Data protection information according to Art. 13 EU General Data Protection Regulation (GDPR)
Please note that this English version of our Privacy Policy is provided for your convenience only. The original German text is the authoritative and legally binding version. While we have made efforts to accurately translate the content, there may be discrepancies or inaccuracies. In case of any inconsistency between the German and English versions, the German version (Link auf Deutsche Version) shall prevail.
Welcome to the Privacy Section of SIC Hospitality GmbH – Kennedy 89 Hotel Frankfurt – Part of The Unbound Collection by Hyatt. We are pleased about your interest in our company. With the following privacy information, we would like to inform you in detail about when we collect which data and how such data are processed.
Data controller:
The data controller according to Article 4(7) of the EU General Data Protection Regulation (GDPR) is
SIC Hospitality GmbH
Kennedy 89 Hotel Frankfurt
Stresemannallee 28, 60596 Frankfurt am Main
Phone: 069 / 2562 1234
E-Mail: info@kennedy-89.com
Data protection officer:
You can contact our data protection officer at:
Gesellschaft für Personaldienstleistungen mbH
Pestalozzistraße 27, 34119 Kassel
Phone: +49 561 78968-80
E-Mail: datenschutz@gfp24.de
General information on the collection of personal Data
The following notices provide you with transparent information about the type and scope of personal data processing that is collected during:
• Your visit to our website,
• The use of our online services,
• External online presences on social media platforms,
• Our hotel location,
• Business relationships with customers and service providers.
The legal basis for our data protection practices are primarily the provisions of the GDPR, the Federal Data Protection Act (BDSG) and the Telecommunications Digital Services Data Protection Act (TDDDG).
Legal bases for processing personal data
In cases where we obtain your consent for processing personal data, Article 6(1)(a) GDPR serves as the legal basis.
When processing personal data necessary for the performance of a contract between you and us, Article 6(1)(b) GDPR serves as the legal basis. This also applies to processing operations required to carry out pre-contractual measures.
If the processing of personal data is necessary to fulfill a legal obligation to which we are subject, Article 6(1)(c) GDPR serves as the legal basis.
In cases where vital interests of the data subject or another natural person make the processing of personal data necessary, Article 6(1)(d) GDPR serves as the legal basis.
If the processing of personal data is necessary to protect a legitimate interest of our company or a third party, and if your interests, fundamental rights, and freedoms do not override this interest, then Article 6(1)(f) GDPR serves as the legal basis for processing.
According to § 25 (1) TDDDG, storage of information in the end-user’s terminal equipment or access to information already stored in the terminal equipment shall only be permitted if the end-user has consented on the basis of clear and comprehensive information.
According to § 25(2) no. 2 TDDDG no consent is required, where the storage of information in the end-user’s terminal equipment or the access to information already stored in the end-user’s terminal equipment is strictly necessary to enable the provider of a telemedia service to provide a telemedia service explicitly requested by the user.
Disclosure of Personal Data
If we transmit or disclose your personal data to other entities as part of our processing activities, this is done solely based on one of the mentioned legal bases. Recipients of such data may include, for example, payment service providers for the fulfillment of contracts. In cases where we are legally or by court order obliged to do so, we must transmit your data to authorized entities.
If external service providers support us in processing your data (e.g., data analysis, newsletter dispatch), this is done within the framework of a data processing agreement according to Article 28 GDPR. We only enter into agreements with service providers who offer sufficient guarantees that appropriate technical and organizational measures will ensure the protection of your data.
Transfer of personal data to Third Countries
Data transfer to third countries (outside the European Union or the European Economic Area) only occurs if it is in accordance with legal requirements. Subject to explicit consent or legally required transfer, we process or allow data to be processed only in third countries with an acknowledged level of data protection (e.g., adequacy decision by the European Commission pursuant to Article 45(1)(3) GDPR for the EU-US Data Privacy Framework https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en or based on appropriate safeguards under Articles 44 ff. GDPR, such as contractual obligations through so-called standard data protection clauses of the EU Commission (EU Commission information page: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_en).
Duration of storage
Unless expressly stated in this privacy policy, the data stored by us will be deleted as soon as they are no longer required for their intended purpose and no legal obligations to retain data conflict with the deletion. If the data are not deleted because they are required for other and legally permissible purposes, their processing is restricted, i.e. the data are blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons.
Definitions
Our privacy notice is based on the terms used in the GDPR and defined therein. To ensure that our privacy policy is easy to read and understand, we would like to explain the key terms in advance.
Personal Data
“Personal data” means any information relating to an identified or identifiable natural person (“data subject”). An identifiable natural person is one who can be identified, directly or indirectly, particularly by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
Processing
“Processing” means any operation or set of operations that is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
Controller
“Controller” means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of processing personal data. Where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
Pseudonymization
“Pseudonymization” means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.
Processor
“Processor” means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.
Recipient
“Recipient” means a natural or legal person, public authority, agency, or another body, to which personal data are disclosed, whether a third party or not. However, public authorities that may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.
Third Party
“Third Party” means a natural or legal person, public authority, agency, or body other than the data subject, controller, processor, and persons who, under the direct authority of the controller or processor, are authorized to process personal data.
Consent
“Consent” of the data subject means any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
Profiling
“Profiling” means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, particularly to analyze or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements
Rights of the data subject
As a natural person affected by the processing of personal data, you have certain rights that you can exercise at any time in relation to us. These rights include:
• Right to withdraw consent for data processing under Article 7(3) GDPR.
• Right of access to your personal data stored by us, in accordance with Article 15 GDPR.
• Right to rectification of inaccurate or incomplete data, pursuant to Article 16 GDPR.
• Right to erasure of your data stored with us, under Article 17 GDPR.
• Right to restriction of processing of your data, in accordance with Article 18 GDPR.
• Right to data portability under Article 20 GDPR.
• Right to object to processing under Article 21 GDPR.
• Right not to be subject to automated decision-making, including profiling, under Article 22 GDPR.
Right of access by the data subjects
You have the right to know whether we are processing your personal data and, if so, to request copies of your personal data. Please note that your right of access may be restricted under certain circumstances in accordance with legal provisions.
