Privacy Policy
Last updated: October 2026
Summary
The controller responsible for processing your data is studiomuc Apartment Rental Service GmbH, Regensburg, Germany. We process your data mainly to answer enquiries, handle bookings and make your stay possible, and to meet legal obligations such as the registration form for foreign guests and tax record-keeping. We currently do not use analytics or advertising services on our website; Google Maps only loads once you allow it. You can change or withdraw your consent at any time via the “Cookie settings” link at the bottom of every page. Some providers transfer data to countries outside the EU, mainly the USA; we state the legal basis for each service. You have the right to access, rectification and erasure, and you can object to advertising at any time without giving reasons (section 3). Some calls are answered by an AI phone assistant (section 5.1). We do not make automated decisions that have legal effects on you.
1. Scope
This privacy policy applies to the website revo-club.com.
It also applies to bookings and stays at our property at Carl-Wery-Straße 35, 81739 Munich, Germany.
In accordance with Articles 13 and 14 of the General Data Protection Regulation (GDPR), it explains which personal data we process, for what purposes, on what legal basis and for how long, and what rights you have. Websites of other providers that we link to are governed by their own privacy policies. This also applies to booking platforms and social networks.
The names and lifetimes of the individual cookies are listed in our cookie policy: https://p-badxlh.project.space/en/cookie-policy-eu/
2. Controller and data protection officer
2.1 Controller
studiomuc Apartment Rental Service GmbH
Dr.-Gessler-Straße 37
93051 Regensburg
Germany
Managing directors: Dipl.-Kfm. Univ. Stephan Schimpel, Sabina Schimpel
Commercial register: Amtsgericht Regensburg, HRB 7874
Email for data protection enquiries: communication@revo-club.com
2.2 Data protection officer
You can reach our external data protection officer at:
LiiDU GmbH
Neupfarrplatz 10
93047 Regensburg
Germany
Email: info@liidu.de
3. Your right to object under Art. 21 GDPR
Objection to advertising
You can object at any time, without giving reasons, to the processing of your data for direct marketing. This also applies to promotional emails to guests and to requests for reviews (section 8). Once you object, we will no longer use your data for advertising.
Objection on grounds relating to your particular situation
Where we process data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you can object at any time on grounds relating to your particular situation. This concerns, for example, server log files, the handling of general enquiries, our social media profiles, recognition by our phone assistant, guest profiles and video surveillance. We will then stop processing the data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
How to object
An informal message is sufficient, by email or post to the contact details in section 2.1. For promotional emails you can also use the unsubscribe link in every email. You can also withdraw any consent you have given at any time (section 16.7).
4. Visiting our website
4.1 Hosting and server log files
Our website is hosted by Mittwald CM Service GmbH & Co. KG, Königsberger Straße 4-6, 32339 Espelkamp, Germany, in Mittwald’s own data centre in Espelkamp. Mittwald and the agency that provides technical support for the website act as our processors (Art. 28 GDPR).
With every request, the server logs: IP address, time of access, page requested and host name, status code, amount of data transferred, the previously visited page (referrer), and browser and operating system. This serves to deliver the website, for security and for troubleshooting. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is secure and stable operation.
In the access logs, the IP address is stored in shortened form. These logs are deleted after 60 days. Error logs, which may contain the full IP address, are deleted after seven days.
4.2 Encryption
Our website uses TLS encryption, which you can recognise by “https://” in your browser’s address bar. This prevents third parties from reading data you send to us via the website, for example in forms.
4.3 Cookies, consent and cookie settings
Cookies are small text files stored by your browser; the browser’s local storage and tracking pixels are comparable. Under Section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG), we may only store or read information on your device with your consent, unless this is strictly necessary for a service you have expressly requested.
The following are active without consent:
- storing your choice in the cookie banner,
- storing your language selection for one day,
- temporarily storing your search details in the booking mask (section 6.1),
- security and session cookies where technically necessary.
All other services that store or read information on your device only load after you consent (Section 25(1) TDDDG, Art. 6(1)(a) GDPR). Where content from another provider is loaded without consent, we say so for the service concerned (newsletter form, section 4.6; booking function, section 6.1; conference and group bookings, section 7.6).
