Data Privacy.

We very much appreciate your interest in our company. Data protection is a particularly high priority for the Bilster Berg Drive Resort GmbH & Co. KG management. In principle, it is possible to use the Bilster Berg Drive Resort GmbH & Co. KG website without providing any personal data whatsoever. However, personal data may need to be processed if the data subject wishes to take advantage of the special services that our company offers through its website. If personal data does need to be processed and no legal basis for such processing exists, we generally seek consent from the data subject.

Personal data, such as the name, address, email address or telephone number of the data subject, is always processed in accordance with the General Data Protection Regulation and in accordance with the country-specific privacy policy applicable to Bilster Berg Drive Resort GmbH & Co. KG. Our company seeks to inform the public by means of this Privacy Policy about the nature, extent and purpose of the personal data that we collect, use and process. In addition, this Privacy Policy also provides information about the rights of the data subjects, whose data we use.

As the party responsible for processing personal data, Bilster Berg Drive Resort GmbH & Co. KG, has taken numerous technical and organizational measures to ensure the most complete personal data protection for information processed via this website. Nevertheless, internet-based data transmissions can generally have security vulnerabilities, so absolute protection cannot be guaranteed. For this reason, every data subject is free to submit personal data to us via alternative routes, for example, by telephone.

Name and address of the controller

The responsible party, within the meaning of the General Data Protection Regulation, other data protection laws in the Member States of the European Union and other provisions relating to data protection, is:

Bilster Berg Drive Resort GmbH & Co. KG
Bilster Berg 1
33014 Bad Driburg
Germany

T +49 5253 973 90 00
F +49 5253973 90 22
E info@bilster-berg.de

www.bilster-berg.de

Data Protection Supervisor

ubb GmbH Unternehmensberatung Beugholt
Gabriela Beugholt

E datenschutz@bilster-berg.de

1. Definitions of terms

Bilster Berg Drive Resort GmbH & Co. KG’s Privacy Policy is based on the terminology used by the European Directive and Regulatory Authorities in their adoption of the General Data Protection Regulation (GDPR). Our Privacy Policy should be easy for the public to read and understand, as well as for our customers and business partners. In order to make sure this is the case, we would like to define the terminology used in advance.

The terms we use in this Privacy Policy include the following:

a) personal data

Personal data means any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

b) data subject

A data subject is any identified or identifiable natural person whose personal data is processed by the controller.

c) processing

Processing means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction,

d) restriction of processing

Restriction of processing means the marking of stored personal data with the aim of limiting their processing in the future.

e) profiling

Profiling is any form of automated processing of personal data consisting of using those data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or movements.

f) pseudonymization

Pseudonymization is the processing of personal data in such a way that the personal data can no longer be attributed to a specific data subject without the need for additional information, as long as such additional information is kept separately and subject to technical and organizational measures to ensure non-attribution of the personal data to an identified or identifiable natural person.

g) controller or entity in charge of processing

The controller or entity in charge of processing is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.

h) processor

Processor means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

i) recipient

Recipient means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.

j) third party

Third party means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorized to process personal data.

k) consent

Consent of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

2. Cookies

Bilster Berg Drive Resort GmbH & Co. KG websites use cookies. Cookies are text files that are recorded and stored on a computer system via an internet browser.

Many websites and servers use cookies. Many cookies contain what is called a cookie ID. A cookie-ID is a unique identifier of the cookie. It consists of a character string through which internet pages and servers can be assigned to the specific Internet browser in which the cookie was stored. This allows visited Internet sites and servers to differentiate the individual browser of the data subject from other internet browsers that contain other cookies. A specific internet browser can be recognized and identified using the unique cookie ID.

Through the use of cookies, Bilster Berg Drive Resort GmbH & Co. KG can provide the users of this website with more user-friendly services that would not be possible without the cookie setting.

By means of a cookie, the information and offers on our website can be optimized with the user in mind. Cookies allow us, as previously mentioned, to recognize our website users. The purpose of this recognition is to make it easier for users to utilize our website. The website user that uses cookies does not, for example, have to enter access data each time the website is accessed, because this is taken over by the website, and the cookie is thus stored on the user’s computer system. Another example is the cookie of a shopping cart in an online shop. The online store remembers the articles that a customer has placed in the virtual shopping cart via a cookie.

The data subject may, at any time, prevent the setting of cookies through our website by means of a corresponding setting of the internet browser used, and may thus permanently deny the setting of cookies. Furthermore, already set cookies may be deleted at any time via an internet browser or other software programs. This is possible in all popular internet browsers. If the data subject deactivates the setting of cookies in the internet browser used, not all functions of our website may be entirely usable.

Ändern Sie Ihre Einwilligung

3. Collection of general data and information

The Bilster Berg Drive Resort GmbH & Co. KG website collects a series of general data and information when a data subject or automated system calls up the website. This general data and information is stored in the server log files. The following may be collected:

(1) the browser types and versions used,
(2) the operating system used by the accessing system,
(3) the website from which an accessing system reaches our website (which are called referrers),
(4) the sub-websites, which are controlled by an accessing system on our website,
(5) the date and time of access to the Internet site,
(6) an Internet Protocol address (IP address),
(7) the accessing system’s internet service provider, and
(8) any other similar data and information that may be used in the case of attacks on our information technology systems.

