Data protection

according to the GDPR

We appreciate your visit to the ATLANTIC Hotels website and your interest in our company and our technical and organizational data protection measures. The confidentiality of your personal data and compliance with data protection regulations are important to us. In the context of this privacy policy, we would like to inform you which of your personal data we process and how you can exercise your rights under Chapter III of the EU-GDPR. We therefore ask you to read the following statements carefully.

Our data protection officer and the entire ATLANTIC Hotels team ensure compliance with data protection regulations, in particular the European General Data Protection Regulation (GDPR) and the Federal Data Protection Act new version (BDSG-new), which has been in force since 25 May 2018. The privacy policy can be accessed at any time via the tab "Data Protection" at the bottom of our website.

I. Name and address of the responsible

The responsible party, within the meaning of basic data protection regulation and other national data protection laws of the member states as well as other data protection regulations is the: 

ATLANTIC Hotels Management GmbH 
Ludwig-Roselius-Allee 2 
28329 Bremen 
Deutschland 
Telephone: +49 (0) 421 944888-0 
Telefax: +49 (0) 421 944888-552 
Email: info@atlantic-hotels.de 
Website: https://www.atlantic-hotels.de 

II. Processing of personal data within our hotel group under a Joint Controllership pursuant to Art. 26 GDPR

Joint controllers 

ATLANTIC Hotels Management GmbH, Ludwig-Roselius-Allee 2 - 28329 Bremen - Deutschland, central administration Bremen, and the respective operating companies of the affiliated hotels (see operating companies) jointly determine the purposes and means of certain group-wide coordinated processing activities (incl. central administration or control). 

operating companies 

ATLANTIC Hotel Airport GmbH (Hotelwebsite
ATLANTIC Grand Hotel Bremen GmbH (Hotelwebsite
ATLANTIC Hotel Rennbahn GmbH (Hotelwebsite
ATLANTIC Hotel Universum GmbH (Hotelwebsite
ATLANTIC Hotel Vegesack GmbH (Hotelwebsite
ATLANTIC Hotel Sail City GmbH (Hotelwebsite
ATLANTIC Hotel Kiel GmbH (Hotelwebsite
ATLANTIC Hotel Lübeck / Hotel Betriebsgesellschaft Schmiedestraße mbH (Hotelwebsite
ATLANTIC Hotel Wilhelmshaven GmbH  (Hotelwebsite
ATLANTIC Hotel Münster GmbH (Hotelwebsite
ATLANTIC Hotel Heidelberg Europaplatz Betriebsgesellschaft mbH (Hotelwebsite
ATLANTIC Hotel Landgut Horn / OPATZ Hotel und Services GmbH (Hotelwebsite
gottlieb Bremen/ ATLANTIC Hotel Rennbahn Catering GmbH (Website
ATLANTIC Hotel Frankfurt Messe GmbH (Hotelwebsite
unique by ATLANTIC Hotels Management GmbH (Hotelwebsite) 
Linnemann Hotel GmbH (Hotelwebsite
unique by ATLANTIC Hotels Betriebs GmbH Kiel (Hotelwebsite
Severin*s Resort & Spa GmbH (Hotelwebsite Severin*s Resort & Spa) / (Hotelwebsite Landhaus Severin*s) / (Hotelwebsite Severin*s Tegernsee
Severin’s Öschberghof GmbH (Hotelwebsite
Severin's Lech GmbH (Hotelwebsite
LOUIS HOTEL GmbH (Hotelwebsite

Legal bases and intra-group data transfers 

We process personal data on the basis of Art. 6 GDPR, in particular for the initiation and performance of contracts such as accommodation agreements, for legal obligations and for legitimate interests. Intra-group transfers between the management company and the hotels are additionally based on the “small group privilege” (Recital 48 GDPR) for internal administrative purposes and, where applicable, on joint controllership under Art. 26 GDPR. Consents within the meaning of Art. 6 Para. 1 lit. a GDPR and, where applicable, Art. 9 Para. 2 lit. a GDPR are obtained separately where required and may be withdrawn at any time with effect for the future. 

 

Data categories and sources 

The data concerned may include in particular master and contact data, contract or booking and billing data, communication and usage data, and security or log data. Special categories of personal data are processed only with the relevant consent, e.g. health information. The data originate from you, from parties involved in handling your booking or stay, e.g. travel agencies, online travel agencies and other travel intermediaries, or from internal group systems for the purposes described above. 

 

Recipients and transfers to third countries 

Recipients include internal units of the central administration in Bremen and of the hotels. Processors within the meaning of Art. 4 No. 8 GDPR and Art. 28 GDPR may also receive data, e.g. IT, cloud, communications and support service providers, as well as other third parties where required, e.g. banks, advisers and authorities. For transfers to third countries, we ensure an adequate level of data protection, e.g. by an adequacy decision of the European Union such as the EU-US Data Privacy Framework or by Standard Contractual Clauses with supplementary measures. 

 

Retention 

Personal data are stored only for as long as necessary for the purposes or as long as statutory retention obligations apply. Afterwards the data are deleted or anonymised. Applicable periods include in particular commercial and tax retention periods. 

 

Obligation to provide data 

Certain information is required for the initiation or performance of contracts and for compliance with legal obligations. Without this information services may not be provided. 

 

Your rights 

You may exercise all rights described in this data protection statement, incl. those under Chapter III GDPR, against any of the joint controllers. We coordinate requests internally within the framework of the joint controllership. The contact details of our data protection officer are provided in this data protection statement.

III. Name and address of the data protection officer

The data protection officer of the responsible party is: 

SHIELD GmbH Datenschutz & Sicherheit 
Managing Director: Martin Vogel 
Ohlrattweg 5 
25497 Prisdorf 
Phone: +49 (0) 4101 8050600 
E-mail: datenschutz@atlantic-hotels.de 
www.shield-datenschutz.de

IV. General data management

1. Scope of processing of personal data 
We process personal data from our users principally only to the extent necessary to provide a functional website and our content and services. The processing of personal data of our users is regularly only carried out with their consent. These consents can be revoked at any time with effect for the future by informing the responsible. The contact details can be found under "I. Name and address of the responsible". 

 
2. Legal basis for the processing of personal data  

Insofar as we obtain the consent of the data subject for the processing of personal data, art. 6 (1) (a) EU General Data Protection Regulation (GDPR) serves as the legal basis for the processing of personal data. 

In the processing of personal data necessary for the performance of a contract to which the data subject is a party, art. 6 (1) (b) GDPR serves as the legal basis. This also applies to processing operations required to carry out pre-contractual actions. 

Insofar as processing of personal data is required to fulfill a legal obligation that is required for our company, art. 6 (1) (c) GDPR serves as the legal basis. In the event that vital interests of the data subject or another natural person require the processing of personal data, art. 6 (1) (d) GDPR serves as the legal basis. If processing is necessary to safeguard the legitimate interests of our company or a third party, and if the interests, fundamental rights and freedoms of the data subject do not prevail over the first interest, art. 6 (1) (f) GDPR serves as legal basis for processing. 

 
3. Data deletion and storage duration 
The personal data of the data subject will be deleted or blocked as soon as the purpose of the storage expires. Additional storage may take place if provided for by the European or national legislator in EU regulations, laws or other regulations to which the data controller is subject. Blocking or deletion of the data also takes place when a storage period prescribed by the standards mentioned expires, unless there is a need for further storage of the data for conclusion of a contract or fulfillment of the contract. 

V. Processing of personal data of guests at hotel check-in

1. Processing of personal data of domestic guests at hotel check-in 

In order to process the accommodation contract, the following personal data must be collected and stored from you as a domestic guest at hotel check-in: 

  • Date of arrival and expected departure (for planning and organising your stay) 

  • Surname and first name (for identification and contact purposes) 

  • E-mail address (to participate in the online check-in/out process to simplify and speed up the check-in and check-out process, to confirm your booking and to send relevant information about your reservation, to send your invoice after the end of your stay) 

  • Address (for identification and contact purposes) - unless you initiate a card-based payment transaction with Strong Customer Authentication (SCA), in which case the earmarked allocation number of the payment method used is collected. In this case, the earmarked allocation number of the payment method used is stored together with the above-mentioned data. 

  • Federal State law may stipulate that further data may be collected on the registration form for the collection of tourist and spa fees (fulfilment of the requirements of the tourist and spa administrations). 

Strong customer authentication is a requirement of the EU Payment Services Directive PSD2, which ensures that online payments are secure, and fraud is reduced. It requires users to confirm their identity when making payments using two of three factors - knowledge (something that only the user knows, e.g. a password), possession (something that only the user has, e.g. a smartphone) and inherence (something that only the user has, e.g. a fingerprint). 

Entering your e-mail address is voluntary. Please note, however, that if you do not provide it, you will not be able to take advantage of the digital procedures, such as online check-in/out, digital reservation confirmation or electronic invoicing. 

Other data collected during the reservation process or during your stay - such as your private or business billing address - will be processed in accordance with the purposes stated in this privacy policy. 

Your personal data is processed on the basis of Art. 6 Para. 1 lit. b GDPR (fulfilment of a contract) and Art. 6 Para. 1 lit. f GDPR (legitimate interest). Our legitimate interest lies in improving our service offering by simplifying processes and digital communication. Voluntary information such as your e-mail address is processed on the basis of Art. 6 Para. 1 lit. a GDPR (consent). You have the right to withdraw your consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. 

Your data will only be passed on to departments and, if necessary, to so-called ‘processors’ within the meaning of Art. 4 No. 8 GDPR, who are entrusted with the processing of your booking and the realisation of your stay. Processors within the EU are not considered third parties. Data will only be passed on to third parties if this is necessary for the fulfilment of the accommodation contract or if you have given us your explicit consent, which can be revoked at any time, or if this is required by law. 

