Privacy Statement
This is a non-binding English translation provided for your convenience. The legally authoritative version of this privacy policy is the German version (“Datenschutzerklärung”). In the event of any discrepancy, the German text prevails.
Privacy Policy
1. Introduction
With the following information we would like to give you, as a “data subject”, an overview of the processing of your personal data by us and of your rights under the data protection laws. Use of our websites is generally possible without entering personal data. However, should you wish to make use of special services of our company via our website, processing of personal data could become necessary. If the processing of personal data is necessary and there is no legal basis for such processing, we generally obtain your consent.
The processing of personal data, for example your name, address or email address, is always carried out in accordance with the General Data Protection Regulation (GDPR) and in compliance with the country-specific data protection provisions applicable to “„Tannerhof“ Dr. von Mengershausen GmbH & Co. KG”. By means of this privacy policy we would like to inform you about the scope and purpose of the personal data we collect, use and process.
As the controller responsible for the processing, we have implemented numerous technical and organisational measures in order to ensure the most complete protection possible of the personal data processed via this website. Nevertheless, internet-based data transmissions can in principle have security gaps, so that absolute protection cannot be guaranteed. For this reason, you are free to transmit personal data to us by alternative means as well, for example by telephone or by post.
You too can take simple and easily implemented measures in order to protect yourself against unauthorised access by third parties to your data. We would therefore like to give you a few notes at this point on the secure handling of your data:
- Protect your account (login, user account or customer account) and your IT system (computer, laptop, tablet or mobile device) with secure passwords.
- Only you should have access to the passwords.
- Make sure that you always use your passwords for one account only (login, user account or customer account).
- Do not use one password for different websites, applications or online services.
- The following applies in particular when using IT systems that are publicly accessible or shared with other people: you should always make sure to log out again after every login to a website, an application or an online service.
Passwords should consist of at least 12 characters and should be chosen in such a way that they cannot easily be guessed. They should therefore not contain common everyday words, your own name or the names of relatives, but rather upper and lower case letters, numbers and special characters.
2. Controller
The controller within the meaning of the DSGVO is:
„Tannerhof“ Dr. von Mengershausen GmbH & Co. KG
Tannerhofstraße 32, 83735 Bayrischzell, Germany
3. Data Protection Officer
You can contact the data protection officer as follows:
Stephan Krischke, datenschutz@tannerhof.de
You can contact our data protection officer directly at any time with any questions and suggestions regarding data protection.
4. Definitions
This privacy policy is based on the terminology used by the European legislator for directives and regulations when the General Data Protection Regulation (GDPR) was adopted. Our privacy policy is intended to be easy to read and understand, both for the general public and for our customers and business partners. In order to ensure this, we would like to explain the terminology used in advance.
In this privacy policy we use, among others, the following terms:
1. Personal data
Personal data means any information relating to an identified or identifiable natural person. A natural person is regarded as identifiable if he or she can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more special characteristics which are an expression of the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
2. Data subject
A data subject is any identified or identifiable natural person whose personal data are processed by the controller responsible for the processing (our company).
3. Processing
Processing means any operation or any set of operations which is performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or any other form of making available, alignment or combination, restriction, erasure or destruction.
4. Restriction of processing
Restriction of processing is the marking of stored personal data with the aim of restricting their future processing.
5. Profiling
Profiling means any form of automated processing of personal data which consists of using such personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
6. Pseudonymisation
Pseudonymisation is the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures which ensure that the personal data are not attributed to an identified or identifiable natural person.
7. Processor
A processor is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
8. Recipient
A recipient is a natural or legal person, public authority, agency or other body to which personal data are disclosed, whether or not it is a third party. However, public authorities which may receive personal data in the framework of a particular inquiry under Union law or the law of the Member States shall not be regarded as recipients.
9. Third party
A third party is a natural or legal person, public authority, agency or other body other than the data subject, the controller, the processor and the persons who, under the direct authority of the controller or of the processor, are authorised to process the personal data.
10. Consent
Consent is any freely given, specific, informed and unambiguous indication of the data subject’s wishes, given for the specific case in the form of a statement or of another clear affirmative action, by which the data subject signifies that he or she agrees to the processing of personal data relating to him or her.
5. Legal basis for the processing
Art. 6 Abs. 1 lit. a) DSGVO (in conjunction with § 25 Abs. 1 TDDDG (formerly TTDSG)) serves our company as the legal basis for processing operations for which we obtain consent for a specific processing purpose.
If the processing of personal data is necessary for the performance of a contract to which you are a party, as is the case, for example, with processing operations that are necessary for a supply of goods or the provision of any other service or consideration, the processing is based on Art. 6 Abs. 1 lit. b) DSGVO. The same applies to such processing operations as are necessary for the performance of pre-contractual measures, for example in cases of enquiries about our products or services.
If our company is subject to a legal obligation by which processing of personal data becomes necessary, such as for the fulfilment of tax obligations, the processing is based on Art. 6 Abs. 1 lit. c) DSGVO.
In rare cases, the processing of personal data could become necessary in order to protect vital interests of the data subject or of another natural person. This would be the case, for example, if a visitor were injured on our premises and, as a result, his name, his age, his health insurance data or other vital information had to be passed on to a doctor, a hospital or other third parties. The processing would then be based on Art. 6 Abs. 1 lit. d) DSGVO.
Finally, processing operations could be based on Art. 6 Abs. 1 lit. f) DSGVO. Processing operations that are not covered by any of the aforementioned legal bases are based on this legal basis if the processing is necessary to safeguard a legitimate interest of our company or of a third party, provided that the interests, fundamental rights and fundamental freedoms of the data subject do not override such interest. Such processing operations are permitted to us in particular because they were specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed if you are a customer of our company (Recital 47 sentence 2 DSGVO).
Our offering is generally directed at adults. Persons under 16 years of age may not transmit any personal data to us without the consent of their parents or legal guardians. We do not request personal data from children and young people, do not collect such data and do not pass it on to third parties.
6. Transfer of data to third parties
Your personal data will not be transferred to third parties for purposes other than those listed below.
