Loftigo

Privacy Policy

GDPR privacy policy

This is a translation provided for your convenience. The German version of this document is the legally binding one; in case of any discrepancy, the German text prevails.

1. We are glad that you are visiting our website.

Protecting your privacy and your personal data when you use our website is important to us.

Under Art. 4(1) GDPR, personal data means any information relating to an identified or identifiable natural person. This includes, for example, your first and last name, your address, your telephone number, your email address, but also your IP address.

Data from which no reference to your person can be established — for instance because it has been anonymised — is not personal data. Processing (e.g. collection, storage, reading, querying, use, transfer, erasure or destruction) within the meaning of Art. 4(2) GDPR always requires a statutory legal basis or your consent. Personal data that has been processed must be erased as soon as the purpose of the processing has been achieved and no statutory retention obligations remain to be observed.

Below you will find information on how your personal data is handled when you visit our website. In order to provide the functions and services of our website, we need to collect personal data about you. We also explain the nature and scope of each processing operation, its purpose, the corresponding legal basis and the respective storage period.

This privacy policy applies to this website only. It does not apply to other websites that we merely refer to via a hyperlink. We cannot accept any responsibility for the confidential handling of your personal data on such third-party websites, as we have no influence over whether those companies comply with data protection law. Please inform yourself about the handling of your personal data by those companies directly on their websites.

2. Controller

The controller responsible for the processing of personal data on this website is: Loftigo UG (haftungsbeschränkt) – Vollmühle 24a, 52538 Selfkant, Germany, represented by Christopher Martin Müller, Vlattenstraße 10, 40223 Düsseldorf, Germany. Phone: +49 2456 7059950, email: help@loftigo.com

3. Provision and use of the website / server log files

a) Nature and scope of the processing

If you use this website without transmitting data to us in any other way (e.g. by registering or using the contact form), we collect technically necessary data via server log files, which your browser automatically transmits to our server, including:

IP address
date and time of the request
name and URL of the file retrieved
website from which the access originates (referrer URL)
access status / HTTP status code
browser type
language and version of the browser software
operating system

b) Purpose and legal basis

This processing is technically necessary in order to display our website to you. We also use the data to ensure the security and stability of our website. The legal basis for this processing is Art. 6(1)(f) GDPR. Processing the data listed above is necessary in order to provide a website and therefore serves a legitimate interest of our company.

c) Storage period

As soon as the personal data listed above is no longer required to display the website, it is erased. Collecting the data to provide the website and storing it in log files is strictly necessary for the operation of the website. Consequently, there is no possibility for the user to object in this respect. Data may be stored for longer in individual cases where this is required by law.

4. Use of cookies

a) Nature, scope and purpose of the processing

We use cookies. Cookies are small files that we send to the browser on your device during your visit to our website and that are stored there.

Some functions of our website cannot be offered without the use of technically necessary cookies. Other cookies allow us to carry out various analyses. Some cookies can recognise the browser you use when you visit our website again and transmit various pieces of information to us. We use cookies to make the use of our website easier and better. Cookies do not damage your device. They cannot execute programs and cannot contain viruses.

Temporary cookies / session cookies: These are deleted automatically as soon as you close your browser. They allow your session ID to be recorded and different requests from your browser to be assigned to a common session.

Permanent cookies: These are stored in your browser for a longer period. The storage period differs from cookie to cookie. You can delete permanent cookies yourself via your browser settings.

The cookies we actually use: Technically necessary cookies for signing in to your customer account (session), for protection against cross-site request forgery (CSRF), for the language you have selected and for storing your cookie choice. In addition — and only after you have given your consent — we use analytics cookies or comparable techniques for the statistical evaluation of website use (see section 16). We do not use advertising cookies, social media cookies or cookies for cross-user profiling.