Your personal data will only be stored for as long as is necessary for the fulfilment and processing of the accommodation contract. Statutory retention obligations remain unaffected by this. 

 

2. Processing of personal data of foreign guests at hotel check-in 

The collection and storage of the following personal data from you as a foreign guest at hotel check-in is necessary for the processing of the accommodation contract and due to legal obligations arising from the Federal Registration Act: 

  • Date of arrival and expected departure (to plan and organise your stay and to fulfil the requirements of the Federal Registration Act) 

  • Surname and first name (for identification and contact purposes and to fulfil the requirement of the Federal Registration Act) 

  • Date of birth (fulfilment of the requirement under the Federal Registration Act) 

  • Nationalities (fulfilment of the requirement under the Federal Registration Act) 

  • Address (for identification and, if necessary, contacting and to fulfil the requirement under the Federal Registration Act) 

  • Number of foreign fellow travellers and their nationality (fulfilment of the requirement under the Federal Registration Act) 

  • Serial number of the recognised and valid passport or passport replacement document (identity document) (fulfilment of the requirement under the Federal Registration Act) 

  • Federal State law may stipulate that further data may be collected on the registration form for the collection of tourist and spa fees (fulfilment of the requirements of the tourist and spa administrations) 

The details on the registration form are compared with those on your identity document. If there are any discrepancies, this will be noted on the registration form. If you do not present any or no valid identity document, this will also be noted on the registration form. 

Other data collected during the reservation process or during the stay - for example the private or business billing address - will be processed in accordance with the purposes stated in this privacy policy. 

Your personal data is processed on the basis of Art. 6 Para. 1 lit. c GDPR (legal obligation) in conjunction with §§ 29, 30 Federal Registration Act, Art. 6 Para. 1 lit. b GDPR (fulfilment of a contract) and Art. 6 Para. 1 lit. f GDPR (legitimate interest). Our legitimate interest lies in improving our service offering by simplifying processes and digital communication. Voluntary information is processed on the basis of Art. 6 Para. 1 lit. a GDPR (consent). You have the right to withdraw your consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. 

Your data will only be passed on to departments and, if necessary, to so-called ‘processors’ within the meaning of Art. 4 No. 8 GDPR, who are entrusted with the processing of your booking and the realisation of your stay. Processors within the EU are not considered third parties. Data will only be passed on to third parties if this is necessary for the fulfilment of the accommodation contract or if you have given us your explicit consent, which can be revoked at any time, or if this is required by law. 

Your personal data will only be stored for as long as is necessary for the fulfilment and processing of the accommodation contract. Statutory retention obligations remain unaffected by this. The Federal Registration Act stipulates, among other things, that registration forms must be kept for one year from the date of departure and destroyed within three months of expiry of the retention period.

VI. Provision of the website and creation of logfiles

1. Description and scope of data processing 

Each time our website is accessed, our system automatically collects data and information from the computer system of the calling computer. 

The following data is collected: 

  1. Information about the browser type and the version used 

  2. The operating system of the users 

  3. The Internet service provider of the user 

  4. The IP address of the user 

  5. Date and time of access 

  6. Websites from which the user's system accesses our website 

  7. Websites accessed by the user's system through our website 

The data is also stored in the log files of our system. A storage of this data together with other personal data of the user does not take place. 

2. Legal basis for data processing 

The legal basis for the temporary storage of data and log files is Art. 6 (1) (f) GDPR. 

3. Purpose of the data processing 

The temporary storage by the system of the IP address is necessary to allow delivery of the website to the computer of the user. To do this, the user's IP address must be kept for the duration of the session. 

Storage in log files is done to ensure the functionality of the website. In addition, the data is used to optimize the website and to ensure the security of our information technology systems. An evaluation of the data for marketing purposes does not take place in this context. 

We have a justified interest in the processing of data for this purpose, according to Art. 6 (1) (f) GDPR. 

In diesen Zwecken liegt auch unser berechtigtes Interesse an der Datenverarbeitung nach Art. 6 Abs. 1 lit. f DSGVO. 

4. Duration of storage 

The data will be deleted as soon as it is no longer necessary for the purpose of its collection. In the case of collecting the data for providing the website, this is the case when the session is completed. In the case of storing the data in log files, data is stored for no more than seven days. After one day, the IP addresses of the users are anonymized, so that an assignment of the calling client is no longer possible. 

5. Objection and removal possibility 

The collection of data for the provision of the website and the storage of the data in log files is essential for the operation of the website. Consequently, there is no possibility for the user to object. 

VII. Use of cookies

1. Description and scope of data processing 

Each time our website is accessed, our system automatically collects data and information from the computer system of the calling computer. 

The following data is collected: 

  1. Information about the browser type and the version used 

  2. The operating system of the users 

  3. The Internet service provider of the user 

  4. The IP address of the user 

  5. Date and time of access 

  6. Websites from which the user's system accesses our website 

  7. Websites accessed by the user's system through our website 

The data is also stored in the log files of our system. A storage of this data together with other personal data of the user does not take place. 

2. Legal basis for data processing 

The legal basis for the temporary storage of data and log files is Art. 6 (1) (f) GDPR. 

3. Purpose of the data processing 

The temporary storage by the system of the IP address is necessary to allow delivery of the website to the computer of the user. To do this, the user's IP address must be kept for the duration of the session. 

Storage in log files is done to ensure the functionality of the website. In addition, the data is used to optimize the website and to ensure the security of our information technology systems. An evaluation of the data for marketing purposes does not take place in this context. 

We have a justified interest in the processing of data for this purpose, according to Art. 6 (1) (f) GDPR. 

In diesen Zwecken liegt auch unser berechtigtes Interesse an der Datenverarbeitung nach Art. 6 Abs. 1 lit. f DSGVO. 

4. Duration of storage 

The data will be deleted as soon as it is no longer necessary for the purpose of its collection. In the case of collecting the data for providing the website, this is the case when the session is completed. In the case of storing the data in log files, data is stored for no more than seven days. After one day, the IP addresses of the users are anonymized, so that an assignment of the calling client is no longer possible. 

5. Objection and removal possibility 

The collection of data for the provision of the website and the storage of the data in log files is essential for the operation of the website. Consequently, there is no possibility for the user to object. 

VIII. Private customer newsletter & conference customer newsletter

1. Description and scope of data processing 
On our website, it is possible to subscribe to a free newsletter that informs customers and business partners about the company’s offers and news at regular intervals. During registration for the newsletter, the data from the input mask are transmitted to us. Here it is mandatory to enter the e-mail address and select the newsletter. Optionally, the salutation, title, first name and last name can be entered. 

In addition, the following data are collected during registration: 

  1. IP address of the calling computer
  2. Date and time of registration
  3. URL
  4. Date/time and IP of the order 

For the processing of the data, your consent is obtained in the context of the registration process and reference is made to this privacy policy. 

The company Revinate Inc, 1 Letterman Dr., Building C, Suite CM100, San Francisco, CA 94129, USA (hereinafter referred to as ‘Revinate’) is commissioned to process the dispatch of the newsletter. Revinate is a service that can be used to organise and analyse the sending of newsletters, among other things. 

If you enter data for the purpose of subscribing to the newsletter (e.g. e-mail address), it will be stored on Revinate's servers in the USA. 
Revinate complies with the ‘EU-US Privacy Shield’. The ‘Privacy Shield’ is an agreement between the European Union (EU) and the USA, which is intended to ensure compliance with European data protection standards in the USA. 
Further information can be found in Revinate's privacy policy at: https://www.revinate.com/privacy/ 

We have concluded a data processing agreement (‘Data Processing Addendum’) with Revinate. In this agreement, we oblige Revinate to protect our customers' data and not to pass it on to third parties. 
The data will be used exclusively for sending the newsletter. In connection with the data processing for the dispatch of newsletters, the data will not be passed on to third parties. 

2. Legal basis for data processing 
The legal basis for the processing of data after registration by the user for the newsletter and for data processing as part of newsletter tracking is Article 6(1)(a) GDPR if the user has given consent. 

3. Purpose of data processing 
The collection of the user’s e-mail address serves to deliver the newsletter. The collection of other personal data as part of the registration process serves to address the user personally. The provision of further personal data is voluntary. 

4. Duration of storage 
The data will be deleted as soon as they are no longer necessary for the purpose of their collection. The user’s e-mail address and the personal data optionally provided during the registration process are therefore stored as long as the newsletter subscription is active. 

5. Objection and removal possibility 
The subscription of the newsletter can be cancelled by the data subject at any time. For this purpose, there is a corresponding unsubscribe link in every newsletter. 
The e-mail address of the user and the personal data collected in the registration process will be deleted immediately in the event of an objection (unsubscribe). 
In addition, you can at any time object to the storage of your data with effect for the future via newsletter@atlantic-hotels.de. Your data will then be deleted immediately and you will no longer receive a newsletter. 

6. Newsletter tracking 
The newsletter contains a so-called web beacon. A web beacon is a transparent 1x1 pixel graphic that is embedded in the e-mail. This is only possible in HTML mails, not in plain text mails, and makes it feasible to record a log file analysis. This allows a statistical evaluation of the success or failure of online marketing campaigns to be carried out. Based on the embedded web beacon, ATLANTIC Hotels Management GmbH can detect if and when an e-mail was opened by a data subject and which links in the e-mail were accessed by the data subject. 

Such personal data collected via the web beacons contained in the newsletters are stored and evaluated by the data controller in order to optimize the newsletter distribution and to adapt the content of future newsletters even better to the interests of the data subject. This personal data will not be passed on to third parties. Data subjects are entitled at any time to revoke the relevant separate declaration of consent submitted via the double opt-in procedure. After revocation, this personal data will be deleted by the data controller. ATLANTIC Hotels Management GmbH automatically interprets any subscription cancellation from the newsletter as a revocation. 