When using these general data and information, Bilster Berg Drive Resort GmbH & Co. KG does not draw any conclusions about the data subject. Rather, this information is needed to

(1) deliver the content of our website correctly,
(2) optimize the content of our website as well as its advertisement,
(3) ensure the long-term viability of our information technology systems and website technology, and
(4) provide law enforcement authorities with the information necessary for criminal prosecution in case of a cyber-attack.

Therefore, Bilster Berg Drive Resort GmbH & Co. KG analyzes anonymously collected data and information statistically, with the aim of increasing the data protection and data security of our company, and to ensure an optimal level of protection for the personal data we process. The anonymous data of the server log files are stored separately from all personal data provided by a data subject.

a) Registration on our website

The data subject has the possibility to register on the controller’s website by providing personal data. The respective input mask used for the registration determines which personal data is transmitted to the controller. The personal data entered by the data subject is collected and stored exclusively for internal use by the controller, and for the controller’s own purposes. The controller may arrange for the transfer to one or more processors – a service provider, for example – which also use(s) personal data exclusively for an internal purpose which is attributable to the controller.

The IP address assigned by the data subject’s Internet Service Provider (ISP), the date and time of the registration are also stored through the registration process on the controller’s website. This data is stored within the confines of the fact that this is the only way to prevent the misuse of our services, and, if necessary, to make it possible to investigate committed offenses. In this respect, storage of this data is necessary to secure the controller. This data is not disclosed to third parties unless there is a legal obligation to pass on the data, or if the disclosure serves law enforcement purposes.

The registration of the data subject, which involves voluntarily providing personal data, is intended to enable the controller to offer the data subject contents or services that may only be offered to registered users because of the nature of the case in question. Registered persons are free at any time to change the personal data they provided during registration, or to have this data completely deleted from the controller’s database

The controller shall, at any time and upon request, provide information to each data subject as to which personal data about the data subject is stored. In addition, the controller shall correct or delete personal data at the request or indication of the data subject, provided that doing so does not conflict with any legal archiving requirements. All of the controller’s employees shall be available to the data subject as contact persons in this respect.

b) Contact via the website

In order to meet legal regulations, the Bilster Berg Drive Resort GmbH & Co. KG website contains information that enables quick electronic contact with our company as well as direct communication with us, which also includes a general address for contact via electronic mail (email address). If a data subject contacts the controller by email or through a contact form, the personal data provided by the data subject will be stored automatically. Such personal data, transmitted on a voluntary basis by a data subject to the controller, is stored for the purposes of processing or contacting the data subject. This personal data will not be disclosed to third parties.

c) Comments in the blog on the website

Bilster Berg Drive Resort GmbH & Co. KG offers users an opportunity to leave individual comments on individual blog posts on a blog located on the controller’s website. A blog is a web-based portal, usually accessible by the public, in which one or more people who are called bloggers or web bloggers can post articles or write their thoughts down in what are called blog posts. Third parties can usually post comments on the blog posts.

If a data subject leaves a comment in the blog published on this website, then not only the comments left by the data subject, but also information about the time that the comment was entered and the data subject’s chosen username (pseudonym) will be stored and published. In addition, the IP address assigned by the data subject’s Internet Service Provider (ISP) is also logged. The IP address is stored for security reasons and in the event that the data subject violates the rights of third parties or posts illegal content when submitting a comment. Storage of such personal data is therefore in the controller’s own best interest so that the controller can be absolved of liability in the event of a breach of the law. This personal data is not disclosed to third parties unless such disclosure is required by law or it is used in connection with the controller’s legal defense.

4. Newsletter

a) Subscription to our newsletters

Users are given the opportunity to subscribe to our company newsletter on the Bilster Berg Drive Resort GmbH & Co. KG website. The input mask used for newsletter subscriptions determines what personal data is transmitted at the time that the newsletter is ordered from the controller.

Bilster Berg Drive Resort GmbH & Co. KG informs its customers and business partners regularly by means of a newsletter about the company’s offers. The company newsletter may in principle only be received by the data subject if

(1) the data subject has a valid email address and
(2) the data subject registers for delivery of the newsletter.

For legal reasons, a confirmation email will be sent to the email address first entered by the data subject to confirm the subscription to the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the data subject has given authorization to receive the newsletter.

During the newsletter registration process, we also store the IP address of the computer system assigned by the Internet Service Provider (ISP) and used by the data subject at the time of the registration, as well as the date and time of registration. Collection of this data is necessary in order to be able to reconstruct and retrace the (potential) misuse of a data subject’s email address at a later date, and it therefore serves as a legal safeguard for the controller.

