1. Data protection at a glance
General information
The following information provides an overview of what happens to your personal data when you visit our website, contact us, enquire about or book a room, or use the services of our hotel. Personal data means any data that can be used to identify you personally. Detailed information can be found in the following sections of this Privacy Policy.
Who is responsible for data processing?
The controller responsible for data processing is:
Garden Hotel Krefeld
Wolfram Lawall e.K.
Schönwasserstraße 12a
47800 Krefeld
Germany
Telephone: +49 (0) 2151 53523-0
Email: info@gardenhotel.de
Data protection enquiries:
datenschutz@gardenhotel.de
The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data.
How do we collect your data?
Some of your data is collected when you provide it to us. This is the case, for example, when you contact us by email or telephone, submit a reservation enquiry, make an online booking or provide information during your stay.
Other data is collected automatically by our IT systems when you visit our website or after you have given your consent. This primarily includes technical data such as your IP address, browser, operating system and the time at which you accessed the website.
We may also receive reservation data from organisations or companies through which you made your booking, such as online booking platforms, tour operators, travel agencies or corporate customers.
What do we use your data for?
We process personal data in particular:
- to ensure the technical provision and security of our website,
- to process enquiries,
- to provide online booking facilities,
- to establish and perform accommodation contracts,
- to organise and invoice hotel stays,
- to comply with legal obligations, and
- to safeguard legitimate interests, such as ensuring the operation of our hotel and establishing, exercising or defending legal claims.
What rights do you have?
Subject to the applicable legal requirements, you have the right to access, rectification, erasure, restriction of processing, data portability and objection. You may withdraw consent that you have previously given at any time with effect for the future. You also have the right to lodge a complaint with a data protection supervisory authority.
You may contact us at any time regarding these or any other questions concerning data protection.
2. Hosting
Hosting by ALL-INKL.COM
Our website is hosted by:
ALL-INKL.COM – Neue Medien Münnich
Proprietor: René Münnich
Hauptstraße 68
02742 Friedersdorf
Germany
When you access our website, the hosting provider processes technical connection and log data in particular. This may include your IP address, the time of access, the page accessed, the volume of data transferred, the referrer URL, your browser and your operating system.
The processing is based on Article 6(1)(f) GDPR. Our legitimate interest lies in the reliable, secure and technically faultless provision of our website.
We have concluded a data processing agreement with the provider in accordance with Article 28 GDPR.
Further information is available in the data protection information provided by ALL-INKL.COM.
3. General information on data processing
Data protection
We treat your personal data confidentially and in accordance with the applicable data protection legislation and this Privacy Policy.
Please note that data transmitted via the internet, for example in email communications, may be subject to security vulnerabilities. Complete protection of data against access by third parties is not possible.
Legal bases
Depending on the purpose, personal data is processed on the following legal bases in particular:
- Article 6(1)(a) GDPR, where you have consented to the processing,
- Article 6(1)(b) GDPR, where processing is necessary in order to take steps prior to entering into a contract or to perform a contract,
- Article 6(1)(c) GDPR, where processing is necessary to comply with a legal obligation, and
- Article 6(1)(f) GDPR, where processing is necessary to safeguard our legitimate interests or those of a third party.
Where information is stored on or accessed from your device, this is additionally carried out in accordance with Section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG).
Recipients of personal data
We disclose personal data only where this is permitted for the performance of a contract, compliance with a legal obligation, the pursuit of a legitimate interest or on the basis of another applicable legal ground.
Recipients may include IT, hosting, reservation, booking, payment, accounting and tax advisory service providers engaged by us, as well as booking platforms, tour operators and legally authorised public authorities.
Processors are engaged in accordance with Article 28 GDPR.
Storage period
Unless a more specific storage period is stated in this Privacy Policy, we retain personal data only for as long as it is required for the relevant purpose.
The data is subsequently deleted unless statutory retention obligations or other legally permissible grounds require its continued storage. In such cases, the relevant data is deleted after expiry of the applicable retention period.
4. Your rights
Withdrawal of consent
You may withdraw consent that you have previously given at any time with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.
Right to object under Article 21 GDPR
Where data processing is based on Article 6(1)(e) or (f) GDPR, you have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data. This also applies to profiling based on those provisions.
If you object, we will no longer process the personal data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing is necessary for the establishment, exercise or defence of legal claims.
