You are here:

GENERAL PRIVACY POLICY

 

We are pleased that you are visiting our website.

 

The protection of your personal data is very important to us. Our goal is not only to provide you with an interesting and extensive online offer, but also to protect your personal rights. The legal basis for processing is in particular the EU General Data Protection Regulation (GDPR) and the Digital-Services-Act (DSA).

 

The following data protection information gives you an initial overview of the processing of your data. You will find all the information below, categorized by topic.

 

Name and address of the responsible

The responsible party, within the meaning of basic data protection regulation and other national data protection laws of the member states as well as other data protection regulations is the:

ATLANTIC Hotels Management GmbH
Ludwig-Roselius-Allee 2
28329 Bremen
Deutschland
Telephone: +49 (0) 421 944888-0
Telefax: +49 (0) 421 944888-552
Email: info@atlantic-hotels.de
Website: https://www.atlantic-hotels.de

 

Name and address of the data protection officer

The data protection officer of the responsible party is:

SHIELD GmbH Datenschutz & Sicherheit
Managing Director: Martin Vogel
Ohlrattweg 5
25497 Prisdorf
Phone: +49 (0) 4101 8050600
E-mail: datenschutz@atlantic-hotels.de
www.shield-datenschutz.de

 

General data management

 

Scope of processing of personal data

We process personal data from our users principally only to the extent necessary to provide a functional website and our content and services. The processing of personal data of our users is regularly only carried out with their consent. These consents can be revoked at any time with effect for the future by informing the responsible. The contact details can be found under "I. Name and address of the responsible".


Legal basis for the processing of personal data

 

Insofar as we obtain the consent of the data subject for the processing of personal data, art. 6 (1) (a) EU General Data Protection Regulation (GDPR) serves as the legal basis for the processing of personal data.


In the processing of personal data necessary for the performance of a contract to which the data subject is a party, art. 6 (1) (b) GDPR serves as the legal basis. This also applies to processing operations required to carry out pre-contractual actions.


Insofar as processing of personal data is required to fulfill a legal obligation that is required for our company, art. 6 (1) (c) GDPR serves as the legal basis. In the event that vital interests of the data subject or another natural person require the processing of personal data, art. 6 (1) (d) GDPR serves as the legal basis. If processing is necessary to safeguard the legitimate interests of our company or a third party, and if the interests, fundamental rights and freedoms of the data subject do not prevail over the first interest, art. 6 (1) (f) GDPR serves as legal basis for processing.


Data deletion and storage duration

The personal data of the data subject will be deleted or blocked as soon as the purpose of the storage expires. Additional storage may take place if provided for by the European or national legislator in EU regulations, laws or other regulations to which the data controller is subject. Blocking or deletion of the data also takes place when a storage period prescribed by the standards mentioned expires, unless there is a need for further storage of the data for conclusion of a contract or fulfillment of the contract

 

Processing of personal data of guests at hotel check-in

 

Processing of personal data of domestic guests at hotel check-in

In order to process the accommodation contract, the following personal data must be collected and stored from you as a domestic guest at hotel check-in:

  • Date of arrival and expected departure (for planning and organising your stay)
  • Surname and first name (for identification and contact purposes)
  • E-mail address (to participate in the online check-in/out process to simplify and speed up the check-in and check-out process, to confirm your booking and to send relevant information about your reservation, to send your invoice after the end of your stay)
  • Address (for identification and contact purposes) - unless you initiate a card-based payment transaction with Strong Customer Authentication (SCA), in which case the earmarked allocation number of the payment method used is collected. In this case, the earmarked allocation number of the payment method used is stored together with the above-mentioned data.
  • Federal State law may stipulate that further data may be collected on the registration form for the collection of tourist and spa fees (fulfilment of the requirements of the tourist and spa administrations).

Strong customer authentication is a requirement of the EU Payment Services Directive PSD2, which ensures that online payments are secure, and fraud is reduced. It requires users to confirm their identity when making payments using two of three factors - knowledge (something that only the user knows, e.g. a password), possession (something that only the user has, e.g. a smartphone) and inherence (something that only the user has, e.g. a fingerprint).

Entering your e-mail address is voluntary. Please note, however, that if you do not provide it, you will not be able to take advantage of the digital procedures, such as online check-in/out, digital reservation confirmation or electronic invoicing.

Other data collected during the reservation process or during your stay - such as your private or business billing address - will be processed in accordance with the purposes stated in this privacy policy.

Your personal data is processed on the basis of Art. 6 Para. 1 lit. b GDPR (fulfilment of a contract) and Art. 6 Para. 1 lit. f GDPR (legitimate interest). Our legitimate interest lies in improving our service offering by simplifying processes and digital communication. Voluntary information such as your e-mail address is processed on the basis of Art. 6 Para. 1 lit. a GDPR (consent). You have the right to withdraw your consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.

Your data will only be passed on to departments and, if necessary, to so-called ‘processors’ within the meaning of Art. 4 No. 8 GDPR, who are entrusted with the processing of your booking and the realisation of your stay. Processors within the EU are not considered third parties. Data will only be passed on to third parties if this is necessary for the fulfilment of the accommodation contract or if you have given us your explicit consent, which can be revoked at any time, or if this is required by law.

Your personal data will only be stored for as long as is necessary for the fulfilment and processing of the accommodation contract. Statutory retention obligations remain unaffected by this.

 

Processing of personal data of foreign guests at hotel check-in

The collection and storage of the following personal data from you as a foreign guest at hotel check-in is necessary for the processing of the accommodation contract and due to legal obligations arising from the Federal Registration Act:

  • Date of arrival and expected departure (to plan and organise your stay and to fulfil the requirements of the Federal Registration Act)
  • Surname and first name (for identification and contact purposes and to fulfil the requirement of the Federal Registration Act)
  • Date of birth (fulfilment of the requirement under the Federal Registration Act)
  • Nationalities (fulfilment of the requirement under the Federal Registration Act)
  • Address (for identification and, if necessary, contacting and to fulfil the requirement under the Federal Registration Act)
  • Number of foreign fellow travellers and their nationality (fulfilment of the requirement under the Federal Registration Act)
  • Serial number of the recognised and valid passport or passport replacement document (identity document) (fulfilment of the requirement under the Federal Registration Act)
  • Federal State law may stipulate that further data may be collected on the registration form for the collection of tourist and spa fees (fulfilment of the requirements of the tourist and spa administrations)

The details on the registration form are compared with those on your identity document. If there are any discrepancies, this will be noted on the registration form. If you do not present any or no valid identity document, this will also be noted on the registration form.

Other data collected during the reservation process or during the stay - for example the private or business billing address - will be processed in accordance with the purposes stated in this privacy policy.

Your personal data is processed on the basis of Art. 6 Para. 1 lit. c GDPR (legal obligation) in conjunction with §§ 29, 30 Federal Registration Act, Art. 6 Para. 1 lit. b GDPR (fulfilment of a contract) and Art. 6 Para. 1 lit. f GDPR (legitimate interest). Our legitimate interest lies in improving our service offering by simplifying processes and digital communication. Voluntary information is processed on the basis of Art. 6 Para. 1 lit. a GDPR (consent). You have the right to withdraw your consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

Your data will only be passed on to departments and, if necessary, to so-called ‘processors’ within the meaning of Art. 4 No. 8 GDPR, who are entrusted with the processing of your booking and the realisation of your stay. Processors within the EU are not considered third parties. Data will only be passed on to third parties if this is necessary for the fulfilment of the accommodation contract or if you have given us your explicit consent, which can be revoked at any time, or if this is required by law.