The personal data collected as part of a registration for the newsletter will only be used for the purpose of sending our newsletter. In addition, subscribers to the newsletter may be informed by email if this proves necessary for the operation of the newsletter service or for matters related to the registration, as may be the case in the event of modifications to the newsletter offering or in the event of technical changes. None of the personal data collected by the newsletter service will be transferred to third parties. Subscription to our newsletter may be terminated by the data subject at any time. Consent to the storage of personal data, which the data subject provided for delivery of the newsletter, may be withdrawn at any time. A corresponding link is found in each newsletter for the purpose of withdrawing consent. It is also possible to unsubscribe from the newsletter directly on the controller’s website at any time, or to inform the controller of this wish by other means of communication.

b) Newsletter tracking

The Bilster Berg Drive Resort GmbH & Co. KG newsletter contains what are called web beacons. A web beacon is a miniature graphic embedded in such e-mails, which are sent in HTML format to enable log file recording and analysis. This makes it possible to carry out a statistical analysis of the success or failure of online marketing campaigns. Using the embedded web beacon, Bilster Berg Drive Resort GmbH & Co. KG can detect whether and when an email was opened by a data subject and which links in the email were accessed by the data subject.

Such personal data collected in the web beacons contained in the newsletters are stored and analyzed by the controller in order to optimize the delivery of the newsletters, as well as to better adapt the content of future newsletters to the data subject’s interests. This personal data will not be disclosed to third parties. Data subjects are entitled at any time to withdraw their respective separate declaration of consent which they provided by means of the double opt-in procedure. This personal data will be deleted by the controller after consent is withdrawn. Bilster Berg Drive Resort GmbH & Co. KG automatically interprets unsubscribing from the newsletter as withdrawal of consent.

5. Routine deletion and blocking of personal data

The controller shall process and store the data subject’s personal data only for the period of time necessary to achieve the purpose of such storage or, to the extent provided for in laws or regulations handed down by the European Directive and Regulatory Authority or by another legislator to which the controller is subject.

If the storage purpose is not applicable, or if a storage period prescribed by the European Directive and Regulatory Authority or another competent legislator expires, then the personal data is blocked or deleted on a routine basis in accordance with legal requirements.

6. The data subject’s rights

a) Right of confirmation

Each data subject shall have the right, granted by the European Directive and Regulatory Authority, to require confirmation from the controller as to whether or not personal data relating to him or her is being processed. If a data subject wishes to exercise this right of confirmation, he or she may contact an employee of the controller at any time.

b) Right of access to information

Each data subject whose personal data is processed shall have the right, granted by the European Directive and Regulatory Authority, to obtain from the controller information about his or her personal data stored at any time, free of charge, and a to receive a copy of that information. In addition, the European Directive and Regulatory Authority has granted the data subject access to the following information:

(1) the processing purposes.
(2) the categories of personal data being processed.
(3) the recipients or categories of recipients to whom the personal data have been disclosed or are yet to be disclosed, in particular to recipients in third countries or to international organizations.
(4) where possible, the planned period for which the personal data will be stored, or, if that is not possible, the criteria used to determine that period.
(5) the existence of the right to request that the controller correct or delete personal data, or restrict the processing of personal data concerning the data subject, or to object to such processing.
(6) the existence of a right to legal remedy from a supervisory authority.
(7) where the personal data was not collected from the data subject: any available information as to the source of such data.
(8) the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) of the GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and intended effects of such processing for the data subject.

In addition, the data subject shall have a right to obtain information as to whether personal data is disclosed to a third country or to an international organization. Where this is the case, the data subject shall have the right to be informed of the appropriate safeguards taken in connection with such disclosure.

If a data subject wishes to exercise this right of access to information, he or she may contact an employee of the controller at any time.

c) Right to rectification

Each data subject whose personal data is processed shall have the right, granted by the European Directive and Regulatory Authority, to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her. The data subject shall also have the right to have incomplete personal data completed, including by means of providing a supplementary statement, taking the purposes of the processing into account.

If a data subject wishes to exercise this right to rectification, he or she may contact an employee of the controller at any time.

d) Right to erasure (the right to be forgotten)

Each data subject whose personal data is processed shall have the right, granted by the European Directive and Regulatory Authority, to require the controller to delete any personal data concerning him or her without undue delay, and the controller shall have the obligation to delete personal data without undue delay where one of the following reasons applies and as long as processing is not necessary:

(1) The personal data is no longer necessary in relation to the purposes for which it was collected or otherwise processed.
(2) The data subject withdraws consent on which the processing is based according to point (a) of Article 6(1) of the GDPR, or point (a) of Article 9(2) of the GDPR, and where there are no other legal grounds for the processing.
(3) The data subject objects to the processing in accordance with Article 21(1) of the GDPR and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing in accordance with Article 21(2) of the GDPR.
(4) The personal data was processed unlawfully.
(5) The personal data must be deleted in order to comply with a legal obligation in Union law or Member State law to which the controller is subject.
(6) The personal data was collected in relation to the offer of information society services referred to in Article 8(1) of the GDPR.