We only pass on your personal data to third parties if:
1. you have given us your express consent to do so pursuant to Art. 6 Abs. 1 lit. a) DSGVO,
2. the disclosure is permissible pursuant to Art. 6 Abs. 1 lit. f) DSGVO in order to safeguard our legitimate interests and there is no reason to assume that you have an overriding interest worthy of protection in your data not being disclosed,
3. in the event that there is a legal obligation for the disclosure pursuant to Art. 6 Abs. 1 lit. c) DSGVO, and
4. this is legally permissible and necessary pursuant to Art. 6 Abs. 1 lit. b) DSGVO for the performance of contractual relationships with you.
In order to protect your data and, where applicable, to enable us to transfer data to third countries (outside the EU/the EEA), we have concluded data processing agreements on the basis of the standard contractual clauses of the European Commission. If the standard contractual clauses are not sufficient to establish an adequate level of security, your consent pursuant to Art. 49 Abs. 1 lit. a) DSGVO may serve as the legal basis for the transfer to third countries. This does not apply, among other things, in the case of a data transfer to third countries for which the European Commission has issued an adequacy decision pursuant to Art. 45 DSGVO.
Your personal data will not be transferred to third parties for purposes other than those listed below.
We only pass on your personal data to third parties if:
1. you have given us your express consent to do so pursuant to Art. 6 Abs. 1 lit. a) DSGVO,
2. the disclosure is permissible pursuant to Art. 6 Abs. 1 lit. f) DSGVO in order to safeguard our legitimate interests and there is no reason to assume that you have an overriding interest worthy of protection in your data not being disclosed,
3. in the event that there is a legal obligation for the disclosure pursuant to Art. 6 Abs. 1 lit. c) DSGVO, and
4. this is legally permissible and necessary pursuant to Art. 6 Abs. 1 lit. b) DSGVO for the performance of contractual relationships with you.
Within the scope of the processing operations described in this privacy policy, personal data may be transferred to the USA. Companies in the USA only have an adequate level of data protection if they have certified themselves under the EU-US Data Privacy Framework and the adequacy decision of the EU Commission pursuant to Art. 45 DSGVO therefore applies. We have explicitly named this in the privacy policy for the service providers concerned. In order to protect your data in all other cases, we have concluded data processing agreements on the basis of the standard contractual clauses of the European Commission. If the standard contractual clauses are not sufficient to establish an adequate level of security, your consent pursuant to Art. 49 Abs. 1 lit. a) DSGVO may serve as the legal basis for the transfer to third countries. This does not apply, among other things, in the case of a data transfer to third countries for which the European Commission has issued an adequacy decision pursuant to Art. 45 DSGVO.
7. Technology
7.1 SSL/TLS encryption
This site uses SSL or TLS encryption in order to ensure the security of data processing and to protect the transmission of confidential content, such as orders, login data or contact enquiries which you send to us as the operator. You can recognise an encrypted connection by the fact that the address bar of the browser shows “https://” instead of “http://” and by the lock symbol in your browser bar.
We use this technology in order to protect the data you transmit.
7.2 Data collection when visiting the website
When our website is used merely for informational purposes, if you do not register or otherwise transmit information to us or do not give consent to processing operations requiring consent, we only collect such data as is technically absolutely necessary for the provision of the service. As a rule, this is data that your browser transmits to our server (“in so-called server log files”). Each time a page is called up by you or by an automated system, our website records a series of general data and information. This general data and information is stored in the log files of the server. The following may be recorded:
1. the browser types and versions used,
2. the operating system used by the accessing system,
3. the website from which an accessing system reaches our website (so-called referrer),
4. the sub-pages which are accessed on our website via an accessing system,
5. the date and the time of an access to the website,
6. an internet protocol address (IP address) and,
7. the internet service provider of the accessing system.
When using this general data and information, we do not draw any conclusions about you as a person. Rather, this information is required in order to
1. deliver the contents of our website correctly,
2. optimise the contents of our website as well as the advertising for it,
3. ensure the permanent functionality of our IT systems and of the technology of our website, and
4. provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber attack.
This collected data and information is therefore evaluated by us on the one hand statistically and, furthermore, with the aim of increasing data protection and data security in our company, in order ultimately to ensure an optimal level of protection for the personal data processed by us. The data of the server log files is stored separately from all personal data provided by a data subject.
The legal basis for the data processing is Art. 6 Abs. 1 S. 1 lit. f) DSGVO. Our legitimate interest follows from the purposes for data collection listed above.
7.3 Amazon CloudFront (Content Delivery Network)
We use Amazon CloudFront, a web service of Amazon Web Services Inc., 410 Terry Avenue North, 98109, Seattle, Washington, USA.
Amazon CloudFront is a Content-Delivery-Network (CDN). It routes the transfer of information between your browser and our website via the CloudFront network. This reduces the latency with which we can provide static and dynamic web content. In addition, it improves the security of our website through data traffic encryption and access controls.
Furthermore, CloudFront stores cookies on your computer for the optimisation of the service. In your browser you can delete cookies, allow cookies only in individual cases and activate the automatic deletion of cookies when the browser is closed.
Amazon Web Services receives and processes personal data as our processor in accordance with EU standard contractual clauses. CloudFront is used to collect statistical data about visits to our website. This includes, among other things:
- IP address
- Website accessed
- Referrer URL
- Browser type
- Operating system
- Device type
If you have consented to CloudFront being used, the legal basis for the processing of personal data is Art. 6 Abs. 1 lit. a DSGVO. In addition, it is in our legitimate interest within the meaning of Art. 6 Abs. 1 lit. f DSGVO to use CloudFront in order to optimise our website, to make it more secure and not to operate a Content-Delivery-Network ourselves. The personal data are stored by Amazon Web Services for as long as is necessary for the described achievement of the purpose.
Amazon Web Services Inc. is certified under the EU-US Data Privacy Framework. An adequacy decision pursuant to Art. 45 DSGVO therefore exists, so that a transfer of personal data may take place even without further guarantees or additional measures..
More detailed information on CloudFront can be found at: https://aws.amazon.com/de/cloudfront/.
7.4 Cloudflare (Content Delivery Network)
Our website uses functions of CloudFlare. The provider is CloudFlare, Inc. 665 3rd St. #200, San Francisco, CA 94107, USA.
CloudFlare provides a globally distributed Content Delivery Network with DNS. Technically, the transfer of information between your browser and our website is routed via the CloudFlare network. CloudFlare is thereby able to analyse the data traffic between users and our web pages in order, for example, to detect and defend against attacks on our services. In addition, CloudFlare may under certain circumstances store cookies on your computer for optimisation and analysis purposes.
