Privacy Policy
Information on data processing pursuant to Articles 13 and 14 of the GDPR
We are delighted that you are visiting our website. The protection and security of your personal information whilst using our website is very important to us. We would therefore like to take this opportunity to inform you about which of your personal data we collect when you visit our website and for what purposes this data is used.
This data processing notice applies to the ARCOTEL Hotels & Resorts website, which is accessible via the domain www.arcotel.com and its various subdomains (‘our website’). Through this data protection notice, we inform you about when we store which data and how we use it – naturally in compliance with applicable legislation. Data protection at ARCOTEL Hotels & Resorts is based in particular on the General Data Protection Regulation (GDPR) and the current national data protection laws. When it comes to internet use, we adhere to the Telecommunications Act (TKG) of the Republic of Austria to protect your personal data. Below, we explain what information we collect during your visit to our websites and how it is used.
Who is the data controller and how can I contact them?
Data controller
for the processing of personal data within the meaning of the EU General Data Protection Regulation (GDPR)
ARCOTEL Hotels & Resorts GmbH
Konstantingasse 6–8
1160 Vienna
Austria
Tel.: +43 1485 5000
Email: office@arcotel.com
Data Protection Officer
Data Solution LUD GmbH
Germany
Andreas Thurmann
Email: mail@ds-lud.de
https://datenschutzberater365.de
What is this about?
This privacy policy complies with the legal requirements regarding transparency in the processing of personal data. This refers to all information relating to an identified or identifiable natural person. This includes, for example, information such as your name, age, address, telephone number, date of birth, email address, IP address or your behaviour when visiting a website. Information for which we cannot establish a link to your person (or can only do so with disproportionate effort), e.g. through anonymisation, does not constitute personal data. The processing of personal data (e.g. collection, retrieval, use, storage or transmission) always requires a legal basis and a defined purpose.
Stored personal data is deleted as soon as the purpose of the processing has been fulfilled and there are no legitimate grounds for further retention of the data. We will inform you of the specific retention periods or criteria for storage in the individual processing operations at . Irrespective of this, we may store your personal data in individual cases to assert, exercise or defend legal claims and where statutory retention obligations apply.
Who receives my data?
We only disclose your personal data, which we process on our website, to third parties if this is necessary to fulfil the purposes and is covered by the legal basis (e.g. consent or the protection of legitimate interests) in each individual case. Furthermore, we may, in individual cases, disclose personal data to third parties where this serves to assert, exercise or defend legal claims. Potential recipients may then include, for example, law enforcement agencies, solicitors, auditors, courts, etc.
Where we use service providers to operate our website who process personal data on our behalf as part of a data processing arrangement in accordance with Article 28 of the GDPR, these may be recipients of your personal data. Further information on the use of data processors and web services can be found in the overview of the individual processing operations.
General information on data processing
We generally collect and use personal data only to the extent necessary to provide a fully functional website and our content and services, or where we collect and process the data for other purposes, independent of the website.
Legal basis for the processing of personal data
We process personal data on the following legal bases:
Where we obtain the data subject’s consent for the processing of personal data, Article 6(1)(a) of the GDPR serves as the legal basis.
Where the processing of personal data is necessary for the performance of a contract to which the data subject is a party, Article 6(1)(b) of the GDPR serves as the legal basis. This also applies to processing operations necessary for the implementation of pre-contractual measures.
Where the processing of personal data is necessary to comply with a legal obligation (statutory provisions) to which our company is subject, Article 6(1)(c) of the GDPR serves as the legal basis.
Where processing is necessary to safeguard a legitimate interest of our company or a third party, and the interests, fundamental rights and freedoms of the data subject do not override the former interest, Article 6(1)(f) of the GDPR serves as the legal basis for the processing.
We will refer to the relevant terminology in connection with the respective processing so that you can understand the basis on which we process personal data.
Where personal data is processed on the basis of your consent, you have the right to withdraw that consent at any time with future effect.
Where we process data on the basis of a balancing of interests, you, as the data subject, have the right to object to the processing of your personal data, subject to the provisions of Article 21 of the GDPR.
Data erasure and retention period
The data subject’s personal data will be erased or blocked as soon as the purpose for which it was stored no longer applies. Data may also be retained if this is provided for by European or national legislation in EU regulations, laws or other provisions to which the controller is subject. Data will also be blocked or erased when a retention period prescribed by the aforementioned standards expires, unless there is a need to continue storing the data for the conclusion or performance of a contract.
Collection, processing and use of personal data at ARCOTEL Hotels & Resorts
The purpose of our hotel group is to operate several hotels in Austria and Germany under joint responsibility. Data is collected, processed and used for the purposes set out above.
ARCOTEL Hotels & Resorts GmbH, Konstantingasse 6–8, A-1160 Vienna, is the data controller responsible for providing centralised services. To enhance our services, we manage all data received within our centralised hotel software system across the hotel group. The data controller is the hotel at which the booking is made. The relevant booking data can only be viewed by the data controller; access to a guest’s master data is shared, for example, to make a reservation for another hotel at a later date, to rebook, or to carry out marketing activities centrally. To this end, central services such as reservations and marketing access this data. The legal basis for processing the data is our legitimate interest in data processing within the framework of the centralised management and use of our customers’ and business partners’ data within the hotel group.
Guests’ contact details may be used at a later date for promotional purposes. Promotional campaigns primarily take the form of mailings. The use of the email address requires the guest’s consent.
Your data will only be processed for purposes other than those mentioned above insofar as such processing is permitted under Article 6(4) of the GDPR and is compatible with the original purposes of the contractual relationship. We will inform you of any such further processing of your data prior to it taking place.
Legal basis for data processing
The legal basis for the processing of data is the conclusion of an accommodation contract with the guest. The data provided is stored in our hotel software and used for the performance of the contract.
Data subjects, data and data categories:
To fulfil the stated purposes, the following categories of personal data are collected, processed and used:
Guest data (in particular, first name and surname, address details, contact details, booking details, guest requests, billing details)
Other customer data (in particular: address details, billing and service data)
Prospective customer data (in particular, interest in accommodation, address details)
Recipients to whom the data may be disclosed:
Data may be disclosed to the following recipients:
Internal departments involved in the execution and fulfilment of the relevant business processes (e.g. hotels within the hotel group, central reservations, accounts, sales & marketing, IT department)
Public authorities that receive data in accordance with statutory provisions (e.g. law enforcement agencies, public sector authorities)
External contractors in accordance with Article 28 of the GDPR (service providers)
Other external bodies (e.g. credit institutions, companies, provided that data subjects have given their written consent or where a transfer is permitted on the basis of an overriding legitimate interest)
Purpose of data processing
The main purpose of the collection, processing or use of personal data is the administration, care and hospitality of guests within the framework of the accommodation contract.
Duration of storage
The legislator has laid down a wide range of retention obligations and time limits. Once these time limits have expired, the relevant data and data records are routinely deleted or anonymised if they are no longer required for the performance of the contract. For example, commercial or financial data relating to a completed financial year is deleted after a further ten years in accordance with legal provisions, provided that no longer retention periods are prescribed or required for legitimate reasons. Reservation documents may be destroyed after 6 years, and the specific registration form after one year has elapsed, at the end of the year.
Right to object
You have the right to object to the processing of your data at any time. We have set up the email addressdatenschutz@arcotel.com for this purpose.
Your stay at the hotel
During your stay at our hotels, we collect and process information about guests in our hotel software. Data relating to the following groups of people may be stored:
Guests, business partners, companies
prospective clients and potential clients (e.g. when enquiring about offers)
The data stored may include:
First name and surname
Date of birth
Contact details (telephone number, email address)
Address
Nationality
Company
ID and passport details
Details of services provided
Billing details
Payment processing details (e.g. credit card details)
Video recordings for the collection of evidence in the event of vandalism, burglary, robbery or other criminal offences
If you have made a booking via a hotel portal, a tour operator or a travel agency, your data will be forwarded to us by these providers for the purpose of fulfilling the contract entered into.
Purposes and legal basis for data processing
We use the personal data you provide exclusively to fulfil the agreed contractual services, namely the administration, care and hospitality of guests within the framework of the accommodation contract.
We store your data in our hotel software as well as in reservation, billing and payment systems. In addition to your personal data, this may also include billing details for food and drink, telephone calls made from your room and/or other hotel-specific services.
Under registration regulations (national registration laws), hotels are obliged to have their guests complete a registration form either on-site or online. In addition to the first name, surname and address, this form also contains details of the date of birth, nationality and any family members travelling with the guest. We are also required to ask foreign guests for their identity document number. All other details are provided on a voluntary basis.
Where services are utilised, only data necessary for the provision of those services is generally collected. If further data is collected, this constitutes voluntary information. The processing of personal data takes place exclusively for the purpose of fulfilling the requested services and to safeguard our legitimate business interests in accordance with Article 6(1)(f) of the GDPR.
The legal basis for the centralised processing of data is our legitimate interest in data processing within the framework of the centralised management and use of our customers’ and business partners’ data within the hotel group. Guests’ contact details may be used at a later date for marketing purposes. The use of the email address requires the guest’s consent.
For the purpose of evaluating our hotel and for internal quality management, former guests may submit a review of our hotel after checking out. To this end, we send an email within 14 days of departure, in which we ask for a hotel review. Each review can be published anonymously if requested. Should you not have felt comfortable during your stay at our hotel, we would like to take this opportunity to contact you. The legal basis for the processing of this data is, incidentally, our legitimate interest in data processing.
Data is used for the following purposes:
Registration on arrival and departure, including completion of the registration form
Issuing room keys for yourself and your fellow travellers
Provision of requested services
Processing of payment arrangements
Storing your preferences for future hotel stays
Online reviews and marketing
Our guests’ contact details may be used at a later date for marketing purposes. The use of your email address requires your consent.
Data will only be processed for purposes other than those mentioned above insofar as such processing is permitted under Article 6(4) of the GDPR and is compatible with the original purposes of the contractual relationship. We will inform you of any such further processing of your data prior to it taking place.
Recipients to whom the data may be disclosed:
Public authorities that receive data on the basis of statutory provisions (e.g. law enforcement agencies, public sector authorities)
Internal departments involved in the execution and fulfilment of the relevant business processes (e.g. administration, accounts, sales & marketing, IT department)
Affiliated hotels (master data in the PMS)
External contractors in accordance with Article 28 of the GDPR (service providers)
Other external bodies (e.g. credit institutions)
Deletion of data
The legislator has enacted a wide range of retention obligations and time limits. Once these periods have expired, the relevant data and data records are routinely deleted if they are no longer required for the performance of a contract. For example, commercial or financial data relating to a completed financial year is deleted in accordance with legal requirements after a further ten years, provided that no longer retention periods are prescribed or required for legitimate reasons. Booking documents may be destroyed after 6 years; the registration form after one year has elapsed, at the end of the quarter. Where data is not affected by these provisions, it will be deleted automatically once the stated purposes no longer apply.
Video recordings are stored for 72 hours.