If one of the aforementioned reasons applies, and a data subject wishes to request the deletion of personal data stored by the Bilster Berg Drive Resort GmbH & Co. KG, he or she may contact an employee of the controller at any time. The Bilster Berg Drive Resort GmbH & Co. KG employee shall ensure that the deletion request is fulfilled immediately.

Where Bilster Berg Drive Resort GmbH & Co. KG has made personal data publicly accessible and our company is obliged, pursuant to Article 17(1) of the GDPR, to delete this personal data, then Bilster Berg Drive Resort GmbH & Co. KG shall take reasonable measures, including technical measures, under consideration of the technology available and the cost of implementation, to inform other controllers processing the personal data that the data subject has requested deletion by such controllers of any links to, or copies or replications of, this personal data, provided that the processing is not required. The Bilster Berg Drive Resort GmbH & Co. KG employee will arrange the necessary measures in individual cases.

e) Right to restrict processing

Each data subject whose personal data is processed shall have the right, granted by the European Directive and Regulatory Authority, to require that the controller restrict processing where one of the following conditions applies:

(1) The accuracy of the personal data is contested by the data subject for a period of time that enables the controller to verify the accuracy of the personal data.
(2) The processing is unlawful, the data subject objects to the deletion of the personal data and instead requests that the use of the personal data be restricted.
(3) The controller no longer needs the personal data for the purposes of processing, but the data subject requires the data in order to establish, exercise or defend legal claims.
(4) The data subject has objected to the processing in accordance with Article 21(1) of the GDPR and it has not yet been determined whether the controller’s legitimate reasons outweigh those of the data subject.

If one of the aforementioned conditions is met and a data subject wishes to request that processing of personal data stored at Bilster Berg Resort GmbH & Co. KG be restricted, he or she may contact an employee of the controller at any time. The Bilster Berg Drive Resort GmbH & Co. KG employee will arrange to have the processing restricted.

f) Right to data portability

Each data subject whose personal data is processed shall have the right, granted by the European Directive and Regulatory Authority, to obtain the personal data that relates to him or her, which the data subject provided to a controller, in a structured, commonly used and machine-readable format. He or she shall also have the right to transfer this data to another controller without hindrance by the controller to whom the personal data was provided, as long as the processing is based on consent in accordance with Article 6(1)(a) of the GDPR or Article 9(2)(a) of the GDPR or on a contract in accordance with Article 6(1)(b) of the GDPR and the data is processed using automated means, provided that the processing is not necessary for the performance of a task carried out in the public interest or in the exercise of official authority assigned to the controller.

In addition, in exercising his or her right to data portability under Article 20(1) of the GDPR, the data subject shall have the right to have personal data transmitted directly from one controller to another, insofar as this is technically feasible and does not adversely affect the rights and freedoms of others.

The data subject may contact an employee at Bilster Berg Drive Resort GmbH & Co. KG at any time in order to assert the right to data portability.

g) Right to object

Each data subject whose personal data is processed shall have the right, granted by the European Directive and Regulatory Authority, to object, for reasons arising from their particular situation, to the processing of personal data that relates to him or her, which is based on Article 6(1)(e) or (f) of the GDPR. This also applies to profiling based on these provisions.

Bilster Berg Drive Resort GmbH & Co. KG will no longer process the data subject’s personal data in the event of an objection, unless we can demonstrate that there are compelling and legitimate reasons for processing it, which outweigh the interests, rights and freedoms of the data subject, or the processing is used in the establishment, exercise or defense of legal claims.

If Bilster Berg Drive Resort GmbH & Co. KG processes personal data for direct marketing purposes, the data subject shall have the right to object at any time to the processing of personal data for the purpose of such marketing. This also applies to the profiling, provided that it is related to such direct marketing. If the data subject objects to Bilster Berg Drive Resort GmbH & Co. KG processing personal data for direct marketing purposes, then Bilster Berg Drive Resort GmbH & Co. KG will no longer process the personal data for these purposes.

In addition, the data subject has the right, for reasons arising from his or her particular situation, to object to the processing of personal data relating to him or her carried out by Bilster Berg Drive Resort GmbH & Co. KG for scientific or historical research purposes or for statistical purposes in accordance with Article 89(1) of the GDPR, unless such processing is necessary for the performance of a task carried out for reasons of public interest.

The data subject may directly contact any employee at Bilster Berg Drive Resort GmbH & Co. KG or a subsidiary in order to exercise the right to object. The data subject is also free, in connection with the use of information society services, Directive 2002/58/EC notwithstanding, to exercise his or her right to object by automated means using technical specifications.

h) Automated individual decision-making, including profiling

Each data subject whose personal data is processed shall have the right, granted by the European Directive and Regulatory Authority, not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her, or similarly affects him or her appreciably, provided that the decision

(1) is not necessary for the conclusion or performance of a contract between the data subject and the controller
(2) is permissible under Union legislation or Member State legislation to which the controller is subject, and where such legislation contains appropriate measures to safeguard the data subject’s rights and freedoms and legitimate interests, or
(3) is made with the data subject’s explicit consent.

