parties. When you use X, your personal data will be collected, transferred, stored, disclosed and used by X Corp. and transferred to, stored and used in the United States, Ireland and any other country in which X Corp. does business, regardless of your country of residence.

X processes all voluntarily entered data such as name and user name, e-mail address, telephone number or the contacts in the address book, insofar as these have been uploaded or synchronized.

On the other hand, X also evaluates the shared content to determine which topics the user is interested in. Confidential messages that are sent directly to other users are processed and stored by X. Using GPS data, information on wireless networks or the IP address, X can determine the user's location.

X also receives information about what content is viewed, even if the user has not created an account.

X processes so-called "log data". This includes the IP address, the browser type, the operating system, information on the previously accessed website and the pages accessed, the location, the mobile phone provider, the end device used (including device ID and application ID), the search terms used and cookie information.

Due to the fact that X Corp. is a non-European provider that only has a European branch in Ireland, it is not bound by German data protection regulations in its own opinion. This concerns, for example, the rights to information, blocking or deletion of data or the possibility of objecting to the use of usage data for advertising purposes.

The processing of data can be restricted in the general settings of the X account and under "Data protection and security". In addition, on mobile devices (smartphones, tablet computers), X's access to contact and calendar data, photos, location data, etc. can be restricted in the settings options there. However, this depends on the operating system used.

Further information can be found here:

https://help.twitter.com/de/safety-and-security/x-privacy-settings.

Information on the processing of data by X can be found in X's privacy policy:

https://twitter.com/de/privacy.

Information can also be requested via the X data protection form or the archive requests:

https://support.twitter.com/forms/privacy.

Pinterest

We operate a Pinterest profile. Pinterest is offered by Pinterest Europe Ltd Palmerston House, 2nd Floor Fenian Street Dublin 2 Ireland.

Shared responsibility

We are jointly responsible for our profile with Pinterest. The underlying joint controlling agreement can be viewed here: https://business.pinterest.com/de/pinterest-advertising-services-agreement/rest-of-apac/.

Pinterest's data protection officer can be contacted here: https://help.pinterest.com/de/data-protection-officer-contact-form.

Data processing by Pinterest

When you visit our Pinterest page, Pinterest collects, among other things, log data that the browser automatically transmits when you visit the website (e.g. IP address, search history, browser type and settings, date and time of the request, etc.). Device information is also processed by Pinterest (e.g. device type, operating system).

Further information can be found at:

https://policy.pinterest.com/de/technical-information-we-collect-when-you-use-our-service  und

https://policy.pinterest.com/de/privacy-policy.

Pinterest can also set cookies. Some of the data processed in this way is assigned to the user's account.

Further information can be found at:

https://policy.pinterest.com/de/cookies.

Data processing by us

When Pinterest users communicate with us via our Pinterest profile, we receive the user's respective message (including their Pinterest user name).

We also process the comments published by users.

Our data processing serves the purpose of presenting our published content on Pinterest and communicating with users.

The legal basis for this is Art. 6 para. 1 lit. f GDPR, as we have a legitimate interest in presenting relevant information to interested users and communicating about this.

The "Pinterest Analytics" function is available to us in our Pinterest profile, which allows us to view statistical evaluations.

The data we receive from Pinterest are merely anonymous statistics about the visitors to our Pinterest profile. These statistics are not personal and do not allow any conclusions to be drawn about individual users.

Passing on the data

When we receive messages from users, we do not transmit the content of these messages to other recipients.

Information about the transmission of data to third parties by Pinterest can be found here:

https://policy.pinterest.com/de/privacy-policy und https://help.pinterest.com/de/article/ads-performance-reporting.

Storage duration

In connection with our Pinterest profile, we only store the messages that we receive when Pinterest users communicate with us via our Pinterest profile. We delete these messages at the latest after the statutory retention period has expired.

The respective storage period by Pinterest is described in their data policy at https://policy.pinterest.com/de/privacy-policy.

YouTube

We operate a profile on YouTube. This is a video platform of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, which enables us to publish video content and interact with our audience.

Data processing by us

We also process the data of profile visitors. In doing so, we process data from your use of our profile, which is provided to us by YouTube.