Online booking via the website
On our website, you can book rooms and packages for any ARCOTEL hotel. If you make a booking in this way, the data entered in the booking form will be transmitted to us and stored. This data comprises:
First name, surname,
email address,
telephone number,
Address,
number of travelling companions,
Booking details,
estimated time of arrival,
Requests,
payment details (credit card).
When you make an online booking via our website, this is processed through the online booking system of Amadeus Hospitality Europe, S.L., Carrer de Cristobal de Moura 115, 08019 Barcelona, Spain. All booking details you enter are transmitted in encrypted form. Our contractual partner has undertaken to handle the data you provide in accordance with data protection regulations. It takes all organisational and technical measures to protect your data.
The data will be used exclusively for processing the booking and for communication purposes.
Legal basis for data processing
The legal basis for the processing of the data is the conclusion of an accommodation contract. The data provided is stored in our hotel software and used for the performance of the contract.
To enhance our services, we manage all data received in our central hotel software within ARCOTEL Hotels & Resorts. The data controller is the hotel at which the booking is made. The relevant booking data can only be viewed by the data controller; access to a guest’s master data is shared, for example, to make a reservation for another hotel at a later date, to rebook, or to carry out marketing activities centrally. To this end, centralised departments such as Reservations and Marketing access this data. The legal basis for processing the data is our legitimate interest in data processing within the framework of the centralised management and use of data relating to our guests, customers and business partners within the hotel group.
Purpose of data processing
We process the personal data entered via the form solely for the purpose of handling the booking enquiry and processing payments.
Duration of storage
The data will be deleted or anonymised as soon as it is no longer required to fulfil the purpose for which it was collected. In the case of a contractual relationship, we will delete the data received as soon as national, commercial law, statutory or contractual retention requirements have been met.
Should no contractual relationship arise, we will delete the data at the end of the year following one year.
Right to object
You have the right to object to the processing of your data at any time. We have set up the email addressdatenschutz@arcotel.com for this purpose. Please note that, in the event of an objection, the booking cannot be completed or the conversation continued.
‘THE GUESTBOOK’ Cash Rewards Programme
Via our website, you have the option to take part in The Guestbook’s Cash Rewards Programme. If you choose to do so, the data entered in the form will be transmitted to The Guestbook and stored. This data comprises: first name, surname and email address; and, in the case of a booking made via our online booking system, the booking reference, guest turnover and reward information.
The Guestbook is a rewards-based direct booking platform developed specifically for the hotel industry. The platform offers our guests three flexible redemption options: 5% cashback, 5% Cash for a Cause, or 15% Cash Forward for future stays at participating hotels. By registering on the platform, you agree to The Guestbook’s Terms and Conditions: https://theguestbook.com/terms. The loyalty programme is operated by Guestbook Rewards, Inc., 10785 W. Twain Ave, Suite 100, Las Vegas, NV 89135, USA. The Guestbook is committed to handling the data you provide in accordance with data protection regulations and is certified under the Data Privacy Framework Programme.
Legal basis for data processing
The legal basis for the processing is our legitimate interest in ensuring that guests who book via our website can take part in the Cash Reward Programme. We thereby offer our guests a price advantage. The Guestbook is itself responsible for the processing of the data.
Purpose of data processing
Your personal data is processed to manage your participation in The Guestbook Cash Rewards Programme and to pay out rewards to you.
Duration of storage
We have no influence over the specific retention period for the processed data; this is determined by The Guestbook. Further information can be found in The Guestbook’s privacy policy: https://theguestbook.com/privacy.
Right to object
You have the right to object to the processing of your data at any time. To do so, you can opt out of using the service via our Consent Manager (cookie banner). In this case, no connection to The Guestbook will be established via our website.
Online booking via other websites
ARCOTEL Hotels & Resorts offers prospective guests and customers (guests) the option to book rooms and packages for any ARCOTEL hotel via hotel booking portals (third-party providers). If you make use of this option, the data entered in the form will be transmitted to us and stored to the extent permitted by the respective hotel booking portal in accordance with its own data protection policy. This data may include:
First name, surname,
email address,
telephone number,
address,
number of travelling companions,
Booking details,
estimated time of arrival,
Requests,
payment details (credit card).
The data provided is transferred to our hotel software via a so-called channel manager. All booking details received are transmitted in encrypted form. Amadeus Hospitality Europe, S.L., Carrer de Cristobal de Moura 115, 08019 Barcelona, Spain, as the provider of the channel manager, has undertaken to handle the personal data transmitted in accordance with data protection regulations. It takes all organisational and technical measures to protect your data.
In this context, the data is not passed on to any third parties. The data is used exclusively for processing the booking and, where necessary, for communication purposes.
Legal basis for data processing
The legal basis for the processing of the data is the conclusion of an accommodation contract. The data provided is stored in our hotel software and used for the performance of the contract.
To enhance our services, we manage all data received in our central hotel software within ARCOTEL Hotels & Resorts. The data controller is the hotel at which the booking is made. The respective booking data can only be viewed by the data controller responsible for ; access to a guest’s master data is shared, for example, to make a reservation for another hotel at a later date, to rebook, or to carry out marketing activities centrally. To this end, centralised services such as reservations and marketing access this data. The legal basis for the processing of the data is our legitimate interest in data processing within the framework of the centralised management and use of the data of our guests, customers and business partners within the hotel group.
Purpose of data processing
We process the personal data entered via the form solely for the purpose of handling the booking enquiry and processing payments.
Duration of storage
The data will be deleted or anonymised as soon as it is no longer required to fulfil the purpose for which it was collected. In the case of a contractual relationship, we will delete the data received as soon as national, commercial law, statutory or contractual retention requirements have been met.
If no contractual relationship is established, we will delete the data at the end of the year following one year.
ARCOTEL has no influence over the retention periods applied by the respective hotel booking portal.
Right to object
You have the right to object to the processing of your data at any time. We have set up the email addressdatenschutz@arcotel.com for this purpose. Please note that, in the event of an objection, the booking cannot be finalised or the conversation continued.
Table reservations
Our website offers the option to reserve a table at our restaurants. If a user makes use of this option, the data entered in the form is transmitted to us. This data comprises:
First name, surname,
email address,
telephone number,
details of the table booking (date, time, number of people, restaurant).
When you make a table reservation, this is also done for selected restaurants in our hotels via the online booking system of Quandoo GmbH, Sonnenburger Str. 73, 10437 Berlin, Germany. All order details you enter are transmitted in encrypted form. Quandoo is committed to handling the data you provide in accordance with data protection regulations. Quandoo takes all organisational and technical measures to protect your data.
Legal basis for data processing
The legal basis for the processing of data is, first and foremost, our legitimate interest in data processing, as well as the user’s consent to data processing, which is given by accepting Quandoo’s privacy policy and terms of use.
Purpose of data processing
The processing of personal data is carried out solely for the purpose of making a table reservation.
Retention period
The data will be deleted at our restaurants as soon as it is no longer required to fulfil the purpose for which it was collected. Please refer to Quandoo’s privacy policy for information on their data retention periods.
Right to object
You have the right to object to the processing of your data at any time. We have set up the email addressdatenschutz@arcotel.com for this purpose.
Online service for corporate customers
On our website, corporate customers have the option to register via ‘Fastlane’ in a secure corporate customer area in order to make bookings through this service. If a corporate customer makes use of this option, the following details will be collected:
Company name,
title, first name, surname,
email address,
telephone number,
business or billing address and
login details
are stored in the customer profile. When a booking is made, the
title, first name and surname,
email address and
requests
for the employee are stored alongside the general booking details on the website.
If you make an online booking via “Login Fastlane” on our websites, this is processed by the protel Web Booking Engine operated by protel hotelsoftware GmbH, Europaplatz 8, D-44269 Dortmund. All booking details you enter are transmitted in encrypted form. Protel is committed to handling the data you provide in accordance with data protection regulations and takes all organisational and technical measures to protect your data.
Legal basis for data processing
The legal basis for the processing of data is the conclusion of a sales contract with the corporate customer. The data transmitted is stored in our hotel software and used for the performance of the contract.
Purpose of data processing
The processing of personal data from the user account and the associated bookings serves solely to process the bookings and handle payment transactions.
Duration of storage
The data will be deleted as soon as it is no longer required to fulfil the purpose for which it was collected. In the case of a contractual relationship, we will delete the data received as soon as national, commercial law, statutory or contractual retention requirements have been met.
Right to object
You have the right to object to the processing of your data at any time. We have set up the email addressdatenschutz@arcotel.com for this purpose.
Purchasing a voucher via the website
Our website offers the option to purchase vouchers. If you choose to do so, the data entered in the input form will be transmitted to us and stored. This data comprises:
Title/Company,
First name, Surname,
Date of birth,
Email address,
Postal address,
Telephone/Fax,
Voucher value,
Preferences,
Payment details,
Password for individual user account.
When you purchase a voucher via our website, this is processed via the online ordering platform of INCERT eTourismus GmbH & Co KG, Leonfeldner Straße 328, A-4040 Linz, Austria. All order details you enter are transmitted in encrypted form. INCERT is committed to handling the data you provide in accordance with data protection regulations. INCERT takes all organisational and technical measures to protect your data.
Legal basis for data processing
The legal basis for the processing of data is the conclusion of a contract of sale.
Purpose of data processing
We process the personal data entered via the form solely for the purpose of processing the voucher purchase and handling the payment transaction.
Duration of storage
The data will be deleted as soon as it is no longer required to fulfil the purpose for which it was collected. In the case of a contractual relationship, we will delete the data received as soon as national, commercial law, statutory or contractual retention requirements have been met.
Right to object
You have the right to object to the processing of your data at any time. We have set up the email addressdatenschutz@arcotel.com for this purpose.
Sending emails prior to arrival
Prior to our guests’ arrival, we would like to send a welcome email to those from whom we have received an email address as part of the booking process, or where we are able to contact the guest via a hotel booking portal. A few days before arrival, the guest will receive a booking summary by email, along with information regarding the booking and any available additional services.
When we send these emails, this is done via Amadeus Hospitality Europe, S.L., Carrer de Cristobal de Moura 115, 08019 Barcelona, Spain. Amadeus is committed to handling the data you provide in accordance with data protection regulations. Amadeus takes all organisational and technical measures to protect your data.
Legal basis for data processing
The legal basis for the processing of data is our legitimate interest in data processing in connection with the booking, in conjunction with Section 107(2) and (3) of the Telecommunications Act (TKG) (in Austria); Section 7(3)(1) to (4) of the Unfair Competition Act (UWG) (in Germany).
Purpose of data processing
By contacting you, we wish to give you the opportunity to check the details of your booking and, if necessary, to book additional services quickly and conveniently.
Duration of storage
The data will be deleted as soon as it is no longer required to fulfil the purpose, i.e. as soon as national, commercial law, statutory or contractual retention requirements have been met.
Right to object
You have the right to object to the processing of your data at any time. We have set up the email addressdatenschutz@arcotel.com for this purpose.
Online check-in with Code2Order (straiv)
We would like to offer the following in our hotels:
Arcotel Castellani
Arcotel Donauzentrum
Arcotel Althanquartier
send a welcome email prior to arrival for online check-in to those guests for whom we have received an email address as part of the booking or for whom we already hold one. A few days before arrival, these guests will receive a booking summary by email and will be asked to register online. The data collected during online check-in may be used by us to generate an electronic registration form.