If the decision

(1) is necessary for the conclusion or performance of a contract between the data subject and the controller or
(2) is made with the data subject’s explicit consent, Bilster Berg Drive Resort GmbH & Co. KG shall take appropriate measures to safeguard the data subject’s rights and freedoms and legitimate interests, including at least the right to have a human on the part of the controller intervene, to express his or her own position and to challenge the decision.

If the data subject wishes to exercise this right with respect to automated decision-making, he or she may contact an employee of the controller at any time.

i) Right to withdraw data protection consent

Each data subject whose personal data is processed shall have the right, granted by the European Directive and Regulatory Authority, to withdraw his or her consent to the processing of his or her personal data at any time.

If the data subject wishes to exercise his or her right to withdraw consent, he or she may contact an employee of the controller at any time.

7. Data protection for applications and application procedures

The controller collects and processes applicants’ personal data for the purpose of completing an application process. The data can also be processed electronically. This is particularly the case when an applicant submits documents of relevance to the application to the controller by electronic means, for example by email or via a web form located on the website. If the controller enters into an employment contract with an applicant, the transmitted data will be stored for the purposes of the employment relationship in compliance with legal requirements. If the controller does not enter into an employment contract with the applicant, the application documents will be automatically deleted two months after notification of the rejection decision is made, unless such deletion conflicts with other legitimate interests of the controller. In this sense, other legitimate interests include, for example, having the burden of proof in a procedure under the General Equal Treatment Act (AGG).

8. Legal basis for processing

Article 6(I)(a) of the GDPR serves our company as the legal basis for processing operations in which we obtain consent for a particular processing purpose. If it is necessary to process personal data in order to fulfill a contract in which the data subject is a party, as is the case, for example, in processing operations necessary for delivering goods or providing any other service or equivalent, then such processing is based on Article 6(I)(b) of the GDPR. The same applies to processing operations that are necessary to carry out pre-contractual activities, such as in cases of inquiries regarding our products or services. If our company is subject to a legal obligation which requires the processing of personal data, such as fulfilling our tax obligations, then such processing is based on Article 6(I)(c) of the GDPR. In rare cases, it may be necessary to process personal data in order to protect the vital interests of the data subject or another natural person. This would be the case, for example, if someone visiting our premises were injured and his or her name, age, health insurance or other vital information would have to be passed on to a doctor, hospital or other third party. Then the processing would be based on Article 6(I)(d) of the GDPR. And finally, processing operations can be based on Article 6(I)(f) of the GDPR. Processing operations are based on this legal basis if they are not covered by any of the legal bases above and if such processing is necessary to safeguard the legitimate interests of our company or a third party, provided that the data subject’s interests, fundamental rights and freedoms do not outweigh them. We are permitted such processing operations in particular because they have been specifically mentioned by the European legislative authority. In this regard, the authority was of the opinion that a legitimate interest could be assumed if the data subject is a customer of the controller (second sentence of recital 47 to the GDPR).

9. Legitimate interests in the processing pursued by the controller or by a third party

Where the processing of personal data is based on Article 6(I)(f) of the GDPR, our legitimate interest is to conduct our business for the benefit and welfare of all of our employees and shareholders.

10. Period for which the personal data will be stored

The criteria used to determine the storage period for personal data is the respective statutory retention period. After that period has elapsed, the corresponding data is routinely deleted, provided that it is no longer necessary for the fulfillment of a contract or the initiation of a contract.

11. Provision of personal data as a legal or contractual requirement; Necessity for the conclusion of the contract; The data subject’s obligation to provide personal data; potential consequences of non-provision

Clarification is made that the provision of personal data is in part required by law (such as for tax regulations) or may also result from contractual arrangements (such as details about the contractual partner). For conclusion of a contract, it may occasionally be necessary for a data subject to provide us with personal data which we will need to process subsequently. The data subject is obliged, for example, to provide us with personal data when our company enters into a contract with him or her. A consequence of non-provision of the personal data would be that the contract with the data subject cannot be concluded. The data subject must contact one of our employees before the data subject provides any personal data. Our employee will inform the data subject on a case-by-case basis whether the provision of the personal data is a legal or a contractual requirement, or required for the conclusion of the contract, whether there is an obligation to provide the personal data and the consequences of failing to provide the personal data.

12. Existence of automated decision-making

As a responsible company, we do not use automatic decision-making or profiling.