This information includes statistics on visits to our profile, reports on the playback time of our videos, user-user interaction (e.g. "I like" or comments), as well as information about individual people who actively interact with our page, e.g. by subscribing or using YouTube's communication options.

The data entered on YouTube, in particular the user name and the content published under the account, is made visible and processed by us through interactions with our profile.

We process this data to enable communication and to optimize our content in terms of reach and target group.

The legal basis for processing is a legitimate interest in accordance with Art. 6 para. 1 lit. f GDPR for the purposes stated.

Data processing by YouTube

When visiting our YouTube channel or interacting with our YouTube channel, YouTube collects personal data such as IP address, device information, geographic information, as well as activity on the platform, including videos viewed, interactions such as likes, comments and subscriptions. This data may be collected through cookies and similar technologies that are stored on the device.

YouTube uses this information to operate and improve the platform, to provide personalized advertising and to perform analyses and measurements to understand how users interact with the content. In addition, data processing helps to evaluate and improve the reach and effectiveness of content.

The processing of data by YouTube takes place, among other things, on the basis of your consent, which is expressed by accepting the cookie policy on YouTube.

The data collected by YouTube may be shared within the Google group of companies and with third parties who may be located in countries outside the European Union, including the USA. Google LLC is certified by the EU-U.S. Data Privacy Framework, which ensures that an adequate level of data protection is maintained even when data is transferred to third countries.

We have no influence on the scope of the data processed by YouTube, the type of processing and use or the transfer of this data to third parties. We also have no effective control options in this respect.

Information about which data is processed by YouTube and for what purposes can be found in YouTube's privacy policy: https://policies.google.com/privacy?hl=de&gl=de.

Google company profile

We have a so-called Google company profile. We use the information service offered by Google and the services of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google").

Data processing by Google

The Google page and its functions are used under your own responsibility. This applies in particular to the use of social and interactive functions (e.g. commenting, sharing, rating, direct messages). When you visit and interact with our Google company profile entry, Google also collects your IP address and other information that is stored on your device in the form of cookies. This may enable Google to assign IP addresses to individual users or user accounts. This information is used to provide us, as the operator of the Google company profile entry, with statistical information about the use of Google services. The data collected in this context is processed by Google and may be transferred to countries outside the European Union. What information Google receives and how it is used is generally described by Google in its privacy policy.

If you contact us via our Google company profile entry or other Google services by direct message, we cannot rule out the possibility that these messages may also be read and analyzed by Google (both by employees and automatically). We therefore advise against providing us with personal data. Instead, another form of communication should be chosen as early as possible.

The use of this service is subject to the Google Privacy Policy, which you - by using it - have already agreed to.

Further information can be found in the privacy policy under the following link: https://policies.google.com/privacy?hl=de.

Data processing by us

As the provider of our Google company profile entry, we do not collect and process any further data from the use of this Google service.

If you contact us or publish a review about us, we process your published profile data and the content of the review/comment.

The legal basis is Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in presenting our company and enabling the evaluation of our services in order to present our company and our services.

Third-party content

Weglot

We use the Weglot service of the company WEGLOT, 7 cité Paradis in Paris (75010), France, on our website.

This is a service that can translate, display and manage a multilingual website. Weglot has automatic content recognition. It scans and recognizes the texts, images and SEO metadata of the website and thus replaces the manual collection of website content for translation.

The legal basis for the processing of data by Weglot is Art. 6 para. 1 lit. f GDPR, based on our legitimate interest in making our website accessible to an international audience. The data transmitted is primarily our URL and the IP address of the website visitor.

The data processed by Weglot will be deleted as soon as they are no longer required for the purpose of their processing and there are no legal obligations to retain them.

Further information:
https://www.weglot.com/de/privacy.

Jetpack

We use the functions of Jetpack. This service is offered by Automattic Inc, 60 29th Street #343, San Francisco, CA 94110, USA.

Jetpack is a WordPress plugin that provides security, performance optimization and website management features, including automatic backups, brute force protection, malware scanning and speed optimization. It also supports website growth through SEO tools, statistics, automated social media posts and advertising options to increase traffic and revenue.