When we send these emails, we do so via the Code2Order platform operated by straiv GmbH, Industriestraße 23, 70565 Stuttgart, Germany. straiv is committed to handling the data you provide in accordance with data protection regulations and takes all organisational and technical measures to protect your data. For further information on data protection, please refer to straiv’s privacy policy.
Personal data is processed in the course of using the software. This may include the following personal data:
Master and communication data (e.g. first name and surname, email address, telephone number)
Address details (e.g. street, house number, postcode, town, country)
Booking and travel data (e.g. arrival and departure dates, booking number, room number)
Registration form data (e.g. nationality, date of birth, passport number, digital signature)
Invoicing data (e.g. billing address, prices, services booked (e.g. parking, gym))
Usage data (e.g. start, duration and end of usage, feature used, language used, browser and operating system used)
Geolocation data (e.g. GPS position)
Not all of the above data categories are collected or requested every time the software is used. This depends on the settings we have individually configured or the services we use. In principle, the software can be used without user registration.
Legal basis for data processing
The legal basis for processing the data is, first and foremost, our legitimate interest in data processing in the context of the booking. When processing data generated in the course of communication, we have a legitimate interest in processing the data in accordance with legal requirements, for internal verification purposes or in line with the specific purpose of the communication, provided that the communication does not serve to fulfil the contractual relationship.
We wish to use the personal data we collect as part of the online check-in process to supplement your details in our hotel software for the purpose of contract fulfilment. In addition, where provided for, the data may be used to unlock your hotel room door via an app. The system automatically checks whether you are authorised to request or use a service provided.
Where we are legally obliged to collect and store personal data (e.g. registration form data), we base the processing on the fulfilment of a legal obligation; in the case of the registration form, this is based on Section 29 et seq. of the Federal Registration Act (BMG).
Where we seek your consent for specific processing operations as part of our data processing activities, we base the processing of this personal data on the legal basis of consent. Please note that consent may be withdrawn at any time. Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent prior to its withdrawal.
Purpose of data processing
By contacting you, we wish to provide you, as a guest, with the opportunity to receive information prior to your upcoming stay and to enable you to check in in advance and complete the electronic registration form.
Categories of recipients
straiv, as the software provider, and its sub-processors for services such as hosting, SMS, email distribution and the provision of a chatbot. Where the data subject has given their consent and this is necessary for the use of various functions, processors in third countries (the USA) may also be used, and data may be transferred to them. straiv enters into contracts with these sub-processors to ensure processing complies with the GDPR. A detailed list of sub-processors can be found here: https://straiv.io/legal/avv/.
Other service providers we engage, e.g. hotel booking systems, door access systems, chatbots, operations and communication software, etc.
Payment service providers
Other external bodies, provided the data subject has given their consent or a transfer is permissible on the grounds of an overriding legitimate interest.
Public authorities where there are legal obligations: We reserve the right, where there is a legal obligation, to disclose information about you if we are required to do so by lawfully acting public authorities or law enforcement agencies. The legal basis is Article 6(1)(c) of the GDPR (legal obligation).
Duration of storage
The data will be deleted as soon as it is no longer required to fulfil the purpose for which it was collected.
Use of cookies and similar technologies, which Straiv uses responsibly
The software uses cookies and similar technologies to enhance the user experience. You can generally prevent the use of cookies by disabling them in your browser. You can adjust your preferences in the system settings at any time. The following technically necessary cookies and similar technologies (local storage) are used:
straiv.io, swVersion, stores the Service Worker version or the current software version, validity: 1 year straiv GmbH, Industriestraße 23, 70565 Stuttgart, Germany
straiv.io, current_version, stores the software version; validity: 1 year; straiv GmbH, Industriestraße 23, 70565 Stuttgart, Germany
straiv.io, current_guest, stores the current guest session; validity: 1 year; straiv GmbH, Industriestraße 23, 70565 Stuttgart, Germany
straiv.io, current_business, stores hotel information: hotel name, hotel address, geolocation, time zone, links to media (logo, icon), contact details, enabled languages, validity: 1 year straiv GmbH, Industriestraße 23, 70565 Stuttgart, Germany
straiv.io, securels_metadata, performs encryption; validity: 1 year; straiv GmbH, Industriestraße 23, 70565 Stuttgart, Germany
The legal basis is the data controller’s legitimate interest in ensuring a secure and fully functional application. The following third-party analytics cookies are used:
Google Maps, validity: 3 months Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland
App Monitoring, Error Tracking & Real User Monitoring, Error Tracking, Validity: Session SmartBear Software Inc., 450 Artisan Way, Somerville, Massachusetts 02145, United States; Error Tracking
eu.datadog.com, Product Analytics, Validity: Session PostHog Inc, 2261 Market St #4008, CA 94114 San Francisco, United States
eu.datadog.com, Product Analytics Datadog, Inc., 620 8th Avenue, 45th Floor, NY 10018 New York, United States
The legal basis is your consent. Consent may be withdrawn at any time. Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent prior to its withdrawal.
Messages via WhatsApp
If you agree to receive messages via WhatsApp, you are giving us your voluntary consent to send you messages, including promotional information on the selected topics, via the instant messaging service ‘WhatsApp’, or to communicate with you via WhatsApp. On the basis of your consent, we process your personal data (e.g. name, telephone number, message content) using WhatsApp, provided by WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
In order to be able to offer you such communication via WhatsApp, straiv, as the software provider, and our data processor, Bird B.V., Gelrestraat 16, 1079 MZ, Amsterdam, act as sub-processors in accordance with Article 28 of the GDPR. In some cases, WhatsApp, LLC in the USA receives personal data (in particular communication metadata) from WhatsApp Ireland Ltd, which is also processed on servers in countries outside the EU (e.g. the USA). WhatsApp passes this data on to other companies within and outside the Facebook group. Further information can be found in WhatsApp’s Privacy Policy (https://www.whatsapp.com/legal/#privacy-policy). WhatsApp LLC is certified under the Trans-Atlantic Data Privacy Framework (TADPF) and thereby guarantees compliance with European data protection law. You may withdraw your consent at any time via the notification settings, by sending a message stating ‘WIDERRUF’ or by emailing one of the email addresses listed above.
Chatbot
We may use a chatbot on our website provided by straiv GmbH, Industriestraße 23, 70565 Stuttgart, Germany (hereinafter “straiv”). The chatbot is designed to answer questions about our hotel and your stay. To optimise these responses, the chatbot processes the following personal data: first name, age, booking number, arrival and departure dates. If you enter personal data into the chatbot’s input field, this data will also be processed by our chatbot. straiv processes your data as a data processor solely for the purpose of answering your questions and does not use this data for its own purposes. The chat data is deleted after one year. The legal basis for the processing of your data is your consent in accordance with Article 6(1)(a) of the GDPR. You may withdraw this consent at any time with future effect by closing the chat window. Please note that withdrawing your consent does not affect the lawfulness of any processing carried out on the basis of your consent prior to its withdrawal.
Right to object
You have the right to object to the processing of your data at any time. We have set up the email addressdatenschutz@arcotel.com for this purpose.
Advice and support for corporate contacts
For the purpose of advising and supporting corporate clients, we collect and use the contact person’s details, telephone number, email address and postal address, in addition to those of the business partner or potential business partner. We obtain this information from various sources, either through an enquiry (by email or telephone), or via events, trade fairs, business cards received by our sales staff, etc.
In this context, no data is passed on to third parties.
Legal basis for data processing
The legal basis for processing the data is our legitimate interest in data processing. If the purpose of establishing contact is to conclude a contract, the additional legal basis for processing is the pre-contractual relationship or the conclusion of the contract.
To enhance our services, we manage all data received in the CRM module of our central hotel software within ARCOTEL Hotels & Resorts. The data controller is the hotel with which a business relationship exists. Central departments such as sales, banqueting, reservations and marketing access this data. The legal basis for processing the data is our legitimate interest in data processing within the framework of the centralised management and use of our customers’ and business partners’ data within the hotel group.
Purpose of data processing
We use this contact data exclusively for our own purposes and to tailor our own sales activities to specific needs.
Duration of storage
In principle, no deletion period is specified. However, should our sales department have had no contact with the company contact within 3 years, the sales department will decide whether to delete the company contact’s contact details.
Should the contact be in relation to a pre-contractual matter (enquiry regarding a quote or booking), the data provided will also be stored in our hotel software and used for the performance of the contract. Should no contractual relationship arise, we will delete the data at the end of the year following one year.
Right to object
As a company contact, you have the right to object to the processing of your data at any time. We have set up the email addressdatenschutz@arcotel.com for this purpose. In this case, all personal data relating to the contact person that has been stored in connection with the business partner will be deleted.
Newsletter service
On our website, there are various ways to subscribe to our newsletter service. If you choose to do so, the data entered in the form will be transmitted to us and stored. This data comprises:
email address and
voluntary details such as title, first name, surname, language, preferred destination or topics.
If you subscribe to the newsletter via our website, the data will be stored in our newsletter tool provided by Revinate Inc., 1 Letterman Drive Building C, Suite CM 100, San Francisco, California 94129, USA. Revinate is committed to handling the data you provide in accordance with data protection regulations. It takes all organisational and technical measures to protect your data. For further information on data protection, please visit the website: https://www.revinate.com/privacy/.
Should we receive an email address by other means, where the recipient clearly informs us that they wish to receive our newsletter, we will collect their data via the input form on our website or also transfer it to the Revinate platform (see also ‘Sending emails prior to arrival’).
Legal basis for data processing
The legal basis for processing the data is the recipient’s consent. This is ensured by a double opt-in procedure.
Purpose of data processing
We process personal data solely for the purpose of sending personalised newsletters.
Duration of storage
The data will be deleted or, if necessary, blocked as soon as the newsletter service is unsubscribed from.
Right to object
As a newsletter recipient, you have the right to object to the processing of your data at any time. You can unsubscribe from the newsletter service at any time via a link included in every newsletter. We have also set up the email addressdatenschutz@arcotel.com . Please provide us with your email address via this address.
Online reviews
Former guests may submit a review of their stay at the hotel after check-out. To this end, we would like to send you an email within 14 days of your departure to ask you to submit a hotel review. You also have the option of submitting your review via a paper questionnaire. In this case, we will enter the feedback you provide into the online review system. Any review can be published anonymously if you wish. Should you not have felt comfortable at one of our hotels, we would like to take the opportunity to contact you.
When we send these emails requesting an online review, this is done via Amadeus Hospitality Europe, S.L., Carrer de Cristobal de Moura 115, 08019 Barcelona, Spain. Amadeus is committed to handling the data you provide in accordance with data protection regulations. Amadeus takes all organisational and technical measures to protect your data.
If you submit an online review on our website, the data will be stored in the review tool provided by TrustYou GmbH, Agnes-Pockels-Bogen 1, D-80992 Munich, Germany. TrustYou GmbH is committed to handling the data you provide in accordance with data protection regulations. It takes all organisational and technical measures to protect your data.