We manage consent with the WordPress plugin Complianz. It runs on our own server and does not send visitor data to its developer. The banner distinguishes technically necessary services, which are always active, from the categories “Statistics” and “Marketing”. On the first level you can reject all services with one click. We store your choice in cookies on your device for twelve months; after that we ask again. The legal basis is Art. 6(1)(c) in conjunction with Art. 7(1) GDPR (proof of consent) and Section 25(2) no. 2 TDDDG.
You can change or withdraw your consent at any time with effect for the future via the “Cookie settings” link at the bottom of every page. Processing carried out before then remains lawful.
We serve fonts and tools such as the date picker from our own server. No data is passed to third parties in the process.
4.4 Google Maps
On the “Location” page and on the home page, we show a map from Google Maps. The map only loads when you click “Load map” in the placeholder or have consented to “Marketing” in the cookie settings. Google then receives your IP address, the page visited and information about your browser, and Google may set cookies. Google is an independent controller for Google Maps (https://business.safety.google/controllerterms/). The legal basis is your consent (Section 25(1) TDDDG, Art. 6(1)(a) GDPR).
The “Open in Google Maps” link is a simple link. Only when you click it do you access a Google page, which is governed by Google’s privacy policy: https://policies.google.com/privacy?hl=en
4.5 Contact and enquiry forms
We offer forms for general and press enquiries, for longer stays and for students. Depending on the form, we process your name, email address, type of enquiry, arrival and departure dates, number of guests, type of stay, discount code and your message, as well as the time of submission. The forms run on the WordPress plugin Gravity Forms. The entries are stored in our website’s database at Mittwald and are sent to our team by email; the plugin’s developer does not receive any form data.
The legal basis is Art. 6(1)(b) GDPR for enquiries about bookings and stays and Art. 6(1)(f) GDPR for general and press enquiries; our legitimate interest is answering them. Consent is not required to submit a form. We delete entries six months after receipt. If your enquiry leads to a contract, the periods in section 13 apply.
Spam protection
To protect against spam, the forms contain a check field that is invisible to people (WordPress plugin WP Armour). It runs on our own server; no data is passed to third parties. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is protection against abusive submissions.
4.6 Newsletter
For our newsletter with offers and news from our property, we only need your email address. After signing up, you receive an email with a confirmation link; we only add you to the mailing list after you confirm (double opt-in). As proof, we store the time of sign-up and confirmation, the IP address used and the wording of the consent.
Using a tracking pixel and personalised links, we analyse whether you open the newsletter and which links you click. We point this out when you sign up; the analysis is part of your consent.
Sign-up, sending and analysis are handled by Brevo GmbH, Köpenicker Straße 126, 10179 Berlin, Germany, as our processor, according to Brevo with servers in France, Germany and Belgium. To display the sign-up form, your browser loads program code from Brevo’s servers; your IP address is transmitted in the process (Art. 6(1)(f) GDPR, legitimate interest in a working sign-up form).
The legal basis is your consent (Art. 6(1)(a) GDPR, Section 7(2) no. 2 of the German Act against Unfair Competition, UWG), and for the proof Art. 6(1)(c) in conjunction with Art. 7(1) GDPR. You can withdraw your consent at any time via the unsubscribe link in every newsletter or by message to the contact details in section 2.1. We store your address until you unsubscribe and the proof for up to three years afterwards. To ensure you receive nothing after unsubscribing, your address remains on a block list (Art. 6(1)(f) GDPR).
4.7 Links to social networks
The Instagram, Facebook and LinkedIn icons at the bottom of our pages and the share buttons in blog articles are simple links. No data flows to these networks when you visit our website. Only when you click a link are you taken to the respective provider’s page.
5. Contact by email, phone and direct message
If you contact us by email, by phone or by direct message on Instagram or Facebook, we process your details, such as name, contact details, user name and the content of your message, to deal with your request. The legal basis is Art. 6(1)(b) GDPR if it concerns a booking or your stay, otherwise Art. 6(1)(f) GDPR (interest in answering enquiries).
Direct messages run through Meta’s systems and are stored there; Meta’s privacy policy also applies. Please do not send confidential information such as payment details by direct message.