Configuring your browser settings: Most browsers accept cookies automatically. You can configure your browser so that it only accepts certain cookies or none at all, delete cookies that have already been stored, or notify you before a cookie is stored. If you deactivate cookies entirely, you may no longer be able to use all functions of the website.

b) Legal basis

Storing information on your device and accessing it is governed by section 25 of the German Digital Services Data Protection Act (TDDDG). For technically necessary cookies that are strictly required for the service you have expressly requested, this is permitted without consent under section 25(2) no. 2 TDDDG; we base the subsequent processing of personal data on Art. 6(1)(b) GDPR (contract or pre-contractual measures) and Art. 6(1)(f) GDPR (legitimate interest in secure and functional operation).

All other cookies and comparable techniques — in particular those used for analytics and statistics — are only used with the consent you give via our cookie banner in accordance with section 25(1) TDDDG and Art. 6(1)(a) GDPR. Your consent is voluntary and can be withdrawn at any time with effect for the future via the cookie settings.

c) Storage period

As soon as the data transmitted to us via cookies is no longer required for the purposes described, that information is erased. Data may be stored for longer in individual cases where this is required by law.

5. Collection of data for pre-contractual measures and performance of the contract

a) Nature and scope of the processing

We collect personal data about you in the pre-contractual phase and when a contract is concluded. This concerns, for example, your first and last name, address, email address, telephone number or bank details.

b) Purpose and legal basis of the processing

We collect and process this data exclusively for the purpose of performing the contract or fulfilling pre-contractual obligations. The legal basis for this is Art. 6(1)(b) GDPR. Where you have additionally given us your consent, Art. 6(1)(a) GDPR is a further legal basis.

c) Storage period

The data is erased as soon as it is no longer required for the purpose of its processing. Statutory retention obligations may apply in addition, for example commercial or tax retention obligations under the German Commercial Code (HGB) or the German Fiscal Code (AO). Where such obligations exist, we restrict or erase your data once those retention periods end.

6. Booking an apartment (booking process)

a) Nature and scope of the processing

You can make a binding booking of an apartment via our website. During the booking process we process:

first and last name of the person making the booking
billing or home address
email address and telephone number
selected apartment, arrival and departure date, number of guests
additional services booked (e.g. cleaning, laundry, parking, early check-in / late check-out)
when booking a private parking space: the vehicle registration number
expected time of arrival as well as any comments and special requests you provide voluntarily
for company bookings, additionally the company name and, where applicable, the VAT identification number

We do not collect payment data (e.g. card numbers or bank details) ourselves. You enter this exclusively and directly with our payment service provider (see section 17).

b) Purpose and legal basis

The purpose is the conclusion and performance of the accommodation contract, including confirmation, invoicing, provision of the apartment, organisation of your arrival and of cleaning, as well as communication with you about your stay. The legal basis is Art. 6(1)(b) GDPR. Where we process data to comply with legal obligations (e.g. tax and commercial record-keeping duties), the legal basis is Art. 6(1)(c) GDPR.

c) Storage period

Booking data is stored for the duration of the contractual relationship. It is then erased unless statutory retention obligations prevent this. Booking, invoice and payment data is subject to commercial and tax retention periods of up to ten years (section 147 AO, section 257 HGB); for that period, processing is limited to fulfilling those obligations.

7. Option to register

a) Nature and scope of the processing

You can create a customer account on our website. When you register, we collect and store the data you enter in the input form (first name, last name, email address, optionally telephone number and profile picture) as well as your password. We store your password exclusively as a non-reversible cryptographic hash, never in plain text.

To confirm that the email address you provided belongs to you, we send you an email containing a confirmation link (double opt-in). Until you confirm, the account cannot be used in full.

Check for compromised passwords: When a password is set or changed, we check whether the chosen password has appeared in known data breaches. For this we use the “Have I Been Pwned” service (Pwned Passwords) operated by Superlative Enterprises Ltd. Only the first five characters of a hash of your password are transmitted (known as k-anonymity); neither your password nor your email address nor your IP address is disclosed to the service for this purpose. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the security of customer accounts.

b) Purpose and legal basis of the processing

Your registration is required in order to use certain content and services, or to perform a contract or carry out pre-contractual measures. After registering you are free to change the data you have provided at any time or to have it deleted in full. Where you have given consent, the legal basis is Art. 6(1)(a) GDPR; where the registration serves to prepare the conclusion of a contract, Art. 6(1)(b) GDPR is an additional legal basis.

c) Storage period

The data collected during registration is stored for as long as you are registered on our website and is then erased. Statutory retention periods remain unaffected.