If, as a former guest, you make use of this online review option, your data will be stored in the review form. This data comprises:
Email address
as well as voluntary information such as first name, surname, language and the details of the review.
Legal basis for data processing
The legal basis for the processing of this data is the legitimate interest of ARCOTEL Hotels & Resorts. However, you may object at any time to receiving emails requesting a review via the registration form.
Purpose of data processing
The purpose of the hotel review is to communicate and summarise hotel guests’ opinions via our website, so that prospective guests can form their own impression of our facilities and services. In addition, the results are used for our internal quality management. The data is used exclusively for the publication of the review and for resolving disputes in the event of negative reviews.
Duration of storage
The data will not be deleted.
Right to object
You may request the removal of a review at any time (right to be forgotten). We have set up the email addressdatenschutz@arcotel.com for this purpose. Please let us know which review you are referring to.
Conducting competitions and surveys
To enable you to take part in the prize draw, we collect personal data (surname, first name, email address, and, where applicable, postal address).
If we combine surveys with prize draws, we will send emails via our newsletter platform Revinate (see Newsletter). The online survey at is conducted via the service provider QuestionPro GmbH, Friedrichstraße 171, D-10117 Berlin, Germany. When taking part in the online survey, you can register with your first name, surname and email address so that we can contact you if you win. Participation in the prize draw is voluntary. If you do not wish to take part in the prize draw, you may also complete the survey anonymously. QuestionPro GmbH is committed to handling the data you provide in accordance with data protection regulations. It takes all organisational and technical measures to protect your data.
Legal basis for data processing
The legal basis for processing the data is the existence of consent when we use our contacts in the newsletter tool. We use this data, for example, when we link surveys to prize draws. The legal basis for the collection and processing of data from participants in prize draws is our legitimate interest in organising prize draws.
Purpose of data processing
Your data will only be used for the purposes of running the prize draw or analysing our survey, and not for any other purposes, unless you have also opted in to receive a newsletter and have expressly consented to this use of your data. Your data will only be disclosed to third parties to the extent necessary for the running of the prize draw (e.g. system operators for online surveys). Your data will not be passed on to any other third parties.
Duration of storage
Once the business purpose of running the prize draw has been fulfilled and you have not been identified as a winner, we will delete your data within one month of the prize draw ending. If you have been identified as a winner, national, tax and commercial law retention periods apply.
Right to object
As a participant, you have the right to object to the processing of your data at any time. We have set up the email addressdatenschutz@arcotel.com for this purpose.
Online application for a job vacancy
If you provide us with personal data as part of the application process, this data will be classified into the following data types and categories for the purposes of collection, processing and/or use:
Personal data (first name and surname, date of birth, address, educational qualifications)
Communication data (telephone number, mobile number, email address)
Data relating to assessment and evaluation during the application process
Education data (school, vocational training, civilian/military service, degree, PhD)
Data on previous professional experience, training and employment references
Details of other qualifications (e.g. language skills, IT skills, voluntary work)
Application photograph
Application history
If you submit an online application via our website, this is done via the online application system operated by d.vinci HR-Systems GmbH, Nagelsweg 37–39, D-20097 Hamburg, Germany. All application data you enter is transmitted in encrypted form. d.vinci is committed to handling the data you provide in accordance with data protection regulations. It takes all organisational and technical measures to protect your data.
We use the personal data you provide exclusively for the purpose of processing your application for the advertised vacancy. Only those persons involved in the application process will have access to your personal data. All staff entrusted with data processing are obliged to maintain the confidentiality of your data. We will not pass on your personal data to third parties unless you have consented to such disclosure or we are obliged to do so under statutory provisions and/or official or court orders.
Should your application match the profile of another job vacancy published by one of our affiliated companies, we will be happy to forward your application documents. We will seek your consent beforehand. Otherwise, the data will be used exclusively for the processing of your application by the relevant department and for communication purposes.
Legal basis for data processing
The legal basis for processing the data is the pre-contractual relationship or the conclusion of a contract with the applicant. We will seek your consent in advance before forwarding your application documents to an affiliated company.
Purpose of data processing
The processing of personal data from the online form and the documents submitted is used solely for the purpose of processing the application.
Duration of storage
Your data will be automatically deleted within six months of the conclusion of the specific application process. This does not apply if statutory provisions preclude deletion, require further storage for the purposes of providing evidence, or if you have expressly consented to longer-term storage. You will not be notified of the deletion of the data.
Right to object
You may object to the processing of your data at any time. We have set up the email addressdatenschutz@arcotel.com for this purpose. Please note that, in the event of an objection, the application cannot be finalised or the correspondence continued.
Contact form / Email contact
Our website features a contact form which can be used to get in touch with us electronically. If you use this option, you can contact the relevant person via the email addresses provided. In this case, the user’s personal data transmitted with the email will be stored in the email system.
Alternatively, you can submit your enquiry to us via the contact form. The data collected includes: your name, email address and the nature of your enquiry.
The data will not be passed on to third parties.
Legal basis for data processing
The legal basis for processing the data is, first and foremost, our legitimate interest in data processing in the context of the enquirer contacting . If the purpose of the contact is to conclude a contract, the additional legal basis for processing is within the framework of a pre-contractual relationship.
Purpose of data processing
We process the personal data provided via the contact form or in an email solely for the purpose of handling the enquiry.
Any other personal data processed during the submission process is used to prevent misuse of the contact form and to ensure the security of our IT systems.
Duration of storage
The data will be deleted as soon as it is no longer required to fulfil the purpose for which it was collected. For personal data sent by email, this is the case once the relevant conversation with the user has ended. The conversation is deemed to have ended when it can be inferred from the circumstances that the matter in question has been conclusively resolved.
Should the contact relate to a pre-contractual relationship (enquiry regarding an offer or booking), the data provided will also be stored in our hotel software and used for the performance of the contract. Should no contractual relationship arise, we will delete the data at the end of the year following one year.
Right to object
You have the right to object to the processing of your data at any time. We have set up the email addressdatenschutz@arcotel.com for this purpose. Please note that, in the event of an objection, the conversation cannot be continued and we will be unable to provide any offers, etc.
Data processing outside the European Union
Where personal data is processed outside the European Union, please refer to the information provided above.
Information on the use of photographs and video recordings
Purpose and legal basis for processing
The purpose of the processing is to promote our company’s public image, facilitate customer communication and build customer loyalty, as well as to carry out public relations work.
The legal basis for processing the data is your consent.
If 10 or more people are visible in a photograph, e.g. at events, photographs or video recordings may, under certain circumstances, be used even without consent. In this case, the legal basis is our legitimate interest in data processing. In such cases, before publishing any photograph, we check whether any personal rights may be restricted or infringed, in particular if:
a person is prominently featured (if so, then event-specific consent is required for that person)
children or minors are depicted (if so, then event-specific consent, signed by their legal guardians)
At events, we provide advance notice via signs that we will be taking photographs and making video recordings. You are given the opportunity to object to publication at this stage.
If you wish to object to publication at a later date, please contact us by email. We have set up the email addressdatenschutz@arcotel.com for this purpose.
Note on special categories of personal data
Under data protection law, information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or health data is subject to special protection. As even items such as spectacles, walking aids, head coverings or skin colour may fall within this category, consent must also cover such information. We have taken this into account accordingly in the consent text.
Images of you and details about your person (in particular your name) may be passed on to service providers involved in the event of publication. Your personal data may be specifically transferred to a so-called third country through our use of social media services such as Facebook, Instagram or TikTok. Should these services be based in third countries, we ensure that the measures required under the GDPR to guarantee an adequate level of data protection are in place.
We hereby point out that sufficient technical measures have been taken to ensure data protection. Nevertheless, comprehensive data protection cannot be guaranteed when personal data is published on the internet. We would therefore like to draw your attention to the risks of a possible infringement of your rights of personality, so that you are aware that:
images published on our websites or social media platforms are also accessible to search engines. You must therefore expect that your name and images of you may be found by search engines,
personal data published on the internet can also be accessed in countries that do not have data protection regulations comparable to those of the Republic of Austria or the Federal Republic of Germany,
content and images of you can be searched for on social media. The providers of the relevant social media services are primarily responsible for this,
the photos and videos used as part of our social media activities may be analysed by the social media providers or third parties using artificial intelligence (AI). This entails certain risks, such as image recognition and association with individuals, the possibility of misinterpretation of content, or the unintended disclosure of information within the AI’s data pool. We would like to point out that we cannot influence the analysis of this data,
and that the confidentiality, integrity, authenticity and availability of personal data cannot be guaranteed.
We store and process your recordings and associated information until you withdraw your consent or object to their publication.
Copyright notice:
You will not receive any remuneration from us for the use of the image material. By giving your consent, you simultaneously grant us the necessary non-exclusive rights of use for the intended purpose in print media, digital media, social media and audiovisual media, provided that we do not already hold the exploitation rights to the recordings ourselves. If you provide us with a photograph that you did not take yourself, you warrant that you are authorised to grant us the rights of use for that photograph for the intended purpose.
What rights do you have?
If your personal data is processed, you are a data subject within the meaning of the GDPR and you are entitled to the following rights vis-à-vis the data controller:
You have the right to access the personal data stored about you, to be informed of the purposes of the processing, of any transfers to other organisations, and of the duration of storage.
Should any data be inaccurate or no longer necessary for the purposes for which it was collected, you may request that it be rectified, erased or that its processing be restricted. Where provided for in the processing procedures, you may also view your data yourself and correct it where necessary.
Should there be reasons arising from your specific personal circumstances that preclude the processing of your personal data, you may object to such processing, provided that it is based on a legitimate interest. The data controller will no longer process your personal data unless they can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing is necessary for the establishment, exercise or defence of legal claims.
If your personal data is processed for the purposes of direct marketing, you have the right to object at any time to the processing of your personal data for the purposes of such marketing; this also applies to profiling insofar as it is related to such direct marketing. If you object to processing for the purposes of direct marketing or profiling, your personal data will no longer be processed for these purposes.
You have the right to withdraw your consent under data protection law at any time. Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent prior to its withdrawal.
If you have any questions regarding your rights or how to exercise them, please contact the management or the Data Protection Officer.
Your right to lodge a complaint with a supervisory authority
As a data subject, without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence or in the Member State where the alleged infringement occurred, if you consider that the processing of your personal data infringes data protection law.
The supervisory authority to which the complaint is lodged will inform you of the status and outcome of your complaint, including the possibility of a judicial remedy.
Further information can be found on the website of the Federal Data Protection Authority.
For Austria, please follow this link.
For Germany, please follow this link.
Protection of minors
Our service is primarily aimed at adults. We do not currently market any specific sections for children. Consequently, we do not knowingly collect information to determine age, nor do we knowingly collect personal data from children under the age of 16. However, we advise all visitors to our website under the age of 16 not to disclose or provide any personal data via our service at . Should we discover that a child under the age of 16 has provided us with personal data, we will, in accordance with the Children’s Online Privacy Protection Act (see the Federal Trade Commission’s website at www.ftc.gov/kidzprivacy for further information on this Act), delete the child’s personal data from our records, insofar as this is technically possible.