Your personal data will only be stored for as long as is necessary for the fulfilment and processing of the accommodation contract. Statutory retention obligations remain unaffected by this. The Federal Registration Act stipulates, among other things, that registration forms must be kept for one year from the date of departure and destroyed within three months of expiry of the retention period.

 

Provision of the website and creation of logfiles

 

Description and scope of data processing

Each time our website is accessed, our system automatically collects data and information from the computer system of the calling computer.

The following data is collected:

  1. Information about the browser type and the version used
  2. The operating system of the users
  3. The Internet service provider of the user
  4. The IP address of the user
  5. Date and time of access
  6. Websites from which the user's system accesses our website
  7. Websites accessed by the user's system through our website

The data is also stored in the log files of our system. A storage of this data together with other personal data of the user does not take place.

 

Legal basis for data processing

The legal basis for the temporary storage of data and log files is Art. 6 (1) (f) GDPR.

 

Purpose of the data processing

The temporary storage by the system of the IP address is necessary to allow delivery of the website to the computer of the user. To do this, the user's IP address must be kept for the duration of the session.

Storage in log files is done to ensure the functionality of the website. In addition, the data is used to optimize the website and to ensure the security of our information technology systems. An evaluation of the data for marketing purposes does not take place in this context.

We have a justified interest in the processing of data for this purpose, according to Art. 6 (1) (f) GDPR.

In diesen Zwecken liegt auch unser berechtigtes Interesse an der Datenverarbeitung nach Art. 6 Abs. 1 lit. f DSGVO.

 

Duration of storage

The data will be deleted as soon as it is no longer necessary for the purpose of its collection. In the case of collecting the data for providing the website, this is the case when the session is completed. In the case of storing the data in log files, data is stored for no more than seven days. After one day, the IP addresses of the users are anonymized, so that an assignment of the calling client is no longer possible.

 

Objection and removal possibility

The collection of data for the provision of the website and the storage of the data in log files is essential for the operation of the website. Consequently, there is no possibility for the user to object.

 

Use of cookies

 

Description and scope of data processing

Our website uses cookies. Cookies are text files that are stored in the Internet browser or by the Internet browser on the user's computer system. When a user visits a website, a cookie may be stored on the user's operating system. This cookie contains a characteristic string that allows the browser to be uniquely identified when the website is reopened.


We use cookies to make our website more user-friendly. Some elements of our website require that the calling browser be identified even after switching pages. In addition, we use cookies on our website that allow an analysis of users' browsing behavior.
In this way, the following data is transmitted:

  1. IP address, age, gender, interests
  2. activities on the website during the visit
  3. frequency of page views
  4. use of website features
  5. origin / visitor source


Technical precautions pseudonymize the data of the users collected in this way. This makes it much more difficult to assign the data to the calling user and is only possible with the help of an appropriate "key". The data will not be stored together with other personal data of the user.

 

Legal basis for data processing

The legal basis for the processing of personal data using cookies that are technically necessary or necessary for the provision of the service is Art. 6 (1) (f) GDPR.
The legal basis for the processing of personal data using all other cookies or cookies not strictly necessary for the provision of the service is Art. 6 (1) (a) GDPR.

 

Purpose of the data processing

The purpose of using technically necessary cookies is to simplify the use of websites for users. Some features of our website cannot be offered without the use of cookies. For these, it is necessary that the browser is recognized even after switching pages. The user data collected through technically necessary cookies will not be used to create user profiles. The use of the analysis cookies is for the purpose of improving the quality of our website and its contents. Through the analysis cookies, we learn how the website is used and so we can constantly optimize our services offered.

 

Duration of storage, objection and removal options

Cookies are stored on the computer of the user and transmitted by it to our page. For cookies requiring consent, a so-called cookie consent banner is made available to you when you visit the website. There you have the possibility, if you wish, to use our website only with the technically necessary cookies.


Furthermore, you as a user also have full control over the use of cookies. By changing the settings in your internet browser, you can disable or restrict the transmission of cookies. Already saved cookies can be deleted at any time. This can also be done automatically. If cookies are disabled for our website, it may not be possible to fully use all the functions of the website.

You can find an overview of the cookies and the option to edit your consent in our Cookie Declaration.

 

Receiver

Öschberghof GmbH uses service providers who support the provision of the technical infrastructure, the design of our websites and the implementation of our services and who can have access to your personal data.

 

In order to process inquiries made by you or commissioned services, it may be necessary to pass on your personal data to contractual partners. You can find out more in the respective modules.

 

Rights of the affected person

If your personal data are processed, you are the person affected within the meaning of  GDPR and you have the following rights vis-à-vis the data controller:

 

Right to information

You may ask the person responsible to confirm whether personal data concerning you is processed by us.
If your data is being processed, you can request information from the person responsible about the following information:

  1. the purposes for which the personal data are being processed;
  2. the categories of personal data being processed;
  3. the recipients or the categories of recipients to whom personal data concerning you have been disclosed or are being disclosed;
  4. the planned duration of the storage of your personal data or, if specific information is not available, criteria for determining the duration of storage;
  5. the existence of a right to rectification or deletion of your personal data, a right to restriction of processing by the data controller or a right to object to such processing;
  6. the existence of a right of appeal to a supervisory authority;
  7. all available information on the source of the data, if the personal data is not collected from the data subject;
  8. the existence of automated decision-making, including profiling under Article 22 (1) and (4) GDPR and, at least in these cases, meaningful information about the logic involved, and the scope and intended impact of such processing on the data subject.

You have the right to request information about whether your personal information is passed on to a third country or an international organization. In this context, you can request to be informed of the appropriate guarantees in accordance with Art. 46 GDPR in connection with the transfer.

 

Right to rectification

You have a right to rectification and / or completion by the data controller, if your personal data being processed is incorrect or incomplete. The responsible person must make the correction immediately.

 

Right to restriction of processing

You may request the restriction of the processing of your personal data under the following conditions:

  1. if you contest the accuracy of the information relating to you for a period of time, that allows the data controller to verify the accuracy of your personal information;
  2. the processing is unlawful and you refuse the deletion of the personal data and instead demand restriction of the use of your personal data;
  3. the data controller no longer needs the personal data for the purposes of processing, but you need it in order to assert, exercise or defend legal claims; or
  4. if you have objected to the processing pursuant to Art. 21 (1) GDPR, and it is not yet certain whether the legitimate reasons of the data controller outweigh your reasons.

If the processing of personal data concerning you has been restricted, this data may only be used with your consent or for the purpose of asserting, exercising or defending legal claims or protecting the rights of another natural or legal person, or for reasons of important public interests of the Union or a Member State. If the restriction of processing was restricted according to the above conditions, you will be informed by the data controller before the restriction is lifted.

 

Right to deletion

a) Obligation to delete

You may demand that the controller delete your personal information immediately, and the controller is required to delete that information immediately if one of the following is true:

  1. Personal data concerning you are no longer necessary for the purposes for which they were collected or otherwise processed.
  2. You revoke your consent, which the processing was based on according to Art. 6 (1) (a) or Art. 9 (2) (a) GDPR and there is no other legal basis for processing.
  3. You object to the processing according to Art. 21 (1) GDPR and there are no prior justifiable reasons for the processing, or you object to the processing according to Art. 21 (2) GDPR.
  4. Your personal data have been processed unlawfully.
  5. The deletion of personal data concerning you is required, in order to fulfill a legal obligation under Union law or the law of the Member States to which the controller is subject.
  6. The personal data concerning you were collected in relation to information society services, pursuant to Article 8 (1) of the GDPR.

b) Information to third parties

If the data controller has made the personal data concerning you public and is required to delete them according to  Article 17 (1) of the GDPR, he must take appropriate measures, including technical means, with due regard to available technology and implementation costs, to inform data controllers that you, the data subject, have requested the deletion of all links to such personal data or copies or replications of this personal data.