Personal data is also collected, stored and processed. For the Jetpack tool to work, Jetpack sets cookies when a website is opened that has components of the tool built in. The collected data is synchronized with Automattic and stored there. In addition to the anonymized IP address and data on user behaviour, this includes, for example, browser type, unique device identifier, preferred language, data and time of the page view, operating system and, if applicable, information on the mobile network.

This is only done with consent. Consent can be withdrawn at any time. The legal basis for this is Art. 6 para. 1 lit. a GDPR.
Otherwise, the legal basis for the processing of personal data is Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in making our website efficient and optimizing its functionality.

The EU Commission's Standard Contractual Clauses (SCC) apply to data transfers to the USA.

Further information:

https://jetpack.com/de/support/cookies/

https://automattic.com/de/privacy/?utm_medium=automattic_referred&utm_source=jpcom_footer.

YOAST SEO

We integrate the functions of YOAST SEO on our website. This service is offered by Yoast B.V., Don Emanuelstraat 3 6602GX, Wijchen, Netherlands.

The visibility of websites in search engines can be optimized with the help of an SEO tool.

The Yoast SEO WordPress plugin does not process any personal data.
Further information:

https://yoast.com/help/gdpr/.

Audio and video conferencing

Zoom

We use Zoom to communicate with customers. Zoom is an online conferencing tool. This service is offered by Zoom Communications Inc, San Jose, 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA.

When communicating with this tool via video or audio conferencing, personal data is processed by us and the provider of the tool. The data collected includes all information that you provide when using the tool. Metadata relating to the conference is also processed. Furthermore, technical information required for the function of online communication is processed. Furthermore, all files that are shared within the tool are stored on the tool provider's servers.

Zoom can also set cookies. These cookies are only set with consent. Consent can be revoked at any time. The legal basis for this is Art. 6 para. 1 lit. a GDPR.

Otherwise, the legal basis for the processing of data by Zoom is Art. 6 para. 1 lit. b GDPR. The communication is related to the performance of a contract or is necessary for the fulfillment of pre-contractual obligations. Furthermore, this tool is used to simplify communication with our company. This constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR.

This data is stored until the data subject requests its deletion, the consent for storage is revoked or the purpose for storage no longer applies. Cookies remain on the end device until the user deletes them. Mandatory statutory provisions on retention periods remain unaffected.

The EU Commission's Standard Contractual Clauses (SCC) apply to data transfers to the USA.

Further information:

https://zoom.us/de-de/privacy.html.

Payment services

American Express

We use American Express on this website. American Express is a payment service provider. This service is offered by American Express Europe S.A., Theodor-Heuss-Allee 112, 60486 Frankfurt am Main, Germany.

For the purpose of payment processing, the payment data of the website visitor is processed by the payment service provider as soon as a purchase is made via this website. The respective contractual and data protection provisions of the payment service provider apply to the respective transaction.

The legal basis is Art. 6 para. 1 lit. b GDPR. The data is processed for the purpose of pre-contractual obligations.

We also have a legitimate interest in the processing of this data within the meaning of Art. 6 para. 1 lit. f GDPR in order to ensure a fast and reliable payment process.

American Express may transfer the data to the parent company in the USA. American Express has Binding Corporate Rules (BCR) for this purpose.

Further details:

https://www.americanexpress.com/de/legal/online-datenschutzerklarung.html.

Mastercard

We use Mastercard on this website. Mastercard is a payment service provider. This service is offered by Mastercard Europe SA, Chaussée de Tervuren 198A, B-1410 Waterloo, Belgium.

For the purpose of payment processing, the payment data of the website visitor is processed by the payment service provider as soon as a purchase is made via this website. The respective contractual and data protection provisions of the payment service provider apply to the respective transaction.

The legal basis is Art. 6 para. 1 lit. b GDPR. The data is processed for the purpose of pre-contractual obligations.

We also have a legitimate interest in the processing of this data within the meaning of Art. 6 para. 1 lit. f GDPR in order to ensure a fast and reliable payment process.