How exactly is your data processed when you visit the website?
Below, we provide information on the individual processing operations, the scope and purpose of data processing, the legal basis, the obligation to provide your data and the respective retention period. No automated decision-making, including profiling, takes place in individual cases.
Provision of the website
Nature and scope of processing
When you access and use our website, we collect the personal data that your browser automatically transmits to our server. The following information is temporarily stored in a so-called log file:
IP address of the requesting computer
Date and time of access
Name and URL of the file accessed
Website from which the access originated (referrer URL)
Browser used and, where applicable, your computer’s operating system, as well as the name of your internet service provider
Our website is not hosted by us, but by a service provider who processes the aforementioned data on our behalf in accordance with Article 28 of the GDPR.
Purpose and legal basis
The processing is carried out to safeguard our overriding legitimate interest in displaying our website and ensuring its security and stability, on the basis of Article 6(f) of the GDPR. The collection of the data and its storage in log files is strictly necessary for the operation of the website. There is no right to object to the processing due to the exception under Article 21(1) of the GDPR. Insofar as the continued storage of log files is required by law, the processing is carried out on the basis of Article 6(1)(c) of the GDPR. There is no legal or contractual obligation to provide the data; however, it is technically impossible to access our website without providing the data.
Retention period
The aforementioned data is stored for the duration of the website’s display and, for technical reasons, for a maximum of 7 days thereafter.
Do we use cookies?
Cookies are small text files which we send to the browser on your device during your visit to our website and which are stored there. As an alternative to the use of cookies, information may also be stored in your browser’s local storage. Some functions of our website cannot be provided without the use of cookies or local storage (technically necessary cookies). Other cookies, however, enable us to carry out various analyses, so that we are, for example, able to recognise the browser you used at when you visit our website again and to transmit various pieces of information to us (non-essential cookies). Among other things, cookies help us to make our website more user-friendly and effective for you by, for example, tracking your use of our website and identifying your preferred settings (such as country and language settings). Where third parties process information via cookies, they collect this information directly via your browser. Cookies do not cause any damage to your device. They cannot execute programmes and do not contain viruses.
We provide information about the specific services for which we use cookies in the individual processing operations. You can find detailed information on the cookies used in the cookie settings or in the Consent Manager on this website.
Cookies used
| Domain | Name | Description | Duration |
|---|---|---|---|
| arcotel.com | _ga | This cookie name is linked to Google Universal Analytics – a major update to Google’s most widely used analytics service. This cookie is used to distinguish unique users by assigning a randomly generated number as a client ID. It is included in every page request on a website and is used to calculate visitor, session and campaign data for the website’s analytics reports. By default, it expires after 2 years, although this can be adjusted by website owners. | approx. 1 year |
| arcotel.com | _gat_UA-4475257-8 | Google Analytics cookies | 4 minutes |
| arcotel.com | _gid | This cookie name is associated with Google Universal Analytics. This appears to be a new cookie, and no information is available from Google as of spring 2017. It appears to store and update a unique value for each page visited. | Approx. 1 day |
| arcotel.com | _hjSession_3251911 | A cookie containing the current session data. As a result, subsequent requests within the session window are assigned to the same Hotjar session. | 33 minutes |
| arcotel.com | _hjSessionUser_3251911 | A Hotjar cookie that is set when a user first lands on a page containing the Hotjar script. It is used to store the Hotjar user ID, which is unique to that website, in the browser. This ensures that behaviour during subsequent visits to the same website is attributed to the same user ID. | approx. 1 year |
| arcotel.com | bassist-session-uuid | Not available | Session |
| arcotel.com | bassist-user-uuid | Not available | approx. 1 year |
| www.arcotel.com | exp_last_activity | This cookie name is associated with the website’s Expression Engine content management system. Most likely relates to the tracking or re-coding of visitor activity. | approx. 1 year |
| www.arcotel.com | exp_last_visit | This cookie name is associated with the website’s Expression Engine content management system. Most likely relates to the tracking or re-coding of visitor activity. | approx. 1 year |
| www.arcotel.com | exp_tracker | This cookie name is associated with the website’s Expression Engine content management system. Most likely relates to the tracking or re-coding of visitor activity. | Session |
| www.arcotel.com | PHPSESSID | A PHP session cookie linked to content embedded from this domain via . | Session |
Presence on social media platforms
We maintain so-called fan pages, accounts or channels on the networks listed below in order to provide you with information and offers within social networks and to offer you further ways to contact us and find out about our services. Below, we explain what data we, or the relevant social network, process in connection with your access to and use of our fan pages/accounts.
Data we process about you
If you wish to contact us via Messenger or direct message on the relevant social network, we will generally process your username, which you use to contact us, and may store any further data you provide, insofar as this is necessary to process or respond to your enquiry.
The legal basis is Article 6(1)(f) of the GDPR (processing is necessary for the purposes of the legitimate interests pursued by the controller).
(Statistical) usage data that we receive from social media platforms
We receive statistics relating to our accounts, which are automatically provided via Insights features. The statistics include, amongst other things, the total number of page views, ‘Likes’, details of page activity and post interactions, reach, video views, and information on the proportion of men and women amongst our fans and followers.
The statistics contain only aggregated data that cannot be traced back to individual persons. We are unable to identify you from this information.
What data the social networks process about you
You do not need to be a member of the relevant social network to view the content on our fan pages or accounts, and therefore no user account for that social network is required.
Please note, however, that when you access the relevant social network, it collects and stores data even from website visitors without a user account (e.g. technical data required to display the website to you) and uses cookies and similar technologies, over which we have no control. Further details can be found in the privacy policies of the relevant social network (see the corresponding links above).
If you wish to interact with the content on our fan pages/accounts – for example, by commenting on, sharing or ‘liking’ our posts – and/or contact us via messaging functions, you must first register with the relevant social network and provide personal data.
We have no control over the data processing carried out by the social media platforms in connection with your use of their services. To the best of our knowledge, your data is stored and processed in particular in connection with the provision of the respective social network’s services, and furthermore to analyse usage behaviour (using cookies, pixels/web beacons and similar technologies), on the basis of which advertising tailored to your interests is displayed both within and outside the respective social network. It cannot be ruled out that your data may be stored by the social networks outside the EU/EEA and passed on to third parties.
Information regarding, amongst other things, the exact scope and purposes of the processing of your personal data, the retention period and deletion, as well as policies on the use of cookies and similar technologies in connection with registration and use of the social networks, can be found in the privacy policies and cookie policies of the social networks. There you will also find information on your rights and options for objecting.
Facebook page
Plugins from the social network Facebook, 1601 South California Avenue, Palo Alto, CA 94304, USA, are integrated into our website. You can recognise the plugins by the logo on our website. An overview of the plugins can be found here: https://developers.facebook.com/docs/plugins/.
We have no influence over the collection of data or its further processing by Facebook. Furthermore, we are unable to ascertain the extent to which, where and for how long the data is stored; the extent to which Facebook complies with existing obligations to delete data; what analyses and links are made with the data; and to whom the data is disclosed. If you wish to prevent Facebook from processing personal data that you have provided to us, please contact us by other means.
Further information on this can be found in Facebook’s privacy policy: https://de-de.facebook.com/policy.php. If you do not wish Facebook to be able to associate your visit to our pages with your user account, please log out of your user account!
Facebook Fan Page
On our Facebook fan page at: https://www.facebook.com/ARCOTELHotels, we use plugins from the provider Facebook.com, which are provided by the company Facebook Inc., 1601 S. California Avenue, Palo Alto, CA 94304, USA.
When you use the fan page, data is transmitted to Facebook’s servers, which contains information about your visits to our fan page. For logged-in users, this means that usage data is linked to their personal Facebook account. As soon as you, as a logged-in Facebook user, actively use the Facebook plugin – for example, by clicking on the ‘Facebook’ logo or using the comment function – this data is transferred to your Facebook account and published. You can only prevent this by logging out of your Facebook account beforehand.
We do not know exactly what data Facebook stores and uses. As a user of the fan page, you must therefore expect that Facebook also stores a complete record of your actions on the fan page.
In addition, the General Terms of Use of Facebook Ireland Limited, Hanover Reach, 5–7 Hanover Quay, Dublin 2, Ireland apply: https://www.facebook.com/terms.php.
The legal basis for this data processing is Article 6(1)(a) and (f) of the GDPR.
Any person depicted, as well as other third parties, has the right at any time to object to the publication of their personal data (photographs). We have set up the email addressdatenschutz@arcotel.com for this purpose: . The right to object applies in particular to the future publication of images.
It may occasionally happen that we inadvertently publish images of people without their consent. If you do not wish your image to be published, we will take immediate steps to comply with your request. In the case of group photographs, we reserve the right to blur faces.
Instagram page
The ‘Instagram button’ is used on this website. When you visit our website: https://www.instagram.com/arcotelhotels/, your browser establishes a connection to the servers of the social network Instagram, provided by Instagram Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA.
When you visit our pages, the plugin establishes a direct connection between your browser and the Instagram server. Instagram thereby receives the information that you have visited our site using your IP address. If you click on the Instagram button whilst logged into your Instagram account, you can link the content of our pages to your Instagram profile. This enables Instagram to associate your visit to our pages with your user account. Please note that, as the provider of this website, we have no knowledge of the content of the data transmitted or how it is used by Instagram.
No data is transferred from our website to Instagram when you visit our website.
Further information on this can be found in Instagram’s privacy policy: http://instagram.com/about/legal/privacy/.
The legal basis for this data processing is Article 6(1)(a) and (f) of the GDPR.
Any person depicted, as well as other third parties, has the right at any time to object to the publication of their personal data (photographs). We have set up the email addressdatenschutz@arcotel.com for this purpose. The right to object applies in particular to the future publication of images.
It may occasionally happen that we inadvertently publish images of people without their consent. If you do not wish your image to be published, we will take immediate steps to comply with your request. In the case of group photographs, we reserve the right to blur faces.
Twitter page
Our website uses social plugins (“plugins”) from the social network operated by Twitter Inc., 795 Folsom St., Suite 600, San Francisco, CA 94107, USA. The Twitter button takes the user via a link to our Twitter page: https://twitter.com/arcotelhotels. No data is transferred from our website to Twitter when you visit our website.
The plugin is marked with a Twitter logo and can be activated directly by the user. If you activate it whilst logged into your Twitter account, you can link the content of our pages to your Twitter profile. This enables Twitter to associate your visit to our pages with your user account if the plugin is activated. Please note that, as the provider of these pages, we have no knowledge of the content of the data transmitted or how it is used by Twitter.
Further information on this can be found in Twitter’s privacy policy: https://twitter.com/privacy.
The legal basis for this data processing is Article 6(1)(a) and (f) of the GDPR.
Any person depicted, as well as other third parties, has the right at any time to object to the publication of their personal data (photographs). We have set up the email addressdatenschutz@arcotel.com for this purpose: . The right to object applies in particular to the future publication of images.
It may occasionally happen that we inadvertently publish images of individuals without their consent. If you do not wish your image to be published, we will take immediate steps to comply with your request. In the case of group photographs, we reserve the right to blur faces.