You can set your browser so that you are informed about the setting of cookies and allow cookies only in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when the browser is closed. If cookies are deactivated, the functionality of this website may be restricted.
We have concluded a corresponding data processing agreement with Cloudflare on the basis of the DSGVO, or in accordance with EU standard contractual clauses. Cloudflare collects statistical data about visits to this website. The access data include: name of the web page accessed, file, date and time of the access, volume of data transferred, notification of successful access, browser type together with version, the user's operating system, referrer URL (the previously visited page), IP address and the requesting provider. Cloudflare uses the log data for statistical evaluations for the purpose of the operation, the security and the optimisation of the offering.
If you have consented to Cloudflare being used, the legal basis for the processing of personal data is Art. 6 Abs. 1 lit. a) DSGVO. In addition, we have a legitimate interest in using Cloudflare in order to optimise our online offering and make it more secure. The corresponding legal basis for this is Art. 6 Abs. 1 lit. f) DSGVO. The personal data are stored for as long as they are necessary for the fulfilment of the processing purpose. The data are deleted as soon as they are no longer necessary for the achievement of the purpose.
This US company is certified under the EU-US Data Privacy Framework. An adequacy decision pursuant to Art. 45 DSGVO therefore exists, so that a transfer of personal data may take place even without further guarantees or additional measures.
Further information on CloudFlare can be found at: https://www.cloudflare.com/privacypolicy/.
7.5 Cloudflare (Worker)
To process newsletter sign-ups as well as enquiry forms we use a Cloudflare Worker (Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA). The Worker receives the data entered by you (in particular email address, name and the contents of your enquiry) and transmits these, depending on the context, to connected services: newsletter sign-ups are processed for administration and dispatch via Campaign Monitor, including assignment to language lists (DE/EN). Form enquiries are additionally used via Resend in order to send confirmation or system emails.
The processing takes place for the purpose of handling your enquiry as well as – in the case of the newsletter – for carrying out the sign-up procedure and sending information (Art. 6 Abs. 1 lit. b DSGVO; for the newsletter, where applicable, Art. 6 Abs. 1 lit. a DSGVO in conjunction with your consent). A transfer to third countries (in particular the USA) cannot be ruled out. We have agreed appropriate safeguards (e.g. standard contractual clauses) with the providers. Further information can be found in the data protection notices of Cloudflare, Campaign Monitor and Resend.
7.6 Hosting by Webflow
We host our website with Webflow, Inc. 398 11th St., Floor 2, San Francisco, CA 94103, USA (hereinafter referred to as Webflow).
When you visit our website, your personal data (e.g. IP addresses in log files) are processed on Webflow's servers.
Webflow is used on the basis of Art. 6 Abs. 1 lit. f) DSGVO. We have a legitimate interest in the most reliable possible presentation and provision as well as securing of our website.
We have concluded a data processing agreement (AVV) pursuant to Art. 28 DSGVO with Webflow. This is a contract prescribed by data protection law which ensures that Webflow processes the personal data of our website visitors only in accordance with our instructions and in compliance with the DSGVO.
Further information on Webflow's data protection provisions can be found at: https://webflow.com/legal/privacy.
7.7 jsDelivr
Components of jsDelivr, operated by the provider Prospect One, Królewska 65A/1, PL-30-081 Kraków, Poland, are integrated into our website.
We use the open-source service jsDelivr on our website in order to be able to deliver the contents of our website to users' various devices as quickly and technically flawlessly as possible.
jsDelivr is a Content-Delivery-Network (CDN) that distributes the contents on our website across various servers in order to ensure optimal worldwide availability. As a rule, a CDN uses servers that are geographically close to the respective website user. It can therefore be assumed that users within the EU are supplied with contents via servers within the EU. In order to provide the contents, jsDelivr collects user data such as the IP address.
According to the information provided by the provider, jsDelivr does not use cookies or similar tracking technologies, but is necessary only for the technical reasons mentioned above.
The data processing takes place on the basis of your consent pursuant to Art. 6 Abs. 1 lit. a) DSGVO.
You can view the data protection provisions of jsDelivr at: https://www.jsdelivr.com/terms/privacy-policy-jsdelivr-net.
7.8 UNPKG
On our website we display icons (favicons) with the aid of the content delivery network (CDN) “UNPKG”. This is an open source CDN operated by CloudFlare, Inc. 665 3rd St. #200, San Francisco, CA 94107, USA. When a page is called up, your browser loads the required icons into your browser cache in order to display them correctly.
For this purpose, the browser you are using must establish a connection to the servers of UNPKG. As a result, UNPKG becomes aware that our website was accessed via your IP address.
The favicons are displayed with the aid of the CDN in the interest of a uniform and appealing presentation of our online offerings. This constitutes a legitimate interest within the meaning of Art. 6 Abs. 1 lit. f DSGVO. Insofar as corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 Abs. 1 lit. a) DSGVO.
Further information on the display of favicons with the aid of the UNPKG CDN can be found at: https://unpkg.com/browse/@mdi/svg@7.2.96/.
7.9 jQuery
For the proper provision of the contents of our website we use jQuery CDN. jQuery CDN is a service of jQuery which functions as a content delivery network (CDN) on our website.
A CDN helps to provide contents of our online offering, in particular files such as graphics or scripts, more quickly with the help of regionally or internationally distributed servers. When you access these contents, you establish a connection to servers of jQuery, whereby your IP address and, where applicable, browser data such as your user agent are transmitted. This data is processed exclusively for the purposes stated above and to maintain the security and functionality of jQuery CDN.
The content delivery network is used on the basis of our legitimate interests, i.e. an interest in the secure and efficient provision as well as the optimisation of our online offering pursuant to Art. 6 Abs. 1 lit. f. DSGVO.
The specific storage period of the processed data cannot be influenced by us, but is determined by jQuery. Further information can be found in the privacy policy for jQuery CDN: https://www.stackpath.com/legal/privacy-statement/.