8. Transfer of data

We only pass your personal data on to third parties where:

a) you have given your express consent to do so pursuant to Art. 6(1)(a) GDPR.

b) this is legally permissible and, pursuant to Art. 6(1)(b) GDPR, necessary for the performance of a contractual relationship with you or for carrying out pre-contractual measures.

c) there is a legal obligation to disclose the data pursuant to Art. 6(1)(c) GDPR. We are legally obliged to transmit data to public authorities, e.g. tax authorities, social insurance institutions, health insurers, supervisory authorities and law enforcement authorities.

d) disclosure is necessary pursuant to Art. 6(1)(f) GDPR to safeguard legitimate business interests and to establish, exercise or defend legal claims, and there is no reason to assume that you have an overriding interest worthy of protection in your data not being disclosed.

e) we use external service providers (processors) for the processing pursuant to Art. 28 GDPR, who are obliged to handle your data with due care. We use such service providers in the areas of IT, logistics, telecommunications, sales and marketing.

Where data is transferred to external bodies in third countries (outside the EU or the EEA), we ensure that those bodies treat your personal data with the same care as within the EU or the EEA. We only transfer data to third countries for which the EU Commission has confirmed an adequate level of protection, or where we ensure careful handling by means of contractual arrangements or other appropriate safeguards.

9. Job applications

a) Nature and scope of the processing

You can apply to us via our website or by email. When you apply, we collect and store the data you enter in the input form or that you send us by email.

b) Purpose and legal basis

We process your data solely for the purpose of processing your application. It is not passed on to third parties. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures), supplemented by section 26(1) sentence 1 of the German Federal Data Protection Act (BDSG) in conjunction with Art. 88(1) GDPR. Where you give us your consent to be included in our applicant pool, the legal basis is Art. 6(1)(a) GDPR.

c) Storage period

If we are unable to offer you a position, we store your data for no longer than six months after the end of the application process, taking into account section 61b(1) of the German Labour Court Act (ArbGG) in conjunction with section 15 of the German General Equal Treatment Act (AGG). The period starts when you receive the rejection letter. If you consent to being included in our applicant pool, we store your data for a maximum of two years.

d) Disclosure of data

Your data is only received by those units involved in the decision (the responsible HR and specialist departments, management, works council). In addition, we are obliged to transmit your data to public bodies and institutions (e.g. public prosecutors, police, supervisory authorities, tax office, social insurance institutions). Further recipients may be bodies for which you have given us your consent.

10. Reviews and feedback after your stay

a) Nature and scope of the processing

After your stay we would like to ask you once, by email, for feedback on your stay. For this we process your name, your email address, the booking data (apartment and period of stay) as well as your rating and any free text you enter voluntarily. If you agree to publication, your review may be displayed on our website with your first name and the month and year of your stay.

b) Purpose and legal basis

The purpose is quality assurance, the improvement of our services and the presentation of guest feedback. We only send the review request by email if you have given us your express consent at check-in or during the booking process; the legal basis in that respect is Art. 6(1)(a) GDPR and section 7(2) of the German Act Against Unfair Competition (UWG). Processing the review itself is based on Art. 6(1)(f) GDPR (legitimate interest in quality assurance) or — in the case of publication — on your consent pursuant to Art. 6(1)(a) GDPR.

You can object to receiving further review requests at any time — via the unsubscribe link in each of these emails or informally to help@loftigo.com. No costs are incurred other than the transmission costs at the basic rates.

c) Storage period

We store published reviews until you withdraw your consent or the purpose ceases to apply. Internal feedback that is not published is erased as soon as it is no longer required for quality assurance, at the latest after three years. We store your unsubscribe request permanently so that we can honour your objection.