Openings, clicks, cancellations etc. are saved as activities for the respective recipient. These data can be viewed in the recipient data record for each recipient addressed. This has a retention period of up to six months and is then deleted again. Then no more evaluations, follow-up campaigns or the like can be carried out. 

The data are also not stored permanently in the report area. Reports that are older than one year are automatically archived by the system. The archived reports can still be viewed by ATLANTIC Hotels Management GmbH, but personalized data are not evaluated here. These are only visible up to six months after the newsletter has been sent. 

IX. Registration & Online booking

1. Description and scope of data processing 
On our website, it is possible to subscribe to a free newsletter that informs customers and business partners about the company’s offers and news at regular intervals. During registration for the newsletter, the data from the input mask are transmitted to us. Here it is mandatory to enter the e-mail address and select the newsletter. Optionally, the salutation, title, first name and last name can be entered. 

In addition, the following data are collected during registration: 

  1. IP address of the calling computer
  2. Date and time of registration
  3. URL
  4. Date/time and IP of the order 

For the processing of the data, your consent is obtained in the context of the registration process and reference is made to this privacy policy. 

The company Revinate Inc, 1 Letterman Dr., Building C, Suite CM100, San Francisco, CA 94129, USA (hereinafter referred to as ‘Revinate’) is commissioned to process the dispatch of the newsletter. Revinate is a service that can be used to organise and analyse the sending of newsletters, among other things. 

If you enter data for the purpose of subscribing to the newsletter (e.g. e-mail address), it will be stored on Revinate's servers in the USA. 
Revinate complies with the ‘EU-US Privacy Shield’. The ‘Privacy Shield’ is an agreement between the European Union (EU) and the USA, which is intended to ensure compliance with European data protection standards in the USA. 
Further information can be found in Revinate's privacy policy at: https://www.revinate.com/privacy/ 

We have concluded a data processing agreement (‘Data Processing Addendum’) with Revinate. In this agreement, we oblige Revinate to protect our customers' data and not to pass it on to third parties. 
The data will be used exclusively for sending the newsletter. In connection with the data processing for the dispatch of newsletters, the data will not be passed on to third parties. 

2. Legal basis for data processing 
The legal basis for the processing of data after registration by the user for the newsletter and for data processing as part of newsletter tracking is Article 6(1)(a) GDPR if the user has given consent. 

3. Purpose of data processing 
The collection of the user’s e-mail address serves to deliver the newsletter. The collection of other personal data as part of the registration process serves to address the user personally. The provision of further personal data is voluntary. 

4. Duration of storage 
The data will be deleted as soon as they are no longer necessary for the purpose of their collection. The user’s e-mail address and the personal data optionally provided during the registration process are therefore stored as long as the newsletter subscription is active. 

5. Objection and removal possibility 
The subscription of the newsletter can be cancelled by the data subject at any time. For this purpose, there is a corresponding unsubscribe link in every newsletter. 
The e-mail address of the user and the personal data collected in the registration process will be deleted immediately in the event of an objection (unsubscribe). 
In addition, you can at any time object to the storage of your data with effect for the future via newsletter@atlantic-hotels.de. Your data will then be deleted immediately and you will no longer receive a newsletter. 

6. Newsletter tracking 
The newsletter contains a so-called web beacon. A web beacon is a transparent 1x1 pixel graphic that is embedded in the e-mail. This is only possible in HTML mails, not in plain text mails, and makes it feasible to record a log file analysis. This allows a statistical evaluation of the success or failure of online marketing campaigns to be carried out. Based on the embedded web beacon, ATLANTIC Hotels Management GmbH can detect if and when an e-mail was opened by a data subject and which links in the e-mail were accessed by the data subject. 

Such personal data collected via the web beacons contained in the newsletters are stored and evaluated by the data controller in order to optimize the newsletter distribution and to adapt the content of future newsletters even better to the interests of the data subject. This personal data will not be passed on to third parties. Data subjects are entitled at any time to revoke the relevant separate declaration of consent submitted via the double opt-in procedure. After revocation, this personal data will be deleted by the data controller. ATLANTIC Hotels Management GmbH automatically interprets any subscription cancellation from the newsletter as a revocation. 

Openings, clicks, cancellations etc. are saved as activities for the respective recipient. These data can be viewed in the recipient data record for each recipient addressed. This has a retention period of up to six months and is then deleted again. Then no more evaluations, follow-up campaigns or the like can be carried out. 

The data are also not stored permanently in the report area. Reports that are older than one year are automatically archived by the system. The archived reports can still be viewed by ATLANTIC Hotels Management GmbH, but personalized data are not evaluated here. These are only visible up to six months after the newsletter has been sent. 

X. Contact form and e-mail contact

1. Description and scope of data processing 

Contact via the provided e-mail address is possible. In this case, the user's personal data that are transmitted by e-mail will be stored. In this context, data is not passed on to third parties. The data is used exclusively for processing the conversation. 

2. Legal basis for data processing 

The legal basis for the processing of the data is in the presence of the consent of the user Art. 6 (1) (a) GDPR. The legal basis for the processing of the data transmitted in the course of sending an e-mail is Art. 6 (1) (f) GDPR. If the e-mail contact aims to conclude a contract, then additional legal basis for the processing is Art. 6 (1) (b) GDPR. 

3. Purpose of the data processing 

The processing of the personal data from the input mask serves us only to establish contact with the user. In the case of contact via e-mail, this also includes the required legitimate interest in the processing of the data. The other personal data processed during the sending process serve to prevent misuse of the contact form and to ensure the security of our information technology systems. 

4. Duration of storage 

The data will be deleted as soon as it is no longer necessary for the purpose of its collection. 

5. Objection and removal possibility 

The user has the option at any time to revoke his or her consent to the processing of the personal data. If the user contacts us by e-mail, he or she may object to the storage of his or her personal data at any time. In such a case, the conversation can not continue. You can always object to the storing of your data for the future by contacting info@atlantic-hotels.de, by mail to ATLANTIC Hotels Management GmbH, Ludwig-Roselius-Allee 2, 28329 Bremen or by phone +49 (0) 421 944888-0. All personal data stored in the course of the conversation will be deleted in this case. 

XI. Rights of the affected person

If your personal data are processed, you are the person affected within the meaning of  GDPR and you have the following rights vis-à-vis the data controller:

1. Right to information 
You may ask the person responsible to confirm whether personal data concerning you is processed by us. 
If your data is being processed, you can request information from the person responsible about the following information:

  1. the purposes for which the personal data are being processed;
  2. the categories of personal data being processed;
  3. the recipients or the categories of recipients to whom personal data concerning you have been disclosed or are being disclosed;
  4. the planned duration of the storage of your personal data or, if specific information is not available, criteria for determining the duration of storage;
  5. the existence of a right to rectification or deletion of your personal data, a right to restriction of processing by the data controller or a right to object to such processing;
  6. the existence of a right of appeal to a supervisory authority;
  7. all available information on the source of the data, if the personal data is not collected from the data subject;
  8. the existence of automated decision-making, including profiling under Article 22 (1) and (4) GDPR and, at least in these cases, meaningful information about the logic involved, and the scope and intended impact of such processing on the data subject.

You have the right to request information about whether your personal information is passed on to a third country or an international organization. In this context, you can request to be informed of the appropriate guarantees in accordance with Art. 46 GDPR in connection with the transfer.

2. Right to rectification

You have a right to rectification and / or completion by the data controller, if your personal data being processed is incorrect or incomplete. The responsible person must make the correction immediately.

3. Right to restriction of processing

You may request the restriction of the processing of your personal data under the following conditions:

  1. if you contest the accuracy of the information relating to you for a period of time, that allows the data controller to verify the accuracy of your personal information;
  2. the processing is unlawful and you refuse the deletion of the personal data and instead demand restriction of the use of your personal data;
  3. the data controller no longer needs the personal data for the purposes of processing, but you need it in order to assert, exercise or defend legal claims; or
  4. if you have objected to the processing pursuant to Art. 21 (1) GDPR, and it is not yet certain whether the legitimate reasons of the data controller outweigh your reasons.

If the processing of personal data concerning you has been restricted, this data may only be used with your consent or for the purpose of asserting, exercising or defending legal claims or protecting the rights of another natural or legal person, or for reasons of important public interests of the Union or a Member State. If the restriction of processing was restricted according to the above conditions, you will be informed by the data controller before the restriction is lifted.

4. Right to deletion

a) Obligation to delete

You may demand that the controller delete your personal information immediately, and the controller is required to delete that information immediately if one of the following is true:

  1. Personal data concerning you are no longer necessary for the purposes for which they were collected or otherwise processed.
  2. You revoke your consent, which the processing was based on according to Art. 6 (1) (a) or Art. 9 (2) (a) GDPR and there is no other legal basis for processing.
  3. You object to the processing according to Art. 21 (1) GDPR and there are no prior justifiable reasons for the processing, or you object to the processing according to Art. 21 (2) GDPR.
  4. Your personal data have been processed unlawfully.
  5. The deletion of personal data concerning you is required, in order to fulfill a legal obligation under Union law or the law of the Member States to which the controller is subject.
  6. The personal data concerning you were collected in relation to information society services, pursuant to Article 8 (1) of the GDPR.

b) Information to third parties

If the data controller has made the personal data concerning you public and is required to delete them according to  Article 17 (1) of the GDPR, he must take appropriate measures, including technical means, with due regard to available technology and implementation costs, to inform data controllers that you, the data subject, have requested the deletion of all links to such personal data or copies or replications of this personal data.

Exceptions

The right to erasure is not in force if the processing is necessary:

  1. to exercise the right to freedom of expression and information;
  2. to fulfill a legal obligation required by the law of the Union or of the Member States to which the controller is subject, or performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
  3. for reasons of public interest in the field of public health pursuant to Art. 9 (2) (h) and (i) and Art. 9 (3) GDPR;
  4. for archival purposes of public interest, scientific or historical research purposes or for statistical purposes according to Article 89 (1) GDPR, to the extent that the law referred to in subparagraph (a) is likely to render impossible or seriously affect the achievement of the objectives of that processing, or
  5. to assert, exercise or defend legal claims.