7.10 Resend
We use the service Resend of the provider Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA, for sending system and transaction e-mails (e.g. order confirmations or technical notifications). In this context we process the recipient’s e-mail address, the content of the message as well as technical dispatch and delivery information (e.g. times, status data). The processing is carried out for the performance of pre-contractual measures or for the performance of the contract pursuant to Art. 6 Abs. 1 lit. b DSGVO as well as on the basis of our legitimate interest in reliable and secure e-mail communication pursuant to Art. 6 Abs. 1 lit. f DSGVO. A transfer of personal data to the USA cannot be excluded. Further information on data protection at Resend can be found at: https://resend.com/legal/privacy-policy.
7.11 Native Forms
On our website we use forms of the platform Webflow (Webflow, Inc., 398 11th Street, 2nd Floor, San Francisco, CA 94103, USA) for the receipt of enquiries, applications and other entries. The data you enter is processed via the infrastructure of Webflow. The processing is carried out in order to deal with your enquiry or to carry out pre-contractual measures or contractual services (Art. 6 Abs. 1 lit. b DSGVO) as well as on the basis of our legitimate interest in efficient communication (Art. 6 Abs. 1 lit. f DSGVO). Further information: https://webflow.com/legal/privacy.
8. Cookies
8.1 General information on cookies
Cookies are small files that your browser creates automatically and that are stored on your IT system (laptop, tablet, smartphone or similar) when you visit our site.
Information is stored in the cookie that arises in each case in connection with the specific end device used. However, this does not mean that we thereby obtain direct knowledge of your identity.
The use of cookies serves to make the use of our offering more pleasant for you. Thus we use so-called session cookies in order to recognise that you have already visited individual pages of our website. These are deleted automatically after you leave our site.
In addition, we likewise use temporary cookies to optimise user-friendliness, which are stored on your end device for a certain defined period of time. If you visit our site again in order to make use of our services, it is automatically recognised that you have already been with us and which entries and settings you have made, so that you do not have to enter these again.
On the other hand, we use cookies in order to record the use of our website statistically and to evaluate our offering for you for the purpose of optimisation. These cookies enable us to recognise automatically, upon a renewed visit to our website, that you have already visited it. The cookies set in this way are deleted automatically after a defined period in each case. The respective storage period of the cookies can be taken from the settings of the consent tool used.
8.2 Legal basis for the use of cookies
The data processed by the cookies which are required for the proper functioning of the website are thus necessary to safeguard our legitimate interests as well as those of third parties pursuant to Art. 6 Abs. 1 lit. f) DSGVO.
For all other cookies it applies that you have given your consent to this within the meaning of Art. 6 Abs. 1 lit. a) DSGVO via our opt-in cookie banner.
8.3 Termly
We have integrated Termly on our website. Termly is a consent solution of Termly Inc., 906 W 2nd Ave, Spokane, WA 99201, USA, with which consent to the storage of cookies can be obtained and documented. Termly uses cookies or other web technologies in order to recognise users and to store the consent granted or withdrawn.
The service is used on the basis of obtaining the legally prescribed consent to the use of cookies pursuant to Art. 6 Abs. 1 lit. c. DSGVO and § 25 Abs. 2 Nr. 2 TDDDG.
The specific storage period of the processed data cannot be influenced by us, but is determined by Termly Inc. Further information can be found in the privacy policy for Termly: https://termly.io/de/unsere-datenschutzpolitik/.
9. Contents of our website
9.1 Order/booking processing
In the course of the order or booking processing we collect your personal data.
In the course of payment processing we pass on your payment data to the commissioned credit institution, insofar as this is necessary for the payment processing. Insofar as payment service providers are used, we provide explicit information on this below.
We process your personal data for the purpose of the booking/order or reservation for the performance of a contract with you pursuant to Art. 6 Abs. 1 lit. b DSGVO. There is a contractual obligation to provide your data insofar as this relates to the mandatory fields, since this information is necessary for the identification of your person as well as for the performance of the contract on our part. There is no legal obligation to provide the data. Without the provision of this information, the booking/order and thus the conclusion of a contract is not possible. For the additional information provided voluntarily there is no obligation to provide it. The booking/order is also possible without disclosing the voluntary information.
Your data is stored insofar as legal retention obligations (for example tax and commercial law) exist.
Booking software & creation of offers
We use the booking software of HotelNetSolutions GmbH, Genthiner Str. 8, 10785 Berlin, for our online bookings. Further information on the service as well as the data protection provisions can be viewed at: https://hotelnetsolutions.de/datenschutz/.
We use the Re:Guest service for processing booking enquiries and for creating individual offers. The provider is ReGuest AG, Kuperionstraße 34, 39012 Meran, Italy. In the course of this use, the data transmitted by you (e.g. name, contact details, booking details) is processed in order to review your enquiry and to create a suitable offer. Further information on the data processing by Re:Guest can be found at: https://www.reguest.io/de/datenschutz.
Payment provider
For the payment processing of our online bookings we use the services of hobex AG, Josef-Brandstätter-Straße 2b, 5020 Salzburg, Austria. Further information on the payment processing by hobex AG can be found at https://www.hobex.at/de/service/datenschutz/.
9.2 Contact forms (vouchers, booking/reservation, enquiries)
Personal data is collected when you contact us (e.g. by contact form or email). Which data is collected in the case of a contact form is apparent from the respective contact form. In addition, you may voluntarily provide additional information which, in your view, is necessary for processing the contact enquiry. When you contact us, your personal data is not passed on to third parties.
Your data is processed for the purpose of communication and of processing your enquiry on the basis of your consent pursuant to Art. 6 Abs. 1 lit. a DSGVO. Insofar as your enquiry relates to an existing contractual relationship with us, the processing takes place for the purpose of performance of the contract on the basis of Art. 6 Abs. 1 lit. b DSGVO. There is no legal or contractual obligation to provide your data; however, processing your enquiry is not possible without the provision of the information in the mandatory fields. If you do not wish to provide this data, please contact us by other means.
Insofar as contact is made on the basis of your consent, we store the data collected for each enquiry for a period of three years, beginning with the completion of your enquiry, or until you withdraw your consent.
Should contact be made within the framework of a contractual relationship, we store the data collected for each enquiry for a period of three years from the end of the contractual relationship.
9.3 Application management
We collect and process the personal data of applicants. The corresponding data processing may also take place by electronic means, for example when applicants submit application documents to us by email or via a web form located on our website. On our website we offer you the option of submitting applications for advertised job vacancies to us by email.
Storage of your data in an applicant database beyond the current application procedure likewise only takes place if you have given us your separate consent to this.