We delete completed enquiries as soon as there is no obligation to retain them. We keep messages relating to a booking as business correspondence for six years (section 13).
5.1 AI phone assistant
Some calls to us are answered by an AI-based phone assistant. We tell you this at the start of the call. The assistant answers questions, takes bookings and requests, and forwards matters it cannot resolve to our team.
The data processed are your phone number, your name if given, your request and booking details such as room number or reservation, a text version of the call (transcript), an automatic summary, and the date and duration of the call. The call is not recorded as audio.
The legal basis is Art. 6(1)(b) GDPR where bookings and your stay are concerned, otherwise Art. 6(1)(f) GDPR; our legitimate interest is handling phone enquiries quickly.
So that you do not have to repeat everything when you call again, the assistant links earlier calls to your phone number. The legal basis is Art. 6(1)(f) GDPR. You can object to this at any time, including during the call; this will not put you at any disadvantage. If you mention health information during the call, such as allergies, section 7.3 applies.
The assistant does not make decisions that have legal effects on you. It is operated technically by CODYCO GmbH, Ortlerstraße 1C, 81373 Munich, Germany, as our processor (data protection contact: datenschutz@codyco.ai). We store transcripts, summaries and the link to your phone number for up to 24 months unless you request deletion earlier.
6. Booking
6.1 Booking mask and booking page
In the booking mask on our website, you enter your travel dates, room type, number of guests and, if applicable, a promotional code. Your browser stores this information locally so that it is retained when you move on to the booking (Section 25(2) no. 2 TDDDG).
For the booking function, your browser loads program code from SiteMinder’s servers when you visit our website; your IP address is transmitted in the process. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is a working booking function.
Bookings are made on our booking page at direct-book.com, which is operated for us by SiteMinder Distribution Limited (England and Wales) as our processor. There you enter your name, address, email address, phone number, travel dates, selected services, requests and payment details, such as credit card details to guarantee the booking. The legal basis is Art. 6(1)(b) GDPR. Without this information we cannot accept the booking.
The booking page has its own cookie banner. There you decide whether Google’s and Meta’s analytics and advertising services run on the booking page. Your choice on our website is not carried over. With your consent, SiteMinder also uses its own analytics tools there (Google Analytics and Hotjar). Without consent, only technical services for security and error monitoring run there. For transfers to third countries, see section 12.
6.2 Bookings via platforms, travel agencies and companies
We do not receive all data directly from you (Art. 14 GDPR). If you book via a booking platform such as Booking.com, a travel agency, your employer or an organiser, they send us your name, contact details (for platforms often a forwarding address of the platform), travel dates, booked services and prices, special requests and, where applicable, payment details. We use the data to perform the accommodation contract (Art. 6(1)(b) GDPR). If a third party books for you, we rely on Art. 6(1)(f) GDPR; our legitimate interest is carrying out the booking.
Booking platforms are responsible for their own processing; their privacy policies apply. The connection between the platforms and our systems is provided by SiteMinder as channel manager and our processor.
Bookings made with the previous operator of the property before 1 October 2026 and fulfilled at our property were passed to us by the previous operator, with the information needed, so that we can perform the contract with you (Art. 6(1)(b) GDPR).
6.3 Hotel software and payment
We manage bookings, guest data and invoices in the hotel software of apaleo GmbH, Sandstraße 3, 80335 Munich, Germany, which acts as our processor. According to apaleo, the data is stored on Amazon Web Services servers in Germany.
We process your payment details to pay for and secure your booking. Depending on the rate and cancellation terms, we check your card when you book, reserve an amount (pre-authorisation) or charge it, for example in the event of a no-show or late cancellation. Card details are processed by our payment service provider, Adyen N.V., Simon Carmiggeltstraat 6-50, 1011 DJ Amsterdam, Netherlands. Adyen is a regulated credit institution and processes payment data partly under its own responsibility, for example to prevent fraud and comply with legal obligations; Adyen’s privacy policy also applies (https://www.adyen.com/policies-and-disclaimer/privacy-policy). Other recipients are the banks and card schemes involved.