Right to rectification
If your information is incorrect or incomplete, you have the right to request the correction of inaccurate personal data concerning you and, if necessary, the completion of incomplete personal data without undue delay.
Right to erasure
You have the right, under the applicable legal requirements, to request that your data be deleted without undue delay, for example, if the data is no longer needed for the purposes pursued, and if there are no statutory retention and archiving requirements that would prevent deletion.
Right to restriction of processing
You have the right, under the conditions of Article 18 GDPR, to request the restriction of processing of your data, for example, if you have objected to the processing for the duration of the examination as to whether your objection can be upheld.
Right to data portability
You have the right to receive the data you have provided to us in a common, machine-readable format, and to request the transmission of these data to a third party. If you request the direct transfer of the data to another controller, this will only be done if it is technically feasible.
Right to withdraw consent
If the processing of your personal data is based on your consent, you have the right to withdraw this consent at any time. The withdrawal of consent does not affect the lawfulness of the processing carried out on the basis of the consent up until the withdrawal.
Please send your withdrawal to:
SIC Hospitality GmbH
Kennedy 89 Hotel Frankfurt
Stresemannallee 28, 60596 Frankfurt am Main
Phone: 069 / 2562 1234
E-Mail: info@kennedy-89.com
Please note that your objection may also occur in other processes or may need to occur due to technical reasons. Further information can be found in the described services.
Right to object
Under the conditions of Article 21(1) GDPR, you may object to the processing of your personal data based on Article 6(1)(e) or (f) GDPR, for reasons arising from your particular situation. This also applies to profiling based on these provisions. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing is for the establishment, exercise, or defense of legal claims.
Please send your objection to:
SIC Hospitality GmbH
Kennedy 89 Hotel Frankfurt
Stresemannallee 28, 60596 Frankfurt am Main
Phone: 069 / 2562 1234
E-Mail: info@kennedy-89.com
Please note that your objection may also occur in other processes or may need to occur due to technical reasons. Further information can be found in the described services.
Right to lodge a complaint with a supervisory authority
Under Article 77 GDPR, you have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data is not lawful. The address of the supervisory authority responsible for our company is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Represented by Dr. Alexander Roßnagel
Gustav-Stresemann-Ring 1, 65189 Wiesbaden
Phone: +49 611 1408 0
E-Mail: poststelle@datenschutz.hessen.de
Automated individual decision-making, including profiling
You have the right not to be subject to a decision based solely on automated processing, including profiling, that has legal effects on you or similarly significantly affects you.
Use of Online Services
The following information explains when and in what context data is processed during the use of our online services.
Data processing on our website
If you use our website purely for informational purposes, i.e., without registering or otherwise transmitting information to us, we only collect the personal data that your browser transmits to our server. When you view our website, we collect the following data, which is technically necessary to display our website to you and to ensure stability and security. The legal basis for storing information in the form of cookies or server log files on your device or for accessing such information is § 25(2) no. 2 TDDDG. The corresponding data processing is based on Article 6(1)(f) GDPR:
· IP address
· Date and time of the request
· Time zone difference to Greenwich Mean Time (GMT)
· Content of the request (specific page)
· Access status / HTTP status code
· Amount of data transferred
· Website from which the request originated
· Browser
· Operating system and its interface
This data is temporarily stored in the log files of our system for a maximum of thirty days. A longer storage period is possible, but in this case, the IP addresses will be partially deleted or altered so that an association with the client making the request is no longer possible.
Use of Cookies
In addition to the aforementioned data, cookies are stored on your device (e.g., PC, laptop, smartphone) when you use our website. Cookies are small text files that are stored on your device and assigned to the browser you are using. They allow us to receive certain information. Cookies cannot run programs or transmit malware to your devices. They help to make our offer more user-friendly, more effective and safer.
This website uses the following types of cookies, the scope and functionality of which are explained below:
Transient Cookies
Transient cookies are automatically deleted when you close your browser. These include session cookies, which store a session ID that allows various requests from your browser to be assigned to the same session. This enables your computer to be recognized when you return to our website. The session cookies are deleted when you log out or close your browser.
Persistent Cookies
Persistent cookies are automatically deleted after a specified period, which may vary depending on the cookie. You can delete cookies at any time in your browser’s security settings.
We use cookies on our website that are generated by us as the website operator and that are necessary for the full functionality and display of our website. The legal basis for storing information in the form of cookies on your device or accessing this information is § 25(2) no. 2 TDDDG. We use these cookies based on our legitimate interest under Article 6(1)(f) GDPR to ensure our online services.
In addition to the cookies set by us as the controller, cookies from third parties are also used. We process these cookies based on your consent under Article 6(1)(a) GDPR and § 25(1) TDDDG (storage of cookies or access to information on a device, e.g., via device fingerprinting). Further information on the use of cookies and cooperation with external service providers can be found in the data protection information for the respective online services.
You can configure your browser settings according to your preferences, for example, to reject cookies from third-party providers or all cookies. However, please note that you may not be able to use all the functions of this website if you do so. If you have consented to the use of cookies and wish to withdraw your consent for the future, you can delete the stored cookies in your browser settings.
Cookie Settings in web browsers
Web browsers can be configured to notify you when cookies are set or to generally reject or disable cookies. By disabling and deleting all cookies, you can also revoke a previously given consent. If you disable or restrict cookies via your browser, some functions on our website may not be available to you. You can delete cookies stored by your web browser at any time, even automatically.
Here are links to information on how to manage cookies in the most commonly used browsers:
Mozilla Firefox: https://support.mozilla.org/en-US/kb/cookies-information-websites-store-on-your-computer
Google Chrome: https://support.google.com/chrome/answer/95647?hl=en
Apple Safari: https://support.apple.com/guide/safari/manage-cookies-sfri11471/mac
Microsoft Internet Explorer: https://support.microsoft.com/en-us/topic/delete-and-manage-cookies-168dab11-0753-043d-7c16-ede5947fc64d
Microsoft Edge: https://support.microsoft.com/en-us/microsoft-edge/delete-cookies-in-microsoft-edge-63947406-40ac-c3b8-57b9-2a946a29ae09
Opera: https://help.opera.com/en/latest/web-preferences/#cookies
If no restrictions on cookie settings have been made, cookies that are necessary to enable and ensure the required technical functions will remain on your device until you close the browser; other cookies may remain on your device for longer. The exact cookie durations are displayed to you in the consent banner for the respective services used.