Where your personal data is processed for direct marketing purposes, you have the right to object at any time to processing for such purposes. After you object, your personal data will no longer be used for direct marketing.
Access, rectification and erasure
Within the scope of the applicable legal provisions, you have the right to obtain information free of charge concerning your stored personal data, its origin and recipients, and the purpose of its processing. Where applicable, you also have the right to request rectification or erasure of this data.
Right to restriction of processing
Subject to the applicable legal requirements, you have the right to request the restriction of processing of your personal data. This applies in particular:
- while we verify the accuracy of data that you have contested,
- where the processing is unlawful and you request restriction rather than erasure,
- where we no longer require the data, but you need it for the establishment, exercise or defence of legal claims, or
- while an objection under Article 21(1) GDPR is being assessed.
Right to data portability
You have the right to receive data that we process by automated means on the basis of your consent or for the performance of a contract in a commonly used, machine-readable format. Where technically feasible, you may also request that the data be transmitted to another controller.
Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. This applies in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement.
The supervisory authority responsible for us is:
State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia
Kavalleriestraße 2–4
40213 Düsseldorf
Germany
Website:
www.ldi.nrw.de
5. Data processing on our website
SSL or TLS encryption
For security reasons and to protect the transmission of confidential content, our website uses SSL or TLS encryption. You can identify an encrypted connection by the fact that the address bar of your browser begins with “https://” and a padlock symbol is displayed.
Cookies and similar technologies
Our website may use cookies or similar technologies. Cookies are small data packages stored on your device. They may be stored temporarily for the duration of a session or for a longer period and may originate either from us or from third-party providers.
Strictly necessary cookies and similar technologies are used where they are essential for transmitting a message over a public telecommunications network or for providing a service expressly requested by you. Where personal data is processed in this context, the legal basis is, depending on the purpose, in particular Article 6(1)(b) or (f) GDPR. Access to your device is governed by Section 25(2) TDDDG.
Cookies or similar technologies that are not strictly necessary are used only with your consent. The legal bases are Article 6(1)(a) GDPR and Section 25(1) TDDDG. You may withdraw your consent at any time with effect for the future.
You can configure your browser to notify you when cookies are set, to allow cookies only in individual cases or to reject cookies in general. Disabling strictly necessary cookies may restrict the functionality of the website.
Enquiries by email, telephone or fax
If you contact us by email, telephone or fax, we process the information you provide, including the resulting contact details, in order to handle your enquiry.
Where necessary to process your enquiry, take steps prior to entering into a contract or perform a contract, your information may be processed in the communication, reservation and administration systems that we use. Contractually engaged processors may be used for this purpose.
The legal basis is Article 6(1)(b) GDPR if your enquiry relates to a contract or is necessary in order to take steps prior to entering into a contract. In other cases, processing is based on our legitimate interest in handling your enquiry effectively pursuant to Article 6(1)(f) GDPR or, where obtained, on your consent pursuant to Article 6(1)(a) GDPR.
The data is deleted once your enquiry has been fully resolved and no statutory retention obligations or other legal grounds require its continued storage.
Matomo
We use the open-source web analytics service Matomo to evaluate the use of our website and improve our services from a technical and content perspective. The data processed may include pages accessed, the time and duration of access, approximate location, referrer URL, browser, operating system and truncated IP address.
Matomo is configured so that no analytics cookies are stored on your device. Your IP address is truncated before analysis so that it can no longer be readily associated with you.
The processing is based on Article 6(1)(f) GDPR. Our legitimate interest lies in the privacy-friendly analysis and improvement of our website.
We host Matomo ourselves on a server used by us. Analytics data is not transferred to an external analytics provider.
6. Processing of guest and reservation data
Nature and purpose of the processing
If you enquire about or book a room, stay at our hotel or use any of our other services, we process the personal data required for these purposes.
This may include in particular:
- personal details, in particular your name, title and, where applicable, date of birth,
- contact details, in particular your address, email address and telephone number,
- reservation and stay details, in particular arrival and departure dates, booked services, room, number of guests and booking channel,
- billing and payment information,
- communications and any requests or comments provided by you,
- registration data required by law, and
- information required under tax and commercial law.
The processing is carried out in order to handle enquiries, take steps prior to entering into a contract, establish and perform the accommodation contract, organise your stay, invoice our services and comply with legal obligations.
The legal bases are Article 6(1)(b) GDPR for steps taken prior to entering into a contract and for performance of the accommodation contract, and Article 6(1)(c) GDPR where we are legally required to process or retain certain data.