The legal basis for the processing of your personal data in this application procedure is primarily Art. 6 Abs. 1 lit. b) DSGVO. Accordingly, the processing of such data is permissible as is necessary in connection with the decision on the establishment of an employment relationship. This also includes the use of the online applicant portal, if available. Insofar as special categories of personal data within the meaning of Art. 9 DSGVO are processed (e.g. health data), the legal basis is § 26 Abs. 3 BDSG or Art. 9 Abs. 2 lit. b) DSGVO in conjunction with Art. 6 Abs. 1 lit. b) DSGVO. In the event that your application documents are passed on to third parties, in particular to companies affiliated with us, as well as in the event that your data is stored beyond the current application procedure, your data is processed on the basis of Art. 6 Abs. 1 Satz 1 lit. a DSGVO in conjunction with § 26 Abs. 2 BDSG. There is no legal or contractual obligation to provide your data; however, processing your application is not possible without the provision of the information.
In the event of a rejection, the data of applicants is deleted after 6 months. In the event that you have consented to further storage of your personal data, we will transfer your data to our applicant pool. There, the data is deleted after a period of 24 months has elapsed.
9.4 Regular guest club (guest club)
This website uses KunLeiSys Gäste-Club Software (regular guest area). The provider is GASTROpoint GmbH, Pommernstraße 17, 83395 Freilassing, Germany. KunLeiSys Gäste-Club Software is a service with which the guest club, offers, loyalty points, emails for special occasions and newsletter dispatch are organised and managed. You can register for the guest club on our website. We use the data entered for this purpose only for the purpose of using the respective offer or service. The mandatory details requested during registration must be provided in full. Otherwise we will refuse the registration. The data entered during registration is processed on the basis of your consent (Art. 6 Abs. 1 lit. a DSGVO). You can withdraw a consent you have given at any time free of charge. You can do this via the unsubscribe link in the email or by unsubscribing in the guest club.
The data you have deposited with us for the purposes of the guest club is stored by us until you unsubscribe and, after unsubscribing and deletion of the guest club account, is deleted both from our servers and from the servers of GASTROpoint GmbH. For important changes, for instance to the scope of the offer or in the case of technically necessary changes, we use the email address provided/deposited during registration or in your profile in order to inform you in this way. Statutory retention periods remain unaffected. We have concluded a contract for commissioned data processing with GASTROpoint GmbH and fully implement the strict requirements of the data protection authorities when using KunLeiSys Gäste-Club Software.
10. Newsletter dispatch
10.1 Promotional newsletter
On our website you are given the opportunity to subscribe to our company’s newsletter. Which personal data is transmitted to us when the newsletter is ordered is apparent from the input mask used for this purpose.
We inform our customers and business partners at regular intervals about our offers by way of a newsletter. As a matter of principle, you can only receive our company’s newsletter if
1. you have a valid email address and
2. you have registered for the newsletter dispatch.
For legal reasons, a confirmation email is sent using the double opt-in procedure to the email address you enter for the newsletter dispatch for the first time. This confirmation email serves to verify whether you, as the owner of the email address, have authorised the receipt of the newsletter.
When you sign up for the newsletter, we furthermore store the IP address of the IT system used by you at the time of registration, as assigned by your internet service provider (ISP), as well as the date and time of the registration. The collection of this data is necessary in order to be able to trace the (possible) misuse of your email address at a later point in time and therefore serves our legal protection.
The personal data collected in the course of signing up for the newsletter is used exclusively for the dispatch of our newsletter. Furthermore, subscribers to the newsletter may be informed by email insofar as this is necessary for the operation of the newsletter service or for a registration relating thereto, as could be the case in the event of changes to the newsletter offering or in the event of changes to the technical circumstances. The personal data collected in the course of the newsletter service is not passed on to third parties. The subscription to our newsletter can be cancelled by you at any time. The consent to the storage of personal data which you have given us for the newsletter dispatch can be withdrawn at any time. For the purpose of withdrawing consent, a corresponding link is included in every newsletter. It is furthermore possible to unsubscribe from the newsletter dispatch directly on our website at any time or to notify us of this by other means.
The legal basis for the data processing for the purpose of the newsletter dispatch is Art. 6 Abs. 1 lit. a) DSGVO.
10.2 Newsletter tracking
Our newsletters contain so-called tracking pixels. A tracking pixel is a miniature graphic which is embedded in those emails that are sent in HTML format in order to enable a log file recording and a log file analysis. This makes it possible to carry out a statistical evaluation of the success or failure of online marketing campaigns. By means of the embedded tracking pixel, the company can recognise whether and when an email was opened by you and which links contained in the email were accessed by you.
Such personal data collected via the tracking pixels contained in the newsletters are stored and evaluated by us in order to optimise the dispatch of the newsletter and to adapt the content of future newsletters even better to your interests. These personal data are not passed on to third parties. Data subjects are entitled at any time to withdraw the separate declaration of consent given in this regard via the double opt-in procedure. Following a withdrawal, these personal data will be deleted by us. We automatically interpret an unsubscription from receipt of the newsletter as a withdrawal.
Such an evaluation takes place in particular pursuant to Art. 6 Abs. 1 lit. f) DSGVO on the basis of our legitimate interests in the display of personalised advertising, market research and/or needs-based design of our website.
10.3 Campaign Monitor
For the dispatch of newsletters we use the service “Campaign Monitor” of Campaign Monitor Pty Ltd., 631 Howard Street, Suite 100, San Francisco, CA 94105, USA.
Campaign Monitor is an all-in-one platform for the automation of marketing and sales processes. Among other things, the platform makes it possible to create emails and automated workflows in order to acquire potential customers and to maintain customer relationships.
When using Campaign Monitor, various personal data may be collected, including:
Email address
Time of access
IP address
Browser type
Operating system
Further information on the Campaign Monitor service as well as the data protection provisions can be viewed at: https://www.campaignmonitor.com/policies/#privacy-policy?tid=134283177.
10.4 Marketing emails
For the dispatch of our marketing emails we use Re:Guest, a service of ReGuest AG, Kuperionstr. 34, 39012 Meran, Italy. We send marketing emails only with your express consent pursuant to Art. 6 Abs. 1 lit. a DSGVO. In doing so, we process in particular your email address as well as, where applicable, further voluntary information for the personalisation of the contents. You can withdraw your consent at any time with effect for the future, e.g. via the unsubscribe link in every email. The processing takes place for the purpose of providing information about our services, offers and news. Further information on the data processing by Re:Guest can be found at: https://www.reguest.io/de/datenschutz.