SSL/TLS Encryption
Our website uses TLS encryption (formerly SSL) for security reasons and to protect the transmission of confidential content. Orders or contact inquiries that you send to us are transmitted via transport encryption. Depending on the browser type, you can recognize this either by the lock symbol and/or the https protocol in the address bar.
External Hosting
This website is hosted by an external service provider (host). The personal data collected on this website is stored on the servers of the hosting provider(s). This may include all information relating to users of our online services that is generated during usage and communication, such as content data (e.g., entries in online forms); usage data (e.g., visited websites, access times); meta/communication data (e.g., device information, IP addresses).
We collect this data to ensure the secure, fast, and efficient provision of our online offerings. The legal basis for storing information in the form of cookies on your end device or accessing such information § 25 (2) no. 2 TDDDG. The associated processing of your data is carried out based on our legitimate interest in ensuring the proper display and functionality of our website according to Art. 6 (1) (f) GDPR.
We use the following hosting provider:
Netgenerator GmbH, Kurpromenade 51E, 14089 Berlin.
For more information on data protection, please visit: https://www.netgenerator.de/kontakt/cookies-und-datenschutz/ .
Furthermore, we have entered into a data processing agreement (DPA) with the above-mentioned provider(s). This agreement regulates the scope, nature, and purpose of the provider’s access to the data. The provider’s access is limited to what is necessary to fulfill the hosting services and is carried out in compliance with the GDPR.
Consent Management Platforms (CMP)
Information on Consent Management Platforms
To ensure the lawful collection and management of user consent for the storage of information on end users’ devices or access to such information (e.g. cookies), we use a so-called Consent Management Platform (CMP).
This tool helps us comply with applicable legal requirements (in particular under the GDPR and the German Telecommunications and Digital Services Data Protection Act – TDDDG) by informing you about the technologies used on our website upon your first visit, offering you choice options, and documenting your consent preferences.
Data Processing by Consent Management Platforms
When using a CMP, the following categories of personal data are processed:
· Your selection (consents granted and withdrawn)
· Date and time of consent
· Technical information (e.g. IP address in truncated/anonymised form, browser type, operating system)
· Where applicable, unique cookie identifiers to recognise your preferences on subsequent visits
Consent data is generally stored locally in your browser (via cookies or local storage) and logged on the servers of the CMP provider in order to fulfil the accountability requirements under Article 7(1) GDPR.
Recipients / Disclosure of Data
The CMP provider necessarily obtains knowledge of the above-mentioned data to the extent required for providing consent management services. When selecting a provider, we ensure an adequate level of data protection and, where required, have concluded a data processing agreement pursuant to Article 28 GDPR.
Data is not disclosed to any further third parties. If data processing takes place in third countries in individual cases, an adequate level of data protection is ensured through appropriate safeguards such as EU Standard Contractual Clauses (SCCs).
Legal Basis
The legal basis for the processing is the fulfilment of legal obligations pursuant to Article 6(1)(c) GDPR in conjunction with Article 7 GDPR and Section 25 TDDDG.
In addition, we have a legitimate interest in the legally compliant administration and documentation of user consents pursuant to Article 6(1)(f) GDPR.
Storage Period
Your consent decision is stored for as long as necessary to comply with statutory documentation obligations or until you delete the stored data in your browser.
Exercise of Data Subject Rights
You may exercise your data subject rights (right of access, rectification, erasure, etc.) both vis-à-vis us and the CMP provider. Please note that we do not have full access to the data stored by the CMP provider.
Our Consent Management Platform
Borlabs Cookie
Anbieter: Borlabs GmbH, Hamburger Str. 11, 22083 Hamburg, Deutschland
Privacy Policy: https://de.borlabs.io/datenschutz/
Contact
Contact Form
When you contact us via a contact form, the data you provide (your email address, your name, phone number, and the content of your message) will be stored by us to respond to your inquiry. The processing of data entered into the contact form is based on your consent in accordance with Art. 6(1)(a) GDPR. If your inquiry is related to the fulfillment of a contract or the implementation of pre-contractual measures, we process your data based on Art. 6(1)(b) GDPR. The data collected in this context will be deleted once the storage is no longer necessary or we will restrict the processing if legal retention obligations exist. You can revoke your consent at any time. The lawfulness of the data processing carried out before the revocation remains unaffected by the revocation.
Inquiries via Email, Telephone, or Fax
When you contact us by email, phone, or fax, the personal data you provide your email address, your name, phone number, and the content of your message will be stored by us in order to handle your inquiry. We do not share this data without your consent.
The data processing is based on Art. 6(1)(b) GDPR if your inquiry is related to the fulfillment of a contract or is required to take steps prior to entering into a contract. In all other cases, we process your data based on your consent pursuant to Art. 6(1)(a) GDPR and/or our legitimate interests in accordance with Art. 6(1)(f) GDPR. Our legitimate interest lies in the effective handling of your request.
The data you send to us via contact requests will remain with us until you request its deletion, revoke your consent to store it, or the purpose for storing the data no longer applies (e.g., after we have completed processing your request). Mandatory legal provisions – especially legal retention periods – remain unaffected.
Analysis Tools
Google Analytics 4
This website uses Google Analytics 4, a web analysis service of Google LLC. The responsible entity for users in the EU, EEA, and Switzerland is Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”).
Google Analytics uses cookies that allow the analysis of your use of our websites. The information collected by the cookies about your use of this website is usually transmitted to and stored on a Google server in the USA.
In Google Analytics 4, IP address anonymization is enabled by default. Because of IP anonymization, your IP address is truncated by Google within EU member states or other contracting states of the European Economic Area Agreement. Only in exceptional cases will the full IP address be sent to a Google server in the USA and truncated there.
