Hotel Maier Tagungen Konferenzraum-Close-Up-Brille

Privacy Policy

§ 1 Controller and general information

(1)  Below we inform you about the processing of personal data when you use our website and when you book and stay with us. Personal data is any data that can be related to you personally, e.g. name, address, e-mail address, user behaviour.

(2)  Controller pursuant to Art. 4(7) GDPR:

Hotel Maier GmbH
Poststraße 1-3
88048 Friedrichshafen
Germany
info@hotel-maier.de
T +49 7541 404-0

(3) If you contact us by e-mail, telephone or contact form, we process the data you provide (e.g. e-mail address, name, telephone number) in order to answer your enquiry. The legal basis is Art. 6(1)(b) GDPR where your enquiry relates to a contract, otherwise Art. 6(1)(f) GDPR (legitimate interest in answering your enquiry). The data is deleted as soon as it is no longer required and no statutory retention obligations apply.

§ 2 Your rights

(1) Under the GDPR you have the following rights:

  • Access to your stored data (Art. 15 GDPR)
  • Rectification or erasure of inaccurate or unlawfully processed data (Art. 16, 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to the processing of your data (Art. 21 GDPR, see § 9)
  • Withdrawal of consent with effect for the future (Art. 7(3) GDPR)
  • Lodging a complaint with a data protection supervisory authority (Art. 77 GDPR)

(2) Competent supervisory authority: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (State Commissioner for Data Protection and Freedom of Information Baden-Württemberg)
Heilbronner Straße 35, 70191 Stuttgart, Germany
Web: https://www.baden-wuerttemberg.datenschutz.de

§ 3 Visiting our website, cookies and consent

(1) If you use our website for information purposes only, we collect only the data technically required to provide the website and ensure its stability and security:

  • IP address
  • Date and time of the request
  • Content of the request (specific page) and HTTP status code
  • Browser type and version, language
  • Operating system

The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure and stable operation).

(2) We only use cookies and similar technologies (e.g. local storage, pixels) if they are technically necessary or you have given your prior consent. The legal basis for technically necessary cookies is Section 25(2) no. 2 TDDDG in conjunction with Art. 6(1)(f) GDPR. All other services in the categories preferences, statistics and marketing are used exclusively on the basis of your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). You can withdraw or change your consent at any time with effect for the future via the "Cookie settings" link.

(3) To manage consents we use Cookiebot by Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark. Your shortened IP address, date and time, browser information and your selection are processed and stored in a cookie ("CookieConsent", retention period 12 months). The legal basis is Art. 6(1)(c) GDPR (obligation to provide proof under Art. 7(1) GDPR).

§ 4 Booking, reservation and stay

(1) Booking and vouchers
If you book or enquire about a room, a package or a voucher, we process your contact details, stay and booking data, payment information and your requests in order to perform the contract. Online bookings and vouchers are handled via OnePageBooking and VoucherBooking by HotelNetSolutions GmbH. Your reservation is managed in our hotel software protel and your guest profile in dailypoint (dailypoint GmbH). These service providers process the data on our behalf.
Legal basis: Art. 6(1)(b) GDPR.
Further information: https://hotelnetsolutions.de/datenschutz

(2) Table reservations
For table reservations in our restaurant we use aleno (aleno AG, Aegertenstrasse 6, CH-8003 Zurich, Switzerland). We collect your name, e-mail address, telephone number, reservation details and any notes, and for guaranteed reservations also payment information. An adequacy decision of the European Commission exists for Switzerland (Art. 45 GDPR).
Legal basis: Art. 6(1)(b) GDPR.
Further information: https://www.aleno.me/de/policy

(3) Payment
Card payments, deposits and guarantees are processed via the payment service providers Planet (Planet Payment Group), Stripe (Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland) and aleno. Card data is processed in encrypted form directly by the payment service provider. We do not store full card numbers.
Legal basis: Art. 6(1)(b) and (c) GDPR.

(4) Digital check-in and guest information
For digital check-in and information about your stay we use Straiv (Straiv GmbH). Straiv processes the data on our behalf.
Legal basis: Art. 6(1)(b) GDPR.