11. Our activities in social networks
So that we can also communicate with you in social networks and inform you about our services, we are represented there with our own pages. If you visit one of our social media pages, we are jointly responsible for the processing, within the meaning of Art. 26 DSGVO, together with the provider of the respective social media platform with regard to the processing operations triggered thereby.
In this respect, we are not the original provider of these pages, but merely use them within the scope of the possibilities offered to us by the respective providers.
We therefore point out as a precaution that your data may possibly also be processed outside the European Union or the European Economic Area. Use may therefore be associated with data protection risks for you, since the safeguarding of your rights, e.g. to information, erasure, objection, etc., could be made more difficult and the processing in the social networks frequently takes place directly for advertising purposes or for the analysis of user behaviour by the providers, without this being able to be influenced by us. If usage profiles are created by the provider, cookies are frequently used in this process, or the usage behaviour is assigned to the member profile of the social networks created by you.
The described processing operations of personal data take place pursuant to Art. 6 Abs. 1 lit. f) DSGVO on the basis of our legitimate interest and the legitimate interest of the respective provider, in order to be able to communicate with you in a contemporary manner or to inform you about our services. If you have to give a consent to the data processing as a user with the respective providers, the legal basis refers to Art. 6 Abs. 1 lit. a) DSGVO in conjunction with Art. 7 DSGVO.
Since we have no access to the data holdings of the providers, we point out that you can best assert your rights (e.g. to information, rectification, erasure, etc.) directly with the respective provider. Further information on the processing of your data in the social networks is listed below under the respective provider of social networks used by us:
11.1 Facebook
(Joint) controller for the data processing in Europe:
Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland
Meta (Facebook) may, provided that no objection is made, process content of users of full age from the EU, e.g. photos, posts or comments, for the training of its own AI models. The basis is a legitimate interest pursuant to Art. 6 Abs. 1 lit. f) DSGVO. As a company, we have no influence on this specific data processing by Meta. Users can object to this via an online form on the Meta platforms.
Privacy policy (data policy): https://www.facebook.com/about/privacy
11.2 Instagram
(Joint) controller for the data processing in Germany:
Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland
Meta (Instagram) may, provided that no objection is made, process content of users of full age from the EU, e.g. photos, posts or comments, for the training of its own AI models. As a company, we have no influence on this specific data processing by Meta. The basis is a legitimate interest pursuant to Art. 6 Abs. 1 lit. f) DSGVO. Users can object to this via an online form on the Meta platforms.
Privacy policy (data policy): https://instagram.com/legal/privacy/
11.3 LinkedIn
(Joint) controller for the data processing in Europe:
LinkedIn Ireland Unlimited Company Wilton Place, Dublin 2, Ireland
Privacy policy: https://www.linkedin.com/legal/privacy-policy
11.4 YouTube
(Joint) controller for the data processing in Europe:
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Privacy policy: https://policies.google.com/privacy
12. Web analytics
12.1 Meta Pixel (formerly Facebook Pixel)
This website uses the “Facebook Pixel” of Meta Platforms, Inc., 1 Hacker Way, Menlo Park, CA 94025, USA (“Meta”). In the event that express consent is given, this makes it possible to track the behaviour of users after they have seen or clicked on a Facebook advertisement. This procedure serves to evaluate the effectiveness of the Facebook advertisements for statistical and market research purposes and can contribute to optimising future advertising measures.
When visiting the website, the following data, among others, may be processed by the Meta Pixel:
- IP address,
- Device information,
- Browser history
The data are stored and processed by Meta, so that a connection to the respective user profile is possible and Meta can use the data for its own advertising purposes in accordance with the Meta (Facebook) data usage policy (https://www.facebook.com/about/privacy/). Meta and its partners are thereby enabled to place advertisements on and outside of Facebook. Furthermore, a cookie may be stored on your computer for these purposes.
The collected data are stored by Meta for a period of 180 days and are subsequently removed if the website is not visited again by the user.
These processing operations take place exclusively where express consent is given pursuant to Art. 6 Abs. 1 lit. a) DSGVO.
This US company is certified under the EU-US Data Privacy Framework. An adequacy decision pursuant to Art. 45 DSGVO thereby exists, so that a transfer of personal data may take place even without further guarantees or additional measures.
12.2 Google Analytics 4 (GA4)
On our websites we use Google Analytics 4 (GA4), a web analytics service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”).
In this context, pseudonymised usage profiles are created and cookies (see the section “Cookies”) are used. The information generated by the cookie about your use of this website may include, among other things:
- a short-term recording of the IP address without permanent storage
- location data
- browser type/version
- operating system used
- referrer URL (previously visited page)
The pseudonymised data may be transferred by Google to a server in the USA and stored there.
The information is used to evaluate the use of the website, to compile reports on the website activities and to provide further services connected with the use of the website and the use of the internet for the purposes of market research and the needs-based design of these internet pages. This information is also transferred to third parties where applicable, provided that this is required by law or insofar as third parties process these data on our behalf.
These processing operations take place exclusively where express consent is given pursuant to Art. 6 Abs. 1 lit. a) DSGVO.
The storage period for the data preset by Google is 14 months. In all other respects, the personal data are retained for as long as they are necessary for the fulfilment of the purpose of the processing. The data are deleted as soon as they are no longer necessary for the achievement of the purpose.
The parent company Google LLC is certified as a US company under the EU-US Data Privacy Framework. An adequacy decision pursuant to Art. 45 DSGVO thus exists, so that a transfer of personal data may take place even without further guarantees or additional measures.
Further information on data protection when using GA4 can be found at: https://support.google.com/analytics/answer/12017362?hl=de.
12.3 Microsoft Clarity
On our website we use the service Microsoft Clarity (“Clarity”), a web analytics service of Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland.
In this context, pseudonymised usage profiles are created and cookies are set on your terminal device.
Processed data include, among other things:
- the browser type/version,
- the operating system used,
- the referrer URL (the previously visited page),
- the host name of the accessing computer (IP address),
- the user behaviour on the website visited,
- mouse movements and clicks,
The information is used to evaluate the use of the website, to compile reports on the website activities and to provide further services connected with the use of the website and the use of the internet for the purposes of market research and the needs-based design of our web pages.