During your website visit, your user behavior is recorded in the form of “events”. Events can include:
· Page views, first visit to the website, start of the session
· Visited pages, your “click path”, interaction with the website
· Scrolls (when a user scrolls down to 90% of the page)
· Clicks on external links, internal search queries, interaction with videos
· File downloads, seen/clicked ads, language settings
In addition, the following data is collected:
· Your approximate location (region), date, and time of the visit
· Your IP address (in truncated form), your Internet provider
· Technical information about your browser and the devices you use (e.g., language settings, screen resolution)
· The referrer URL (the website or advertisement that brought you to this site)
We use the User-ID function. Using the User-ID, we can assign one or more sessions (and the activities within those sessions) to a unique, permanent ID and analyze user behavior across devices.
Google uses this information to evaluate your use of the website and to compile reports on website activity. The reports provided by Google Analytics are used to analyze the performance of our website and the success of our marketing campaigns.
We use the Google Signals service as part of Google Analytics. Google Signals is a cross-device tracking service provided by Google Inc. (“Google”). Google Signals collects and processes additional information about affected individuals (website visitors, app users, etc.) who have activated the “Personalized Ads” feature in Google. Users’ interests and demographic data are analyzed by Google and provided to website and app operators in anonymized and aggregated form. The gathered statistics enable ads to be displayed to these users in cross-device remarketing campaigns.
Storage Duration
The data we send and link with cookies will be automatically deleted after a maximum of 2 years. The deletion of data whose retention period has expired occurs automatically once a month.
Legal Basis
The legal basis for this data processing is your consent in accordance with Art. 6 (1) lit. a GDPR and § 25 (1) TDDDG. You can revoke your consent at any time with future effect.
Transfer to Third Countries
The company is certified under the “EU-US Data Privacy Framework” (DPF). More information on this can be found at https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt000000001L5AAI&status=Active.
Information on the EU Standard Contractual Clauses can be found at https://privacy.google.com/businesses/controllerterms/mccs/
You can prevent the storage of cookies from the outset by adjusting your browser settings accordingly. If you configure your browser to reject all cookies, it may limit the functionality of this and other websites. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) by Google and the processing of this data by Google by:
a) Not giving consent for the setting of cookies, or
b) Downloading and installing the browser add-on to disable Google Analytics HERE
Further information on Google Analytics’ terms of use and data privacy can be found at
https://marketingplatform.google.com/about/analytics/terms/en/
and at https://policies.google.com/?hl=en.
Marketing-Tools
Google Tag Manager
This website uses “Google Tag Manager,” a service provided by Google Ireland Limited. Google Tag Manager allows website tags to be managed via an interface. The Google Tag Manager tool, which implements the tags, is a cookie-less domain. However, Google Tag Manager captures your IP address, which may also be transmitted to Google’s parent company in the USA.
Google Tag Manager triggers other tags that may, in turn, collect data. Google Tag Manager does not access this data. If a deactivation has been carried out at the domain or cookie level, it remains in place for all tracking tags implemented with Google Tag Manager.
The legal basis for the processing of your data is Article 6(1)(a) of the GDPR (consent) and § 25(1) of the TDDDG.
The company is certified under the “EU-US Data Privacy Framework” (DPF). For more information, please visit https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt000000001L5AAI&status=Active.
Information on the conclusion of EU Standard Contractual Clauses can be found at https://privacy.google.com/businesses/controllerterms/mccs/.
Google Tag Manager FAQ: https://www.google.com/intl/de/tagmanager/faq.html
Google Tag Manager Terms of Service: https://www.google.com/intl/de/tagmanager/use-policy.html
Facebook Custom Audiences
This website uses “Facebook Custom Audiences,” a remarketing tool provided by Meta Platforms, Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (hereinafter referred to as “Facebook”). Facebook Custom Audiences enables the display of interest-based ads, known as “Facebook Ads,” when visiting this website, the social network Facebook, or other websites that also use Facebook Custom Audiences. By using Facebook Custom Audiences, your web browser automatically establishes a direct connection to the Facebook server. If you have a Facebook account and are registered, Facebook may associate your visit with your user account. Even if you are not registered or logged into Facebook, Facebook may still collect your IP address and possibly other identifiers. We have no control over the extent and further use of data collected by Facebook using Facebook Custom Audiences.
We use Facebook Custom Audiences for marketing and optimization purposes, especially to display relevant and customized content to visitors and to improve and make our offerings more interesting for users. The legal basis is Article 6(1)(a) of the GDPR (consent) and § 25(1) of the TDDDG.
Logged-in users can deactivate Facebook Custom Audiences at https://www.facebook.com/settings/?tab=ads#_.You can also adjust cookie settings in your browser.
You can opt out of tracking by disabling interest-based ads via the following links. An opt-out cookie will be set through the self-regulation campaigns. However, this setting will be deleted if you clear your cookies.
http://optout.networkadvertising.org/
http://optout.aboutads.info
You are currently viewing a placeholder content from Default. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
The company is certified under the “EU-US Data Privacy Framework” (DPF). For more information, please visit https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt0000000GnywAAC&status=Active.
Information on data processing based on Standard Contractual Clauses can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum.
Service provider information: Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. More information from the third-party provider about data protection can be found on Facebook’s website: https://www.facebook.com/about/privacy.
Meta-Pixel
This website uses “Meta-Pixel” (formerly “Facebook Pixel”), a service provided by Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (hereinafter referred to as “Facebook”). Meta-Pixel allows Facebook to show our ads on Facebook (“Facebook Ads”) only to those Facebook users who have visited our website, especially those who have shown interest in our offerings or specific topics or products. Meta-Pixel also helps to track whether a user was redirected to our website after clicking on one of our Facebook Ads. Additionally, Meta-Pixel tracks “events,” such as adding an item to a shopping cart or completing a purchase, providing insight into how to improve Facebook ad performance and measurement.
Meta-Pixel uses cookies, which are stored locally in the cache of your web browser on your device. If you are logged into Facebook with your user account, your visit to our online offering will be noted in your account. The data collected about you is anonymous for us and does not allow us to identify you. However, this data may be associated with your Facebook account. We have no control over the extent and further use of data collected by Facebook using Meta-
Pixel. Even if you are not registered or logged into Facebook, Facebook may still collect your IP address and other identifiers.