5. Right to information

If you have the right of rectification, erasure or restriction of processing to the controller, he / she is obliged to notify all recipients, to whom your personal data have been disclosed, of this correction or deletion of the data or restriction of processing, unless: this proves to be impossible or involves a disproportionate effort. You have a right to be informed about these recipients by the data controller.

6. Right to Data Portability

You have the right to receive personally identifiable information that you provided to the controller in a structured, common and machine-readable format. In addition, you have the right to transfer this data to another person without hindrance by the person responsible for providing the personal data, provided that

  1. the processing is based on consent according to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract according to Art. 6 (1) (b) GDPR
  2. the processing is done by automated means.

In exercising this right, you also have the right to obtain that your personal data are transmitted directly from one controller to another, as far as technically feasible. This situation should not affect the freedoms and rights of other persons. 
The right to data portability does not apply to the processing of personal data necessary for the performance of a task in the public interest or in the exercise of official authority vested in the controller.

7. Right to object

You have the right at any time, for reasons arising from your particular situation, to object to the processing of your personal data, which occurs pursuant to Art. 6 (1) (e) or (f) GDPR; this also applies to profiling based on these provisions. 
The controller will no longer process the personal data concerning you, unless he can demonstrate compelling legitimate grounds for processing that outweigh your interests, rights and freedoms, or the processing is for the purpose of enforcing, exercising or defending legal claims. 
If the personal data relating to you are processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for the purpose of such advertising; this also applies to profiling insofar as it is associated with such direct advertising. 
If you object to processing for direct advertising purposes, your personal data will no longer be processed for these purposes. 
Regardless of Directive 2002/58/EC, you have the option, in the context of the use of information society services, to exercise your right to object through automated procedures that use technical specifications.

8. Right to revoke the data protection consent declaration

You have the right to revoke your data protection declaration at any time. The revocation of consent does not affect the legality of the processing carried out on the basis of the consent before the revocation.

9. Automated decision in individual cases, including profiling

You have the right not to be subjected to a decision based solely on automated processing - including profiling - that will have legal effect or negatively affect you in a similar manner. This does not apply if the decision

  1. is required for the conclusion or performance of a contract between you and the controller,
  2. is permitted by Union or Member State legislation to which the controller is subject, and where such legislation contains appropriate measures to safeguard your rights and freedoms and legitimate interests, or
  1. occurs with your express consent.
  2. However, these decisions may not be based on special categories of personal data pursuant to Art. 9 (1) GDPR, unless Art. 9 (2) (a) or (g) apply, and reasonable measures have been taken to protect your rights and freedoms and your legitimate interests.
  3. With regard to the cases referred to in (1) and (3), the person responsible shall take reasonable measures to safeguard your rights and freedoms and your legitimate interests, including at least the right to obtain the intervention of a person from the side of the controller, to present the case and to challenge the decision.
  4. Right to complain to a supervisory authority

Without prejudice to any other administrative or judicial remedy, you shall have the right to complain to a supervisory authority, in particular in the Member State of your place of residence, employment or the place of the alleged infringement, if you believe that the processing of the personal data concerning you violates the GDPR.

The supervisory authority to which the complaint has been submitted shall inform the complainant of the status and results of the complaint, including the possibility of a judicial remedy pursuant to Article 78 of the GDPR.

Die Landesbeauftragte für Datenschutz und Informationsfreiheit der Freien Hansestadt Bremen (State Data Protection and Freedom of Information Officer) 
Arndtstraße 1, 27570 Bremerhaven 
Tel.: +49 471 596 2010 oder +49 421 361 2010 
Fax: +49 421 496 18495 
E-Mail: office@datenschutz.bremen.de

XII. Ordering Vouchers via the Incert system

On our website we have integrated the voucher and ticket system of Incert eTourismus GmbH & Co. KG (Leonfeldnerstr. 328, A-4040 Linz, Austria) to order vouchers. 

If you order vouchers from us, it is necessary for the conclusion of the contract that you provide your personal data, which we need to process your order. Mandatory information required for the execution of the contracts is marked separately, further information is voluntary. The data is entered in an input mask and transmitted to us and saved. The following data is collected during the booking process: 

Mandatory information: 

  • First name
  • Surname
  • Street
  • Postcode
  • City
  • Country
  • E-mail address
  • Payment method

Optional information: 

  • Company
  • Telephone number
  • E-mail address of additional voucher recipient
  • Dedication (For, From, Message)

  • Own pictures
  • Own videos

The following data is also stored at the time the voucher is ordered: 

  • The user's IP address
  • Date and time of the booking
  • Order number
  • Voucher code
  • value
  • Transaction number

For the processing of the data, your consent is obtained as part of the sending process and reference is made to this Data Protection Statement. 

In addition, the data will only be passed on to third parties if the transfer is necessary for the purpose of contract execution or for billing purposes or for collecting the fee or if you have given your express consent. In this regard, we only pass on the data required in each case.  

The data recipients are typically delivery / shipping companies, payment institutions, payment service providers and, in the event of payment default, also collection agencies. 

A Data Processing Agreement was concluded with Incert eTourismus GmbH & Co. KG in accordance with Art. 28 Para. 3 GDPR. 

The legal basis is Art. 6 Para. 1 lit. b GDPR. Regarding the voluntary data, the legal basis for the processing of the data is Art. 6 Para. 1 lit. a GDPR. 

The mandatory data collected is required for the fulfillment of the contract with the user (for the purpose of sending the goods and confirming the content of the contract). We therefore use the data to answer your inquiries, to process your booking, if necessary to check creditworthiness or to collect a debt and for the purpose of technical administration of the websites. The voluntary information is provided for the prevention of misuse and, if necessary, for the investigation of criminal offences. We may also process the data you provide to inform you about other interesting products from our portfolio or to send you e-mails with information. 

The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. We are required by commercial and tax law to store your address, payment  
and order data for a period of ten years after the execution of the contract. However, we will restrict processing after six years, i.e. your data will only be used to comply with legal  obligations. If a continuing obligation exists between us and the user, we store the data for the entire term of the contract and for ten years thereafter (see above). Regarding data provided voluntarily, we will delete the data upon expiration of six years after execution of the contract, provided that no further contract is concluded with the user during this period; in this case, the data will be deleted upon expiration of six years after execution of the last contract. 

If the data is required for the performance of a contract or for the execution of pre-contractual measures, early deletion of the data is only possible insofar as contractual or legal obligations do not prevent deletion. Otherwise, you are free to have the personal data provided during registration completely deleted from the data stock of the responsible party. Regarding the voluntary data, you can declare your revocation to the person responsible at any time. In this case, the voluntary data will be deleted immediately. 

More information on data protection at Incert eTourismus GmbH & Co. KG can be found at: https://www.incert.at/unternehmen/datenschutz/ (in German only) 

Payment provider 

Your security is our top priority! For this reason, data such as credit card number, bank sort code, account number, name and address are transmitted via a secure SSL/TLS connection  
when paying by credit card. This means that no unauthorised person can read the data you enter during transmission over the Internet. 

You can find information about our payment providers and the associated data protection measures in our Privacy Policy under the heading ‘Payment Providers’.

XIII. Data protection for job applications and in the application process

The Controller processes applicants’ personal data for the purpose of managing the application process.

 

Processing is carried out in particular for the following purposes:

  • Receipt, review and assessment of your application
  • Communication with you (e.g. scheduling appointments, follow-up questions, sending/receiving documents)
  • Conducting interviews and making selection decisions
  • Preparing an employment relationship (initiation of a contract)
  • Where applicable: asserting/defending legal claims (e.g. documentation obligations, in particular in connection with the German General Equal Treatment Act (AGG))
  • Optional: inclusion in an applicant pool for future vacancies (only if you give us your consent)

 

Categories of personal data:

Depending on the type and scope of your application, we process in particular the following data:

  • Master data: surname, first name, where applicable form of address
  • Contact data: address, email address, telephone number
  • Application data: cover letter, CV, references, qualification certificates, references (if provided by you), salary expectations, earliest possible start date, preferred area/working hours
  • Communication data: content of messages/phone calls/emails, interview notes, appointment arrangements

 

Important note:

Please only provide us with data that are necessary for the application process. If you voluntarily provide information relating to special categories of personal data (Art. 9 GDPR; e.g. health data, religious affiliation), we will process such data only insofar as this is permitted and necessary in the individual case or you have expressly consented.

 

Legal bases for processing:

Depending on the circumstances, processing is carried out on the following legal bases:

  • § 26 Para. 1 BDSG (data processing for purposes of the employment relationship, in particular for deciding on the establishment of an employment relationship) in conjunction with Art. 6 Para. 1 lit. b GDPR (pre-contractual measures)
  • Art. 6 Para. 1 lit. c GDPR, insofar as we are subject to legal obligations (e.g. documentation obligations)
  • Art. 6 Para. 1 lit. f GDPR (legitimate interests) (in particular: efficient conduct of the application process, internal organisation/communication, IT security, as well as asserting/defending legal claims (in particular in the context of the AGG))
  • Art. 6 Para. 1 lit. a GDPR (consent) (e.g. for extended retention (applicant pool) or for processing special information where required)
  • Where special categories of personal data are concerned: Art. 9 Para. 2 GDPR (in particular lit. b and/or lit. a) in conjunction with § 26 Para. 3 BDSG, where applicable

 

Recipients / categories of recipients:

Within our company, only those persons have access to your data who require them for the decision-making and implementation of the application process (e.g. HR managers, management, the responsible department).