13. Integration of third-party services and content

a) Links to other websites

Our site contains links to other websites. We have no influence over the extent to which these linked websites comply with the applicable data protection regulations. Therefore, we recommend that you read the respective website’s privacy policy.

b) Social Bookmarks

Social bookmarks (e.g. from Facebook and Twitter) are integrated on our website. Social bookmarks are Internet bookmarks with which the users of such a service can collect links and news messages. These are only integrated on our website as a link to the corresponding services. After clicking on the embedded graphic, you will be redirected to the page of the respective provider, i.e. only then will user information be transmitted to the respective provider. For information on how your personal data is handled when using these websites, please refer to the respective provider’s privacy policy.

c) Regiondo

To distribute our offers, we use the booking system of Regiondo GmbH, Neumarkter Str. 63, 81673 Munich. When you make a booking on our site, you agree to the storage and processing of your personal data by Regiondo. Your personal data will be forwarded to Regiondo and processed. This storage and processing of data is for the purpose of supporting and processing your orders, authenticating you, processing payments and improving Regiondo’s services. For more information on terms of use and data protection and the possible commissioning of third parties for data processing by Regiondo, please visit https://pro.regiondo.com/de/datenschutz/.

d) PayPal

The PayPal service is provided by PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. When using PayPal to make a payment, you will be redirected to PayPal’s website by a link. For the use of this service, PayPal collects, stores and processes your personal data such as your name, address, telephone number and email address, as well as your credit card or bank account details. PayPal alone is responsible for protecting and handling the data that PayPal collects. PayPal’s terms of use apply in this respect; you can access them at www.PayPal.com. For additional information about how your data is handled and the potential commissioning of third parties, please refer to PayPal’s Privacy Policy which is available at https://www.paypal.com/de/webapps/mpp/ua/privacy-full.

e) Stripe

Services for payment by [bank transfer, credit and debit cards, SEPA direct debit, Sofortüberweisung, Giropay, iDeal and Bancontact] are provided by Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA. For the use of these services, Stripe collects, stores and processes personal data in accordance with the Stripe Terms of Use, and is responsible for the lawful handling thereof. For more information, please see Stripe’s privacy policy at https://stripe.com/de/privacy#translation.

Stripe, Inc. also processes your personal data in the U.S. and has submitted to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework –  Complied with the requirements of the European Commission’s adequacy decision on the EU-US data protection framework of July 10, 2023.

f) YouTube.com

This website integrates videos from the website YouTube. The operator of the pages is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. Through this integration, the provider of this service receives the same information as we do (see under 5.) , when you call up our pages. In addition, it receives the information that the call was made via our site. To what extent this data is collected and processed is beyond our knowledge. The regulations of the respective service apply.

YouTube is used in the interest of an appealing presentation of our online offers.

This represents a legitimate interest within the meaning of Art. 6 Para. 1 lit. f DSGVO. If a corresponding consent has been requested, the processing is based exclusively on Art. 6 (1) aDSGVO; the consent can be revoked at any time.

Further information on the handling of user data can be found in YouTube’s privacy policy at: https://policies.google.com/privacy?hl=de.

Google also processes your personal data in the USA and has submitted to the EU-US Privacy Shield: https://www.privacyshield.gov/EU-US-Framework – Complied with the requirements of the European Commission’s adequacy decision on the EU-US data protection framework of July 10, 2023.

g) Google Maps

This website uses Google Maps to display maps and create driving directions.

Google Maps is operated by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

By using this website, you consent to allowing Google, one of its agents or third party providers to collect, process and use the data that is automatically collected as well as the data you enter on the site.

The terms of use for Google Maps can be found at http://www.google.com/intl/de_de/help/terms_maps.html

You can find detailed information in the google.de Privacy Center: Transparency and choices (http://www.google.com/intl/en/policies/privacy/) and privacy policy (http://www.google.de/intl/de/policies/privacy/)

Google also processes your personal data in the USA and has submitted to the EU-US Privacy Shield: https://www.privacyshield.gov/EU-US-Framework – Complied with the requirements of the European Commission’s adequacy decision on the EU-US data protection framework of July 10, 2023.

h) Google Analytics

Since the Hamburg Commissioner for Data Protection and Freedom of Information reached agreement with Google on the basis of the Düsseldorf Circle’s resolution on the data protection-compliant design of analysis procedures for measuring the reach of Internet offerings, it has been possible to use Google Analytics in a data protection-compliant and complaint-free manner under certain conditions. It goes without saying that we adhere to these conditions. In particular, we point out that on this website Google Analytics has been extended by the code “gat._anonymizeIp();” to ensure anonymized collection of IP addresses (so-called IP masking).

Please also note the following information on the use of Google Analytics:

This website uses Google Analytics, a web analytics service provided by Google Inc (“Google”). Google Analytics uses “cookies”, which are text files placed on your computer, to help the website analyze how users use the site. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there. However, by activating IP anonymization on this website, your IP address will be truncated beforehand by Google within member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other data from Google.

You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser plugin available at the following link: http://tools.google.com/dlpage/gaoptout?hl=de.

Further information on terms of use and data protection can be found at http://www.google.com/analytics/terms/de.html or at https://www.google.de/intl/de/policies/.

Google also processes your personal data in the USA and has submitted to the EU-US Privacy Shield: https://www.privacyshield.gov/EU-US-Framework – Complied with the requirements of the European Commission’s adequacy decision on the EU-US data protection framework of July 10, 2023.