11. Contact form

a) Nature and scope of the processing

Our website offers you the option of contacting us via a form we provide. During the sending process, reference is made to this privacy policy in order to obtain your consent. The following is processed: first name, last name, telephone number, email address, content of your message.

b) Purpose and legal basis

Providing your email address serves the purpose of allowing us to reply to your enquiry. The data is not passed on to third parties. The legal basis is consent pursuant to Art. 6(1)(a) GDPR (which can be withdrawn at any time with effect for the future).

c) Storage period

The data remains with us until you ask us to erase it, withdraw your consent or the purpose ceases to apply. Mandatory statutory retention periods (HGB, AO) remain unaffected.

12. Contact by email

a) Nature and scope of the processing

You can contact us by email. Our data collection is limited to the email address of the account used and to the data you provide when contacting us.

b) Purpose and legal basis

The purpose is to be able to respond appropriately to your request. The legal basis is Art. 6(1)(f) GDPR (legitimate interest).

c) Storage period

The storage period depends on the background of your enquiry. Data is erased as soon as the purpose of the communication no longer applies and storage is no longer necessary.

13. Newsletter

a) Nature and scope of the processing

You can subscribe to a free, regular email newsletter. For this we use the double opt-in procedure: we only send the newsletter once you have confirmed via a confirmation link. We store your first and last name, email address, IP address and the date and time of both your sign-up and your confirmation, so that misuse can be traced.

b) Purpose and legal basis

The data collected is used solely for promotional communication by newsletter. The legal basis is Art. 6(1)(a) GDPR and section 7(2) no. 3 UWG (consent, which can be withdrawn at any time) as well as Art. 6(1)(f) GDPR (evidence of consent).

c) Storage period

Your email address is stored for as long as you subscribe to the newsletter. After you unsubscribe it is erased, unless you have expressly consented to further use.

14. Tracking and analytics tools

We use tracking and analytics tools to ensure the continuous optimisation and needs-based design of our website and to record its use statistically. We have a legitimate interest in this (Art. 6(1)(f) GDPR). Where you have given us your consent via a cookie banner, lawfulness additionally follows from Art. 6(1)(a) GDPR.

You can find a precise overview of the web analytics and social media tools we use here: /tracking-tools

15. AI-supported features (chat assistant & automated draft replies)

a) Nature and scope of the processing

We use an AI-supported chat assistant (“James”) and use AI to prepare replies to customer enquiries. In doing so we process your input, in particular your chat messages and enquiries as well as any contact and booking data you provide. To operate these features we use the service of Anthropic PBC, San Francisco, CA, USA (“Anthropic”) as a processor. Content transmitted via the application programming interface (API) is not used by Anthropic to train its AI models.

To ensure the security of our systems and to prevent and investigate misuse (e.g. spam, fraudulent, unlawful or abusive input), we additionally log and store your IP address and your browser identifier (user agent) for every message sent in the chat. This also applies to visitors who are not signed in.

b) Purpose and legal basis

The purpose is the efficient answering and handling of your enquiries. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in handling enquiries efficiently) or Art. 6(1)(b) GDPR where the processing serves the initiation or performance of a contract. Where you have given us your consent, Art. 6(1)(a) GDPR is an additional legal basis. There is no automated decision-making in individual cases within the meaning of Art. 22 GDPR; replies prepared by the AI are reviewed and released by us before they are sent.

Where we log the IP address and browser identifier (user agent) for each chat message, this is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the security of our systems and in preventing and investigating misuse.

c) Transfer to a third country

As Anthropic is based in the USA, personal data is transferred to a third country. This transfer is safeguarded by the conclusion of the EU standard contractual clauses (Art. 46(2)(c) GDPR) within the framework of a data processing agreement pursuant to Art. 28 GDPR.

d) Storage period

Content is only stored for as long as it is required for the stated purpose. The IP address and browser identifier stored with a chat message are automatically erased or anonymised after 90 days at the latest; the chat message itself may be retained beyond that in order to handle your request. Please do not enter special categories of personal data (e.g. health data) in the chat.

