Privacy Policy
Privacy Policy
1. Controller
Nägele GmbH
Boutique-Hotel Bayerischer Hof
Füssener Straße 96
87437 Kempten
Germany
Phone: +49 (0) 831 5718-0
E-mail: hotel@bayerischerhof-kempten.de
2. Your Rights
You have the right to:
- Access your personal data (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Withdraw consent at any time (Art. 7 para. 3 GDPR)
- Object to processing (Art. 21 GDPR)
- Lodge a complaint with a supervisory authority
Competent supervisory authority:
Bavarian State Office for Data Protection Supervision (BayLDA), Ansbach, Germany.
3. General Information on Data Processing
We process personal data in accordance with applicable data protection regulations, in particular the General Data Protection Regulation (GDPR) and the German TTDSG.
Please note that data transmission over the Internet (e.g. via e-mail) may have security vulnerabilities.
4. Hosting
Our website is hosted by:
IONOS SE
Elgendorfer Straße 57
56410 Montabaur
Germany
IONOS processes personal data (e.g. IP addresses) on our behalf in accordance with Art. 28 GDPR.
Legal basis: Art. 6 para. 1 lit. f GDPR
(legitimate interest in secure and stable website operation)
5. Server Log Files
When visiting our website, the following data is automatically collected:
- IP address
- Browser type
- Operating system
- Referrer URL
- Date and time of access
Legal basis: Art. 6 para. 1 lit. f GDPR.
6. Cookies & Consent Management
Our website uses a consent management tool. When visiting our website for the first time, you can decide whether to allow cookies beyond those that are technically necessary.
Legal basis:
- Section 25 TTDSG
- Art. 6 para. 1 lit. a GDPR (consent)
You may change your selection at any time.
7. Contact
If you contact us via contact form, telephone or e-mail, we process your data to handle your request.
Legal basis:
- Art. 6 para. 1 lit. b GDPR (pre-contractual measures)
- Art. 6 para. 1 lit. f GDPR (legitimate interest for general inquiries)
8. Online Booking (Hotel)
For online room bookings we use:
HotelNetSolutions GmbH
Genthiner Straße 8
10785 Berlin
Germany
The following data is processed:
- Name
- Contact details
- Stay details
- Payment information
Processing is carried out for the performance of the accommodation contract.
Legal basis: Art. 6 para. 1 lit. b GDPR.
HotelNetSolutions processes data on our behalf in accordance with Art. 28 GDPR.
9. Voucher Shop
For the sale and processing of online vouchers we use:
Gurado GmbH
Wittelsbacherallee 120
60385 Frankfurt am Main
Germany
When ordering a voucher, the following personal data is processed:
- First and last name
- Billing and, if applicable, delivery address
- E-mail address
- Order details
- Name of the voucher recipient (if applicable)
- Payment data
Processing is carried out for contract performance, payment processing and issuing/delivering the voucher.
Legal basis: Art. 6 para. 1 lit. b GDPR.
Gurado processes data on our behalf in accordance with Art. 28 GDPR.
Payment Methods
We offer the following payment methods:
- Advance payment (bank transfer)
- Invoice (for schools, public authorities and registered companies after verification)
- Cash on delivery
- Direct debit
- PayPal
Depending on the selected payment method, the necessary payment data is processed.
Legal basis: Art. 6 para. 1 lit. b GDPR.
PayPal
If you choose PayPal as a payment method, payment processing is carried out via:
PayPal (Europe) S.à r.l. et Cie, S.C.A.
22–24 Boulevard Royal
L-2449 Luxembourg
The data required for payment processing will be transmitted to PayPal. PayPal processes this data under its own responsibility.
Further information can be found at:
https://www.paypal.com/de/webapps/mpp/ua/privacy-full
Legal basis: Art. 6 para. 1 lit. b GDPR.
10. Newsletter
For sending our newsletter we use:
Smarthost GmbH
Dornbirn, Austria
Processed data: e-mail address, name (if provided), subscription data.
Legal basis: Art. 6 para. 1 lit. a GDPR (consent).
You may withdraw your consent at any time via the unsubscribe link.
11. Analytics Tools
Google Analytics
Provider: Google Ireland Limited, Dublin, Ireland
IP anonymization is activated.
Data retention: 14 months.
A transfer of data to third countries (e.g. USA) cannot be excluded.
Legal basis: Art. 6 para. 1 lit. a GDPR (consent).
12. External Content & Plugins
We use external services such as:
- Google Maps
- Facebook / Instagram
- TrustYou
These services are only activated after your consent.
Legal basis: Art. 6 para. 1 lit. a GDPR or Art. 6 para. 1 lit. f GDPR (legitimate interest in presenting guest reviews – TrustYou).
13. Data Retention
We store personal data only as long as necessary for the respective purpose or as required by statutory retention obligations (in particular 6 or 10 years under German commercial and tax law). After that, the data will be deleted.
For more information about the handling of user data by Google Analytics, please consult Google’s Data Privacy Declaration at: https://support.google.com/analytics/answer/6004245?hl=en.
Contract data processing
We have executed a contract data processing agreement with Google and are implementing the stringent provisions of the German data protection agencies to the fullest when using Google Analytics.
Archiving period
Data on the user or incident level stored by Google linked to cookies, user IDs or advertising IDs (e.g. DoubleClick cookies, Android advertising ID) will be anonymized or deleted after 14 month. For details please click the following link: https://support.google.com/analytics/answer/7667196?hl=en
5. Newsletter
Newsletter data
If you would like to subscribe to the newsletter offered on this website, we will need from you an e-mail address as well as information that allow us to verify that you are the owner of the e-mail address provided and consent to the receipt of the newsletter. No further data shall be collected or shall be collected only on a voluntary basis. We shall use such data only for the sending of the requested information and shall not share such data with any third parties.
The processing of the information entered into the newsletter subscription form shall occur exclusively on the basis of your consent (Art. 6 Sect. 1 lit. a GDPR). You may revoke the consent you have given to the archiving of data, the e-mail address and the use of this information for the sending of the newsletter at any time, for instance by clicking on the „Unsubscribe“ link in the newsletter. This shall be without prejudice to the lawfulness of any data processing transactions that have taken place to date.
The data deposited with us for the purpose of subscribing to the newsletter will be stored by us until you unsubscribe from the newsletter or the newsletter service provider and deleted from the newsletter distribution list after you unsubscribe from the newsletter. Data stored for other purposes with us remain unaffected.
After you unsubscribe from the newsletter distribution list, your e-mail address may be stored by us or the newsletter service provider in a blacklist to prevent future mailings. The data from the blacklist is used only for this purpose and not merged with other data. This serves both your interest and our interest in complying with the legal requirements when sending newsletters (legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR). The storage in the blacklist is indefinite. You may object to the storage if your interests outweigh our legitimate interest.