We use Meta-Pixel for marketing and optimization purposes, particularly to display relevant and interesting ads on Facebook and to improve our offerings, make them more interesting to users, and avoid annoying ads. The legal basis is Article 6(1)(a) of the GDPR (consent) and § 25(1) of the TDDDG.
You can revoke your consent to the processing of personal data by Meta-Pixel and the use of your data for displaying Facebook Ads at any time with effect for the future. You can adjust the settings regarding what types of ads are shown to you on Facebook directly on the Facebook website: https://www.facebook.com/settings?tab=ads. Please note that this setting will be deleted if you clear your cookies in the browser.
You can also opt out of tracking by disabling interest-based ads via the following links. An opt-out cookie will be set through the self-regulation campaigns. However, this setting will be deleted if you clear your cookies.
http://optout.networkadvertising.org/
http://www.aboutads.info/choices
You are currently viewing a placeholder content from Default. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
The company is certified under the “EU-US Data Privacy Framework” (DPF). For more information, please visit https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt0000000GnywAAC&status=Active.
Information on data processing based on Standard Contractual Clauses can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum.
Third-party provider information: Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
More information from the third-party provider about data protection can be found on Facebook’s website: https://www.facebook.com/about/privacy
Information on Meta-Pixel can be found here https://www.facebook.com/business/help/651294705016616
Google Ads
This website uses Google Ads (formerly Google AdWords), a service provided by Google Ireland Limited, Google Building Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter “Google”).
Google Ads enables us to draw attention to our offers on external websites by means of advertising materials. This allows us to determine the effectiveness of individual advertising measures. The ads are delivered by Google via so-called ad servers. For this purpose, ad server cookies are used, which allow certain performance parameters to be measured, such as the display of ads or user clicks.
If you access our website via a Google advertisement, Google Ads stores a cookie on your device. These cookies generally expire after 30 days and are not intended to personally identify you. As a rule, the following information is stored as analysis values within these cookies: a unique cookie ID, the number of ad impressions per placement (frequency), the last impression (relevant for post-view conversions), and opt-out information (indicating that the user no longer wishes to be targeted).
These cookies enable Google to recognise your web browser. If a user visits certain pages of a Google Ads customer’s website and the cookie stored on their device has not yet expired, Google and the respective customer can recognise that the user clicked on the ad and was redirected to that page. Each Google Ads customer receives a different cookie, meaning that cookies cannot be tracked across the websites of different Google Ads customers.
We ourselves do not collect or process any personal data within the scope of these advertising measures. We only receive anonymised, aggregated statistical reports from Google, which allow us to assess the effectiveness of our advertising campaigns. We do not receive any further data and are not able to identify users on the basis of this information.
Due to the use of Google Ads, your browser automatically establishes a direct connection to Google servers. We have no influence on the scope or further use of the data collected by Google through the use of Google Ads. To the best of our knowledge, Google receives information that you have accessed the relevant part of our website or clicked on one of our ads. If you are logged into a Google account, Google may associate your visit with your user account. Even if you are not registered with Google or not logged in, it is possible that Google may obtain, store and further process your IP address.
We use Google Ads for marketing and optimisation purposes, in particular to display relevant and interesting advertisements, to improve campaign performance analyses, and to ensure fair calculation of advertising costs.
The legal basis for the processing is your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TDDDG.
You can prevent the storage of cookies by deleting existing cookies and disabling the storage of new cookies in your browser settings. Please note that this may limit the functionality of our website. You may also configure your browser to block cookies from the domain www.googleadservices.com via https://www.google.de/settings/ads. Please note that these settings will be deleted if you delete your cookies. In addition, you can opt out of interest-based advertising via https://optout.aboutads.info.This opt-out will also be deleted if you delete your browser cookies.
Third-party provider:
Google Ireland Limited, Google Building Gordon House, Barrow Street, Dublin 4, Ireland
Google is certified under the EU–US Data Privacy Framework (DPF). Further information is available at:
https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt000000001L5AAI&status=Active
Information on the use of EU Standard Contractual Clauses can be found at:
https://privacy.google.com/businesses/controllerterms/mccs/
Further information on data use by Google, settings options and data protection can be found at:
https://policies.google.com/privacy
https://services.google.com/sitestats/
Pinterest Retargeting
This website uses a tracking pixel, the so-called Pinterest Tag, provided by Pinterest Europe Limited, Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland (hereinafter “Pinterest”). For users outside Europe, the service is operated by Pinterest, Inc., 808 Brannan Street, San Francisco, CA 94103, USA.
By means of this pixel, Pinterest collects information about the use of this website (e.g. viewed content). These data may be associated with your person using additional information that Pinterest may have stored about you, for example through your Pinterest account. Based on the information collected via the pixel, interest-based advertisements relating to our offers may be displayed to you within your Pinterest account (retargeting).
The information collected via the Pinterest Tag may also be aggregated by Pinterest and used for Pinterest’s own advertising purposes as well as for advertising purposes of third parties. Pinterest may, for example, infer certain interests from your browsing behaviour on this website and use this information to display tailored third-party offers. In addition, Pinterest may combine the information collected via the pixel with other data that Pinterest has collected about you on other websites and/or in connection with the use of the Pinterest social network, thereby creating a user profile that may be used for advertising purposes.
The legal basis for this processing is your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TDDDG.
Further information on data protection at Pinterest can be found at:
https://policy.pinterest.com/privacy-policy
Your data may also be processed by Pinterest in the United States. Pinterest relies on EU Standard Contractual Clauses pursuant to Article 46(2) GDPR as the legal basis for such data transfers. Further information is available at:
https://policy.pinterest.com/privacy-policy#section-residents-of-the-eea
Third-Party Content
Google Maps
On this website, we use the Google Maps service. This allows us to display interactive maps directly on the website and provides you with the convenient use of the map function.