16. Visitor statistics, location analysis and checkout tracking

a) Nature and scope of the processing

For the statistical evaluation of the use of our website (reach, origin of visitors) and to optimise our booking process, we record your IP address when you access our pages, the approximate location derived from it (country, region and city), the page or page type accessed and, where applicable, the referring website (referrer). The IP address is matched to a location using a geo database operated locally on our server (MaxMind GeoLite2); no data is transmitted to third parties for this purpose. The location is accurate to city or region level and does not allow any conclusions about your exact address.

In addition, we record the course of a booking process that has been started (checkout): the apartment selected, the desired period, the number of guests, the additional services chosen and the cart value, as well as whether a booking process was started, abandoned or completed. This serves to analyse and improve our booking process (for example to identify abandoned bookings). These evaluations can only be viewed by our authorised employees in the internal administration area.

b) Purpose and legal basis

The purpose is the statistical evaluation of website use, determining the geographical origin of our visitors and optimising our booking process. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR, which you give via our cookie/consent banner (“analytics/statistics” category). Without your consent, this data is not recorded. You can withdraw your consent at any time with effect for the future via the cookie settings.

c) Storage period

The data recorded for analytics purposes, including the IP address, is automatically erased or anonymised after 90 days at the latest. To distinguish returning visitors within a single day, we additionally use a non-reversible checksum of your IP address that changes daily.

17. Payment processing (Stripe)

a) Nature and scope of the processing

To process payments we use the payment service provider Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (“Stripe”). When you select a payment method, you are redirected to a secure payment page operated by Stripe. You enter your payment data (e.g. card number, bank details, data for payment services such as Apple Pay, Google Pay, PayPal or Klarna) exclusively there; we do not receive this data.

The invoice amount, the currency, a booking or transaction reference, your name and email address and the description of the service booked are transmitted to Stripe. From Stripe we receive back whether and when a payment was successful, the payment method used in abbreviated form (e.g. card type and the last four digits) as well as transaction and receipt references. Stripe also processes your data under its own responsibility for fraud prevention and to comply with its own legal obligations (anti-money-laundering, financial and regulatory law).

b) Purpose and legal basis

The purpose is processing the payment, assigning payments to bookings and handling refunds and chargebacks. The legal basis is Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest in secure payment processing free of misuse).

c) Transfer to a third country

Stripe may transfer data to affiliated companies in the USA. This transfer is safeguarded by EU standard contractual clauses (Art. 46(2)(c) GDPR). You can find further information in Stripe’s privacy policy at stripe.com/privacy.

d) Storage period

The payment records stored by us are subject to commercial and tax retention periods of up to ten years (section 147 AO, section 257 HGB). Stripe is responsible for the storage period at Stripe.

18. Invoicing and accounting (Lexware Office)

a) Nature and scope of the processing

To create invoices, cancellation invoices and credit notes and for our accounting, we use the software “Lexware Office” (formerly lexoffice) provided by Haufe-Lexware GmbH & Co. KG, Munzinger Straße 9, 79111 Freiburg, Germany. In doing so, your first and last name or your company, your billing address, your email address, where applicable your VAT identification number as well as the line items and amounts relating to your booking are processed. The servers are located in Germany.

b) Purpose and legal basis

The purpose is compliance with our statutory obligations regarding invoicing, record-keeping and retention. The legal basis is Art. 6(1)(c) GDPR in conjunction with section 14 of the German VAT Act (UStG), section 147 AO and section 257 HGB, as well as Art. 6(1)(b) GDPR. The provider acts for us as a processor pursuant to Art. 28 GDPR.

c) Storage period

Records are stored for the statutory retention period of ten years.