Exceptions

The right to erasure is not in force if the processing is necessary:

  1. to exercise the right to freedom of expression and information;
  2. to fulfill a legal obligation required by the law of the Union or of the Member States to which the controller is subject, or performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
  3. for reasons of public interest in the field of public health pursuant to Art. 9 (2) (h) and (i) and Art. 9 (3) GDPR;
  4. for archival purposes of public interest, scientific or historical research purposes or for statistical purposes according to Article 89 (1) GDPR, to the extent that the law referred to in subparagraph (a) is likely to render impossible or seriously affect the achievement of the objectives of that processing, or
  5. to assert, exercise or defend legal claims.

 

Right to information

If you have the right of rectification, erasure or restriction of processing to the controller, he / she is obliged to notify all recipients, to whom your personal data have been disclosed, of this correction or deletion of the data or restriction of processing, unless: this proves to be impossible or involves a disproportionate effort. You have a right to be informed about these recipients by the data controller.

 

Right to Data Portability

You have the right to receive personally identifiable information that you provided to the controller in a structured, common and machine-readable format. In addition, you have the right to transfer this data to another person without hindrance by the person responsible for providing the personal data, provided that

  1. the processing is based on consent according to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract according to Art. 6 (1) (b) GDPR
  2. the processing is done by automated means.

In exercising this right, you also have the right to obtain that your personal data are transmitted directly from one controller to another, as far as technically feasible. This situation should not affect the freedoms and rights of other persons.
The right to data portability does not apply to the processing of personal data necessary for the performance of a task in the public interest or in the exercise of official authority vested in the controller.

 

Right to object

You have the right at any time, for reasons arising from your particular situation, to object to the processing of your personal data, which occurs pursuant to Art. 6 (1) (e) or (f) GDPR; this also applies to profiling based on these provisions.
The controller will no longer process the personal data concerning you, unless he can demonstrate compelling legitimate grounds for processing that outweigh your interests, rights and freedoms, or the processing is for the purpose of enforcing, exercising or defending legal claims.
If the personal data relating to you are processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for the purpose of such advertising; this also applies to profiling insofar as it is associated with such direct advertising.
If you object to processing for direct advertising purposes, your personal data will no longer be processed for these purposes.
Regardless of Directive 2002/58/EC, you have the option, in the context of the use of information society services, to exercise your right to object through automated procedures that use technical specifications.

 

Right to revoke the data protection consent declaration

You have the right to revoke your data protection declaration at any time. The revocation of consent does not affect the legality of the processing carried out on the basis of the consent before the revocation.

 

Automated decision in individual cases, including profiling

You have the right not to be subjected to a decision based solely on automated processing - including profiling - that will have legal effect or negatively affect you in a similar manner. This does not apply if the decision

  1. is required for the conclusion or performance of a contract between you and the controller,
  2. is permitted by Union or Member State legislation to which the controller is subject, and where such legislation contains appropriate measures to safeguard your rights and freedoms and legitimate interests, or
  3. occurs with your express consent.
  4. However, these decisions may not be based on special categories of personal data pursuant to Art. 9 (1) GDPR, unless Art. 9 (2) (a) or (g) apply, and reasonable measures have been taken to protect your rights and freedoms and your legitimate interests.
  5. With regard to the cases referred to in (1) and (3), the person responsible shall take reasonable measures to safeguard your rights and freedoms and your legitimate interests, including at least the right to obtain the intervention of a person from the side of the controller, to present the case and to challenge the decision.
  6. Right to complain to a supervisory authority

Without prejudice to any other administrative or judicial remedy, you shall have the right to complain to a supervisory authority, in particular in the Member State of your place of residence, employment or the place of the alleged infringement, if you believe that the processing of the personal data concerning you violates the GDPR.

The supervisory authority to which the complaint has been submitted shall inform the complainant of the status and results of the complaint, including the possibility of a judicial remedy pursuant to Article 78 of the GDPR.

Die Landesbeauftragte für Datenschutz und Informationsfreiheit der Freien Hansestadt Bremen (State Data Protection and Freedom of Information Officer)
Arndtstraße 1, 27570 Bremerhaven
Tel.: +49 471 596 2010 oder +49 421 361 2010
Fax: +49 421 496 18495
E-Mail: office@datenschutz.bremen.de

 

Consent

If you have consented to processing operations, you can revoke your consent at any time with effect for the future. You can find more information in the following section

 

If you no longer agree that we use technologies to improve our offer and website analysis and optimization, you will also find deactivation links in the section on technologies.

 

Data security

We take technical and organizational measures to protect your personal data from loss, unauthorized access and misuse. Your details are transmitted in encrypted form. This protects the communication between you and our web server and helps to prevent misuse of the data by third parties. We use TLS (Transport Layer Security) for encryption.

 

Data collection on our website

On the basis of Art. 6 Paragraph 1 lit. a, b, f GDPR and Sections 12, 15 DSA, we use our own technologies and technologies from third parties, which we use to improve our offer and website analysis and optimization, among other things support the creation and evaluation of pseudonymised usage profiles.

 

Insofar as your consent is required for the use of the technologies (Art. 6 Para. 1 lit. a GDPR), when you visit the page for the first time, we ask you to decide whether you consent to their use. You can revoke your consent at any time with effect for the future by deleting the cookies that have been set or using the respective opt-out links. You will find more information on the various technologies and your options for subsequently excluding tracking.

 

Data protection notice for the job application process

The protection of your personal data is important to us. ATLANTIC Hotels Management
GmbH collects, processes your applicant data on the basis of § 26 (1) sentence 1 of the
Federal Data Protection Act new version (BDSG-new). The personal data you provide as part of the application process will be processed and used by ATLANTIC Hotels Management GmbH exclusively for the purpose of applicant selection and recruitment.


We would like to point out that the transmission of personal data via e-mail is classified as insecure. Please make sure that you only send application documents by e-mail if you
consider the risk to be low. You are welcome to send further documents that you do not
wish to send by e-mail (such as medical reports and doctor’s certificates) by post or to
submit them at the interview.


If your application is followed by the conclusion of a contract, your data will be stored and
used within the scope of the usual organizational and administrative processes in
compliance with the applicable legal regulations.
If your application is not successful, your data will be deleted three months after completion of the application procedure on the basis of § 15 (4) of the General Equal Treatment Act (AGG).


Should you wish to submit an unsolicited application or wish to have ATLANTIC Hotels
Management GmbH keep your application documents for further vacancies after an
unsuccessful application, we require written notification that we have been requested to
save the application documents. ATLANTIC Hotels Management GmbH will hold applications for further recruitment procedures for a maximum of 12 months.

 

Contact form

If you send us inquiries using the contact form, your details from the inquiry form, including the contact details you provided there, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We do not pass on this data without your consent.

 

The processing of the data entered in the contact form takes place exclusively on the basis of your consent (Art. 6 Para. 1 lit. a GDPR). You can revoke this consent at any time. An informal e-mail to us is sufficient. The legality of the data processing operations carried out before the revocation remains unaffected by the revocation.

 

The data you enter in the contact form will remain with us until you ask us to delete it, revoke your consent to storage or the purpose for data storage no longer applies (e.g. after your request has been processed). Mandatory legal provisions - in particular retention periods - remain unaffected.

 

Send us your application by e-mail, we collect, process and use your data exclusively for the purpose of the application and delete your data after a reasonable period of time (max. Six months after receipt), unless you have expressly given us permission to submit your application can also be used for later vacancies.