The legal basis is Art. 6(1)(b) GDPR. Where we or our payment service provider check payments for signs of fraud, this is based on Art. 6(1)(f) GDPR. We keep invoices and booking records for eight years (section 13).
7. Your stay
7.1 Accommodation contract and stay
For your stay, we process your name, address, contact details, travel dates, room or apartment number, services booked and used, billing data, your requests and our communication with you. We need this data for check-in and check-out, the agreed services, billing and dealing with requests and complaints. The legal basis is Art. 6(1)(b) GDPR, and Art. 6(1)(c) GDPR for legal obligations. For longer stays we conclude a rental agreement with you; the same applies to the information required for it.
So that we can take your preferences into account on a later stay, we keep a guest profile with your contact details, previous stays and preferences, for example regarding room choice. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is personal service for returning guests. We delete the guest profile three years after your last stay. You can object to the guest profile at any time (section 3).
If your stay lasts longer than six months, the general obligation to register with the registration authority applies to you (Section 29(1) of the Federal Registration Act, BMG). If you register a residence with us, we issue the landlord’s confirmation under Section 19 BMG and process the information required for it (Art. 6(1)(c) GDPR).
We accept letters for you at reception. For this we process your name, your room or apartment number and details of the item (Art. 6(1)(b) GDPR).
You receive parcels via our parcel station, a myRENZbox from Erwin Renz Metallwarenfabrik GmbH & Co KG. To use it, you register in the Renz portal or app, for example with your name and email address, and are notified as soon as a parcel has arrived for you. Processing in the portal and app is governed by Renz’s privacy policy, which you accept when registering. We process the link to your apartment so that you can use the service (Art. 6(1)(b) GDPR).
If you rent a parking space from us, we process the booking and billing data (Art. 6(1)(b) GDPR). Number plates are not recorded.
7.2 Registration form
If you are not a German national, we must have you fill in and sign a special registration form on arrival (Sections 29 and 30 of the Federal Registration Act, BMG, as amended with effect from 1 January 2025). This obligation no longer applies to German nationals.
The registration form contains only: date of arrival and expected departure, surname, first names, date of birth, nationalities, address, number and nationality of accompanying foreign persons, and the serial number of your passport or passport substitute. Accompanying spouses, partners and minor children are only stated by number. For travel groups of more than ten people, only the tour leader fills in the registration form.
The legal basis is Art. 6(1)(c) GDPR in conjunction with Sections 29 and 30 BMG. We keep the registration form for one year from the day of your departure and destroy or delete it within the following three months. On request, we must present it to the competent authorities, such as the police, public prosecutors or courts (Section 30(4) BMG).
7.3 Allergies and other health information
If you tell us about allergies, intolerances or other health-related requests, for example for meals or accessible facilities, we only process this information to meet your request. Because this is health data, we need your explicit consent (Art. 9(2)(a) GDPR). Providing it is voluntary, and you can withdraw your consent at any time. Only staff who need the information have access to it. We delete it after your stay or the event unless you expressly want us to keep it for future stays.
7.4 Video surveillance
We use video cameras in selected areas of our property. These areas are marked with signs on site. The purposes are exercising our house rules, protecting guests, staff and property, and investigating criminal offences. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in these purposes.
We store the recordings on our own systems on site, without an external service provider, and delete them automatically after 72 hours. If they are needed to investigate a specific incident, we keep them until it has been resolved and may pass them on to the police, public prosecutors, insurers or lawyers. You can object to video surveillance on grounds relating to your particular situation (section 3).
7.5 Guest Wi-Fi
Our guest Wi-Fi is operated for us by DATA PLEXX IT- und Telekommunikationslösungen GmbH, Hosnedlgasse 16A, 1220 Vienna, Austria. When you connect, a start page opens on which you accept the terms of use; registration with personal details is not required. The data processed is the technical connection data needed for access, such as device identifier, assigned IP address and start and end of the connection. This serves to provide access as part of your stay (Art. 6(1)(b) GDPR) and for security and troubleshooting in our network (Art. 6(1)(f) GDPR, Section 12 TDDDG). We do not analyse the content of your communications. The connection data is deleted as soon as it is no longer needed for these purposes.