(5) Registration form
For guests who are not German nationals we are legally required to keep a registration form (Sections 29, 30 German Federal Registration Act). Registration forms are kept for one year and destroyed within three months thereafter.
Legal basis: Art. 6(1)(c) GDPR.

(6) Communication about your stay
Before your arrival we send you information about your stay, and after departure we ask you for a review. You can object to receiving these e-mails at any time, e.g. via the link in the e-mail.
Legal basis: Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR (legitimate interest in a smooth stay and quality assurance).

(7) Retention period
We store booking and invoice data for as long as statutory retention periods require: accounting vouchers 8 years, commercial and business letters 6 years, books and annual financial statements 10 years (Section 257 German Commercial Code, Section 147 German Fiscal Code). The data is deleted thereafter.

§ 5 Analytics and marketing services (only with your consent)

(1) Google Tag Manager and Google Analytics
We use Google Tag Manager and Google Analytics 4 by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). The Tag Manager controls the loading of other services but does not create user profiles itself. Google Analytics evaluates how visitors use our website (e.g. pages viewed, time spent, origin, device, completed bookings without names). IP addresses are shortened by Google within the EU. Google Consent Mode ensures that no analytics cookies are set without your consent. For the booking process we measure across domains between our website and OnePageBooking.
The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG), which you can withdraw at any time via the cookie settings. Data may be transferred to Google LLC in the USA. Google LLC is certified under the EU-US Data Privacy Framework; the transfer is based on the European Commission's adequacy decision (Art. 45 GDPR).
Further information: https://policies.google.com/privacy

(2) Google Ads and remarketing
We use Google Ads conversion tracking and remarketing by Google (address see above). This allows us to measure whether a booking or enquiry results from one of our ads and to show you relevant ads on other websites. Online identifiers, IP address, browser and device data and booking information (arrival, departure, number of guests, revenue, without names) are processed.
The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG), which you can withdraw at any time via the cookie settings. For transfers to third countries see item (1). You can also deactivate personalised advertising at https://adssettings.google.com.

(3) Microsoft Advertising and Microsoft Clarity
We use Microsoft Advertising conversion tracking (UET tag) and Microsoft Clarity by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Microsoft Advertising measures whether bookings result from ads on the Bing search engine. Clarity records in pseudonymised form how visitors interact with our website (clicks, scrolling, mouse movements) so that we can identify usability issues. Entries in form fields are not recorded. The cookies are stored for up to 13 months.
The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG), which you can withdraw at any time via the cookie settings. Data may be transferred to Microsoft Corporation in the USA. Microsoft is certified under the EU-US Data Privacy Framework; the transfer is based on the European Commission's adequacy decision (Art. 45 GDPR).
Further information: https://privacy.microsoft.com/en-gb/privacystatement

(4) Meta Pixel
We use the Meta Pixel by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. This allows us to measure the effectiveness of our ads on Facebook and Instagram and to show visitors to our website relevant ads there. Online identifiers, IP address, browser and device information and the pages viewed are processed. We are jointly responsible with Meta for the collection and transmission to Meta (Art. 26 GDPR, https://www.facebook.com/legal/controller_addendum).
The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG), which you can withdraw at any time via the cookie settings. Data may be transferred to Meta Platforms, Inc. in the USA. Meta is certified under the EU-US Data Privacy Framework; the transfer is based on the European Commission's adequacy decision (Art. 45 GDPR).
Further information: https://www.facebook.com/privacy/policy

(5) Contentsquare
To analyse usability we use Contentsquare (formerly Hotjar) by Contentsquare SAS, 7 rue de Madrid, 75008 Paris, France. Contentsquare records in pseudonymised form clicks, scrolling and mouse movements as well as device type, screen size, browser, language setting and country. IP addresses are shortened; form entries are not recorded.
The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG), which you can withdraw at any time via the cookie settings.
Further information: https://contentsquare.com/privacy-center/

(6) myhotelshop
To market our rooms on hotel comparison platforms (e.g. Google Hotel Ads, Trivago) we use myhotelshop (myhotelshop GmbH). This measures whether a booking was made via such a channel. Online identifiers, referring channel and booking information without names are processed.
The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG), which you can withdraw at any time via the cookie settings.