 

Processing of personal data within our hotel group under a Joint Controllership pursuant to Art. 26 GDPR

 

Joint controllers

ATLANTIC Hotels Management GmbH, Ludwig-Roselius-Allee 2 - 28329 Bremen - Deutschland, central administration Bremen, and the respective operating companies of the affiliated hotels (see operating companies) jointly determine the purposes and means of certain group-wide coordinated processing activities (incl. central administration or control).

 

Operating companies

ATLANTIC Hotel Airport GmbH (Hotelwebsite)
ATLANTIC Grand Hotel Bremen GmbH (Hotelwebsite)
ATLANTIC Hotel Rennbahn GmbH (Hotelwebsite)
ATLANTIC Hotel Universum GmbH (Hotelwebsite)
ATLANTIC Hotel Vegesack GmbH (Hotelwebsite)
ATLANTIC Hotel Sail City GmbH (Hotelwebsite)
ATLANTIC Hotel Kiel GmbH (Hotelwebsite)
ATLANTIC Hotel Lübeck / Hotel Betriebsgesellschaft Schmiedestraße mbH (Hotelwebsite)
ATLANTIC Hotel Wilhelmshaven GmbH  (Hotelwebsite)
ATLANTIC Hotel Münster GmbH (Hotelwebsite)
ATLANTIC Hotel Heidelberg Europaplatz Betriebsgesellschaft mbH (Hotelwebsite)
ATLANTIC Hotel Landgut Horn / OPATZ Hotel und Services GmbH (Hotelwebsite)
gottlieb Bremen/ ATLANTIC Hotel Rennbahn Catering GmbH (Website)
ATLANTIC Hotel Frankfurt Messe GmbH (Hotelwebsite)
unique by ATLANTIC Hotels Management GmbH (Hotelwebsite)
Linnemann Hotel GmbH (Hotelwebsite)
unique by ATLANTIC Hotels Betriebs GmbH Kiel (Hotelwebsite)
Severin*s Resort & Spa GmbH (Hotelwebsite Severin*s Resort & Spa) / (Hotelwebsite Landhaus Severin*s) / (Hotelwebsite Severin*s Tegernsee)
Severin’s Öschberghof GmbH (Hotelwebsite)
Severin's Lech GmbH (Hotelwebsite)
LOUIS HOTEL GmbH (Hotelwebsite)

 

Legal bases and intra-group data transfers

We process personal data on the basis of Art. 6 GDPR, in particular for the initiation and performance of contracts such as accommodation agreements, for legal obligations and for legitimate interests. Intra-group transfers between the management company and the hotels are additionally based on the “small group privilege” (Recital 48 GDPR) for internal administrative purposes and, where applicable, on joint controllership under Art. 26 GDPR. Consents within the meaning of Art. 6 Para. 1 lit. a GDPR and, where applicable, Art. 9 Para. 2 lit. a GDPR are obtained separately where required and may be withdrawn at any time with effect for the future.

 

Data categories and sources

The data concerned may include in particular master and contact data, contract or booking and billing data, communication and usage data, and security or log data. Special categories of personal data are processed only with the relevant consent, e.g. health information. The data originate from you, from parties involved in handling your booking or stay, e.g. travel agencies, online travel agencies and other travel intermediaries, or from internal group systems for the purposes described above.

 

Recipients and transfers to third countries

Recipients include internal units of the central administration in Bremen and of the hotels. Processors within the meaning of Art. 4 No. 8 GDPR and Art. 28 GDPR may also receive data, e.g. IT, cloud, communications and support service providers, as well as other third parties where required, e.g. banks, advisers and authorities. For transfers to third countries, we ensure an adequate level of data protection, e.g. by an adequacy decision of the European Union such as the EU-US Data Privacy Framework or by Standard Contractual Clauses with supplementary measures.

 

Retention

Personal data are stored only for as long as necessary for the purposes or as long as statutory retention obligations apply. Afterwards the data are deleted or anonymised. Applicable periods include in particular commercial and tax retention periods.

 

Obligation to provide data

Certain information is required for the initiation or performance of contracts and for compliance with legal obligations. Without this information services may not be provided.

 

Your rights

You may exercise all rights described in this data protection statement, incl. those under Chapter III GDPR, against any of the joint controllers. We coordinate requests internally within the framework of the joint controllership. The contact details of our data protection officer are provided in this data protection statement.

 

Bonus card login / Ö-Member Card

We provide a bonus card login on our website for the Ö-Member Card programme, through which registered members can access the protected members’ area.

 

The bonus card login is used for the administration and use of the Ö-Member Card programme. Within the scope of the bonus card login, registration and contact data such as title, name, address, email address and telephone number, login data, bonus card or membership number, information on membership status, details of stays and bookings, benefits used as well as technical usage and access data may be processed in particular. Through the members’ area, participants in the bonus programme may also be provided with information on benefits, events, offers and other services in connection with the Ö-Member Card. The mandatory information requested during registration is required in order to check participation in the bonus programme and to provide the bonus card login.

 

The data are processed, insofar as this serves registration, provision, administration and use of the bonus card login as well as the implementation of the Ö-Member Card programme, on the basis of Art. 6 Para. 1 lit. b GDPR. Where we inform participants about important changes to the bonus programme, the scope of services or technically necessary changes, the processing is also carried out on the basis of Art. 6 Para. 1 lit. b GDPR. Where we provide information on benefits, events or offers within the scope of the bonus programme, this is carried out on the basis of Art. 6 Para. 1 lit. b GDPR or, where the information is promotional in nature and consent is required, on the basis of Art. 6 Para. 1 lit. a GDPR. Where technically necessary cookies are set or information is stored on or accessed from the end device when using the bonus card login, this is carried out on the basis of Art. 6 Para. 1 lit. b GDPR or Art. 6 Para. 1 lit. f GDPR and Section 25 Para. 2 No. 2 TDDDG. Where non-technically necessary cookies or comparable technologies are used, this is done only on the basis of consent pursuant to Art. 6 Para. 1 lit. a GDPR and Section 25 Para. 1 TDDDG.

 

The data processed within the scope of the bonus card login and the Ö-Member Card programme are stored for as long as this is necessary for participation in the bonus programme, the provision of the bonus card login and the processing of the related services. After termination of participation, the data are deleted unless statutory retention obligations exist or further storage is required for the establishment, exercise or defence of legal claims.

 

Online booking and reservation requests

As part of your online booking, we need the following personal data from you: first and last name, address, e-mail address, telephone number and credit card details, which are used for verification. Further information is voluntary.

 

With complete processing of the booking and after the legal retention period has expired Your data will be completely erased after the deadline, unless we have given your consent for further use or we are legally obliged to do so.

 

As part of your reservations for our restaurants, golf club, conferences, events, catering, golf group courses and individual lessons or for our SPA offers, we require the following personal data from you: first and last name, address, email address, telephone number. Further information is voluntary.

 

Your data will be completely deleted once the booking has been fully processed and after the statutory retention periods have expired.

 

The data is processed on the basis of Art. 6 Paragraph 1 lit. b GDPR.

 

Data transfer when concluding a contract for services and digital content

We only transfer personal data to third parties if this is necessary in the context of contract processing, for example to the credit institute commissioned to process payments.

 

A further transmission of the data does not take place or only if you have expressly consented to the transmission. Your data will not be passed on to third parties without your express consent, e.g. for advertising purposes.

 

The basis for data processing is Article 6 (1) (b) GDPR, which allows the processing of data for the fulfillment of a contract or pre-contractual measures.