Our website also uses the remarketing function of Google Inc (“Google”). This technology is used to present interest-based advertisements to visitors of the website within the Google Partner Network. The ads are displayed through the use of cookies, which are used to analyze user behavior when visiting the website and can then be used for targeted product recommendations and interest-based advertising. On these pages, the visitor can then be presented with advertisements that relate to content that the visitor has previously accessed on websites that use Google’s remarketing technology. According to its own information, Google does not collect any personal data during this process.

If you do not wish to receive interest-based advertising via Google’s remarketing technology, you can disable Google’s use of cookies for these purposes by making the appropriate settings at http://www.google.com/settings/ads. Alternatively, you can disable the use of cookies for interest-based advertising via the advertising network initiative by following the instructions at http://www.networkadvertising.org/managing/opt_out.asp.

Further information on Google Remarketing and Google’s privacy policy can be found at: https://policies.google.com/technologies/ads?hl=de.

Additional information and Google’s applicable privacy policy can be found at https://www.google.de/intl/de/policies/privacy/ and at http://www.google.com/analytics/terms/de.html. Google Analytics is explained in more detail under this link https://www.google.com/intl/de_de/analytics/.

Google also processes your personal data in the USA and has submitted to the EU-US Privacy Shield: https://www.privacyshield.gov/EU-US-Framework – Complied with the requirements of the European Commission’s adequacy decision on the EU-US data protection framework of July 10, 2023.

i) Google Tag Manager

This website uses Google Tag Manager from Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, to control advertising. Google Tag Manager is a solution that allows marketers to manage website tags through one interface. The Tag Manager tool itself (which implements the tags) is a cookie-less domain and does not collect any personal data. The tool takes care of triggering other tags, which in turn may collect data. Google Tag Manager does not access this data. If a deactivation has been made at the domain or cookie level, it remains in place for all tracking tags implemented with Google Tag Manager.

Google also processes your personal data in the USA and has submitted to the EU-US Privacy Shield: https://www.privacyshield.gov/EU-US-Framework – Complied with the requirements of the European Commission’s adequacy decision on the EU-US data protection framework of July 10, 2023.

j) Google Ads

To raise attention to our services, we place ads on Google Ads. These are displayed after search queries on Google. Our website uses cookies to register how many users have found us via one of our ads. With the anonymous statistics obtained from this, we can optimize our ads. The cookie is stored by Google when you click on an ad and can be disabled via your browser settings. In this case, your visit to our website will also not be included in the anonymous user statistics. You can find more information in the Google website statistics.

Google also processes your personal data in the USA and has submitted to the EU-US Privacy Shield: https://www.privacyshield.gov/EU-US-Framework – Complied with the requirements of the European Commission’s adequacy decision on the EU-US data protection framework of July 10, 2023.

14. Social Media

We maintain publicly accessible profiles on social networks. You can find the social networks we use below.

a) Data processing by social networks

Social networks such as Facebook, Twitter, etc. can generally analyze your user behavior extensively when you visit their website or a website with integrated social media content (e.g. like buttons or advertising banners). Visiting our social media presences triggers numerous processing operations relevant to data protection. In detail:

If you are logged into your social media account and visit our social media presence, the operator of the social media portal can assign this visit to your user account. However, your personal data may also be collected under certain circumstances if you are not logged in or do not have an account with the respective social media portal. In this case, this data collection takes place, for example, via cookies that are stored on your end device or by recording your IP address.

With the help of the data collected in this way, the operators of the social media portals can create user profiles in which your preferences and interests are stored. In this way, you can be shown interest-based advertising inside and outside the respective social media presence. If you have an account with the respective social network, the interest-based advertising can be displayed on all devices on which you have an account.
devices on which you are logged in or have been logged in.

Please also note that we cannot track all processing on the social media portals. Depending on the provider, further processing operations may therefore be carried out by the operators of the social media portals. For details, please refer to the terms of use and data protection provisions of the respective social media portals.

b)  Legal basis

Our social media presences are intended to ensure the most comprehensive presence possible on the Internet. This is a legitimate interest within the meaning of Art. 6 (1) lit. f DSGVO. The analysis processes initiated by the social networks may be based on different legal bases, which are to be specified by the operators of the social networks (e.g. consent within the meaning of Art. 6 (1) aDSGVO).

c) Responsible person and assertion of rights

If you visit one of our social media sites (e.g. Facebook), we are jointly responsible with the operator of the social media platform for the data processing operations triggered during this visit. In principle, you can assert your rights (information, correction, deletion, restriction of processing, data portability and complaint) both against us and against the operator of the respective social media portal (e.g. against Facebook).

Please note that despite the joint responsibility with the social media portal operators, we do not have full influence on the data processing operations of the social media portals. Our options are largely determined by the corporate policy of the respective provider.

d)  Storage duration

The data collected directly by us via the social media presence will be deleted from our systems as soon as you request us to delete it, revoke your consent to store it, or the purpose for storing the data no longer applies. Stored cookies remain on your terminal device until you delete them. Mandatory legal provisions – in particular retention periods – remain unaffected.