LinkedIn page
Our website uses social plugins (“plugins”) from the social network LinkedIn, or rather LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA (hereinafter referred to as “LinkedIn”).
The plugin is marked with a LinkedIn logo and can be activated directly by you. When you activate it, the plugin establishes a direct connection to our website: https://www.linkedin.com/company/arcotel-hotels. This means that, when the plugin is activated, LinkedIn receives the information that you have visited our site using your IP address. If you click on the LinkedIn button whilst logged into your LinkedIn account, you can link the content of our pages to your LinkedIn profile. This enables LinkedIn to associate your visit to our pages with your user account.
Please note that, as the provider of these pages, we have no knowledge of the content of the data transmitted or how it is used by LinkedIn. Further information on this can be found in LinkedIn’s privacy policy: https://www.linkedin.com/legal/privacy-policy.
Amazon Web Services
We use the ‘Amazon Web Services’ (AWS) service on our website to host and manage our online infrastructure. The provider is Amazon EU S.à r.l. (“Amazon”), 38 avenue John F. Kennedy, L-1855 Luxembourg.
The legal basis for the use of AWS is our legitimate interest pursuant to Article 6(1)(f) of the GDPR to host our website securely and to ensure its reliable operation, performance and protection against technical problems or misuse.
The data processed by Amazon Web Services includes your IP address, device and browser information, usage data and log data; cookies may also be set for authentication and to enable the service to function.
The purpose of data processing is to provide cloud computing infrastructure and services, including storage, hosting and data management.
It cannot be ruled out that personal data may be transferred to non-EU countries (the USA) where data protection standards are lower than in the EU. Amazon is certified under the EU-US Data Privacy Framework, which governs the secure processing of EU citizens’ data in the USA. We have entered into a data processing agreement (DPA) with Amazon, which ensures that personal data is processed only in accordance with our instructions and in compliance with the GDPR.
Further information on AWS’s data protection policies is available at: https://aws.amazon.com/privacy/
AWS CloudFront
We use AWS CloudFront to ensure the proper delivery of our website’s content. AWS CloudFront is a service provided by Amazon Web Services, Inc., which acts as a Content Delivery Network (CDN) on our website.
A CDN helps to deliver content from our online offering – in particular files such as graphics or scripts – more quickly with the aid of servers distributed regionally or internationally. When you access this content, you establish a connection to servers operated by Amazon Web Services, Inc., during which your IP address and, where applicable, browser data such as your user agent are transmitted. This data is processed exclusively for the purposes mentioned above and to maintain the security and functionality of AWS CloudFront.
The use of the Content Delivery Network is based on our legitimate interests, i.e. our interest in the secure and efficient provision and optimisation of our online service.
We have no influence over the specific retention period of the processed data; this is determined by Amazon Web Services, Inc. Further information can be found in the AWS CloudFront Privacy Policy: https://aws.amazon.com/de/privacy/.
Adobe Typekit
We use Adobe Typekit from Adobe Inc., San Jose, California, US, as a service for providing fonts for our online offering. To access these fonts, a connection is established with Adobe Inc.’s servers, during which your IP address is transmitted.
The use of Adobe Typekit is based on your consent in accordance with Article 6(1)(a) of the GDPR.
We have no influence over the specific retention period of the processed data; this is determined by Adobe Inc. Further information can be found in the privacy policy for Adobe Typekit: https://www.adobe.com/de/privacy/policies/adobe-fonts.html.
Bookassist
Bookassist is a booking portal used to offer hotel rooms and packages to prospective guests. If this option is used, the data entered in the form is transmitted to the participating hotel and stored. This data may include, amongst other things: first name, surname, email address, postal address, number of travelling companions, booking details, estimated time of arrival, preferences, payment details (credit card), date and time.
When an online booking is made, this is processed via the Bookassist online booking system operated by Automatic Netware Limited, Suite 3, One Earlsfort Centre, Lower Hatch Street, Dublin 2, Ireland.
We process the personal data entered via the form solely for the purpose of handling the booking enquiry and processing payments.
The legal basis for the processing of the data is the conclusion of an accommodation contract in accordance with Article 6(1)(b) of the GDPR. The data provided is stored and used for the performance of the contract.
The data will be deleted or anonymised as soon as it is no longer required to fulfil the purpose for which it was collected. Further information on data processing can be found in Bookassist’s Privacy Policy: https://bookassist.org/de/datenschutzerklaerung/.
Use of Google services
Please note that when using the service, personal data may be transferred to third countries outside the European Economic Area, in particular the USA. Data transfers to the USA are carried out in accordance with Article 45(1) of the GDPR on the basis of the European Commission’s adequacy decision. The US companies involved and/or their US sub-processors are certified under the EU-US Data Privacy Framework (EU-US DPF).
In cases where no adequacy decision by the European Commission exists (including US companies that are not certified under the EU-US DPF), we have agreed on other suitable safeguards with the recipients of the data in accordance with Articles 44 et seq. of the GDPR. Unless otherwise stated, these are the European Commission’s standard contractual clauses in accordance with Implementing Decision (EU) 2021/914 of 4 June 2021. You can view a copy of these standard contractual clauses at https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:32021D0914&from=DE.
Furthermore, prior to any such transfer to a third country, we will obtain your consent in accordance with Article 49(1), first sentence, point (a) of the GDPR, which you provide via the Consent Manager (or other forms, registrations, etc.). Please note that transfers to third countries may involve risks of which the details are unknown (e.g. data processing by the third country’s security authorities, the exact scope of which and the consequences for you we do not know, over which we have no influence and of which you may not become aware).
Google Tag Manager
We use Google Tag Manager, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Tag Manager is used to manage website tags via a single interface and enables us to control the precise integration of services on our website.
This allows us to flexibly integrate additional services in order to analyse users’ access to our website.
The use of Google Tag Manager is based on your consent in accordance with Article 6(1)(a) of the GDPR.
We intend to transfer personal data to third countries outside the European Economic Area, in particular the USA. Data transfers to the USA are carried out in accordance with Article 45(1) of the GDPR on the basis of the European Commission’s adequacy decision. The US companies involved and/or their US sub-processors are certified under the EU-US Data Privacy Framework (EU-US DPF).
In cases where no adequacy decision by the European Commission exists (including US companies that are not certified under the EU-US DPF), we have agreed on other suitable safeguards with the recipients of the data in accordance with Articles 44 et seq. of the GDPR. Unless otherwise stated, these are the European Commission’s standard contractual clauses in accordance with Implementing Decision (EU) 2021/914 of 4 June 2021. You can view a copy of these standard contractual clauses at https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:32021D0914&from=DE.
Furthermore, prior to any such transfer to a third country, we obtain your consent in accordance with Article 49(1), first sentence, point (a) of the GDPR, which you provide via the Consent Manager (or other forms, registrations, etc.). We would like to draw your attention to the fact that transfers to third countries may involve risks of which the details are unknown (e.g. data processing by security authorities in the third country, the exact scope of which and the consequences for you we do not know, over which we have no influence and of which you may not become aware).
We have no influence over the specific retention period of the processed data; this is determined by Google Ireland Limited. Further information can be found in the privacy policy for Google Tag Manager: https://marketingplatform.google.com/about/analytics/tag-manager/use-policy/.
Google Analytics
Our website uses Google Analytics 4, a web analytics service provided by Google LLC. The data controller for users in the EU/EEA and Switzerland is Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (‘Google’).
Google Analytics uses cookies that enable an analysis of your use of our websites. The information collected via the cookies about your use of this website is usually transferred to a Google server in the USA and stored there.
We use the User ID feature. The User ID enables us to assign a unique, persistent ID to one or more sessions (and the activities within those sessions) and to analyse user behaviour across devices.
We also use Google Signals. This allows Google Analytics to collect additional information about users who have enabled personalised adverts (interests and demographic data), and adverts can be served to these users in cross-device remarketing campaigns.
In Google Analytics 4, IP address anonymisation is enabled by default. Due to IP anonymisation, your IP address is truncated by Google within Member States of the European Union or in other signatory states to the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and truncated there. According to Google, the IP address transmitted by your browser as part of Google Analytics is not merged with other Google data.
During your visit to the website, your user behaviour is recorded in the form of ‘events’. Events may include:
Page views
First visit to the website
Start of the session
Your ‘click path’, interaction with the website
Scrolls (whenever a user scrolls to the bottom of the page (90%))
Clicks on external links
Internal search queries
Interaction with videos
File downloads
Ads viewed / clicked
Language settings
The following is also recorded:
Your approximate location (region)
Your IP address (in truncated form)
Technical information about your browser and the devices you use (e.g. language setting, screen resolution)
Your internet service provider
the referrer URL (the website or advertising material via which you arrived at this website)
Purposes of processing
On our behalf, Google will process the information provided in order to analyse how visitors use the website and to compile reports on website activity. We use the reports provided by Google Analytics to analyse the website’s performance.
Recipients
Recipients of the data are/may be
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (as a data processor under Article 28 of the GDPR)
Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Alphabet Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
It cannot be ruled out that US authorities may access the data stored by Google.
Transfers to third countries
Where data is processed outside the EU/EEA and there is no level of data protection equivalent to European standards, we have entered into EU Standard Contractual Clauses with the service provider to ensure an adequate level of data protection. The parent company of Google Ireland, Google LLC, is based in California, USA. The transfer of data to the USA and access by US authorities to data stored by Google cannot be ruled out. From a data protection perspective, the USA is currently regarded as a third country. You do not have the same rights there as you do within the EU/EEA. You may not have any legal remedies available to you against access by authorities.
Retention period
The data we send and which is linked to cookies is automatically deleted after 14 months. Data for which the retention period has expired is automatically deleted once a month.
Legal basis and withdrawal of consent
We process your data using Google Analytics 4 on the basis of your consent in accordance with Article 6(1)(a) of the GDPR. You give your consent by setting your preferences regarding the use of cookies (cookie banner / consent manager), through which you may also withdraw your consent at any time with future effect in accordance with Article 7(3) of the GDPR.
You can also prevent the storage of cookies from the outset by adjusting the settings in your browser software accordingly. However, if you configure your browser to reject all cookies, this may result in restricted functionality on this and other websites. Furthermore, you can prevent the collection of data generated by the cookie and relating to your use of the website (including your IP address) by Google, as well as the processing of this data by Google, by either (I) not giving your consent to the setting of the cookie or (II) downloading and installing the browser add-on to deactivate Google Analytics here: https://tools.google.com/dlpage/gaoptout?hl=de.
Further information can be found in the Terms of Service (https://marketingplatform.google.com/about/analytics/terms/de/) and in Google’s Privacy Policy: https://policies.google.com/?hl=de.
Google DoubleClick
We have integrated components from Google DoubleClick into our website. DoubleClick is a Google brand under which specialised online marketing solutions are primarily marketed to advertising agencies and publishers. DoubleClick by Google transmits data to the DoubleClick server with every impression, as well as with clicks or other activities.
Each of these data transfers triggers a cookie request to the data subject’s browser. If the browser accepts this request, DoubleClick sets a cookie in your browser.