19. Bookings via booking portals and channel managers

a) Nature and scope of the processing

Our apartments are also offered via third-party booking portals, in particular Booking.com and Airbnb (the “portals”). If you book via such a portal, those portals initially collect your data under their own responsibility; their privacy notices apply in that respect. From the portal we receive the data required to carry out your stay, generally your name, the booking number, the period of stay, the number of guests, the price booked, where applicable an anonymised email address provided by the portal, a telephone number and your messages to us.

For the technical connection to these portals and the synchronisation of availability, prices and bookings we use the channel manager “Beds24” as a processor. The booking data described above and the message communication conducted via the portals between you and us are transmitted through it and stored in our system so that we can answer your enquiries.

b) Purpose and legal basis

The purpose is the performance of the accommodation contract concluded via the portal, the avoidance of double bookings and communication with you about your stay. The legal basis is Art. 6(1)(b) GDPR and, for availability synchronisation, additionally Art. 6(1)(f) GDPR (legitimate interest in error-free occupancy planning).

c) Storage period

The periods set out in section 6 apply. We erase message histories as soon as they are no longer required to handle your request and for documentation purposes, but at the latest when the statutory retention periods expire.

20. Digital check-in, access codes and electronic door locks

a) Nature and scope of the processing

Access to our apartments is provided via electronic door locks from Nuki Home Solutions GmbH, Münzgrabenstraße 92/4, 8010 Graz, Austria (“Nuki”), which we use as a processor. For your stay we create an individual numeric code limited in time to your booking period. For this purpose, a designation of the authorisation (generally your name or your booking number), the validity period and log data on locking operations (time and authorisation used) are processed in Nuki’s system. Nuki’s servers are located in the European Union.

Sending your check-in code by email: We send you your personal check-in code and your arrival information by email before you arrive. This also applies if you booked via a booking portal (section 19); in that case we use the email address transmitted by the portal or the one you provided during check-in. In addition, we make the access details available in the digital check-in or in your customer account.

As part of the digital check-in we also process the details you provide there, in particular your contact details, your expected arrival time and the details of your fellow travellers.

b) Purpose and legal basis

The purpose is to provide the contractually owed access to the apartment, to organise your arrival and to keep the property secure. The legal basis is Art. 6(1)(b) GDPR. Logging locking operations is based on Art. 6(1)(f) GDPR; our legitimate interest lies in investigating misuse and damage and in protecting property.

c) Storage period

Access authorisations are automatically revoked and deleted after the end of your stay. We erase log data on locking operations no later than 90 days after your departure, unless it is exceptionally still required to establish, exercise or defend legal claims.

21. Statutory registration obligation for foreign guests (accommodation establishments)

a) Nature and scope of the processing

This section concerns exclusively guests who are not German nationals. For them, we as an accommodation business are legally obliged to keep a registration form. For this purpose we collect first and family name, date of birth, address, nationality, number of fellow travellers, day of arrival and departure as well as the type, number and issuing state of the identity document carried.

German nationals have been exempt from the special registration obligation for accommodation establishments since 1 January 2025 (Fourth Bureaucracy Relief Act). We do not collect this data from them.

b) Purpose and legal basis

The purpose is compliance with the special registration obligation for accommodation establishments. The legal basis is Art. 6(1)(c) GDPR in conjunction with sections 29 and 30 of the German Federal Registration Act (BMG). For foreign guests, providing this data is required by law; without it we may not accommodate you. It is transmitted exclusively to the authorities entitled to receive it under the Federal Registration Act, upon their request.

c) Storage period

We keep registration forms for one year in accordance with section 30(4) BMG and destroy them within three months thereafter.

22. Video surveillance of outdoor areas and publicly accessible hallways

a) Nature and scope of the processing

We use video cameras at all of our properties. These record exclusively the outdoor area (in particular entrance, driveway and parking areas) or the publicly accessible hallway of the building. There is no surveillance of the apartments, interior rooms or other private areas; nor are toilets, changing areas or comparable areas recorded. No audio is recorded. We indicate the video surveillance on site by means of clearly visible signs that can be seen before entering the area covered.