(7) dailypoint
If you have given your consent, dailypoint (dailypoint GmbH) records which pages and offers you view on our website and may link this information to your guest profile if you have booked with us or subscribed to our newsletter. This enables us to make you offers that match your interests. dailypoint processes the data on our behalf.
The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG), which you can withdraw at any time via the cookie settings.

§ 6 Other services and embedded content

(1) DialogShift (chatbot)
Our website uses the chat service of DialogShift GmbH, Torstr. 201, 10115 Berlin, Germany. Chat history, cookies for recognition and voluntarily provided contact details are collected.
Legal basis: Art. 6(1)(a) GDPR.
Further information: https://www.dialogshift.com/datenschutz

(2) Eye-Able Assist (accessibility assistant)
Eye-Able® is software by Web Inclusion GmbH that gives everyone low-barrier access to our website. The required files are loaded via the content delivery network of BunnyWay d.o.o. (Cesta komandanta Staneta 4A, 1215 Medvode, Slovenia). Settings are stored only locally in your browser's local storage. All data and servers remain in the EU; personal user behaviour is not analysed.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in an accessible, secure and fast website).
Further information: https://eye-able.com/datenschutz-eye-able/, https://bunny.net/privacy

(3) Google Maps and YouTube
Our website embeds maps from Google Maps and videos from YouTube (both Google, address see § 5). These are only loaded once you have given your consent. Your IP address and device information, among other things, are transmitted to Google.
The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG), which you can withdraw at any time via the cookie settings. Data may be transferred to Google LLC in the USA. Google LLC is certified under the EU-US Data Privacy Framework; the transfer is based on the European Commission's adequacy decision (Art. 45 GDPR).

(4) Social media
On our website we link to our profiles on Facebook and Instagram (Meta Platforms Ireland Limited), TikTok (TikTok Technology Limited, Ireland) and LinkedIn (LinkedIn Ireland Unlimited Company). We use social media plug-ins with the "two-click solution": a connection to the respective network is only established when you click the link or plug-in. Processing on the platforms themselves is governed by their privacy policies:

§ 7 Newsletter

(1) With your consent you can subscribe to our newsletter, in which we inform you about current offers, news and events.

(2) We use the double opt-in procedure for registration. After registering you will receive an e-mail asking you to confirm. Your registration only becomes effective after confirmation. If you do not confirm within 24 hours, your details will be blocked and automatically deleted after one month. We store your IP address and the time of registration and confirmation in order to be able to prove your registration.

(3) The only mandatory information is your e-mail address. Further, separately marked information (e.g. name) is voluntary and used to address you personally.

(4) The newsletter is sent via dailypoint (dailypoint GmbH) as our processor. We evaluate whether and when you open the newsletter and which links you click in order to improve our content. Further information: https://www.dailypoint.com/de/datenschutz

(5) You can unsubscribe from the newsletter at any time via the unsubscribe link in every newsletter e-mail or by e-mail to info@hotel-maier.de. Your data will be deleted after you unsubscribe unless statutory retention obligations apply.

Legal basis: Art. 6(1)(a) GDPR (consent).

§ 8 Recipients and processors

We only pass on personal data if this is necessary to perform a contract, if there is a legal obligation, if you have given your consent or if we have a legitimate interest. Service providers who process data on our behalf (e.g. website hosting, hotel software, booking and payment systems) have been carefully selected and contractually bound in accordance with Art. 28 GDPR. Data is only transferred to countries outside the EU if an adequacy decision or appropriate safeguards pursuant to Art. 44 et seq. GDPR exist.

§ 9 Objection to the processing of your data

If we process your data on the basis of a legitimate interest (Art. 6(1)(f) GDPR), you may object to this processing at any time on grounds relating to your particular situation (Art. 21(1) GDPR). You may object to processing for direct marketing purposes at any time without giving reasons (Art. 21(2) GDPR). Please contact us at:

Hotel Maier GmbH
Poststraße 1-3
88048 Friedrichshafen
Germany
info@hotel-maier.de