Mastercard may transfer the data to the parent company in the USA. Mastercard has Binding Corporate Rules (BCR) for this purpose.

Further details:

https://www.mastercard.us/content/dam/mccom/global/documents/mastercard-bcrs.pdf

https://www.mastercard.de/de-de/datenschutz.html.

VISA

We use VISA on this website. VISA is a payment service provider. This service is offered by Visa Europe Services Inc, London Branch, 1 Sheldon Square, London W2 6TT, United Kingdom.

For the purpose of payment processing, the payment data of the website visitor is processed by the payment service provider as soon as a purchase is made via this website. The respective contractual and data protection provisions of the payment service provider apply to the respective transaction.

The legal basis is Art. 6 para. 1 lit. b GDPR. The data is processed for the purpose of pre-contractual obligations.

We also have a legitimate interest in the processing of this data within the meaning of Art. 6 para. 1 lit. f GDPR in order to ensure a fast and reliable payment process.

The EU Commission's Standard Contractual Clauses (SCC) apply to data transfers to the USA.

Further details:

https://www.visa.de/nutzungsbedingungen/visa-privacy-center.html.

Services for processing bookings

vioma booking

www.vioma.de

CRM systems

protel pms

www.weareplanet.com

Further services

resmio table reservation system

www.resmio.com

4. what else is important

Finally, we would like to inform you in detail about your rights and how you will be informed about changes to data protection requirements.

Your rights in detail

Right to information in accordance with Art. 15 GDPR

You can request information about whether your personal data is being processed. If this is the case, you can request further information on the type and manner of processing. A detailed list can be found in Art. 15 para. 1 lit. a to h GDPR.

Right to rectification in accordance with Art. 16 GDPR

This right includes the correction of incorrect data and the completion of incomplete personal data.

Right to erasure in accordance with Art. 17 GDPR

This so-called 'right to be forgotten' gives you the right, under certain conditions, to request the deletion of your personal data by the controller. This is generally the case if the purpose of the data processing no longer applies, if consent has been withdrawn or the initial processing took place without a legal basis. A detailed list of reasons can be found in Art. 17 para. 1 lit. a to f GDPR. This "right to be forgotten" also corresponds to the controller's obligation under Art. 17 para. 2 GDPR to take appropriate measures to ensure the general erasure of data.

Right to restriction of processing in accordance with Art. 18 GDPR

This right is subject to the conditions set out in Art. 18 para. 1 lit. a to d.

Right to data portability pursuant to Art. 20 GDPR

This regulates the basic right to receive your own data in a commonly used form and to transfer it to another controller. However, this only applies to data processed on the basis of consent or a contract in accordance with Art. 20 (1) (a) and (b) and insofar as this is technically feasible.

Right to object pursuant to Art. 21 GDPR

In principle, you can object to the processing of your personal data. This applies in particular if your interest in objecting outweighs the legitimate interest of the controller in the processing and if the processing relates to direct marketing and/or profiling.

Right to "individual decision-making" pursuant to Art. 22 GDPR

In principle, you have the right not to be subject to a decision based solely on automated processing (including profiling) which produces legal effects concerning you or similarly significantly affects you. However, this right is also restricted and supplemented by Art. 22 (2) and (4) GDPR.

Further rights

The GDPR contains comprehensive rights to inform third parties whether or how you have asserted rights under Art. 16, 17, 18 GDPR. However, this is only possible or feasible with reasonable effort.

We would like to take this opportunity to draw your attention once again to your right to withdraw your consent in accordance with Art. 7 (3) GDPR. However, this does not affect the lawfulness of the processing carried out up to that point.

We would also like to draw your attention to your rights under §§ 32 ff. BDSG, which, however, are largely congruent with the rights just described.

Right to lodge a complaint pursuant to Art. 77 GDPR

You also have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of personal data relating to you infringes this Regulation.

5 What if the GDPR is abolished tomorrow or other changes take place?

The current status of this privacy policy is 19.11.2024.

From time to time it is necessary to adapt the content of the data protection declaration in order to react to actual and legal changes. We therefore reserve the right to amend this privacy policy at any time. We will publish the amended version in the same place and recommend that you read the privacy policy regularly.