These processing operations take place exclusively where express consent is given pursuant to Art. 6 Abs. 1 lit. a) DSGVO.
Microsoft processes the data in principle within the European Union within the framework of the so-called EU Data Boundary. In order to provide and safeguard the services and to fulfil legal obligations, Microsoft Ireland may transfer personal data to affiliated companies of Microsoft Corporation (Redmond, Washington, USA). The intra-group data transfer takes place on the basis of standard contractual clauses pursuant to Art. 46 Abs. 2 lit. C) DSGVO as well as supplementary technical and organisational measures, as laid down in the Microsoft Data Protection Addendum.
Microsoft Corporation is additionally certified under the EU?US Data Privacy Framework (DPF). An adequacy decision under Art. 45 DSGVO thus exists for data transfers to the USA. Transfers of personal data to Microsoft in the USA are therefore permissible even without further guarantees or additional measures.
You can view Microsoft’s data protection provisions at: https://privacy.microsoft.com/de-de/privacystatement.
12.4 Meta Conversions / Stape
On our website we use server-side tracking via the Meta Conversions API (CAPI) in order to analyse user interactions and to improve the effectiveness of our marketing measures. In doing so, certain event data (e.g. page views, interactions or conversions) are transmitted from our server to the servers of Meta. The provider for the European area is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; further processing may be carried out by Meta Platforms Inc., 1601 Willow Road, Menlo Park, CA 94025, USA. The implementation takes place via the Meta Conversions API Gateway using the hosting infrastructure of the provider Stape. The provider is STAPE, INC., 8 The Green, Suite 12892, Dover, DE 19901, USA, as well as – depending on the hosting configuration – Stape Europe OÜ, Sepapaja tn 6, 15551 Tallinn, Estonia. In particular, technical usage data (e.g. IP address, user agent, device information) as well as, where applicable, hashed identifiers may be transmitted in this process.
The processing takes place exclusively on the basis of your consent pursuant to Art. 6 Abs. 1 lit. a DSGVO as well as § 25 Abs. 1 TDDDG. Without your consent, no data transfer to Meta takes place. Further information on data protection can be found at: https://www.facebook.com/privacy/policy/ and, for Stape, at: https://stape.io/privacy-policy.
13. Advertising
13.1 Google Ads (AdWords) Remarketing/Retargeting
We have integrated Google Ads on this internet site. The operating company of the Google Ads services is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”).
With this we advertise for this website in the Google search results as well as on third-party websites. For this purpose, Google places a cookie in the browser of your terminal device, which automatically enables interest-based advertising by means of a pseudonymous cookie ID and on the basis of the pages you have visited.
Any data processing going beyond this only takes place if you have consented vis-à-vis Google that your internet and app browsing history is linked by Google with your Google account and that information from your Google account is used to personalise advertisements that you view on the web. If, in this case, you are logged in to Google while visiting our website, Google uses your data together with Google Analytics data in order to create and define target group lists for cross-device remarketing. For this purpose, your personal data are temporarily linked by Google with Google Analytics data in order to form target groups.
These processing operations take place exclusively where express consent is given pursuant to Art. 6 Abs. 1 lit. a) DSGVO.
The parent company Google LLC is certified as a US company under the EU-US Data Privacy Framework. An adequacy decision pursuant to Art. 45 DSGVO thus exists, so that a transfer of personal data may take place even without further guarantees or additional measures.
You can view the data protection provisions and further information of Google Ads at: https://www.google.com/policies/technologies/ads/
13.2 Google Ads with conversion tracking
We have integrated Google Ads on this website. The operating company of the Google Ads services is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Ads is an internet advertising service which permits advertisers to place ads both in Google's search engine results and in the Google advertising network. Google Ads enables an advertiser to define certain keywords in advance, by means of which an ad is displayed in Google's search engine results exclusively when the user retrieves a keyword-relevant search result using the search engine. In the Google advertising network, the ads are distributed across topic-relevant websites by means of an automatic algorithm and in observance of the previously defined keywords.
The purpose of Google Ads is the promotion of our website through the display of interest-relevant advertising on the websites of third-party companies and in the search engine results of the Google search engine, and the display of third-party advertising on our website.
If you reach our website via a Google ad, a so-called conversion cookie is stored on your IT system by Google. A conversion cookie loses its validity after thirty days and does not serve to identify you. By means of the conversion cookie, provided that the cookie has not yet expired, it is traced whether certain sub-pages, for example the shopping cart of an online shop system, were called up on our website. By means of the conversion cookie, both we and Google can trace whether a user who reached our website via an AdWords ad generated revenue, that is to say completed or aborted a purchase of goods.
The data and information collected through the use of the conversion cookie are used by Google in order to create visit statistics for our website. These visit statistics are in turn used by us in order to determine the total number of users who were referred to us via Ads advertisements, that is to say in order to determine the success or failure of the respective Ads advertisement and in order to optimise our Ads advertisements for the future. Neither our company nor other advertising customers of Google Ads receive information from Google by means of which you could be identified.
By means of the conversion cookie, personal information, for example the websites visited by you, is stored. Accordingly, each time you visit our websites, personal data, including the IP address of the internet connection used by you, are transmitted to Google in the United States of America. These personal data are stored by Google in the United States of America. Google may under certain circumstances pass on these personal data collected by means of the technical procedure to third parties.
These processing operations take place exclusively where explicit consent has been granted pursuant to Art. 6 Abs. 1 lit. a) DSGVO.
The parent company Google LLC is certified as a US company under the EU-US Data Privacy Framework. An adequacy decision pursuant to Art. 45 DSGVO thus exists, so that a transfer of personal data may take place even without further guarantees or additional measures.
You can view the data protection provisions and further information of Google AdSense at: https://www.google.de/intl/de/policies/privacy/.
14. Plugins and other services
14.1 Google Tag Manager
On this website we use the Google Tag Manager service. The operating company of Google Tag Manager is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Ireland Limited is part of the Google group of companies with its head office at 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
By means of this tool, “website tags” (i.e. keywords which are embedded in HTML elements) can be implemented and managed via an interface. Through the use of the Google Tag Manager we can trace in automated fashion which button, which link or which personalised image you actively clicked on, and can then record which contents of our website are of particular interest to you.