Where processing is necessary to organise and secure our hotel operations, handle subsequent enquiries or establish, exercise or defend legal claims, it is based on Article 6(1)(f) GDPR.
Source of reservation data
We receive reservation data either directly from you or from organisations or companies through which you made your booking. These may include online booking platforms, tour operators, travel agencies, corporate customers and booking or distribution systems used by us.
Where we do not obtain personal data directly from you, we generally process the same categories of data for the same purposes and on the same legal bases as described in this section.
Recipients
Where necessary to process the booking, provide the stay, issue invoices or comply with legal obligations, personal data may be disclosed to appropriately engaged IT, reservation, booking, payment, accounting and tax advisory service providers, as well as to legally authorised public authorities.
Storage period
We retain guest and reservation data for as long as necessary to provide and invoice the stay, handle subsequent enquiries or establish, exercise or defend legal claims.
Where statutory retention obligations apply, the relevant documents are retained for the legally prescribed period and subsequently deleted. Operational data is retained in accordance with the periods defined in our data deletion policy.
Use of the ibelsa hotel software
We use the cloud-based “ibelsa.rooms” hotel software provided by the following company to manage reservations, guests, stays, services, invoicing and related communications:
ibelsa GmbH
Sybelstraße 41
10629 Berlin
Germany
ibelsa GmbH processes the personal data required for these purposes on our behalf and in accordance with our instructions. We have concluded a data processing agreement with the provider pursuant to Article 28 GDPR.
Further information is available in the Privacy Policy of ibelsa GmbH.
Online bookings and booking distribution via SiteMinder
We use a booking engine and channel manager provided by the SiteMinder group of companies to display room availability and prices, accept direct bookings through our website and transmit reservations between booking platforms and our hotel software.
When you use the booking engine or a reservation is transmitted through the channel manager, the following categories of personal data may be processed in particular:
- technical connection data, in particular your IP address and browser and device information,
- travel dates, length of stay, room selection and number of guests,
- personal and contact details, in particular your name, address, email address and telephone number,
- reservation, price, rate and booking-channel information,
- payment or guarantee information, where applicable, and
- requests or comments provided by you in connection with the booking.
The processing is carried out to provide the online booking facility, handle pre-contractual enquiries and establish and perform the accommodation contract. The legal basis is Article 6(1)(b) GDPR.
Where information must be stored on or accessed from your device in order to provide the booking engine, this is carried out on the basis of Section 25(2) no. 2 TDDDG. Where cookies or similar technologies that are not strictly necessary are used, this is done only with your consent pursuant to Section 25(1) TDDDG and Article 6(1)(a) GDPR.
SiteMinder generally processes the personal data required for booking administration and distribution as a processor in accordance with Article 28 GDPR.
SiteMinder is part of an international group of companies and uses additional sub-processors. According to SiteMinder, processing within the systems operated by SiteMinder generally takes place in the United States. Depending on the service and sub-processor used, personal data may also be processed in other countries within and outside the European Economic Area.
Where personal data is transferred to a country for which the European Commission has not adopted an adequacy decision, SiteMinder states that it relies in particular on the European Commission’s Standard Contractual Clauses pursuant to Article 46(2)(c) GDPR. SiteMinder also states that it implements additional contractual, technical and organisational safeguards.
Further information is available in SiteMinder’s Privacy Policy and on SiteMinder’s GDPR compliance page.
7. Video surveillance
To protect our guests, employees and property, and to prevent and investigate criminal offences, clearly identified publicly accessible areas of our hotel are subject to video surveillance. Private areas such as hotel rooms and bathrooms are not monitored.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interests include the protection of persons and property, the exercise of our domestic authority and the prevention and investigation of criminal offences.
Recordings may be accessed only by authorised persons. They are disclosed only where this is required to investigate or prosecute an incident or where disclosure is required by law, in particular to the police, public prosecutors, insurers or legal advisers.
Recordings are retained only for a short period necessary for the purposes stated above and are then deleted automatically. They are retained for a longer period only where this is necessary in connection with a specific incident in order to preserve evidence, pursue legal claims or comply with legal obligations.
8. Objection to unsolicited advertising emails
We object to the use of the contact details published in fulfilment of legal notice requirements for the purpose of sending unsolicited advertising or informational materials. We reserve the right to take legal action in the event of unsolicited advertising, including spam emails.