What is processed are images of the persons who enter the area covered as well as the date and time of the recording. We use cameras from the manufacturer Anker Innovations (“eufy Security”). The recordings are stored in the manufacturer’s cloud storage and are automatically erased there after 60 days. Where this involves a transfer to a third country, it is safeguarded by EU standard contractual clauses pursuant to Art. 46(2)(c) GDPR. Access to recordings is limited to a narrowly defined, expressly authorised group of people.

b) Purpose and legal basis

The purpose of the video surveillance is the exercise of our domiciliary rights, the protection of our property and that of our guests against theft, vandalism and criminal damage, the security of the access areas and the investigation of criminal offences and damage. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest follows from the purposes stated above; there is no monitoring of the behaviour of individual persons and no evaluation for other purposes.

c) Storage period

Recordings are automatically erased after 60 days. Longer storage occurs only in exceptional cases where a specific recording is needed to investigate an incident or to establish, exercise or defend legal claims; in such a case the relevant sequence is secured separately and erased once the purpose no longer applies.

d) Your right to object

Under Art. 21 GDPR you have the right to object at any time, on grounds relating to your particular situation, to this processing. To do so, please contact the controller named in section 2.

23. Room temperature control (smart home)

a) Nature and scope of the processing

In our apartments we use smart home components of the Homematic IP system from eQ-3 AG, Maiburger Straße 29, 26789 Leer, Germany, to control the heating. Technical device data such as the measured room temperature, the target temperature set, window-open states and the battery status is processed, in each case in relation to the apartment. No image, audio or motion data is recorded.

b) Purpose and legal basis

The purpose is providing a pleasant room temperature on your arrival, preventing frost and moisture damage and operating the heating efficiently. The legal basis is Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR (legitimate interest in protecting the building and in the economical use of energy). Drawing conclusions about your specific behaviour is neither intended nor carried out by us.

c) Storage period

Device states are held only as a current cache and are continuously overwritten.

24. Retrieving the Wi-Fi access details

a) Nature and scope of the processing

Guests can retrieve the Wi-Fi access details of the apartment they are staying in themselves via a separate page. To do so you enter the first and last name of the person who made the booking; we compare this with the booking active at the time of the request and, if it matches, display the network name and password.

b) Purpose and legal basis

The purpose is providing the contractually owed service without additional contact effort. The legal basis is Art. 6(1)(b) GDPR.

c) Storage period

The details entered are only used for the comparison and are not stored permanently.

25. Features in your customer account (wishlist, messages, loyalty programme)

a) Nature and scope of the processing

When you are signed in, further features are available to you. For the wishlist we store which apartments you have marked, linked to your customer account. Via the messaging feature you can send us messages; we store the message history in order to handle your request and keep it traceable (for AI support see section 15). As part of our loyalty programme we store how many qualifying direct bookings you have made in a calendar year, as well as the resulting tier and the benefits granted.

b) Purpose and legal basis

The purpose is providing the respective feature and granting the benefits you are entitled to. The legal basis is Art. 6(1)(b) GDPR; for the wishlist additionally Art. 6(1)(f) GDPR (legitimate interest in convenient use).

c) Storage period

The data is stored for as long as your customer account exists and is removed when it is deleted (see section 26). Loyalty programme details are reset at the end of each calendar year.

26. Deleting your customer account

a) Nature and scope of the processing

You can request the deletion of your customer account yourself at any time via the corresponding function on our website. For security, you confirm the deletion request via a link that we send to the email address stored for you. After confirmation we delete your account data, your profile picture, your wishlist and your communication history.

We cannot delete booking, invoice and payment data in full for as long as commercial and tax retention obligations apply (section 147 AO, section 257 HGB). These records are therefore separated from your account and anonymised, or their processing restricted, as far as those obligations permit; they are erased once the periods expire.

b) Legal basis

The legal basis is Art. 17 GDPR and — for the continued retention of accounting records — Art. 6(1)(c) GDPR in conjunction with Art. 17(3)(b) and (e) GDPR.