 

Sending newsletter via Smart Host

We use 'Smart Host' for sending and managing our newsletter. The provider is Smart Host GmbH, Am Kupfergraben 6 A, 10117 Berlin, Germany (hereinafter referred to as 'Smart Host').

 

With our newsletter, we inform you by email about news, offers, events, services and other information relating to our establishment. For the newsletter subscription, we process in particular your email address and, where provided, further data such as your name, title or other information that you provide to us as part of the subscription process or your communication with us. Subscription to our newsletter is generally carried out using the double opt-in procedure. After subscribing, you will receive an email asking you to confirm your subscription. To document the subscription and confirmation, we may process in particular the date and time of subscription, the date and time of confirmation, IP address, email address and the content of the declaration of consent.

 

To evaluate and optimise our newsletter offering, we may track whether a newsletter has been opened and which content has been clicked. For this purpose, opening and click data, time of access, technical information about the end device used, browser and email programme, IP address and derived usage data may be processed in particular. These evaluations serve to measure the use of our newsletter, to improve its content from a technical and editorial perspective and to further develop our newsletter offering in line with recipients’ interests.

 

Smart Host may use the service 'Twilio SendGrid' for the technical sending and evaluation of our newsletter. The provider is Twilio Inc., 101 Spear Street, 5th Floor, San Francisco, CA 94105, USA (hereinafter referred to as 'Twilio'). When Twilio SendGrid is used, newsletter data, technical sending data, delivery information, opening and click data as well as further technical log and analytics data may be processed by Twilio.

 

The collected data are stored and processed in the USA, a third country for which there is no adequacy decision by the European Commission.

 

However, Twilio bases the transfer of data to the USA on the EU-U.S. Data Privacy Framework of the European Commission. Where Smart Host or Twilio transfer personal data to other third countries or have it processed by sub-processors in other third countries, they state that they additionally base such transfers on appropriate safeguards, in particular standard contractual clauses within the meaning of Art. 46 GDPR.

 

The processing of your data for sending the newsletter is carried out on the basis of your consent pursuant to Art. 6 Para. 1 lit. a GDPR. The logging of the subscription and confirmation is carried out on the basis of our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR in being able to prove proper subscription and prevent misuse. The evaluation of opening and click behaviour and the optimisation of our newsletter offering based on this are carried out on the basis of your consent pursuant to Art. 6 Para. 1 lit. a GDPR. Where cookies or comparable technologies are set or information is stored on or accessed from the end device when using the newsletter, this is carried out on the basis of Art. 6 Para. 1 lit. a GDPR and Section 25 Para. 1 TDDDG.

 

You can withdraw your consent to receive the newsletter and to the related data processing at any time with effect for the future. For this purpose, you can in particular use the unsubscribe link included in every newsletter. After unsubscribing from the newsletter, your data processed for sending the newsletter will be deleted unless statutory retention obligations exist or further storage is required for the establishment, exercise or defence of legal claims. Data that we need to prove consent previously given may be stored until the expiry of possible limitation periods.

 

Smart Host processes personal data of recipients of our newsletter as a processor within the meaning of Art. 4 No. 8 GDPR, insofar as this processing is carried out on our behalf for the provision and operation of the newsletter service. We have concluded a data processing agreement with Smart Host within the meaning of Art. 28 Para. 3 GDPR. In this agreement, Smart Host undertakes in particular to process personal data only in accordance with our instructions and for the provision of the agreed services, to implement appropriate technical and organisational protective measures, and to use sub-processors only in accordance with the contractual provisions.

 

Further information on data processing by Smart Host can be found at https://www.smart-host.com/en/privacy-policy . Further information on data processing by Twilio can be found at https://www.twilio.com/en-us/legal/privacy

 

 

Technologies

 

Cookies

Some of the websites use so-called cookies. Cookies do not harm your computer and do not contain viruses. Cookies serve to make our offer more user-friendly, more effective and safer. Cookies are small text files that are stored on your computer and saved by your browser.

 

Most of the cookies we use are so-called “session cookies”. They are automatically deleted after your visit. Other cookies remain stored on your device until you delete them. These cookies enable us to recognize your browser the next time you visit.

 

You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or generally, and activate the automatic deletion of cookies when you close the browser. If cookies are deactivated, the functionality of this website may be restricted.

 

Cookiebot

We use 'Cookiebot' on our website. The provider is Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark (hereinafter referred to as 'Cookiebot').


Cookiebot is a consent management technology which enables us to inform you about the use of cookies and comparable technologies on our website, obtain, manage and document consent, and control the use of services requiring consent in accordance with your selection. When you access our website, Cookiebot may display an overview of the cookies and comparable technologies used, structured by categories. You can specify there which categories or services you wish to allow.


When you make a selection or change your consent, your IP address in shortened or anonymised form, the date and time of your consent decision, the URL of our website, browser and device information, an encrypted anonymous key and the consent status for the individual cookie categories or services may be processed in particular. These data are processed in order to store your consent decision, recognise your selection during later visits to the website, demonstrate consent and withdrawals, and control the use of cookies and comparable technologies in accordance with your selection.


The processing of consent data is carried out for the fulfilment of our legal obligation to obtain and be able to demonstrate consent for the use of certain cookies and comparable technologies, on the basis of Art. 6 Para. 1 lit. c GDPR. Where the processing additionally serves the legally compliant, user-friendly and technically reliable management of your consent decision, it is carried out on the basis of our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR. The storage and access of the technically necessary Cookiebot cookie, in particular the 'CookieConsent' cookie, are carried out on the basis of Section 25 Para. 2 No. 2 TDDDG, as this cookie is necessary to store the consent decision you have made and to provide the website in accordance with your selection.


The consent data processed by Cookiebot are stored for as long as this is necessary for documenting your consent decision and demonstrating consent. You can withdraw or change your consent at any time with effect for the future by reopening the cookie settings on our website. Statutory retention and documentation obligations remain unaffected.
Usercentrics A/S has its registered office in Denmark and therefore within the European Union. Where Cookiebot transfers personal data to third countries or has them processed by sub-processors in third countries, this is carried out in accordance with the data protection requirements of Art. 44 et seq. GDPR, in particular on the basis of appropriate safeguards such as standard contractual clauses within the meaning of Art. 46 GDPR.


Cookiebot processes personal data of visitors to our website as a processor within the meaning of Art. 4 No. 8 GDPR, insofar as this processing is carried out on our behalf for the provision and operation of the consent management technology. We have concluded a data processing agreement with Cookiebot within the meaning of Art. 28 Para. 3 GDPR. In this agreement, Cookiebot undertakes in particular to process personal data only in accordance with our instructions and for the provision of the agreed services, to implement appropriate technical and organisational protective measures, and to use sub-processors only in accordance with the contractual provisions.


Further information on data processing by Cookiebot can be found at https://www.cookiebot.com/en/privacy-policy/ . Further information on Cookiebot’s Data Processing Agreement can be found at https://www.cookiebot.com/en/data-processing-agreement/

 

Google Analytics

This website uses functions of the web analysis service Google Analytics. The provider is Google Inc., 1600 Amphitheater Parkway, Mountain View, CA 94043, USA.

 

We have concluded an order data processing contract with Google and fully implement the strict requirements of the German data protection authorities when using Google Analytics.

 

Google Analytics uses so-called "cookies". These are text files that are saved on your computer and that enable your use of the website to be analyzed. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there for 36 months.

 

The storage of Google Analytics cookies is based on Art. 6 Para. 1 lit.f GDPR. The website operator has a legitimate interest in analyzing user behavior in order to optimize both its website and its advertising.

 

IP anonymization

We have activated the IP anonymization function on this website. As a result, your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before it is transmitted to the USA. The full IP address is only transmitted to a Google server in the USA and shortened there in exceptional cases. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity and to provide the website operator with other services relating to website activity and internet usage. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.