 

External recipients may include:

  • IT/system service providers, hosting and communication service providers (e.g. email), insofar as we use them as processors pursuant to Art. 28 GDPR
  • Legal advisers, courts, authorities or other bodies, insofar as this is necessary for the assertion/defence of legal claims or where a legal obligation exists

 

Transfers to third countries:

We generally process your application data within the European Union / the European Economic Area. Where, in individual cases, service providers in third countries are used, this is done only in compliance with the requirements of Art. 44 et seq. GDPR (e.g. EU standard contractual clauses, adequacy decision).

 

Retention period / deletion:

We store your personal data only for as long as this is necessary for the purposes stated above.

If your application is successful, relevant application documents will be transferred to the personnel file and stored in accordance with statutory retention periods.

Longer retention (e.g. applicant pool) will take place only with your consent; in that case until withdrawal or until expiry of the agreed period (maximum one year).

If the Controller does not conclude an employment contract with the applicant, the application documents will be automatically deleted six months after notification of the rejection decision, unless other legitimate interests of the Controller prevent deletion. Such other legitimate interests in this sense include, for example, an obligation to provide evidence in proceedings under the German General Equal Treatment Act (AGG).

Additional Plugins and online services

Google analytics

The data controller has integrated on this website the component Google Analytics. Google Analytics is a web analytics service. Web analysis is the collection and analysis of data about the behavior of visitors to websites. Among other things, a web analysis service collects data about referrers - from which website the user came to the website, which subpages of the website were accessed, or how often and for how long a subpage was viewed. A web analysis is mainly used for optimization of a website and for cost-benefit analysis of Internet advertising.

The operating company of the Google Analytics component is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland.

The controller uses the addition "_gat._anonymizeIp" for web analytics via Google Analytics. By means of this addition, the IP address of the Internet connection of the data subject will be shortened and anonymized by Google, if the access to our website is from a Member State of the European Union or from another state party to the Agreement on the European Economic Area.

The purpose of the Google Analytics component is to analyze streams of visitors on our website. Among other things, Google uses the data and information obtained to evaluate the use of our website, to compile online reports for us showing the activities on our websites, and to provide other services related to the use of our website.

Google Analytics uses a cookie on the information technology system of the person concerned. What cookies are has already been explained above. Using this cookie makes it possible for Google to analyze the usage of our website. Each time one of the pages of this website, that is processed by the data controller and where a Google Analytics component is integrated, is accessed, the Internet browser on the information technology system of the person concerned is automatically initiated by the respective Google Analytics component to submit data to Google for online analysis purposes. As part of this technical process, Google receives information about personal data, such as the IP address of the person concerned, which among other things serves Google to track the origin of visitors and clicks, and subsequently to allow commission billing.
The cookie stores personal data, such as access time, the location from which access was made, and the frequency of site visits by the data subject. Each time a user visits our website, this personal information, including the IP address of the Internet connection used by the data subject, is transferred to Google in the United States of America. This personal data is stored by Google in the United States of America. Google may transfer such personal data collected through this technical process to third parties.

The data subject can prevent the setting of cookies at any time by our website, as explained above, by changing the Internet browser settings and thus permanently preventing the setting of cookies. Such Internet browser settings would also prevent Google from setting a cookie on the data subject's information technology system. In addition, a cookie already set by Google Analytics can be deleted at any time through the Internet browser or other software programs.
Furthermore, the data subject has the option of objecting to and preventing the collection of the data generated by Google Analytics for the use of this website and the processing of this data by Google. To do this, the person must download and install a browser add-on at tools.google.com/dlpage/gaoptout. This browser add-on informs Google Analytics via JavaScript that no data and information about website visits may be transmitted to Google Analytics. The installation of the browser add-on is considered by Google to be an objection. If the data subject's information technology system is later deleted, formatted or reinstalled, the data subject must re-install the browser add-on to disable Google Analytics. If the browser add-on is uninstalled or disabled by the data subject or any other person within their sphere of control, it is possible to reinstall or reactivate the browser add-on.
Additional information and Google's privacy policy can be found at https://www.google.com/intl/en/policies/privacy/ and http://www.google.com/analytics/terms/en.html. Google Analytics is explained in more detail at https://www.google.com/intl/de_de/analytics/.

You can prevent collection by Google Analytics by clicking on the following link. An opt-out cookie will be set, which prevents the future collection of your data when visiting this website: Disable Google Analytics

Google Ads Enhanced Conversions and Customer Match

We use Google Ads with the functions ‘Enhanced Conversions’ and – subject to your consent – ‘Customer Match’ on our website. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter referred to as ‘Google’).

If you access our website via a Google advertisement and complete a booking or another conversion there, data you enter, in particular your email address and telephone number, may be transmitted to Google in hashed form (using a cryptographic hash procedure). Google may use this data to attribute conversions to our Google Ads campaigns and to improve the measurement and optimisation of our advertising activities.

Where you have given your consent, the hashed data transmitted in the context of Enhanced Conversions may also be used by Google to create so-called Customer Match lists. This enables us to target users who have previously interacted with us or made a booking with personalised advertising and to reach similar audiences.

The data collected may also be stored and processed in the USA, i.e. a third country for which no adequacy decision of the European Commission exists.

However, Google relies on the European Commission’s EU-U.S. Data Privacy Framework for the transfer of data to the USA.

The use of Google Ads Enhanced Conversions and Customer Match is based exclusively on your consent pursuant to Art. 6 Para. 1 lit. a GDPR and § 25 Para. 1 TDDDG. You may withdraw your consent at any time with effect for the future via the consent settings on our website.

Where personal data is collected on our website by means of the functions described above and transmitted to Google, we and Google Ireland Limited are jointly responsible for this data processing (Art. 26 GDPR). The joint responsibility is limited exclusively to the collection of the data and its transmission to Google. The processing carried out by Google after the transfer is not part of the joint responsibility. The obligations incumbent upon us jointly have been set out in an agreement on joint processing. The wording of the agreement can be found at https://business.safety.google/adscontrollerterms/

Further information about data protection at Google can be found at https://policies.google.com/privacy?hl=en and at https://support.google.com/google-ads/answer/9888656?hl=en

Google Ads

The controller has integrated Google Ads on this website. Google Ads is an Internet advertising service that allows advertisers to run ads in both Google search engine results and in the Google advertising network. Google Ads allows an advertiser to set keywords in advance, that will display an ad on Google's search engine results only when user uses the search engine to retrieve a search result relevant to the key words. In the Google advertising network, ads are distributed on relevant web pages using an automated algorithm and according to pre-defined keywords.

The operating company for the services of Google Ads is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland.

The purpose of Google Ads is to advertise our website by displaying interest-based advertising on the websites of third-party companies and in the search engine results of the search engine Google.

If a data subject comes to our website via a Google ad, a conversion cookie will be stored on the user's information technology system by Google. What cookies are has already been explained above. A conversion cookie expires after thirty days and is not used to identify the data subject. If the conversion cookie has not yet expired, it will be traced whether certain sub-pages, such as the shopping cart from an online shop system, were accessed on our website. The conversion cookie allows both us and Google to understand whether a data subject who came to our website via an Ads ad generated revenue, i.e. completed or interrupted a purchase.

The data and information collected through the use of the conversion cookie are used by Google to create visitor statistics for our website. These visit statistics are then used by us to determine the total number of users who have been sent to us through Ads ads, in order to determine the success or failure of each Ads ad and to optimize our Ads ads for the future. Neither our company nor any other Google Ads advertiser receives any information from Google that could identify the data subject.

The conversion cookie stores personal information, such as the web pages visited by the data subject. Each time a user visits our website, this personal information, including the IP address of the Internet connection used by the data subject, is transferred to Google in the United States of America. This personal data is stored by Google in the United States of America. Google may transfer such personal data collected through this technical process to third parties.

The affected person can prevent the setting of cookies at any time by our website, as explained above, by changing the Internet browser settings and thus permanently preventing the setting of cookies. Such Internet browser settings would also prevent Google from setting a conversion cookie on the data subject's information technology system. In addition, a cookie already set by Google Ads can be deleted at any time through the Internet browser or other software programs.

Furthermore, the data subject has the opportunity to object to Google's interest-based advertising. To do this, the data subject must access the link www.google.com/settings/ads from each of the Internet browsers they use and make the desired settings there.
Additional information and Google's privacy policy can be found at https://www.google.com/intl/en/policies/privacy/.

Google Remarketing

The data controller has integrated Google Remarketing services into this website. Google Remarketing is a feature of Google Ads that allows a business to show advertisements to internet users that have previously been on the company's website. The integration of Google Remarketing allows a company to create user-friendly advertising and thus show the Internet user interest-related ads.

The Google Remarketing Services operating company is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland.

The purpose of Google Remarketing is to show interest-based advertising. Google Remarketing allows us to display ads through the Google advertising network or other websites tailored to the individual needs and interests of Internet users.
Google Remarketing places a cookie on the information technology system of the data subject. What cookies are has already been explained above. By setting the cookie, Google will be able to recognize the visitor to our website, if he subsequently accesses websites that are also members of the Google advertising network. With each visit to a website on which Google Remarketing's service has been integrated, the data subject's Internet browser is automatically identified with Google. As part of this technical process, Google receives personal data, such as the IP address or the surfing behavior of the user, which Google uses among other things to display interest-relevant advertising.

The cookie is used to store personal data, such as the websites visited by the data subject. Each time a user visits our website, this personal information, including the IP address of the Internet connection used by the data subject, is transferred to Google in the United States of America. This personal data is stored by Google in the United States of America. Google may transfer such personal data collected through this technical process to third parties.

The affected person can prevent the setting of cookies at any time by our website, as explained above, by changing the Internet browser settings and thus permanently preventing the setting of cookies. Such Internet browser settings would also prevent Google from setting a cookie on the data subject's information technology system. In addition, a cookie already set by Google Ads can be deleted at any time through the Internet browser or other software programs.