27. Map display

a) Nature and scope of the processing

On some pages we show the approximate location of our apartments on an interactive map. The map is rendered in your browser using the open-source library MapLibre; the map material is loaded from an external map service (CARTO / basemaps.cartocdn.com). For technical reasons your IP address is transmitted to that service, along with information on the map section displayed and the browser used. Your location is only accessed if you expressly permit this in your browser.

b) Purpose and legal basis

The purpose is presenting the location of our apartments in a comprehensible way. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in an appealing and informative presentation of our offering); where you have given us your consent, additionally Art. 6(1)(a) GDPR.

c) Storage period

We ourselves do not store any data in this context.

28. Hosting, operation and email delivery

a) Nature and scope of the processing

Our website, our database and our outgoing mail server are operated at STRATO AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany, in a data centre in Germany. STRATO AG acts for us as a processor pursuant to Art. 28 GDPR; a corresponding data processing agreement is in place and the data is processed solely on our instructions. The data processed there includes in particular the contents of our database as well as the server log files (section 3) and backups.

We send all emails to you — such as booking confirmations, invoices, arrival and check-in information including your access code, and system and service messages — via our own outgoing mail server. To document proper delivery, we log the recipient, subject, time and delivery status of the messages sent.

b) Purpose and legal basis

The purpose is the technical operation of our services, the performance of the contract concluded with you and ensuring and documenting delivery. The legal basis is Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR (legitimate interest in secure, stable and traceable operation).

c) Storage period

Backups are overwritten after 30 days at the latest. We erase delivery logs after 90 days at the latest, unless they form part of a transaction subject to retention obligations.

29. Data security and protective measures

We undertake to protect your privacy and to treat your personal data confidentially. To this end we take extensive technical and organisational security measures, which are reviewed regularly and adapted to technological progress. These include, among other things, the use of recognised encryption methods (SSL or TLS).

Data disclosed without encryption, for example by unencrypted email, may potentially be read by third parties. We have no influence over this. It is the responsibility of the respective user to protect the data provided against misuse by means of encryption or in some other way.

30. Changes to this privacy policy

We reserve the right to update this policy as required at any time.

31. Your rights

Below you will find your rights in relation to your personal data. The details follow from Articles 7, 15–22 and 77 GDPR. You can contact the controller (section 2) in this regard.

a) Right to withdraw your data protection consent under Art. 7(3) sentence 1 GDPR

You can withdraw consent to the processing of your personal data at any time with effect for the future. The lawfulness of the processing carried out up to the withdrawal remains unaffected.

b) Right of access under Art. 15 GDPR

You have the right to request confirmation as to whether we process personal data concerning you, as well as the right to access that data and further information (e.g. the purposes of processing, the categories concerned, the recipients and the envisaged storage period).

c) Right to rectification and completion under Art. 16 GDPR

You have the right to request the rectification of inaccurate data and the completion of incomplete data without undue delay.

d) Right to erasure (“right to be forgotten”) under Art. 17 GDPR

You have a right to erasure where the processing is not necessary — e.g. where the data is no longer needed for the original purposes, where you have withdrawn your consent, or where the data has been processed unlawfully.

e) Right to restriction of processing under Art. 18 GDPR

You have a right to restriction of processing, for example if you consider the personal data to be inaccurate.

f) Right to data portability under Art. 20 GDPR

You have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format.

g) Right to object under Art. 21 GDPR

You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you. In the case of direct marketing you have the right to object at any time; this also applies to profiling insofar as it is related to such direct marketing.

h) Automated individual decision-making, including profiling, under Art. 22 GDPR

You have the right not to be subject to a decision based solely on automated processing — including profiling — except in the cases set out in Art. 22 GDPR.

i) Complaint to a data protection supervisory authority under Art. 77 GDPR

You can also lodge a complaint with a data protection supervisory authority at any time, for example if you consider that the processing of your data does not comply with data protection law.

Fassung 2.0 vom 11.08.2026

Home

Explore

Account