 

Browser plugin

You can prevent the storage of cookies by setting your browser software accordingly; however, we would like to point out that in this case you may not be able to use all functions of this website to their full extent. You can also prevent Google from collecting the data generated by the cookie and relating to your use of the website (including your IP address) and from processing this data by Google by downloading the browser plug-in available under the following link and install: https://tools.google.com/dlpage/gaoptout?hl=de.

 

Objection against data collection

You can prevent Google Analytics from collecting your data by clicking on the following link. An opt-out cookie will be set which prevents the collection of your data on future visits to this website: Deactivate Google Analytics.

 

You can find more information on how Google Analytics handles user data in Google's data protection declaration: https://support.google.com/analytics/answer/6004245?hl=de.

 

Demographic characteristics in Google Analytics

This website uses the “demographic characteristics” function of Google Analytics. This allows reports to be created that contain information on the age, gender and interests of the site visitors. This data comes from interest-based advertising from Google and visitor data from third-party providers. These data cannot be assigned to a specific person. You can deactivate this function at any time via the ad settings in your Google account or generally prohibit the collection of your data by Google Analytics as described in the point “Objection to data collection”.

 

Google Analytics remarketing

Our websites use the functions of Google Analytics Remarketing in conjunction with the cross-device functions of Google AdWords and Google DoubleClick. The provider is Google Inc., 1600 Amphitheater Parkway, Mountain View, CA 94043, USA.

 

This function makes it possible to link the advertising target groups created with Google Analytics Remarketing with the cross-device functions of Google AdWords and Google DoubleClick. In this way, interest-based, personalized advertising messages that have been adapted to you depending on your previous usage and surfing behavior on one device (e.g. mobile phone) can also be displayed on another of your devices (e.g. tablet or PC).

 

If you have given your consent, Google will link your web and app browser history to your Google account for this purpose. In this way, the same personalized advertising messages can be displayed on every device on which you log in with your Google account.

 

To support this function, Google Analytics collects Google-authenticated user IDs, which are temporarily linked to our Google Analytics data in order to define and create target groups for cross-device advertising.

 

You can permanently object to cross-device remarketing / targeting by deactivating personalized advertising in your Google account; follow this link: https://myadcenter.google.com/home.

 

The collected data is summarized in your Google account exclusively on the basis of your consent, which you can give to Google or revoke (Art. 6 Para. 1 lit. a GDPR). In the case of data collection processes that are not merged in your Google account (e.g. because you do not have a Google account or have objected to the merging), the collection of data is based on Art. 6 Paragraph 1 lit.f GDPR. The legitimate interest arises from the fact that the website operator has an interest in the anonymized analysis of the website visitors for advertising purposes.

 

Further information and the data protection provisions can be found in Google's data protection declaration at: https://www.google.com/policies/technologies/ads/.

 

Google AdWords and Google Conversion Tracking

This website uses Google AdWords. AdWords is an online advertising program from Google Inc., 1600 Amphitheater Parkway, Mountain View, CA 94043, United States (“Google”).

 

We use so-called conversion tracking as part of Google AdWords. When you click on an ad placed by Google, a conversion tracking cookie is set. Cookies are small text files that the Internet browser stores on the user's computer. These cookies lose their validity after 30 days and are not used to personally identify users. If the user visits certain pages on this website and the cookie has not yet expired, we and Google can see that the user clicked on the ad and was redirected to this page.

 

Every Google AdWords customer receives a different cookie. The cookies cannot be tracked via the websites of AdWords customers. The information obtained using the conversion cookie is used to generate conversion statistics for AdWords customers who have opted for conversion tracking. Customers find out the total number of users who clicked on their ad and were redirected to a page with a conversion tracking tag. However, they do not receive any information with which users can be personally identified. If you do not want to participate in tracking, you can object to this use by easily deactivating the Google conversion tracking cookie in your internet browser under user settings. You will then not be included in the conversion tracking statistics.

 

"Conversion cookies" are saved on the basis of Article 6 Paragraph 1 lit. f GDPR. The website operator has a legitimate interest in analyzing user behavior in order to optimize both its website and its advertising.

 

You can find more information about Google AdWords and Google Conversion Tracking in Google's privacy policy: https://www.google.de/policies/privacy/.

 

You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or generally, and activate the automatic deletion of cookies when you close the browser. If cookies are deactivated, the functionality of this website may be restricted.

 

Plugins and tools

In order to be able to offer you a comprehensive service, we refer to other websites or their offers on our website. We expressly emphasize that our employees or other persons involved in this website have no influence on the design and content of the linked pages.

 

For third-party content that is made available for use via links, take overWe are not responsible and do not adopt their content as our own. The provider of the website referred to is solely liable for illegal, incorrect or incomplete content as well as for damage caused by the use or non-use of the information.

 

Our data protection notice only applies to our website. Please note the data protection regulations and notes on the linked pages. Your data will not be passed on to third parties unless we are legally obliged to do so or it is carried out to fulfill our contractual obligations or in the exercise of the services you have chosen.

 

WhatsApp Communication

We offer you the option of contacting us via 'WhatsApp' on our website. The provider of the messenger service for users in the European Region is WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland (hereinafter referred to as 'WhatsApp').

 

Contact via WhatsApp may be used in particular for enquiries to our Guest Relations team, table reservations, appointment coordination and other communication with our establishment. If you contact us via WhatsApp, we process the personal data transmitted by you, in particular your name, telephone number, profile picture, where you have stored one in WhatsApp, the content of your message, reservation and appointment data, communication data as well as the date and time of the communication. Depending on the content of your enquiry, further personal data that you provide to us in the course of the WhatsApp communication may also be processed. The use of WhatsApp is voluntary. You may also contact us alternatively via other communication channels, in particular by telephone or email.

 

When WhatsApp is used, WhatsApp processes personal data in accordance with its own privacy policy. This may include, in particular, your telephone number, device and connection data, usage data, communication metadata, IP address, location information, where you have enabled this, as well as information about your interaction with WhatsApp. We do not have full control over the data processing carried out by WhatsApp.

 

The collected data may also be stored and processed in the USA, a third country for which there is no adequacy decision by the European Commission.

 

However, WhatsApp bases the transfer of data to the USA on the EU-U.S. Data Privacy Framework of the European Commission.

 

The data transmitted to us are processed, insofar as your enquiry is aimed at the initiation or performance of a contract, in particular in the case of table reservations, appointment coordination or other service-related enquiries, on the basis of Art. 6 Para. 1 lit. b GDPR. In all other cases, the processing is carried out on the basis of our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR in enabling simple, fast and user-friendly communication with guests and interested parties. Where information is stored on or accessed from the end device when using WhatsApp, this is carried out by WhatsApp in accordance with the applicable WhatsApp terms and privacy notices.

 

The data transmitted to us via WhatsApp are deleted as soon as they are no longer required for processing your enquiry, unless statutory retention obligations exist or further storage is required for the establishment, exercise or defence of legal claims.

 

Further information on data processing by WhatsApp can be found at https://www.whatsapp.com/legal/privacy-policy-eea

 

Booking system OnePageBooking

We use the OnePageBooking service from HotelNetSolutions GmbH, Genthiner Strasse 8, 10785 Berlin for online room reservations. Clicking the corresponding button opens a browser window that redirects you to the OnePageBooking website.

 

If you would like to book a room with us, it is necessary for the conclusion of the contract that you provide your personal data, which we need to process your booking. Mandatory information required for the execution of the contracts is marked separately, further information is voluntary. The data is entered in an input mask and transmitted to us and saved.