Furthermore, the data subject has the opportunity to object to Google's interest-based advertising. To do this, the data subject must access the link www.google.com/settings/ads from each of the Internet browsers they use and make the desired settings there.

Additional information and Google's privacy policy can be found at https://www.google.com/intl/en/policies/privacy/.

Google DoubleClick

A web service from Google Ireland Limited, Gordon House, Barrow Street, 4 Dublin, Ireland (hereinafter: DoubleClick) is loaded on our website. We use this data to ensure the full functionality of our website. In this context, your browser may transmit personal data to DoubleClick.

You can prevent DoubleClick from collecting and processing your data by refusing your consent when you enter the website, deactivating the execution of script code in your browser or installing a script blocker in your browser.
The legal basis for the use of Google Double Click is your consent in accordance with Art. 6 Para. 1 lit. a GDPR.

The data will be deleted as soon as the purpose of their collection has been fulfilled. Further information on the handling of the transferred data can be found in the DoubleClick data protection declaration: policies.google.com/privacy

Microsoft Ads (former Bing Ads)

Our website uses conversion tracking from Microsoft (Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA). Microsoft Bing Ads places a cookie on your computer if you have reached our website via a Microsoft Bing ad. In this way, Microsoft Bing and we can recognize that someone clicked on an ad, was redirected to our website and reached a previously determined target page (conversion page). We only find out the total number of users who clicked on a Bing ad and were then forwarded to the conversion page. No personal information about the identity of the user is disclosed. If you do not want to participate in the tracking process, you can also reject the setting of a cookie required for this - for example via a browser setting that generally disables the automatic setting of cookies.


The legal basis for the use of Bing Ads is your consent pursuant to Art. 6 Para. 1 lit. a GDPR.


Further information on data protection and the cookies used by Microsoft Bing can be found on the Microsoft website: https://www.microsoft.com/en-us/privacy/privacystatement

Google Tag Manager

We use Google Tag Manager, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Tag Manager allows us to manage and deploy website tags via a centralized interface. While the Tag Manager itself does not set cookies or directly access personal data collected by individual tags, it may process personal data such as your IP address or other metadata during the loading process. It cannot be ruled out that Google may use this data for its own purposes, such as service optimization or error analysis.

For this reason, Google Tag Manager is only activated after you have given your explicit consent via our cookie banner.

The storage and processing of the data collected takes place in the USA, i.e. a third country for which there is no adequacy decision by the European Commission.

However, Google bases the data transfer to the USA on the EU-U.S. Data Privacy Framework of the European Commission.

The legal basis for the use of Google Tag Manager is your consent pursuant to Art. 6 Para. 1 lit a GDPR and, where applicable, Section 25 Para. 1 TDDDG, insofar as the processing involves access to information on your device (e.g., IP address, device configuration).

You can withdraw your consent at any time with future effect by adjusting your preferences in the cookie settings.

For more information about how Google handles your data, please refer to Google's Tag Manager Use Policy:
marketingplatform.google.com/about/analytics/tag-manager/use-policy/

Google Maps

This website uses the "Google Maps" service from Google to display maps or map sections and thus enables you to conveniently use the map function on the website. The Google Maps Geocoding API is used to determine and display locations. Google Maps is operated by Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043, USA.

When you visit the website, Google receives the information that you have accessed the
corresponding subpage of our website. In addition, the data mentioned under the "Access data" section is transmitted to Google. This takes place regardless of whether Google provides a user account that you are logged in to or whether there is no user account. If you are logged in to Google, your data will be assigned directly to your account. If you do not want your profile to be assigned to Google, you must log out before activating the button.

Google also processes your personal data in the USA and has submitted to the EU-US Privacy Shield. You can view Google's certification here: https://www.dataprivacyframework.gov/participant/5780

The legal basis for the use of Google Maps is your consent in accordance with Art. 6 Para. 1 lit. a GDPR. We have no knowledge of the storage period at Google and have no influence on it.

Further information on the purpose and scope of processing by the plug-in provider can be found in Google's privacy policy. There you will also find further information on your rights and setting options to protect your privacy: http://www.google.de/intl/de/policies/privacy

Further information on the terms of use of Google Maps can be found at:
https://www.google.com/intl/de_de/help/terms_maps.html

Gstatic

A web service from Google Ireland Limited, Gordon House, Barrow Street, 4 Dublin, Ireland (hereinafter: Gstatic) is loaded on our website. We use this data to ensure the full functionality of our website. In this context, your browser may transmit personal data to Gstatic.

The legal basis for the use of this web service is your consent in accordance with Art. 6 Para. 1 lit. a GDPR.

You can prevent Gstatic from collecting and processing your data by refusing your consent when you enter the website, deactivating the execution of script code in your browser or installing a script blocker in your browser.

The data will be deleted as soon as the purpose of their collection has been fulfilled. Further information on the handling of the transferred data can be found in Google's data protection declaration: https://policies.google.com/privacy

Google Fonts

Google Fonts (https://fonts.google.com/) are used to visually improve the presentation of various information on this website. The web fonts are transferred to the cache of the browser when the page is called up so that they can be used for display. If the browser does not support Google Fonts or prevents access, the text is displayed in a standard font.

When the page is called up, no cookies are stored by the website visitor. Data that are transmitted in connection with the page view are sent to resource-specific domains such as fonts.googleapis.com or fonts.gstatic.com. You will not be associated with data that may be collected or used in connection with the parallel use of authenticated Google services such as Gmail.

You can prevent the collection and processing of your data by this web service by refusing your consent when entering the website, deactivating the execution in your browser or installing a script blocker in your browser. If your browser does not support the Google Fonts or you prevent access to the Google servers, the text is displayed in the system's standard font.

The legal basis for the use of this web service is your consent in accordance with Art. 6 Para. 1 lit. a GDPR.

You can find information on the data protection conditions of Google Fonts at: https://developers.google.com/fonts/faq#Privacy

General information on data protection can be found in the Google Privacy Center at: https://policies.google.com/privacy

YouTube

Videos from the YouTube platform are integrated on our website. The provider of this service is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland or Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter referred to as ‘YouTube’).
When you access a page with an embedded YouTube video, personal data is transmitted to YouTube/Google, in particular your IP address and - depending on the configuration - other device and browser-related information. If you are logged into your Google account, this assignment can also be made directly to your user profile. The data processing is carried out by Google under its own responsibility.

The data collected may also be stored and processed in the USA, i.e. a third country for which there is no adequacy decision by the European Commission.

However, Google bases the data transfer to the USA on the EU-U.S. Data Privacy Framework of the European Commission. The integration of YouTube videos and the associated data processing are based on your consent in accordance with Art. 6 Para. 1 lit. a GDPR in conjunction with § 25 Para. 1 TDDDG. Consent can be revoked at any time with effect for the future via our Consent Banner. Further information on data processing by YouTube can be found in Google's privacy policy at https://policies.google.com/privacy

Meta-Pixel (former „Facebook-Pixel“)

This website uses the Meta Pixel for conversion measurement and to optimise advertising activities. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (hereinafter referred to as 'Meta').

With the help of the Meta Pixel, the behaviour of website visitors can be tracked after they have been redirected to our website by clicking on a Meta advert (e.g. on Facebook or Instagram). This allows us to evaluate the effectiveness of adverts, create audiences (e.g. 'Custom Audiences') and optimise future advertising measures. In this context, usage and interaction data (e.g. page views, content accessed, click paths, time of access), technical information (e.g. IP address, device and browser information) and event data ('events') are processed.

We use the Advanced Matching function within the Meta Pixel. In doing so, additional hashed customer data (e.g. email address or phone number) may be transmitted to Meta in order to improve conversion attribution and create more precise audiences.

The use of this service is based on your consent pursuant to Art. 6 Para. 1 lit. a GDPR and § 25 Para. 1 TDDDG. Your consent may be withdrawn at any time.

Insofar as personal data is collected on our website and transmitted to Meta by means of the Meta Pixel, we and Meta Platforms Ireland Limited are joint controllers for this processing (Art. 26 GDPR). Joint controllership is limited solely to the collection of the data and its transmission to Meta. Any processing carried out by Meta after transmission is not part of the joint controllership and is carried out under Meta’s own responsibility. Meta provides terms for joint controllership for this purpose.

The data collected may also be stored and processed in the USA, i.e. a third country for which no adequacy decision of the European Commission exists. However, Meta relies on the European Commission’s EU-U.S. Data Privacy Framework for the transfer of data to the USA.

Further information about data protection at Meta can be found in Meta’s privacy policy at https://www.facebook.com/privacy/policy/

You can also manage settings for interest-based advertising with Meta in your advertising preferences (login required) at https://accountscenter.facebook.com/ad_preferences/

LinkedIn Insight

This website uses the Insight Tag from LinkedIn. The provider of this service is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland (hereinafter referred to as "LinkedIn").

With the help of the LinkedIn Insight Tag, we receive information about visitors to our website. If a website visitor is registered with LinkedIn, we can, among other things, analyse the key professional data (e.g. career level, company size, country, location, industry and job title) of our website visitors and thus better tailor our site to the respective target groups. Furthermore, we can use LinkedIn Insight Tags to measure whether visitors to our websites make a purchase or take another action (conversion measurement). Conversion measurement can also take place across devices (e.g. from PC to tablet). LinkedIn Insight Tag also offers a retargeting function that allows us to display targeted advertising outside the website to visitors to our website, whereby, according to LinkedIn, no identification of the advertising addressee takes place.

LinkedIn itself also collects so-called log files (URL, referrer URL, IP address, device and browser properties and time of access). The IP addresses are shortened or (if they are used to reach LinkedIn members across devices) hashed (pseudonymised).