DoubleClick uses a cookie ID, which is required to carry out the technical process. The cookie ID is needed, for example, to display an advert in a browser. DoubleClick can also use the cookie ID to track which adverts have already been displayed in a browser, in order to prevent duplicate adverts from appearing. Furthermore, the cookie ID enables DoubleClick to track conversions. Conversions are tracked, for example, when a user has previously been shown a DoubleClick advert and subsequently makes a purchase on the advertiser’s website using the same web browser.
A DoubleClick cookie does not contain any personal data, but may contain additional campaign identifiers. A campaign identifier is used to identify the campaigns with which you have already come into contact on other websites. As part of this service, Google receives information which it also uses to generate commission statements. Among other things, Google can track that you have clicked on certain links on our website. In this case, your data is transferred to the operator of DoubleClick, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Further information and the applicable privacy policy of DoubleClick by Google can be found at https://policies.google.com/privacy.
We process your data using the DoubleClick cookie for the purpose of optimising and displaying advertising on the basis of your consent in accordance with Article 6(1)(a) of the GDPR. Among other things, the cookie is used to serve and display user-relevant advertising, as well as to generate reports on advertising campaigns or to improve them. Furthermore, the cookie serves to prevent the same advert from being displayed multiple times. Each time you visit a page on our website that incorporates a DoubleClick component, your browser is automatically prompted by the relevant DoubleClick component to transmit data to Google for the purposes of online advertising and the settlement of commissions. There is no legal or contractual obligation to provide your data. If you do not give us your consent, you may still visit our website without restriction; however, not all functions may be fully available.
We intend to transfer personal data to third countries outside the European Economic Area, in particular the USA. Data transfers to the USA are carried out in accordance with Article 45(1) of the GDPR on the basis of the European Commission’s adequacy decision. The US companies involved and/or their US sub-processors are certified under the EU-US Data Privacy Framework (EU-US DPF).
In cases where no adequacy decision by the European Commission exists (including US companies that are not certified under the EU-US DPF), we have agreed on other suitable safeguards with the recipients of the data in accordance with Articles 44 et seq. of the GDPR. Unless otherwise stated, these are the European Commission’s standard contractual clauses in accordance with Implementing Decision (EU) 2021/914 of 4 June 2021. You can view a copy of these standard contractual clauses at https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:32021D0914&from=DE.
Furthermore, prior to any such transfer to a third country, we will obtain your consent in accordance with Article 49(1), first sentence, point (a) of the GDPR, which you provide via the Consent Manager (or other forms, registrations, etc.). Please note that transfers to third countries may involve risks of which the details are unknown (e.g. data processing by the third country’s security authorities, the exact scope of which and the consequences for you we do not know, over which we have no influence and of which you may not become aware).
We have no influence over the specific retention period of the processed data; this is determined by Google Ireland Limited. Further information can be found in the privacy policy for Google DoubleClick: https://policies.google.com/privacy.
Google Maps
This website uses the Google Maps API, a mapping service provided by Google Inc. (“Google”), to display an interactive map and to generate route plans. Google Maps is operated by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
When you use Google Maps, information about your use of this website (including your IP address) may be transmitted to a Google server in the USA and stored there. Google may pass on the information obtained via Maps to third parties where required by law or where such third parties process the data on Google’s behalf.
Google will under no circumstances associate your IP address with any other data held by Google. Nevertheless, it is technically possible that Google could identify at least individual users on the basis of the data received. It is possible that personal data and user profiles of website users could be processed by Google for other purposes over which we have no control and cannot exert any influence.
The use of Google Maps is based on your consent in accordance with Article 6(1)(a) of the GDPR
The purpose of using Google Maps is to show users our location on the website and to enable them to find different routes to our premises using Google Maps services.
You have the option to disable the Google Maps service and thus prevent the transfer of data to Google by disabling JavaScript in your browser. However, please note that in this case you will not be able to use the map display on our website.
Google Ads
We have integrated Google Ads into our website. Google Ads is a service provided by Google Ireland Limited to display targeted advertising to users. Google Ads uses cookies and other browser technologies to analyse user behaviour and recognise users.
Google Ads collects information about visitor behaviour across various websites. This information is used to optimise the relevance of the adverts. Furthermore, Google Ads delivers targeted adverts based on behavioural profiles and geographical location. Your IP address and other identifying characteristics, such as your user agent, are transmitted to the provider.
If you are registered with a Google Ireland Limited service, Google Ads may associate your visit with your account. Even if you are not registered with Google Ireland Limited or are not logged in, it is possible that the provider may identify and store your IP address and other identifying characteristics.
In this case, your data is transferred to the operator of Google Ads, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
The use of Google Ads is based on your consent in accordance with Article 6(1)(a) of the GDPR
We intend to transfer personal data to third countries outside the European Economic Area, in particular the USA. Data transfers to the USA are carried out in accordance with Article 45(1) of the GDPR on the basis of the European Commission’s adequacy decision. The US companies involved and/or their US sub-processors are certified under the EU-US Data Privacy Framework (EU-US DPF).
In cases where no adequacy decision has been adopted by the European Commission (including US companies that are not certified under the EU-US DPF), we have agreed on other appropriate safeguards with the recipients of the data in accordance with Articles 44 et seq. of the GDPR. Unless otherwise stated, these are the European Commission’s standard contractual clauses in accordance with Implementing Decision (EU) 2021/914 of 4 June 2021. You can view a copy of these standard contractual clauses at https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:32021D0914&from=DE.
Furthermore, prior to any such transfer to a third country, we will obtain your consent in accordance with Article 49(1), first sentence, point (a) of the GDPR, which you provide via the Consent Manager (or other forms, registrations, etc.). Please note that transfers to third countries may involve risks of which the details are unknown (e.g. data processing by the third country’s security authorities, the exact scope of which and the consequences for you we do not know, over which we have no influence and of which you may not become aware).
We have no influence over the specific retention period of the processed data; this is determined by Google Ireland Limited. Further information can be found in the Google Ads Privacy Policy: https://policies.google.com/privacy.
Google Ads Conversion Tracking
We use the ‘Google Ads Conversion Tracking’ service on our website to measure the effectiveness of our advertising campaigns. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
The legal basis for the use of Google Ads Conversion Tracking is your consent in accordance with Article 6(1)(a) of the GDPR. You may withdraw your consent at any time with future effect.
The data processed by Google Ads Conversion Tracking includes your IP address, browser and device information, details of interactions with adverts, and the use of cookies to track conversions.
If you are signed in to a Google account, data from Google Ads Conversion Tracking may be linked to a user profile.
The purpose of data processing is to measure the effectiveness of advertising campaigns and to track user interactions following a click on an advert.
We intend to transfer personal data to third countries outside the European Economic Area, in particular the USA. Data transfers to the USA are carried out in accordance with Article 45(1) of the GDPR on the basis of the European Commission’s adequacy decision. The US companies involved and/or their US sub-processors are certified under the EU-US Data Privacy Framework (EU-US DPF).
In cases where no adequacy decision by the European Commission exists (including US companies that are not certified under the EU-US DPF), we have agreed on other suitable safeguards with the recipients of the data in accordance with Articles 44 et seq. of the GDPR. Unless otherwise stated, these are the European Commission’s standard contractual clauses in accordance with Implementing Decision (EU) 2021/914 of 4 June 2021. You can view a copy of these standard contractual clauses at https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:32021D0914&from=DE.
Further information on the privacy policy for Google Ads Conversion Tracking is available at: https://policies.google.com/privacy
Google CDN
We use Google CDN to ensure the proper delivery of our website’s content. Google CDN is a service provided by Google Ireland Limited, which acts as a Content Delivery Network (CDN) on our website.
A CDN helps to deliver content from our online service – in particular files such as graphics or scripts – more quickly with the aid of servers distributed regionally or internationally. When you access this content, you establish a connection to servers operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, whereby your IP address and, where applicable, browser data such as your user agent are transmitted. This data is processed exclusively for the purposes mentioned above and to maintain the security and functionality of Google CDN.
The use of the Content Delivery Network is based on our legitimate interests, i.e. our interest in the secure and efficient provision and optimisation of our online services in accordance with Article 6(1)(f) of the GDPR.
We intend to transfer personal data to third countries outside the European Economic Area, in particular the USA. Data transfers to the USA are carried out in accordance with Article 45(1) of the GDPR on the basis of the European Commission’s adequacy decision. The US companies involved and/or their US sub-processors are certified under the EU-US Data Privacy Framework (EU-US DPF).
In cases where no adequacy decision by the European Commission exists (including US companies that are not certified under the EU-US DPF), we have agreed on other appropriate safeguards with the recipients of the data in accordance with Articles 44 et seq. of the GDPR. Unless otherwise stated, these are the European Commission’s standard contractual clauses in accordance with Implementing Decision (EU) 2021/914 of 4 June 2021. You can view a copy of these standard contractual clauses at https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:32021D0914&from=DE.
Furthermore, prior to any such transfer to a third country, we will obtain your consent in accordance with Article 49(1), first sentence, point (a) of the GDPR, which you provide via the Consent Manager (or other forms, registrations, etc.). Please note that transfers to third countries may involve risks of which the details are unknown (e.g. data processing by the third country’s security authorities, the exact scope of which and the consequences for you we do not know, over which we have no influence and of which you may not become aware).
We have no influence over the specific retention period of the processed data; this is determined by Google Ireland Limited. Further information can be found in the privacy policy for Google CDN: https://policies.google.com/privacy.
Google Fonts
We use Google Fonts from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, as a service for providing fonts for our online offering. To access these fonts, a connection is established with our own servers in Germany, during which your IP address is transmitted.
The use of Google Fonts is based on our legitimate interests, i.e. our interest in ensuring a consistent presentation and optimising our online offering. No data is transferred to Google.
Google Hosted Libraries
We use the ‘Google Hosted Libraries’ service on our website to load common JavaScript libraries efficiently. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
The legal basis for the use of Google Hosted Libraries is your consent in accordance with Article 6(1)(a) of the GDPR. You may withdraw your consent at any time with future effect.
The data processed by Google Hosted Libraries includes your IP address, browser type, operating system, and the date and time of your request; Google may also set cookies for analytics and security purposes.
The purpose of data processing is to efficiently deliver frequently used JavaScript libraries from Google’s servers in order to improve the performance and reliability of the website.
It cannot be ruled out that personal data may be transferred to non-EU countries (the USA) where data protection standards are lower than in the EU. We have entered into a data processing agreement (DPA) with Google, which ensures that personal data is processed only in accordance with our instructions and in compliance with the GDPR. Google is certified under the EU-US Data Privacy Framework, which governs the secure processing of EU citizens’ data in the USA.
Further information on the privacy policy of Google Hosted Libraries is available at: https://policies.google.com/privacy
Hotjar Behaviour Analytics
We have integrated Hotjar into our website. Hotjar is a service provided by Hotjar Ltd. and offers optimisation tools that analyse the behaviour and feedback of users of our website using analytics and feedback tools.
Hotjar uses cookies and other browser technologies to analyse user behaviour and recognise users.
This information is used, amongst other things, to compile reports on website activity and to statistically analyse visitor data. Furthermore, Hotjar records clicks, mouse movements and scroll depths to create so-called heatmaps and session replays.