7.6 Events, meeting rooms, food and drink, coworking and common rooms
If you book an event, a meeting room, a coworking desk or our food and drink services, we process your contact details, the booking details, the number of participants, your requests and the billing data (Art. 6(1)(b) GDPR). If we receive a list of participants from you or your employer, we only use it to run the event (Art. 6(1)(f) GDPR). Our property includes common rooms such as a library, cinema, gaming and darts room and a gym. If you reserve one of them, we process your name, your room or apartment number and the reservation period (Art. 6(1)(b) GDPR).
For meeting room enquiries and for booking rooms from a group allotment, we use software from customice GmbH, Welfenstraße 22, 81541 Munich, Germany, as our processor. The meeting room configurator and the page for booking from a group allotment on our website are customice content. When they load, customice receives your IP address and information about your browser; what you enter there goes directly to customice. The legal basis is Art. 6(1)(b) GDPR for your enquiry or booking and Art. 6(1)(f) GDPR for loading the content; our legitimate interest is a working enquiry and booking service.
7.7 Online check-in
You can check in online before you arrive. We record the information needed for your stay, such as contact details, arrival time and billing address, and, if you are not a German national, the information for the registration form (section 7.2). The legal basis is Art. 6(1)(b) GDPR, and Art. 6(1)(c) GDPR for the registration form. The check-in system is provided by a service provider acting as our processor. We do not use a digital room key.
8. Advertising and surveys
8.1 Promotional emails to guests
If you have booked directly with us and given us your email address, we may send you information about our own offers similar to your booking, for example about further stays at our property. We only do this if we informed you of your right to object when we collected your email address. Section 7(3) UWG permits this without separate consent. Under data protection law, we additionally rely on Art. 6(1)(f) GDPR (direct marketing, Recital 47 GDPR). We do not use addresses received via booking platforms for this.
You can object to this use at any time without incurring any costs other than transmission costs at basic rates: via the unsubscribe link in every email or by message to the contact details in section 2.1.
8.2 Guest surveys and reviews
If we ask you by email after your stay to write a review or take part in a short survey, this legally counts as advertising. We therefore only send such a request under the conditions of section 8.1 or with your consent. Participation is voluntary. For sending and analysis, we use MARA Solutions GmbH, Tullastraße 15, 68161 Mannheim, Germany, as our processor. Public reviews you post on platforms are the responsibility of the respective platform. We analyse and respond to them with MARA’s support; in doing so we process the publicly visible information such as name or user name, rating and text (Art. 6(1)(f) GDPR; our legitimate interest is dealing with feedback from our guests).
9. Our social media profiles
We run profiles on Instagram, Facebook and LinkedIn to provide information about our property and to get in touch with guests and interested parties. The platforms also process your data for their own purposes, for example for advertising; we have no influence on this. We process comments, messages and reactions you send us in order to communicate with you. The legal basis for running the profiles and for communication is Art. 6(1)(f) GDPR (public relations and communication), and Art. 6(1)(b) GDPR for booking enquiries.
9.1 Instagram
The provider is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Meta provides us with aggregated statistics (Insights) on the use of our profile, such as reach, interactions and demographic information. According to the case law of the Court of Justice of the European Union, we are jointly responsible with Meta for collecting this data (CJEU, judgment of 5 June 2018, C-210/16). Meta has set out the details on Insights in the Page Insights Controller Addendum (https://www.facebook.com/legal/terms/page_controller_addendum). Under it, Meta assumes primary responsibility for processing Insights data and for fulfilling your rights. You can exercise your rights with us and with Meta; we forward enquiries about Insights to Meta. Instagram’s privacy policy: https://privacycenter.instagram.com/policy
9.2 Facebook
The provider is also Meta. We are jointly responsible with Meta for the statistics on our Facebook page; the Page Insights Controller Addendum applies (link in section 9.1). Information on Insights data: https://www.facebook.com/legal/terms/information_about_page_insights_data. We also place ads on Facebook and Instagram via our Facebook page. Meta’s privacy policy: https://www.facebook.com/privacy/policy
9.3 Lead forms in ads on Facebook and Instagram
In some ads on Facebook and Instagram, you can fill in an enquiry form directly, for example for student apartments, longer stays or relocation. It asks for contact details and information such as preferred move-in date, length of stay and university. Meta may pre-fill fields such as name and email address from your profile; you see the information before sending and can change it. After you send it, Meta makes your information available to us.