The direct identifiers of LinkedIn members are deleted by LinkedIn after seven days. The remaining pseudonymised data is then deleted within 180 days.

The data collected by LinkedIn cannot be assigned to specific individuals by us as website operators. LinkedIn will store the collected personal data of website visitors on its servers in the USA and use it in the context of its own advertising measures.

The use of LinkedIn Insight exclusively on the basis of your consent pursuant to Art. 6 Para. 1 lit. a GDPR and § 25 Para. 1 TDDDG. The consent can be revoked at any time with effect for the future.

Data transfer to the USA is based on the standard contract clauses of the EU Commission (“SCC”). Details can be found here: https://www.linkedin.com/legal/l/dpa and https://www.linkedin.com/legal/l/eu-sccs

You can object to the analysis of usage behaviour and targeted advertising by LinkedIn at the following link: https://www.linkedin.com/psettings/guest-controls

Furthermore, LinkedIn members can control the use of their personal data for advertising purposes in their account settings. To prevent LinkedIn from linking data collected on our website with your LinkedIn account, you must log out of your LinkedIn account before visiting our website. For more information on data protection at LinkedIn, please see their privacy policy at https://www.linkedin.com/legal/privacy-policy#choices-oblig

Microsoft Clarity

We use the web analysis software Microsoft Clarity for our website. The service provider is the US company Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA (hereinafter referred to as "Microsoft").

Microsoft Clarity refers to a procedure by Microsoft in which user analysis is possible on the basis of a pseudonymous user ID and thus on the basis of pseudonymous data, such as the evaluation of data on mouse movements or performance data on certain Internet presentations.

In particular, we process usage data (for example, internet presentations visited, interest in content, access times), meta or communication data (for example, device information, IP addresses), location data (information on the geographical position of a device or a person), movement data (mouse movements, scrolling movements) in pseudonymised form. We have made the corresponding settings in such a way that the data collection to and by Microsoft alone is pseudonymised, in particular in the form of IP masking (pseudonymisation of the IP address).

The purpose of the processing is tracking (e.g. interest/behavioural profiling, use of cookies), remarketing, conversion measurement (measurement of the effectiveness of marketing measures), interest-based and behavioural marketing, profiling (creation of user profiles), reach measurement (e.g. access statistics, recognition of returning users), cross-device tracking (cross-device processing of user data for marketing purposes).

The storage and processing of the collected data takes place in the USA, i.e. a third country for which there is no adequacy decision by the European Commission.

However, Microsoft bases the data transfer to the USA on the EU-U.S. Data Privacy Framework of the European Commission.

All visitors to our website who have consented to the corresponding use via our consent banner are affected by data processing by Microsoft Clarity. The data processing is thus based solely on your consent in accordance with Art. 6 Para. 1 lit. a GDPR and § 25 Para. 1 TDDDG.

Please note that we have concluded a so-called Data Processing Agreement (“DPA”) with Microsoft to enable this activity in accordance with Art. 28 Para. 3 S. 1 GDPR.

You will be informed of your rights of objection in accordance with this data protection statement. In addition, you can set an opt-out with the respective provider:

For further information on data protection at Microsoft, please see the data protection declaration at https://privacy.microsoft.com/en-us/privacystatement

DialogShift Chat Application on Our Website

Our website uses the chat application from DialogShift GmbH, Torstr. 201, 10115 Berlin. This application processes and stores data for the purpose of web analysis, operating the chat application, and responding to inquiries. For the operation of the chat function, chat texts are stored, and a cookie with a unique ID is set—this serves to recognize you as a customer. A cookie is a small text file that is stored locally in the cache on your device. With the help of this cookie, our application recognizes the device again and can retrieve past chat logs. This cookie is stored for 90 days since its last use. You can disable the storage of cookies in your browser settings. However, without the use of cookies, the chat function cannot be executed. The possible disclosure of, for example, names, email addresses, or a telephone number is voluntary and with the consent to temporarily use and store these data for the purpose of making contact until the end of the contact. These personal data are deleted after 90 days. The legal basis for data processing is according to Art. 6 Para. 1 lit. a GDPR, § 25 Para. 1 TDDDG based on your consent. DialogShift offers further information on data collection and use as well as your rights and options for protecting your privacy at https://www.dialogshift.com/datenschutz.

Facebook Conversion API

We use the Facebook Conversion API (CAPI), a service provided by Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (hereinafter referred to as ‘Meta’), to transmit usage data to Meta from our web server. The purpose is to measure the effectiveness of our advertising on Facebook and Instagram and to optimise our marketing activities in a targeted manner.

The Conversion API enables us to transmit certain events (e.g. page visits, submitted forms) directly from our web server to Meta – independent of the user’s browser or device. No client-side tracking technologies are used in this context.

Depending on the configuration, the following categories of personal data may in particular be processed when using the Conversion API:

  • IP address
  • Information about the device and browser used
  • Visited URLs and timestamps
  • HTTP header information
  • Facebook-specific parameters (e.g. click ID)
  • Hashed user information (e.g. email address, telephone number, if available)
  • Transaction or conversion data (e.g. order values)

Personal data may be transferred to Meta Platforms Inc., 1601 Willow Road, Menlo Park, California 94025, USA. For the United States, there is an adequacy decision pursuant to Art. 45 Para. 1 GDPR.

Meta is certified under the EU-U.S. Data Privacy Framework (DPF). The current certification can be viewed at:

https://www.dataprivacyframework.gov/s/participant-search

To the extent that the use of the Conversion API involves access to information stored on the end user’s device (e.g. by reading the Facebook click ID from cookies), this is carried out on the basis of your consent pursuant to § 25 Para. 1 TDDDG.

The subsequent transmission of personal data to Meta is carried out on the basis of your consent pursuant to Art. 6 Para. 1 lit. a GDPR.

Consent is obtained through our consent management platform. You may withdraw your consent at any time with effect for the future.

Further information on data processing by Meta can be found at: https://www.facebook.com/privacy/policy

straiv

We use the straiv solution provided by straiv GmbH, Industriestraße 23, 70565 Stuttgart, Germany (hereinafter referred to as 'straiv').

Straiv enables hotels to offer their guests digital information (e.g. digital guest directory, guest messaging) and services (e.g. digital check-in and check-out including registration form) on their own devices throughout all phases of the stay.

Each hotel decides independently which contents and services are provided through straiv.

Personal data are only collected if you provide them voluntarily or if legal regulations require their collection. For certain functions, entering personal data may be necessary to verify your authorisation to use a service. In particular, the following categories of data may be processed:

  • Cookie ID, geo-data, room number
  • Usage data (e.g. modules used and duration of visit)
  • Booking data (e.g. booking number, arrival and departure date)

Not all of the data categories mentioned above are necessarily processed; this depends on the specific configuration and modules used by each hotel. The use of the solution is generally possible without registration. When submitting or requesting a service, you will at least once be asked to give your consent to data processing.

Categories of recipients:

  • Public authorities where overriding legal provisions apply
  • Other external recipients if you have given your consent or the transfer is permissible due to overriding legitimate interests
  • The respective hotel and its authorised employees with system access

Data processing is carried out – depending on the module used – either on the basis of your consent pursuant to Art. 6 Para. 1 lit. a GDPR or on the basis of our legitimate interests pursuant to Art. 6 Para. 1 lit. f GDPR, in particular our interest in efficiently providing digital guest services. You may withdraw your consent at any time with effect for the future.

If, in the course of using straiv, data are transferred to third countries, such transfer is carried out on the basis of appropriate safeguards pursuant to Art. 46 GDPR, in particular the standard contractual clauses.

We have concluded a Data Processing Agreement within the meaning of Art. 28 Para. 3 GDPR with straiv, under which straiv is obliged to protect our guests’ data and not to disclose them to third parties. Straiv implements all necessary technical and organisational measures to ensure the security of your data.

Further information on data processing by straiv can be found in straiv’s Privacy Policy at https://straiv.io/en/legal/privacy/ 

If you make an online payment in connection with the use of straiv (e.g. during digital check-in or to guarantee your booking), the payment process is carried out via the external payment service provider Adyen N.V., Simon Carmiggeltstraat 6-50, 1011 DJ Amsterdam, Netherlands (hereinafter referred to as 'Adyen').

Adyen processes the data required for payment processing (e.g. name, credit card or bank account details, amount, transaction number, date, time and IP address).

Processing takes place for the purpose of payment handling and fraud prevention on the basis of Art. 6 Para. 1 lit. b GDPR (performance of a contract) and Art. 6 Para. 1 lit. f GDPR (legitimate interest in secure payment processing).

Further information on data processing by Adyen can be found in Adyen’s Privacy Policy at https://www.adyen.com/policies-and-disclaimer/privacy-policy

Freshdesk Ticketsystem

For the processing of enquiries by our Central Services and our online marketing team, we use the ticketing system ‘Freshdesk’. The provider of this service is Freshworks GmbH, Neue Grünstraße 17, 10179 Berlin, Germany (hereinafter referred to as ‘Freshdesk’).

Freshdesk is used for the structured recording, processing and management of incoming enquiries (e.g. via email or other communication channels). In this context, we process in particular contact and communication data (e.g. name, email address, telephone number, content of the enquiry, correspondence history) as well as organisational metadata (e.g. ticket number, processing status, responsibilities).

Processing is carried out predominantly for the internal organisation, documentation and quality assurance of our communication and service processes. Where, in individual cases, personal data of guests is processed, this is done for the purpose of handling the respective enquiry either pursuant to Art. 6 Para. 1 lit. b GDPR for the initiation or performance of a contract or on the basis of our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR in ensuring an efficient and structured organisation of our communication and service processes.

The data collected may also be stored and processed in the USA, i.e. a third country for which no adequacy decision of the European Commission exists. In this case, data may be transferred to Freshworks Inc., 2950 S. Delaware Street, Suite 201, San Mateo, CA 94403, USA.