When you visit the website, Google receives information that you have accessed the corresponding subpage of our website. Metadata, which may include personal data, is transmitted to the service provider. Additionally, Google obtains your IP address. This occurs regardless of whether Google provides a user account that you are logged into or if no user account exists. If you are logged into Google, your data will be directly associated with your account. If you do not wish for the data to be associated with your Google profile, please log out before activating the function. The information collected by Google is also transmitted to servers of Google Inc. in the USA. Google stores your data as usage profiles and uses it for purposes such as advertising, market research, and/or the needs-based design of its website. This evaluation is particularly conducted (even for users who are not logged in) to provide targeted advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles, and you should preferably contact Google to exercise this right.
The function is activated only when the service is activated, and data is transmitted to the service provider. The legal basis for processing your data is Art. 6(1)(a) GDPR (consent) and § 25(1) TDDDG.
Information about the third party: Google Dublin, Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, Fax: +353 (1) 436 1001.
The company is certified under the “EU-US Data Privacy Framework” (DPF). Further information can be found at https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt000000001L5AAI&status=Active.
Information about the conclusion of EU Standard Contractual Clauses can be found at https://privacy.google.com/businesses/controllerterms/mccs/.
For further information on the purpose and scope of data collection and processing by the plug-in provider, please refer to the provider’s privacy policy. There you will also find additional information on your rights and privacy protection options: https://policies.google.com/privacy?hl=en.
YouTube
We have integrated YouTube videos into our online offering, which are stored on https://www.youtube.com/ and can be played directly from our website. These videos are all embedded in “enhanced privacy mode,” meaning that no data about you as a user is transmitted to YouTube unless you play the videos. According to YouTube, data is only transmitted once you start playing the videos. We have no control over this data transmission.
By visiting the website, YouTube receives the information that you have accessed the corresponding subpage of our website. Additionally, metadata, which may potentially be personal data, is transmitted to the service provider. This occurs regardless of whether YouTube provides a user account through which you are logged in or whether no user account exists. If you are logged into Google, your data will be directly associated with your account. If you do not wish for this association with your YouTube profile, log out before activating the feature. YouTube stores your data as usage profiles and uses it for advertising, market research, and/or the customized design of its website. Such an analysis is carried out, in particular, to deliver targeted advertising and to inform other users of the social network about your activities on our website, even for users who are not logged in. You have the right to object to the creation of these usage profiles, and to exercise this right, you should preferably contact YouTube directly.
The function and the data transmission to the service provider will only be activated once you consent. The legal basis for processing your data is Art. 6(1)(a) GDPR (consent) and § 25(1) TDDDG. You can revoke your consent at any time in the future.
The company is certified under the “EU-US Data Privacy Framework” (DPF). For more information, please visit: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt000000001L5AAI&status=Active.
For information regarding the conclusion of EU Standard Contractual Clauses, visit: https://privacy.google.com/businesses/controllerterms/mccs/.
Third-party information: Google Ireland Limited, Google Building Gordon House, Barrow St, Dublin 4, Ireland.
Further information on data protection can be found on Google’s privacy page: https://policies.google.com/privacy?hl=en.
Bing Maps
This website uses Bing Maps, a mapping service provided by Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA.
Bing Maps allows us to display interactive maps directly on our website and enables convenient use of map and navigation functions to help you locate our business locations.
The use of Bing Maps serves our interest in a functional presentation of our online services and in making our locations easy to find. The service is used only with your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TDDDG.
When using Bing Maps, Microsoft receives information that the relevant subpage of our website has been accessed. In order to provide the map and navigation features, it is technically necessary to process your IP address and, where applicable, location data. These data may also be processed on Microsoft servers in the United States.
Microsoft is certified under the EU–US Data Privacy Framework (DPF). Further information is available at:
https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt0000000KzNaAAK&status=Active
We have no influence over the scope or further use of data processed by Bing Maps. Further information on the purpose and scope of data processing by Microsoft can be found in Microsoft’s privacy policy at:
https://privacy.microsoft.com/privacystatement
Google Fonts
We use “Google Fonts” on our website, a service provided by Google Ireland Limited (hereinafter referred to as “Google”). This service allows us to use external fonts, known as Google Fonts. When you visit our website, the required Google Font is loaded into your browser’s cache. This is necessary to ensure an improved visual presentation of our text content. If your browser does not support this function, a default font from your computer will be used for display.
The integration of these web fonts involves a server request, usually to a Google server in the USA. This means that the server receives information about which of our web pages you have visited. Additionally, the IP address of the browser on your device is stored by Google. We have no control over the extent and further use of the data collected and processed by Google using Google Web Fonts.
We use Google Web Fonts for optimization purposes, particularly to enhance your experience of our website and improve its user-friendly design. The legal basis for this is your consent in accordance with Article 6(1)(a) GDPR and § 25(1) TDDDG.
The company is certified under the “EU-US Data Privacy Framework” (DPF). For more information, visit https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt000000001L5AAI&status=Active
Information on the conclusion of EU Standard Contractual Clauses can be found at https://privacy.google.com/businesses/controllerterms/mccs/
For more information on data protection, please refer to Google’s privacy policy: https://policies.google.com/privacy?hl=en
Further details about Google Web Fonts can be found at
https://fonts.google.com/,
https://developers.google.com/fonts/faq?hl=en,
and https://www.google.com/fonts#AboutPlace
Social media presences
Information on social media
We operate publicly accessible profiles on social networks to draw attention to our services and products. There we would like to get in touch with you as a visitor and user of these pages as well as our website.
User data may be processed outside the European Union. This may result in risks for you as a user, and it may make it more difficult to enforce your rights. When selecting the social media platforms we use, we make sure that the operators commit to complying with EU data protection standards.
If you visit one of our social media sites, we are jointly responsible with the operator of the respective social media platform within the meaning of the GDPR and other data protection regulations.
Data processing on social media platforms
We have no influence on the processing of personal data by the respective platform operator. For example, social networks such as Facebook use your data for market research and advertising purposes. Among other things, user behavior can be analyzed, and a user profile can be created from the resulting interests of the user. Social media operators use cookies to store and further process this information. These are text files that are stored on the user’s various terminals. If you have a profile on the respective social media platform and are logged in to it, the storage and analysis is even carried out across devices. In this way, interest-based advertising can be displayed to you inside and outside the respective social media presence. People who are not registered as users with the respective social media platform may also be affected by the data processing.