We only use the information to deal with your enquiry (Art. 6(1)(b) GDPR). Meta is responsible for processing on the platform; Meta’s privacy policy applies. The same retention period applies as for our website forms (section 13).
9.4 LinkedIn
The provider is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. We are jointly responsible with LinkedIn for the statistics on our company page. The agreement can be found at https://www.linkedin.com/legal/l/page-joint-controller-addendum. LinkedIn’s privacy policy: https://www.linkedin.com/legal/privacy/eu
10. Job applications
We accept applications by email and via our job ads on Hotelcareer and StepStone. Both portals are operated by The Stepstone Group Deutschland GmbH, Völklinger Straße 1, 40219 Düsseldorf, Germany, which is responsible for processing on its platforms; its privacy policy applies. If you apply to us, we process your details and documents, such as contact details, CV, references and correspondence with you, to carry out the application process. The legal basis is Art. 6(1)(b) GDPR (steps prior to entering into an employment relationship). We process voluntary information on special categories, such as a severe disability, under Art. 9(2)(b) GDPR. Only the people involved in the process have access.
If you are hired, we transfer the necessary data to your personnel file. If you are rejected, we delete your data no later than six months after you receive the rejection. Until then, we only keep it to be able to defend against possible claims under the German General Equal Treatment Act (Art. 6(1)(f), Art. 17(3)(e) GDPR). We only add you to a talent pool with your consent, which you can withdraw at any time.
11. Recipients
We only pass on personal data where there is a legal basis. Recipients are:
- processors who work for us on our instructions: hosting (Mittwald), the agency supporting the website, booking technology and channel manager (SiteMinder), hotel software (apaleo), online check-in, newsletter sending (Brevo), conference and group bookings (customice), phone assistant (CODYCO), guest Wi-Fi (DATA PLEXX), surveys and reviews (MARA), and IT service providers for email and office IT;
- independent controllers or joint controllers with us: Google (Google Maps), Meta (Instagram, Facebook), LinkedIn, booking platforms and travel agencies, job portals (Hotelcareer, StepStone), Erwin Renz (parcel station);
- payment service providers (Adyen), banks and card schemes for payment processing;
- authorities and courts where we are legally obliged (for example for the registration form, section 7.2) or an incident needs to be investigated;
- tax advisers, auditors and lawyers bound by professional secrecy, and insurers in the event of a claim.
We conclude contracts with processors under Art. 28 GDPR.
12. Transfers to third countries
Some services process data outside the EU and the European Economic Area (EEA). We only transfer data to such a third country if the requirements of Articles 44 to 49 GDPR are met:
- Google (Google Maps): the contracting party is Google Ireland Limited. Data may be transferred to Google LLC in the USA, which is certified under the EU-US Data Privacy Framework; the European Commission’s adequacy decision of 10 July 2023 applies (Art. 45 GDPR). In addition, Google’s terms provide for standard contractual clauses (Art. 46(2)(c) GDPR).
- Meta (Instagram, Facebook, lead forms in ads): the contracting party is Meta Platforms Ireland Limited. Data is transferred to Meta Platforms, Inc. in the USA, which is certified under the EU-US Data Privacy Framework (adequacy decision of 10 July 2023).
- LinkedIn (company page): data may be transferred to LinkedIn Corporation in the USA, which is certified under the EU-US Data Privacy Framework.
- Brevo (newsletter): Brevo GmbH, Berlin, with servers in France, Germany and Belgium. For individual sub-processors in the USA, Brevo states that it relies on the Data Privacy Framework and standard contractual clauses, and on standard contractual clauses for support from India.
- SiteMinder (booking function and booking page): the contracting party is SiteMinder Distribution Limited in the United Kingdom, for which an adequacy decision of the European Commission applies. According to SiteMinder, it stores data with Amazon Web Services in the USA; Amazon.com, Inc. is certified under the Data Privacy Framework. SiteMinder group companies are based in Australia, for which there is no adequacy decision; SiteMinder states that it uses standard contractual clauses for this.