We have no influence on the storage period of your data, which is stored by the operators of social networks for their own purposes. For details, please contact the operators of the social networks directly (e.g. in their privacy policy, see below).

Social Media in detail

(1) Facebook

We have a profile on Facebook. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (hereinafter Meta). According to Meta, the collected data is also transferred to the USA and other third countries. This also happens if you yourself are not a registered user of Facebook or are not currently logged in to your Facebook account. The data collected includes, among other things, IP address, information about the operating system, hardware versions and browser type, data about your usage behavior collected from cookies set by Facebook and other technical data.This also happens if you yourself are not a registered user of Facebook or are not currently logged into your Facebook account. The data collected includes, among other things, IP address, operating system information, hardware versions and browser type, data about your usage behavior collected from cookies set by Facebook, and other technical data.

To this extent, we are jointly responsible with Meta for data processing, “joint controllers” within the meaning of Art. 26 DSGVO. The main contents of the joint responsibility agreement between Meta and us can be found at https://de-de.facebook.com/legal/terms/page_controller_addendum.

You can independently adjust your advertising settings in your user account. To do so, click on the following link and log in: https://www.facebook.com/settings?tab=ads

Meta also processes your personal data in the USA and has submitted to the EU-US Privacy Shield: https://www.privacyshield.gov/EU-US-Framework – Complied with the requirements of the European Commission’s adequacy decision on the EU-US data protection framework of July 10, 2023.

For details, see Facebook’s privacy policy:
https://www.facebook.com/about/privacy/

(2) Instagram

We have a profile on Instagram. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. If you visit our account, Instagram collects data and may process it in the USA. This also happens if you are not a registered user of Instagram or are not currently logged in to your Instagram account. According to Instagram, the data collected includes, among other things, IP address, operating system information, hardware versions and browser type, data about your usage behavior collected from cookies set by Instagram, and other technical data. Facebook and we process the data as joint controllers within the meaning of Art. 26 DSGVO.

The main contents of the joint responsibility agreement can be found here.

For details on their handling of your personal data, please refer to Instagram’s privacy policy: https://help.instagram.com/519522125107875.

Meta also processes your personal data in the USA and has submitted to the EU-US Privacy Shield: https://www.privacyshield.gov/EU-US-Framework https://facebook.com/privacy/policies/data_privacy_framework – Complied with the requirements of the European Commission’s adequacy decision on the EU-US data protection framework of July 10, 2023.

(3) Youtube

We have a profile on YouTube. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. (“Google”). If you visit our channel, data will be collected by YouTube and possibly processed in the USA. This also happens if you yourself are not a registered user of Youtube or are not currently logged into your Youtube account. The data collected includes, among other things, IP address, information on the operating system, hardware versions and browser type, data collected from cookies set by Youtube about your usage behavior and other technical data.

For more details, please refer to the privacy policy of Youtube, which you can access at https://policies.google.com/privacy.

This website embeds videos from the website YouTube. When you visit one of our websites on which YouTube is embedded, a connection to the YouTube servers is established. In the process, the YouTube server is informed which of our pages you have visited. Furthermore, YouTube may store various cookies on your terminal device or use comparable technologies for recognition (e.g. device fingerprinting). In this way, YouTube can obtain information about visitors to this website. This information is used, among other things, to collect video statistics, improve the user experience, and prevent fraud attempts. If you are logged into your YouTube account, you allow YouTube to associate your browsing behavior directly with your personal profile. You can prevent this by logging out of your YouTube account.

YouTube is used in the interest of an appealing presentation of our online offers. This represents a legitimate interest within the meaning of Art. 6 para. 1 lit. f DSGVO. If a corresponding consent was requested, the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. aDSGVO; the consent can be revoked at any time.

Further information on the handling of user data can be found in YouTube’s privacy policy at: https://policies.google.com/privacy?hl=de.

Google also processes your personal data in the USA and has submitted to the EU-US Privacy Shield: https://www.privacyshield.gov/EU-US-Framework – Complied with the requirements of the European Commission’s adequacy decision on the EU-US data protection framework of July 10, 2023.

(4) LinkedIn

We have a profile on LinkedIn. The provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. LinkedIn Ireland Unlimited Company is, for the countries of the European Union (EU), the European Economic Area (EEA) and Switzerland, the controller of personal data provided to LinkedIn or collected or processed by or on behalf of LinkedIn.

If you are located outside of the designated countries, LinkedIn Corporation (headquartered in the U.S.) is the controller for your personal data provided to or collected by or for or processed in connection with our Services.

As a visitor or member and of LinkedIn, the collection, use and disclosure of your personal information is subject to the LinkedIn Privacy Policy and other documents referenced in this Privacy Policy and updates.

For details on their handling of your personal information, please refer to the privacy policy
From LinkedIn: https://www.linkedin.com/legal/privacy-policy.

LinkedIn uses advertising cookies. If you wish to disable LinkedIn advertising cookies, please use the following link: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.