 

Data is also passed on to the relevant payment service providers. The data will only be passed on to third parties if the transfer is necessary for the purpose of contract execution or for billing purposes or for collecting the fee or if you have given your express consent. In this regard, we only pass on the data required in each case. The data recipients are: the respective delivery / shipping company (transfer of name and address), collection agencies, insofar as the payment has to be collected (transfer of name, address, order details), payment institutions for the purpose of collecting claims, insofar as you have chosen direct debit as the method of payment and payment service providers - depending on the choice of payment method.

 

The legal basis is Art. 6 Para. 1 lit. b GDPR. Regarding the voluntary data, the legal basis for the processing of the data is Art. 6 Para. 1 lit. a GDPR. There is a Data Protection Agreement between us and HotelNetSolutions GmbH.

 

The compulsory information collected is required to fulfill the contract with the user (for the purpose of providing the goods or service and confirming the content of the contract). We therefore use the data to answer your inquiries, to process your booking, if necessary, to check the creditworthiness or recovery of a claim and for the purpose of technical administration of the website. The voluntary information is provided to prevent abuse and, if necessary, to investigate crimes.

 

The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. Due to commercial and tax regulations, we are obliged to store your address, payment and order data for a period of 10 years after the contract has been carried out. However, after 6 years, we restrict processing, i.e. H. Your data will only be used to comply with legal obligations. If there is a permanent obligation between us and the user, we save the data for the entire term of the contract and for a period of ten years thereafter (see above). With regard to the voluntarily provided data, we will delete the data 6 years after the contract has been executed, provided that no further contract is concluded with the user during this time; In this case, the data will be deleted 6 years after the last contract has been carried out.

 

If the data is necessary to fulfill a contract or to carry out pre-contractual measures, the data can only be deleted prematurely unless there are contractual or legal obligations to prevent deletion. Otherwise, you are free to have the personal data provided during registration completely deleted from the data base of the person responsible. Regarding the voluntary data, you can revoke your consent to the person responsible at any time. In this case, the voluntary data will be deleted immediately.

 

Information on data protection at HotelNetSolutions GmbH can be found here: https://hotelnetsolutions.de/Datenschutz/ (in German)

 

Voucher purchase via vBooking

We use the vBooking service from HotelNetSolutions GmbH, Genthiner Straße 8, 10785 Berlin for online voucher orders. Clicking the corresponding button opens a browser window that redirects you to the vBooking website.

 

If you order vouchers from us, it is necessary for the conclusion of the contract that you provide your personal data, which we need to process your order. Mandatory information required for the execution of the contracts is marked separately, further information is voluntary. The data is entered in an input mask and transmitted to us and saved.

 

Data is also passed on to the relevant payment service providers. The data will only be passed on to third parties if the transfer is necessary for the purpose of contract execution or for billing purposes or for collecting the fee or if you have given your express consent. In this regard, we only pass on the data required in each case. The data recipients are: the respective delivery / shipping company (transfer of name and address), collection agencies, insofar as the payment has to be collected (transfer of name, address, order details), payment institutions for the purpose of collecting claims, insofar as you have chosen direct debit as the method of payment and payment service providers - depending on the choice of payment method.

 

The legal basis is Art. 6 Para. 1 lit. b GDPR. Regarding the voluntary data, the legal basis for the processing of the data is Art. 6 Para. 1 lit. a GDPR. There is a Data Protection Agreement between us and HotelNetSolutions GmbH.

 

The compulsory information collected is required to fulfill the contract with the user (for the purpose of providing the goods or service and confirming the content of the contract). We therefore use the data to answer your inquiries, to process your booking, if necessary, to check the creditworthiness or recovery of a claim and for the purpose of technical administration of the website. The voluntary information is provided to prevent abuse and, if necessary, to investigate crimes.

 

The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. Due to commercial and tax regulations, we are obliged to store your address, payment and order data for a period of 10 years after the contract has been carried out. However, after 6 years, we restrict processing, i.e. H. Your data will only be used to comply with legal obligations. If there is a permanent obligation between us and the user, we save the data for the entire term of the contract and for a period of ten years thereafter (see above). With regard to the voluntarily provided data, we will delete the data 6 years after the contract has been executed, provided that no further contract is concluded with the user during this time; In this case, the data will be deleted 6 years after the last contract has been carried out.

 

If the data is necessary to fulfill a contract or to carry out pre-contractual measures, the data can only be deleted prematurely unless there are contractual or legal obligations to prevent deletion. Otherwise, you are free to have the personal data provided during registration completely deleted from the data base of the person responsible. Regarding the voluntary data, you can revoke your consent to the person responsible at any time. In this case, the voluntary data will be deleted immediately.

 

Information on data protection at HotelNetSolutions GmbH can be found here: https://hotelnetsolutions.de/Datenschutz/ (in German)

 

Spa bookings via TAC

We use 'TAC' for booking and managing treatments in our spa area. The provider is TAC Informationstechnologie GmbH, Schildbach 211, 8230 Hartberg, Austria (hereinafter referred to as 'TAC').

 

TAC is a software solution for booking, managing and organising spa, wellness, leisure and other treatment services. If you book a treatment or other service in our spa area via our website, the data you provide during the booking process may be processed. This may include in particular your name, contact details, booking details, desired treatment or service, date and time of the booking, appointment and availability data, payment and billing information, communication data as well as technical access data. The processing serves to receive, manage, perform and bill your spa booking as well as to communicate with you in connection with the booked service.

 

The data are processed, insofar as this is necessary for the initiation, performance or processing of the booked spa treatment or other service, on the basis of Art. 6 Para. 1 lit. b GDPR. Where we are legally obliged to retain certain booking, payment or billing data, the processing is carried out on the basis of Art. 6 Para. 1 lit. c GDPR. Where the processing is necessary for the organisation of our spa operations, appointment management, prevention of misuse or the establishment, exercise or defence of legal claims, it is carried out on the basis of our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR. Where technically necessary cookies are set or information is stored on or accessed from the end device when using TAC, this is carried out on the basis of Art. 6 Para. 1 lit. b GDPR or Art. 6 Para. 1 lit. f GDPR and Section 25 Para. 2 No. 2 TDDDG. Where non-technically necessary cookies or comparable technologies are used, this is done only on the basis of consent pursuant to Art. 6 Para. 1 lit. a GDPR and Section 25 Para. 1 TDDDG.

 

The data processed in connection with the spa booking are stored for as long as this is necessary for the performance and processing of the booking. The data are then deleted unless statutory retention obligations, in particular commercial or tax law retention obligations, apply or further storage is required for the establishment, exercise or defence of legal claims.

 

TAC processes personal data of visitors to our website as a processor within the meaning of Art. 4 No. 8 GDPR, insofar as this processing is carried out on our behalf for the provision and operation of the service. We have concluded a data processing agreement with TAC within the meaning of Art. 28 Para. 3 GDPR. In this agreement, TAC undertakes in particular to process personal data only in accordance with our instructions and for the provision of the agreed services, to implement appropriate technical and organisational protective measures, and to use sub-processors only in accordance with the contractual provisions.

 

Further information on data processing by TAC can be found at https://tac.eu.com/en/privacy-policy/

 

PC CADDY

We use 'PC CADDIE' for the online booking and management of tee times, trainer lessons, courses and tournament participation. The provider is PC CADDIE://online GmbH & Co. KG, Lily-Braun-Straße 10–12, 23843 Bad Oldesloe, Germany (hereinafter referred to as 'PC CADDIE').