In this case, your data is transferred to the operator of Hotjar, Hotjar Ltd, Level 2, St Julians Business Centre, 3 Elia Zammit Street, St Julians, STJ 3155, Malta.
The use of Hotjar is based on your consent in accordance with Article 6(1)(a) of the GDPR.
We have no influence over the specific retention period of the processed data; this is determined by Hotjar Ltd. Further information can be found in Hotjar’s privacy policy: https://www.hotjar.com/privacy/.
Hotjar CDN
We use Hotjar CDN to ensure the proper delivery of our website’s content. Hotjar CDN is a service provided by Hotjar Ltd., which acts as a Content Delivery Network (CDN) on our website to ensure the functionality of other services provided by Hotjar Ltd. A separate section in this privacy policy covers these services. This section deals solely with the use of the CDN.
A CDN helps to deliver content from our online offering – in particular files such as graphics or scripts – more quickly with the aid of servers distributed regionally or internationally. When you access this content, you establish a connection to servers operated by Hotjar Ltd., Level 2, St Julians Business Centre, 3 Elia Zammit Street, St Julians, STJ 3155, Malta, whereby your IP address and, where applicable, browser data such as your user agent are transmitted. This data is processed exclusively for the purposes mentioned above and to maintain the security and functionality of the Hotjar CDN.
The use of the Content Delivery Network is based on our legitimate interests, i.e. our interest in the secure and efficient provision and optimisation of our online services in accordance with Article 6(1)(f) of the GDPR.
We have no influence over the specific retention period of the processed data; this is determined by Hotjar Ltd. Further information can be found in the privacy policy for Hotjar CDN: https://www.hotjar.com/privacy/.
Issuu CDN
We use Issuu CDN to ensure the proper delivery of our website’s content. Issuu CDN is a service provided by Issuu, Inc., which acts as a Content Delivery Network (CDN) on our website to ensure the functionality of other services provided by Issuu, Inc. A separate section of this privacy policy covers these services. This section deals solely with the use of the CDN.
A CDN helps to deliver content from our online offering – in particular files such as graphics or scripts – more quickly with the aid of servers distributed regionally or internationally. When you access this content, you establish a connection to servers operated by Issuu, Inc., 131 Lytton Ave, Palo Alto, CA 94301, USA, whereby your IP address and, where applicable, browser data such as your user agent are transmitted. This data is processed exclusively for the purposes mentioned above and to maintain the security and functionality of the Issuu CDN.
The use of the Content Delivery Network is based on our legitimate interests, i.e. our interest in the secure and efficient delivery and optimisation of our online service in accordance with Article 6(1)(f) of the GDPR.
We have no influence over the specific retention period of the processed data; this is determined by Issuu, Inc. Further information can be found in the privacy policy for Issuu CDN: https://issuu.com/legal/privacy.
Issuu PDF Reader
We use Issuu PDF Reader from Issuu, Inc., 131 Lytton Ave, Palo Alto, CA 94301, USA, to publish catalogues, magazines and other media digitally and to enable you to view them. In doing so, data such as your IP address, the exact URL you were visiting at the time you accessed the relevant online media, and the duration of the session are transmitted.
Use of the service is based on our legitimate interests, i.e. our interest in making our content available on a platform-independent basis in accordance with Article 6(1)(f) of the GDPR.
We have no influence over the specific retention period of the processed data; this is determined by Issuu, Inc. Further information can be found in the privacy policy for Issuu PDF Reader: https://issuu.com/legal/privacy.
THE HOTELS NETWORK
We have integrated THE HOTELS NETWORK into our website. THE HOTELS NETWORK is a service provided by THE HOTELS NETWORK, S.L., Av. Diagonal, 439, 3º-1ª, 08036 Barcelona, Spain. We use THE HOTELS NETWORK to accept bookings and to measure their success.
THE HOTELS NETWORK uses cookies and other browser technologies to analyse user behaviour, recognise users and increase direct bookings. This information is used, amongst other things, to compile reports on website activity.
Furthermore, THE HOTELS NETWORK enables us to finalise direct bookings via our website.
Your IP address and other identifying characteristics, such as your user agent, are transmitted to the provider.
The use of THE HOTELS NETWORK is based on your consent in accordance with Article 6(1)(a) of the GDPR.
We have no influence over the specific retention period of the processed data; this is determined by THE HOTELS NETWORK, S.L. Further information can be found in THE HOTELS NETWORK’s privacy policy: https://www.thehotelsnetwork.com/de/privacy-policy.
Unpkg CDN
We use Unpkg CDN to ensure the proper delivery of our website’s content. Unpkg CDN is a service provided by Cloudflare, Inc., which acts as a Content Delivery Network (CDN) on our website.
A CDN helps to deliver content from our website – in particular files such as graphics or scripts – more quickly by utilising servers distributed regionally or internationally. When you access this content, you establish a connection to servers operated by Cloudflare, Inc., during which your IP address and, where applicable, browser data such as your user agent are transmitted. This data is processed exclusively for the purposes mentioned above and to maintain the security and functionality of the Unpkg CDN.
The use of the Content Delivery Network is based on our legitimate interests, i.e. our interest in the secure and efficient provision and optimisation of our online service in accordance with Article 6(1)(f) of the GDPR.
We have no influence over the specific retention period of the processed data; this is determined by Cloudflare, Inc. Further information can be found in the privacy policy for Unpkg CDN: https://www.cloudflare.com/privacypolicy/.
YouTube NoCookie
We have integrated YouTube NoCookie into our website. YouTube NoCookie is a component of the video platform operated by YouTube, LLC, which allows users to upload content, share it via the internet and obtain detailed statistics.
YouTube NoCookie enables us to integrate content from the platform into our website.
YouTube NoCookie uses cookies and other browser technologies to analyse user behaviour, recognise users and create user profiles. This information is used, amongst other things, to analyse the activity of the content accessed at and to generate reports. If a user is registered with YouTube, LLC, YouTube NoCookie can associate the videos played with that user’s profile.
When you access this content, you establish a connection to servers operated by YouTube, LLC, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, whereby your IP address and, where applicable, browser data such as your user agent are transmitted.
We intend to transfer personal data to third countries outside the European Economic Area, in particular the USA. Data transfers to the USA are carried out in accordance with Article 45(1) of the GDPR on the basis of the European Commission’s adequacy decision. The US companies involved and/or their US sub-processors are certified under the EU-US Data Privacy Framework (EU-US DPF).
In cases where no adequacy decision by the European Commission exists (including US companies that are not certified under the EU-US DPF), we have agreed on other appropriate safeguards with the recipients of the data in accordance with Articles 44 et seq. of the GDPR. Unless otherwise stated, these are the European Commission’s standard contractual clauses in accordance with Implementing Decision (EU) 2021/914 of 4 June 2021. You can view a copy of these standard contractual clauses at https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:32021D0914&from=DE.
Furthermore, prior to any such transfer to a third country, we will obtain your consent in accordance with Article 49(1), first sentence, point (a) of the GDPR, which you provide via the Consent Manager (or other forms, registrations, etc.). Please note that transfers to third countries may involve risks of which the details are unknown (e.g. data processing by the third country’s security authorities, the exact scope of which and the consequences for you we do not know, over which we have no influence and of which you may not become aware).
We have no influence over the specific retention period of the processed data; this is determined by YouTube, LLC. Further information can be found in the privacy policy for YouTube NoCookie: https://policies.google.com/privacy.
YouTube Video
We have integrated YouTube Video into our website. YouTube Video is a component of the YouTube, LLC video platform, on which users can upload content, share it via the internet and receive detailed statistics.
YouTube Video enables us to integrate content from the platform into our website.
YouTube Video uses cookies and other browser technologies to analyse user behaviour, recognise users and create user profiles. This information is used, amongst other things, to analyse the activity of the content viewed and to generate reports. If a user is registered with YouTube, LLC, YouTube Video can associate the videos played with that user’s profile.
When you access this content, you establish a connection to the servers of YouTube, LLC, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, whereby your IP address and, where applicable, browser data such as your user agent are transmitted.
Use of the service is based on your consent in accordance with Article 6(1)(a) of the GDPR.
We intend to transfer personal data to third countries outside the European Economic Area, in particular the USA. Data transfers to the USA are carried out in accordance with Article 45(1) of the GDPR on the basis of the European Commission’s adequacy decision. The US companies involved and/or their US sub-processors are certified under the EU-US Data Privacy Framework (EU-US DPF).
In cases where no adequacy decision by the European Commission exists (including US companies that are not certified under the EU-US DPF), we have agreed on other suitable safeguards with the recipients of the data in accordance with Articles 44 et seq. of the GDPR. Unless otherwise stated, these are the European Commission’s standard contractual clauses in accordance with Implementing Decision (EU) 2021/914 of 4 June 2021. You can view a copy of these standard contractual clauses at https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:32021D0914&from=DE.
Furthermore, prior to any such transfer to a third country, we will obtain your consent in accordance with Article 49(1), first sentence, point (a) of the GDPR, which you provide via the Consent Manager (or other forms, registrations, etc.). Please note that transfers to third countries may involve risks of which the details are unknown (e.g. data processing by the third country’s security authorities, the exact scope of which and the consequences for you we do not know, over which we have no influence and of which you may not become aware).
We have no influence over the specific retention period of the processed data; this is determined by YouTube, LLC. Further information can be found in the YouTube Video Privacy Policy: https://policies.google.com/privacy.
d.vinci Applicant Management
We have integrated components of d.vinci Applicant Management into our website. d.vinci Applicant Management is a service provided by d.vinci HR-Systems GmbH, Nagelsweg 37–39, 20097 Hamburg, Germany, which offers applicant and HR management software.
d.vinci Applicant Management is used in connection with recruitment processes to optimise applicant management, for example through the automated analysis of employment references. Furthermore, d.vinci Applicant Management enables us to create and evaluate job advertisements.
The use of the service is based on our legitimate interests, i.e. our interest in optimising our recruitment processes in accordance with Article 6(1)(f) of the GDPR.
We have no influence over the specific retention period for the processed data; this is determined by d.vinci HR-Systems GmbH. Further information can be found in the privacy policy for d.vinci Applicant Management: https://www.dvinci.de/datenschutz.
Data processing outside the European Union
Where personal data is processed outside the European Union, please refer to the information provided above.
Security
We implement technical and organisational security measures in accordance with Article 32 of the GDPR to protect the data we manage against accidental or deliberate manipulation, loss, destruction or access by unauthorised persons. Our security measures are continuously improved in line with technological developments. Access to this data is restricted to a small number of authorised individuals who are bound by specific data protection obligations and who are responsible for the technical, administrative or editorial management of the data.
For security reasons and to protect the transmission of confidential content that you send to us as the website operator, our website uses SSL or TLS encryption. This ensures that data you transmit via this website cannot be read by third parties. You can recognise an encrypted connection by the ‘https://’ in your browser’s address bar and by the padlock icon in the browser bar.
Changes to this privacy policy
We revise this privacy policy in the event of changes to this website or for any other reasons that make this necessary. You can always find the latest version on this website.
Last updated February 2026