The tool furthermore ensures the triggering of other tags, which for their part may under certain circumstances collect data. Google Tag Manager does not access these data. If you have carried out a deactivation at domain or cookie level, this remains in place for all tracking tags which are implemented with Google Tag Manager.
These processing operations take place exclusively where explicit consent has been granted pursuant to Art. 6 Abs. 1 lit. a) DSGVO.
The parent company Google LLC is certified as a US company under the EU-US Data Privacy Framework. An adequacy decision pursuant to Art. 45 DSGVO thus exists, so that a transfer of personal data may take place even without further guarantees or additional measures.
You can view further information on the Google Tag Manager as well as Google's privacy policy at: https://www.google.com/intl/de/policies/privacy/.
14.2 Google WebFonts
For the uniform display of fonts, our website uses so-called web fonts. The Google WebFonts are provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Ireland Limited is part of the Google group of companies with its head office at 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
These processing operations take place exclusively where explicit consent has been granted pursuant to Art. 6 Abs. 1 lit. a) DSGVO.
The parent company Google LLC is certified as a US company under the EU-US Data Privacy Framework. An adequacy decision pursuant to Art. 45 DSGVO thus exists, so that a transfer of personal data may take place even without further guarantees or additional measures.
You can view further information on the Google WebFonts as well as Google's privacy policy at: https://developers.google.com/fonts/faq ; https://www.google.com/policies/privacy/.
14.3 Re:Guest Messenger
We have integrated components of the customer communication platform Re:Guest on our website. The messenger is a service of ReGuest AG and offers us the possibility of being able to communicate by chat with visitors to our website and to provide targeted assistance with queries. The messenger uses cookies and further browser technologies in order to evaluate user behaviour and to recognise users again. Furthermore, the messenger is used in order to store and transmit data entered in chats by means of cookies, together with your IP address. In this case your data are passed on to the operator, ReGuest AG, Kuperionstr. 34, 39012 Meran, Italy.
The messenger is used on the basis of your consent pursuant to Art. 6 Abs. 1 lit. a. DSGVO and § 25 Abs. 1 TDDDG. You can find further information in the privacy policy: https://www.reguest.io/de/information/datenschutzerkl%C3%A4rung/5-0.html.
14.4 TagEmbed
On our website we use a social media widget of the Tagembed service in order to embed Instagram content. The provider is Social Scape Tech LLP, a company based in India (B138 Vidhyut Nagar, JPR 302021, Rajasthan). When a page with an embedded widget is accessed, personal data, in particular the IP address, browser information (user agent) as well as further technical connection data, are transmitted to the provider's servers through the reloading of external content. In addition, cookies and comparable technologies may be used.
The embedding and the data processing take place exclusively on the basis of your consent pursuant to Art. 6 Abs. 1 lit. a DSGVO and § 25 Abs. 1 TDDDG. The widget is therefore only loaded after your express consent given via our consent management tool. Without your consent, no data transmission takes place in connection with this service. Further information on the data processing by Tagembed can be found in the provider's privacy policy at: https://tagembed.com/privacy-policy/.
15. Your rights as a data subject
15.1 Right to confirmation
You have the right to request confirmation from us as to whether personal data concerning you are being processed.
15.2 Right of access – Art. 15 DSGVO
15.3 Right to rectification – Art. 16 DSGVO
You have the right to request the rectification of inaccurate personal data concerning you. Furthermore, taking into account the purposes of the processing, you have the right to request the completion of incomplete personal data.
15.4 Erasure – Art. 17 DSGVO
You have the right to request that we erase the personal data concerning you without undue delay, provided that one of the reasons provided for by law applies and insofar as the processing or storage is not necessary.
15.5 Restriction of processing – Art. 18 DSGVO
You have the right to request that we restrict processing where one of the statutory conditions is met.
15.6 Data portability – Art. 20 DSGVO
You have the right to receive the personal data concerning you which you have provided to us in a structured, commonly used and machine-readable format. You also have the right to transmit these data to another controller to whom the personal data have been provided, without hindrance from us, provided that the processing is based on consent pursuant to Art. 6 Abs. 1 lit. a) DSGVO or Art. 9 Abs. 2 lit. a) DSGVO or on a contract pursuant to Art. 6 Abs. 1 lit. b) DSGVO and the processing is carried out by automated means, provided that the processing is not necessary for the performance of a task which is carried out in the public interest or in the exercise of official authority vested in us.
Furthermore, in exercising your right to data portability pursuant to Art. 20 Abs. 1 DSGVO, you have the right to obtain that the personal data are transmitted directly from one controller to another controller, insofar as this is technically feasible and provided that the rights and freedoms of other persons are not adversely affected thereby.
15.7 Objection – Art. 21 DSGVO
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6 Abs. 1 lit. e) (data processing in the public interest) or f (data processing on the basis of a balancing of interests) DSGVO.
This also applies to profiling based on these provisions within the meaning of Art. 4 Nr. 4 DSGVO.
If you lodge an objection, we will no longer process your personal data, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or unless the processing serves the establishment, exercise or defence of legal claims.
In individual cases we process personal data in order to carry out direct marketing. You may object at any time to the processing of the personal data for the purposes of such advertising. This also applies to profiling insofar as it is connected with such direct marketing. If you object to us in respect of processing for the purposes of direct marketing, we will no longer process the personal data for these purposes.
In addition, you have the right, on grounds relating to your particular situation, to object to the processing of personal data concerning you which is carried out by us for scientific or historical research purposes or for statistical purposes pursuant to Art. 89 Abs. 1 DSGVO, unless such processing is necessary for the performance of a task carried out in the public interest.
You are free, in connection with the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise your right to object by automated means using technical specifications.
15.8 Withdrawal of consent under data protection law
You have the right to withdraw consent to the processing of personal data at any time with effect for the future.
15.9 Complaint to a supervisory authority
You have the right to lodge a complaint with a supervisory authority responsible for data protection about our processing of personal data.
16. Duration of storage of personal data
The criterion for the duration of storage of personal data is the respective statutory retention period. After the period has expired, the corresponding data are routinely erased, provided they are no longer required for the performance of a contract or for the initiation of a contract.
17. Currency and amendment of this privacy policy
This privacy policy is currently valid and has the status: June 2026.