- apaleo (hotel software) states that it uses Amazon Web Services with servers in Germany; Amazon.com, Inc. is certified under the Data Privacy Framework.
- Mittwald processes data in Germany. Adyen (Netherlands), DATA PLEXX (Austria), CODYCO and MARA (Germany) are based in the EU.
If other service providers use locations outside the EU and the EEA, this only happens under the conditions above. You can obtain a copy of the standard contractual clauses on request via the contact details in section 2.1.
13. Retention periods
We only store personal data for as long as necessary for the respective purpose or as required by a statutory retention obligation. We then delete it. Where only a retention obligation remains, we restrict processing until the end of the period. Overview:
- Server log files: access logs with shortened IP address 60 days, error logs seven days
- Choice in the cookie banner: twelve months
- Individual cookies: see cookie policy
- Website form entries and enquiries from ad forms: six months after receipt
- Newsletter: email address until you unsubscribe, proof of consent up to three years afterwards, block list as long as necessary
- Registration form: one year from departure, destruction within the following three months (Section 30(4) BMG)
- Invoices and other booking records: eight years (Section 147 AO, Section 257 HGB, Section 14b UStG)
- Commercial and business correspondence, such as booking correspondence: six years (Section 147 AO, Section 257 HGB)
- Books and annual financial statements: ten years (Section 147 AO, Section 257 HGB)
- Phone assistant transcripts and summaries: up to 24 months
- Guest profile: three years after your last stay
- Health information: until the end of the stay or event, unless you have agreed to longer storage
- Video recordings: 72 hours, in the event of an incident until it has been resolved
- Wi-Fi connection data: as long as needed for operating and securing the network
- Job applications: six months after you receive a rejection
The commercial and tax retention periods begin at the end of the calendar year in which the record was created.
14. Obligation to provide data
You can use our website without providing any personal information; technically necessary data such as the IP address is still generated. For an enquiry, booking or application, we need the information marked as mandatory. Without it, we cannot deal with your request or conclude a contract. Guests who are not German nationals are legally obliged to fill in the registration form (Section 29(2) BMG). All consents are voluntary.
15. Automated decision-making and profiling
We do not make decisions based solely on automated processing within the meaning of Art. 22 GDPR that have legal effects on you or similarly significantly affect you. This also applies to our AI phone assistant: it records requests and handles standard enquiries according to our instructions; individual decisions are made by our team.
16. Your rights
16.1 Access: You can ask whether and which data we process about you and receive a copy (Art. 15 GDPR).
16.2 Rectification: You can ask us to correct inaccurate data and complete incomplete data (Art. 16 GDPR).
16.3 Erasure: You can ask us to delete your data where we no longer need it, there is no retention obligation and no other exception under Art. 17(3) GDPR applies (Art. 17 GDPR).
16.4 Restriction of processing: You can ask us to restrict the processing of your data, for example while its accuracy is disputed (Art. 18 GDPR).
16.5 Data portability: On request, you will receive data you have provided to us, and that we process automatically on the basis of your consent or a contract, in a common, machine-readable format. You can also ask us to transfer it directly to another controller where technically feasible (Art. 20 GDPR).
16.6 Objection: Your right to object under Art. 21 GDPR is described in section 3.
16.7 Withdrawal of consent: You can withdraw consent at any time with effect for the future (Art. 7(3) GDPR): for cookies via the “Cookie settings” link at the bottom of every page, for the newsletter via the unsubscribe link, and otherwise by message to us. The lawfulness of processing before the withdrawal is not affected.
16.8 Complaint: You can lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement (Art. 77 GDPR). The authority responsible for us is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany
Postal address: Postfach 1349, 91504 Ansbach, Germany
https://www.lda.bayern.de
How to exercise your rights: contact us using the details in section 2.1 or contact our data protection officer (section 2.2). Exercising your rights is free of charge. We respond within one month (Art. 12(3) GDPR). If there are doubts about your identity, we may ask for additional information.
17. Changes to this privacy policy
We update this privacy policy when our processing or the legal situation changes. The version published on our website applies.
Last updated: October 2026
In case of doubt, the German version of this privacy policy prevails.