 

PC CADDIE is a software solution for golf facilities that can be used in particular to book and manage tee times, trainer lessons, courses, tournaments and other golf-related services online. If you book a tee time, trainer lesson, course participation or tournament participation via our website, the data you provide during the booking process may be processed. This may include in particular your name, contact details, membership or customer number, user account and login data, booked service, desired appointment, tee time, trainer, course or tournament data, participant data, handicap or game-related information, payment and billing information, communication data as well as technical access data. The processing serves to check availability, receive, manage, perform and bill your booking as well as to communicate with you in connection with the booked service.

 

The data are processed, insofar as this is necessary for the initiation, performance or processing of the booked tee time, trainer lesson, course participation, tournament participation or other service, on the basis of Art. 6 Para. 1 lit. b GDPR. Where we are legally obliged to retain certain booking, payment or billing data, the processing is carried out on the basis of Art. 6 Para. 1 lit. c GDPR. Where the processing is necessary for the organisation of our golf operations, appointment, course and tournament management, prevention of misuse or the establishment, exercise or defence of legal claims, it is carried out on the basis of our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR. Where technically necessary cookies are set or information is stored on or accessed from the end device when using PC CADDIE, this is carried out on the basis of Art. 6 Para. 1 lit. b GDPR or Art. 6 Para. 1 lit. f GDPR and Section 25 Para. 2 No. 2 TDDDG. Where non-technically necessary cookies or comparable technologies are used, this is done only on the basis of consent pursuant to Art. 6 Para. 1 lit. a GDPR and Section 25 Para. 1 TDDDG.

 

The data processed in connection with the booking are stored for as long as this is necessary for the performance and processing of the booking as well as for the management of the booked services. The data are then deleted unless statutory retention obligations, in particular commercial or tax law retention obligations, apply or further storage is required for the establishment, exercise or defence of legal claims.

 

PC CADDIE processes personal data of visitors to our website as a processor within the meaning of Art. 4 No. 8 GDPR, insofar as this processing is carried out on our behalf for the provision and operation of the service. We have concluded a data processing agreement with PC CADDIE within the meaning of Art. 28 Para. 3 GDPR. In this agreement, PC CADDIE undertakes in particular to process personal data only in accordance with our instructions and for the provision of the agreed services, to implement appropriate technical and organisational protective measures, and to use sub-processors only in accordance with the contractual provisions.

 

Further information on data processing by PC CADDIE can be found at https://www.pccaddie.de/datenschutz/ (in German)

 

Trust you

We use 'TrustYou' on our website. The provider is TrustYou GmbH, Schmellerstraße 9, 80337 Munich, Germany (hereinafter referred to as 'TrustYou').

 

TrustYou is a service for displaying and evaluating guest reviews and other guest feedback. The TrustYou widget can be used to display current reviews, review scores and summarised review information about our establishment on our website. When the page on which the TrustYou widget is embedded is accessed, a connection to TrustYou servers is established. In this context, technical access data may be processed, including in particular the IP address, date and time of access, page or embedded resource accessed, referrer URL, browser type and browser version, operating system, device information and the amount of data transferred. Depending on the technical implementation, cookies or comparable technologies may also be used where these are necessary for the display, functionality or evaluation of the widget.

 

The storage and processing of personal data may also be carried out by TrustYou sub-processors in third countries, in particular in the USA. Where TrustYou transfers personal data to third countries or has it processed by sub-processors in third countries, TrustYou states that it bases such transfers on appropriate safeguards, in particular standard contractual clauses within the meaning of Art. 46 GDPR.

 

The processing is carried out on the basis of your consent pursuant to Art. 6 Para. 1 lit. a GDPR. Where cookies are set or information is stored on or accessed from the end device when using the TrustYou widget, this is carried out on the basis of Art. 6 Para. 1 lit. a GDPR and Section 25 Para. 1 TDDDG. Consent is voluntary and can be withdrawn at any time with effect for the future.

 

TrustYou processes personal data of visitors to our website as a processor within the meaning of Art. 4 No. 8 GDPR, insofar as this processing is carried out on our behalf for the provision and operation of the service. We have concluded a data processing agreement with TrustYou within the meaning of Art. 28 Para. 3 GDPR. In this agreement, TrustYou undertakes in particular to process personal data only in accordance with our instructions and for the provision of the agreed services, to implement appropriate technical and organisational protective measures, and to use sub-processors only in accordance with the contractual provisions.

 

Further information on data processing by TrustYou can be found at https://www.trustyou.com/privacy-policy/

 

YouTube

Our website uses plugins from YouTube, operated by Google. The operator of the website is YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA.

 

The plug-in is integrated in "extended data protection mode". By integrating in the "extended data protection mode", the third-party provider does not save any information about your visit to our website until the plug-in is activated. We would like to point out that, as a website provider, we do not transmit any of your personal data to YouTube. Communication takes place exclusively between your device and the systems of the third party provider. We have no way of influencing or knowing the content of the data transmitted between your device and the operators of the network platforms (third-party providers) and their processing by the third-party providers. The purpose and scope of further data processing by the respective platform operator as well as your related rights and setting options to protect your privacy can be found in the data protection information of the third party providers via the links to the privacy policies (data protection declarations) provided by the respective third party providers.

 

Google Web Fonts

This site uses so-called web fonts, which are provided by Google, for the uniform display of fonts. When you call up a page, your browser loads the required web fonts into your browser cache in order to display texts and fonts correctly.

 

For this purpose, the browser you are using must connect to the Google servers. This gives Google knowledge that our website has been accessed via your IP address. The use of Google Web Fonts takes place in the interest of a uniform and appealing presentation of our online offers. This represents a legitimate interest in minde of Art. 6 Para. 1 lit.f GDPR.

 

If your browser does not support web fonts, a standard font will be used by your computer.

 

Further information about Google Web Fonts can be found at https://developers.google.com/fonts/faq and in Google's data protection declaration: https://www.google.com/policies/privacy/.

 

Google Maps

This site uses the Google Maps map service via an API. The provider is Google Inc., 1600 Amphitheater Parkway, Mountain View, CA 94043, USA.

 

Öschberghof GmbH does not process any personal data here.

 

When using these services, personal data is transferred to the third-party card provider and only processed by them on their own responsibility. The data processing of the third party includes at least the following types of data:

 

Information about the use of our website

Your IP address

You have the option of deactivating the interactive map service and preventing data transmission to the third party provider. To do this, deactivate JavaScript in your browser. In this case, the interactive map service can no longer be used by you.

 

You can find more information on handling user data in Google's data protection declaration: https://www.google.de/intl/de/policies/privacy/.

 

DialogShift Chat application on our website

Our website uses the chat application of DialogShift GmbH, Rheinsberger Str. 76/77, 10115 Berlin. This application processes and stores data for the purpose of web analysis, to operate the chat application and to answer queries.

 

For the operation of the chat function, the chat texts are stored and a cookie with a unique ID is set - this is used to recognise you as a customer.

A cookie is a small text file that is stored locally in the cache on your device. Using this cookie, our application recognises the device and can retrieve past chat logs. This cookie is stored for 90 days since last use. You can disable the storage of cookies in your browser settings. However, without the use of cookies, the chat function cannot be performed.

 

The possible disclosure of e.g. name, e-mail address or a telephone number is voluntary and with the consent to temporarily use and store this data for the purpose of contacting you until the end of the contact. This personal data is deleted after 90 days.

 

The legal basis for data processing is Article 6 (1) lit. F DS-GVO based on our legitimate interest in effective customer support, for statistical analysis of user behaviour and for optimisation purposes of our offers.

DialogShift offers at

https://www.dialogshift.com/de/dsvgo  

for further information on the collection and use of data and on your rights and options for protecting your privacy.



 

as of 1st July 2026