Statistical data of different categories can be accessed by us via social media platforms. These statistics are generated and provided by the social media operator. As the operator of the fan page, we have no influence on the generation and presentation. We use this data available in aggregated form (total number of page views, “likes”, page activities, post interactions, reach, video views, post reach, comments, shared content, answers, proportion of men and women, origin in terms of country and city, language, views and clicks in the shop, clicks on route planners, clicks on telephone numbers) to make our posts and activities on our fan page more attractive to users. Due to the constant development of social media platforms, the availability and processing of data is changing, so we refer to the privacy policies of the platforms for further details.
Legal basis
The operation of these fan pages, including the processing of users’ personal data, is based on our legitimate interests in a contemporary and supportive information and interaction option for and with our users and visitors in accordance with Article 6(1)(f) GDPR. Under certain circumstances, you may also have given a platform operator your consent to data processing, in which case Article 6(1)(a) GDPR is the legal basis.
For a comprehensive description of the respective data processing and the possibilities of objection (opt-out), we refer to the data protection declarations and information of the corresponding platform operator.
Storage period
The data collected directly by us via social media presences will be deleted from our systems as soon as the purpose for which it was stored no longer applies, you request us to delete it or revoke your consent to its storage. Stored cookies remain on your device until they are deleted by you. Mandatory legal provisions – esp. Retention periods – remain unaffected.
We have no influence on the storage period of your data, which is stored by social network providers for their own purposes. You can find more information on this directly from the operator of the social network (e.g. in their privacy policy, see below).
Assertion of rights
In principle, you can assert your rights (information, correction, deletion, restriction of processing, data portability and complaint) both against us and against the operator of the respective portal (e.g. Facebook).
Despite joint responsibility, we would like to point out that we do not have complete access to your personal data. For this reason, you should contact the providers of the social media platforms directly for requests for information and the assertion of data subject rights. This is
because only the providers have access to user data and can take direct action and provide information. If you need help with this, please contact us (see contact details above).
Our social networks
Facebook:
Provider: Meta Platforms, Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland
Agreement on Joint Processing of Personal Data on Facebook Pages: https://www.facebook.com/legal/terms/page_controller_addendum
Certification under the “EU-US Data Privacy Framework” (DPF): https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt0000000GnywAAC&status=Active
Privacy Policy: https://www.facebook.com/about/privacy
Opt-Out Option: https://www.facebook.com/settings?tab=ads
Instagram:
Provider: Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland
Privacy Policy: http://instagram.com/about/legal/privacy
Opt-Out Option: http://instagram.com/about/legal/privacy
Certification under the “EU-US Data Privacy Framework” (DPF): https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt0000000GnywAAC&status=Active
LinkedIn:
Provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland
Privacy Policy: https://www.linkedin.com/legal/privacy-policy
Opt-Out Option: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out
Pinterest:
Provider: Pinterest Europe Ltd, WeWork, 2 Dublin Landings, N Wall Quay, Dublin 1, D01 V4A3, Ireland
Privacy Policy: https://policy.pinterest.com/en/privacy-policy
Opt-Out Option: https://help.pinterest.com/en/article/personalization-and-data
YouTube:
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Privacy Policy: https://policies.google.com/privacy
Opt-Out Option: https://adssettings.google.com/authenticated
Certification under the “EU-US Data Privacy Framework” (DPF): https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt000000001L5AAI&status=Active
Hotel premise
Video surveillance
In our stores, video surveillance is used for the purposes of crime detection, property protection, and vandalism prevention. No audio recording is performed. The legal basis for this processing is Article 6(1)(f) of the GDPR, reflecting our legitimate interest in ensuring security. The use of video surveillance is indicated by a clearly visible pictogram in the branches. As a matter of principle, we delete the resulting footage from the security cameras 72 hours after recording. In the event of a criminal offence, we reserve the right to store the image material until the purpose for which it was collected no longer applies. The images will not be transmitted to third parties, except for investigating authorities that request the images in the event of a criminal offence. For installation and maintenance, maintenance companies commissioned by us may have access to stored data.
Processing of Cashless Payments
When you make a payment using your debit card (EC card), credit card, or a contactless payment method (NFC), we process personal data via our payment terminal. The data collected in this process is subsequently transmitted to the network operator. The network operator and the respective payment service providers responsible for accepting and settling payment transactions (so-called acquirers) further process the data, in particular for payment processing, the prevention of card misuse, the limitation of payment default risks, and for legally required purposes such as anti-money laundering and criminal prosecution. For these
purposes, your data may also be transmitted to other controllers, such as your card-issuing bank.
Controllers
We and the network operator and/or acquirer each act as independent controllers within the meaning of the GDPR.
As the payment recipient, we are responsible for operating the payment terminal at the point of sale and, where applicable, for our internal network up to the secure transmission of data via internet or telephone line to the network operator. The network operator and the acquirer are responsible for the further processing of the data, in particular for the execution and settlement of payment transactions.
When electronic payment methods are used, data is transmitted to Planet Payment Group Holding Limited acting as the network operator.
Information on data processing by Planet Payment Group Holding Limited can be found in its privacy policy at:
https://www.weareplanet.com/legal/privacy-policy
For credit card payments (e.g. VISA, MasterCard), Planet Payment Group Holding Limited is also involved as the acquirer. In this context, both parties act as independent controllers within the meaning of the GDPR.
Further information on data processing by Planet Payment Group Holding Limited can be found at: https://www.weareplanet.com/legal/privacy-policy
Scope and Categories of Data Processed
We process your card data (IBAN or account number and BIC, card expiry date, and card sequence number) as well as additional payment-related data (amount, date, time, terminal ID, location, company and branch where the payment is made, and your signature).
If a direct debit transaction is not honoured (e.g. due to revocation), we process data relating to the chargeback as well as data associated with the outstanding claim (first and last name, address, purchase receipt, incurred bank fees, reminder fees, and the reason for the chargeback).
A large portion of the above-mentioned data is stored on your card and is read when the card is used at the payment terminal. Your PIN or signature is provided directly by you. In the event of a chargeback, we may receive additional data from your bank or financial institution.