However, Freshdesk relies on the European Commission’s EU-U.S. Data Privacy Framework for the transfer of data to the USA.

We have concluded a Data Processing Agreement with Freshdesk in accordance with Art. 28 Para. 3 GDPR. In this agreement, we oblige Freshdesk to protect our customers' data and not to pass it on to third parties.

Further information about data protection at Freshdesk can be found at https://www.freshworks.com/privacy/

Cituro

We use 'Cituro' for the online booking and management of appointments in our spa area. The provider is cituro GmbH, Peter-Dörfler-Straße 30, 86199 Augsburg, Germany (hereinafter referred to as 'Cituro'). 

Cituro is an online appointment booking and appointment management service that can be used to book, manage and organise appointments for spa, wellness, treatment and other service offerings online. If you book an appointment in our spa area via Cituro, the data you provide during the booking process may be processed. This may include in particular your name, title, contact details, email address, telephone number, desired service or treatment, appointment request, date and time of booking, booked service, communication data, organisational booking data and technical access data. Depending on the specific configuration, further information that you provide as part of the appointment booking or communication with us may also be processed. 

The processing serves to receive, manage, organise, perform and bill your appointment booking as well as to communicate with you in connection with the booked spa, wellness or treatment service. Depending on the configuration used, Cituro may also be used for appointment reminders, appointment changes, cancellations, resource planning, customer management, vouchers, discounts, reviews or online payments. 

The data are processed, insofar as this is necessary for the initiation, performance or processing of the booked spa, wellness, treatment or other service, on the basis of Art. 6 Para. 1 lit. b GDPR. Where we are legally obliged to retain certain booking, payment or billing data, the processing is carried out on the basis of Art. 6 Para. 1 lit. c GDPR. Where the processing is necessary for the organisation of our spa operations, appointment and resource management, communication with guests, prevention of misuse or the establishment, exercise or defence of legal claims, it is carried out on the basis of our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR. Where technically necessary cookies are set or information is stored on or accessed from the end device when using Cituro, this is carried out on the basis of Art. 6 Para. 1 lit. b GDPR or Art. 6 Para. 1 lit. f GDPR and Section 25 Para. 2 No. 2 TDDDG. Where non-technically necessary cookies or comparable technologies are used, this is done only on the basis of consent pursuant to Art. 6 Para. 1 lit. a GDPR and Section 25 Para. 1 TDDDG. 

The data processed in connection with the appointment booking are stored for as long as this is necessary for the performance and processing of the booking as well as for the management of the booked services. The data are then deleted unless statutory retention obligations, in particular commercial or tax law retention obligations, apply or further storage is required for the establishment, exercise or defence of legal claims. 

Cituro processes personal data of visitors to our website and users of the appointment booking as a processor within the meaning of Art. 4 No. 8 GDPR, insofar as this processing is carried out on our behalf for the provision and operation of the service. We have concluded a data processing agreement with Cituro within the meaning of Art. 28 Para. 3 GDPR. In this agreement, Cituro undertakes in particular to process personal data only in accordance with our instructions and for the provision of the agreed services, to implement appropriate technical and organisational protective measures, and to use sub-processors only in accordance with the contractual provisions. 

Further information on data processing by Cituro can be found at https://www.cituro.com/datenschutz (in German) 

Payment providers

We offer various payment methods on our websites:

Credit card – NEXI Germany GmbH

If you select “credit card” as the payment method, the payment processing is carried out by NEXI Germany GmbH, Helfmann-Park 7, 65760 Eschborn, Germany.

NEXI Germany GmbH uses your personal data in particular to process the payments, to prevent card abuse, to limit the risk of payment defaults and also for statutory purposes, such as the prevention of money laundering and criminal prosecution.

We as the credit card accepting entity, NEXI Germany GmbH and the payment service providers are each separately responsible for the processing of personal data within the respective technical sphere of influence.

We would like to point out that NEXI Germany GmbH transfers your personal data to other bodies necessary for the processing of the transaction, in particular to the credit institutions, banks and credit card companies involved. Processing of your personal data for the completion of the payment also takes place at these points. You will find the respective privacy policies on the websites of NEXI Germany GmbH and the payment service providers. Please address any enquiries regarding data protection and the exercise of your rights to NEXI Germany GmbH or the respective payment service providers.

The transmission of your data takes place on the basis of GDPR Article 6(1)(b) for the processing of the contract or your order. The secure transfer of your data takes place in accordance with the statutory provisions, § 25a KWG (German Banking Act), § 27 ZAG (Payment Services Oversight Act) and the provisions of the respective credit card companies. The processing and transfer are based on GDPR Article 6(1)(c) (legal obligations) and (f) (our legitimate interest). You have the possibility of revoking your consent to data processing at NEXI Germany GmbH and the respective payment service providers at any time for the future. Revocation has no effect on the effectiveness of data processing operations that have taken place in the past. However, in the event of revocation, we can no longer offer you the payment method “credit card”.

Further information on data protection and your rights pursuant to GDPR Articles 15 to 21 for NEXI Germany GmbH can be found at Data Policy | Nexi.

Adyen

If you make payments with us (e.g. by credit card on site or as part of digital payment processes), payment processing is carried out via the payment service provider Adyen N.V., Simon Carmiggeltstraat 6, 1011 DJ Amsterdam, Netherlands (hereinafter referred to as 'Adyen').

In doing so, Adyen processes the personal data required for payment processing, in particular payment and transaction data (e.g. amount, time, transaction reference), card or payment instrument data (e.g. card type, partially masked card details), merchant and terminal data and, in the case of online payments, potentially also technical data (e.g. IP address, device and browser information). As the accepting entity, we generally only receive the information necessary to confirm and account for the payment.

Adyen processes personal data in particular for payment handling, preventing card misuse and fraud, managing risk and complying with statutory requirements (e.g. anti-money laundering obligations and supervisory requirements). In this context, Adyen may transfer data to other parties required to complete the transaction, in particular participating banks, financial institutions, payment networks and card schemes.

We, as the accepting entity, and Adyen each process personal data as separate controllers for processing activities within our respective areas of responsibility. The same applies to banks and payment networks involved in the payment process to the extent they carry out their own processing.

Processing in connection with payment handling is carried out on the basis of Art. 6 Para. 1 lit. b GDPR (performance of a contract), insofar as processing is necessary to carry out the payment. In addition, processing may be based on Art. 6 Para. 1 lit. c GDPR (legal obligation) where required by law, and on Art. 6 Para. 1 lit. f GDPR (legitimate interest) for fraud prevention, misuse prevention and ensuring the security of payment processing.

Further information on data processing by Adyen can be found in Adyen’s Privacy Policy at https://www.adyen.com/privacy-policy

PayPal – PayPal (Europe) S.à.r.l. & Cie. S.C.A

The data controller has integrated components from PayPal on this website. PayPal is an online payment service provider. Payments are made through PayPal accounts, which are virtual private or business accounts. In addition, PayPal has the ability to process virtual payments with credit cards if a user does not have a PayPal account. A PayPal account is managed via an email address, which is why there is no classic account number. PayPal makes it possible to make online payments to third parties or to receive payments. PayPal also takes on fiduciary functions and offers buyer protection services.

The European operating company of PayPal is PayPal (Europe) S.à.rl & Cie. SCA, 22-24 Boulevard Royal, 2449 Luxembourg, Luxembourg.
If the data subject selects "PayPal" as the payment option during the order process in our online shop, data of the data subject will be automatically transmitted to PayPal. By selecting this payment option, the data subject consents to the transfer of personal data required for payment processing.

The personal data transmitted to PayPal is usually first name, last name, address, e-mail address, IP address, telephone number, mobile phone number or other data required for payment processing. Personal information connection with the respective order is also necessary for the execution of a purchase contract.

The purpose of the transmission of the data is payment processing and fraud prevention. The data controller will provide PayPal with personal data, in particular if there is a legitimate interest for the transfer. The personal data exchanged between PayPal and the data controller may potentially be transferred by PayPal to credit reporting agencies. The reason for this transmission is for identity verification and credit checking.

PayPal may disclose personal information to affiliates and service providers or subcontractors, to the extent necessary to fulfill its contractual obligations or to process the data on behalf of them. The data subject has the option to revoke the consent to the handling of personal data by PayPal at any time. A revocation has no effect on personal data which must be processed, used or transmitted for (contractual) payment processing.
PayPal's applicable privacy policy is available at https://www.paypal.com/webapps/mpp/ua/privacy-full.


etracker
The provider of this website uses the services of etracker GmbH, Hamburg, Germany (www.etracker.com) to analyse usage data. We do not use cookies for web analysis by default. If we use analysis and optimisation cookies, we will obtain your explicit consent separately in advance. If this is the case and you agree, cookies are used to enable a statistical range analysis of this website, a measurement of the success of our online marketing measures and test procedures, e.g. to test and optimise different versions of our online offer or its components. Cookies are small text files that are stored by the Internet browser on the user's device. etracker cookies do not contain any information that could identify a user.

The data generated by etracker on behalf of the provider of this website is processed and stored by etracker solely in Germany by commission of the provider of this website and is thus subject tothe strict German and European data protection laws and standards. In this regard, etracker was independently checked, certified and awarded with theePrivacyseal data protection seal of approval.

The data processing is based on Art. 6 Section 1 lit f (legitimate interest) of the General Data Protection Regulation (GDPR). Our legitimate interest is the optimisation of our online offer and our website. As the privacy of our visitors is very important to us, the data that may possibly allow a reference to an individual person, such as IP address, registration or device IDs, will be anonymised or pseudonymised as soon as possible. etracker does not use the data for any other purpose, combine it with other data or pass it on to third parties.

You can object to the outlined data processing at any time. Your objection has no disadvantageous consequences.


Further information on data protection with etracker can be found here.