Purpose and Legal Basis
We process your data in particular for the performance of the purchase contract (Article 6(1)(b) GDPR), for compliance with legal obligations (Article 6(1)(c) GDPR), and for the investigation of fraud and other criminal offences (Article 6(1)(f) GDPR), based on our legitimate interest in protecting our assets and preventing payment defaults.
The network operator processes the data in particular for payment processing (Article 6(1)(b) GDPR), for the prevention of card misuse and limitation of payment default risks (Article 6(1)(f) GDPR, legitimate interest in asset protection), and for legally required purposes such as anti-money laundering and criminal prosecution (Article 6(1)(c) GDPR). Further information can be obtained from your payment service provider or bank.
Disclosure to Third Parties
For the purpose of payment processing, we transmit the above-mentioned data to our network operator, who in turn forwards the data to your participating bank or the relevant credit card company. Where necessary for payment processing, your data may also be transmitted to other service providers involved in the payment transaction.
Transfer to Third Countries
We do not transfer your payment data to third countries or to organisations outside the European Union. Such a transfer may only occur if you pay by credit card and the credit card company is located outside the EU.
Provision of Data
The provision of your data is voluntary. You are neither legally nor contractually obliged to provide us with your data. However, payment by card is not possible without the provision of the required data.
Use of Wi-Fi
We provide you with access to the Internet in the form of free Wi-Fi access (“guest Wi-Fi”) in our business premises. In the following, we inform you about the personal data collected in this context.
Processing purposes and legal basis
When using our guest Wi-Fi, only such personal or device-related data are processed as are strictly necessary for the technical provision, authentication, and security of the internet access. This includes in particular:
- the MAC address of your device (usually randomised by the operating system),
- the IP address assigned to your device,
- the authentication method used (e.g. captive portal, PMS validation, or Passpoint profile),
- log data relating to successful and failed authentication attempts,
- session data such as the start and end of the connection, assignment to the access point, session duration, transmitted data volumes (bytes in/out), and protocol types used.
If you access the internet via Passpoint, the following technically required identifiers are additionally processed:
- the current (usually randomised) MAC address,
- a pseudonymous identifier (CUI – Chargeable User Identity) derived as a hash value from the Passpoint profile,
- a network or location identifier (NAS identifier) identifying the respective network access point (e.g. hotel location).
No evaluation of browser histories, visited websites, communication content, or deep packet inspection is carried out. No personal data are collected beyond the information you expressly provide as part of the authentication process (e.g. room number during PMS login or a loyalty identifier when using Passpoint).
The data are provided directly by our guests during the registration for and use of the guest Wi-Fi or are generated automatically for technical reasons.
Recipients
We do not share your personal data with third parties. Your data will only be passed on or transmitted if it is necessary for the execution of the contract, if it is based on a legal basis, if there is a legitimate interest or based on your prior consent.
If external service providers support us in the processing of your data (e.g. IT service providers), this is done within the framework of order processing in accordance with Art. 28 GDPR. In doing so, we only conclude appropriate contracts with service providers that offer sufficient guarantees that appropriate technical and organizational measures ensure the protection of your data.
Data transfer to a third country
A transfer of data to third countries does not take place and is not intended.
Duration of storage
The duration of storage is determined by the purpose of the respective data processing activity and by statutory requirements:
Operational and error logs are generally stored for 24 to 72 hours and are then automatically deleted, unless there is a statutory obligation to retain them for a longer period.
Access and authentication logs (in particular MAC address, IP address, and the start and end of the session) are regularly stored for a period of up to 30 days and are subsequently deleted automatically.
Passpoint session data are stored for the duration of the respective session and for up to 24 hours after the end of the session in order to ensure proper provision of the service and to enable error analysis.
Passpoint profile data, insofar as such data are processed (e.g., name and email address of guests without a World of Hyatt membership), are deleted once the profile is removed from the end device or, at the latest, after 12 months of inactivity.
Authentication logs (e.g., RADIUS logs) are stored for a period of up to 3 months, unless different statutory retention obligations apply.
Data will only be stored for a longer period where this is required by law or is necessary for the establishment, exercise, or defense of legal claims.
Provision of data
The provision of personal data about the data subject is technically necessary for the use of the Wi-Fi. Without this data, you will not be able to use our t Wi-Fi.
Business relationships
The following information shows you how we handle your data when you contact us, when contract negotiations take place with us and/or when contractual agreements exist with us.
Processing purposes and legal basis
The data processing is carried out for the purpose of contract processing. The processing of your data is required in accordance with Article 6(1)(b) GDPR for the initiation and fulfillment of contracts.
Furthermore, the processing of your personal data may be carried out on the basis of Art. 6 para. 1 lit. f GDPR may be necessary to protect our legitimate interests. Our legitimate interests consist in the avoidance of economic disadvantages through credit checks, invitations to events, assertion of legal claims and avoidance of legal disadvantages (e.g. in the event of insolvencies), defence against dangers and liability claims and avoidance of legal risks, e-mails, prevention of criminal offences.
Data category and data origin
We process the following categories of data:
Master and contact data: title, name (first and last name), department and function in the company, address, e-mail, telephone, fax, date of birth, purchase history, contract data, billing data.
The data were transmitted directly to us by our customers and interested parties.
Recipients
We do not pass on your personal data to third parties. Excluded from this are our service partners if this is necessary for the fulfillment of the contract, such as parcel and letter deliverers, banks for the collection of direct debits, tax authorities, if necessary further enumerations such as credit agencies, etc.
Duration of storage
The data stored about you will be deleted after fulfillment of the contract, provided that there are no further legal obligations to retain it. These include, for example, commercial and financial law data. These will be deleted after ten years in accordance with the legal regulations, unless longer retention periods are prescribed or necessary for legitimate reasons. If you revoke your consent to the use of your data, it will be deleted immediately, unless the above reasons speak against it.
Right to object
You have the right to object to the processing. You can object to the use of your data at any time in the future.
Provision of data
The provision of personal data is contractually required or necessary for the conclusion of a contract. If the required personal data is not provided, we will not be able to enter into a business relationship with you.
Status: 01/2026
Data protection Information – German