Privacy Policy
Privacy Policy
1. General Information
The protection of your personal data is important to us. We process personal data in accordance with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), the German Federal Registration Act (BMG) and all other applicable legal provisions. Personal data means any information relating to an identified or identifiable natural person.
2. Controller
Hotel Biederstein
Munich Rooms Hotel e.K.
Proprietor: Selcuk Gürler
Keferstr. 18
80802 Munich
Germany
Email: info@hotel-biederstein.de
3. Purposes and Legal Bases of Processing
3.1 Booking and Performance of the Accommodation Contract
We process personal data insofar as this is necessary to handle your enquiry, manage a reservation and perform the accommodation contract concluded with you. This includes, in particular, reservation management, communication before and during the stay, online check-in, provision of access information, payment processing, invoicing and handling changes, cancellations and other matters relating to your stay. The legal basis is Art. 6(1)(b) GDPR.
3.2 Legal Obligations
Where we are legally required to process or retain personal data, processing is based on Art. 6(1)(c) GDPR. This includes, in particular, retention obligations under commercial and tax law and, where applicable, obligations under the German Federal Registration Act.
3.3 Legitimate Interests
We may also process personal data on the basis of Art. 6(1)(f) GDPR where this is necessary to protect our legitimate interests or those of a third party and where the interests, fundamental rights or freedoms of the data subject do not override those interests. This includes, in particular, ensuring orderly hotel operations, IT and data security, preventing and investigating misuse or criminal offences, and establishing, exercising or defending legal claims.
3.4 Consent
Where we obtain your consent for a specific processing activity, processing is based on Art. 6(1)(a) GDPR. Consent may be withdrawn at any time with effect for the future.
4. Categories of Personal Data
Depending on the type of booking and stay, we process in particular master and contact data, reservation and stay data, information about accompanying guests, legally required identification and registration data where applicable, invoice data, as well as payment, credit card, transaction and payment-status information. We also process correspondence and other information you provide to us in connection with your reservation or stay.
5. Website and Technically Necessary Data
When you access our website, technically necessary information is processed in order to provide the website and ensure its stability and security. This may include, in particular, IP address, date and time of access, pages or files accessed, browser and operating-system information and technical log data. The legal basis is Art. 6(1)(f) GDPR.
6. Consent and Cookie Settings
Our website uses a Privacy Preference Center through which visitors can manage their consent and cookie settings. Where processing requires consent, it is carried out only on the basis of consent given in accordance with Art. 6(1)(a) GDPR. Consent can be changed or withdrawn with effect for the future via the settings provided.
7. Contacting Us
If you contact us by email or telephone, we process the information you provide in order to handle your enquiry. Where the enquiry relates to a contract or pre-contractual measures, the legal basis is Art. 6(1)(b) GDPR; otherwise, processing may be based on Art. 6(1)(f) GDPR.
8. Online Booking via VIATO
For online bookings via our website, we use the VIATO booking engine. During the booking process, the personal data required for the reservation is processed. This includes, in particular, name, contact details, booking and stay information, and the information required for the guarantee or payment process. The legal basis is Art. 6(1)(b) GDPR.
9. Payment and Credit Card Processing via Stripe
We use Stripe to process credit card payments and credit card guarantees. The required credit card, payment and transaction data is processed through the secure systems provided for this purpose. Processing is carried out in particular for the performance of the accommodation contract pursuant to Art. 6(1)(b) GDPR and, where applicable, to comply with legal obligations and protect legitimate interests. Where personal data is processed outside the European Economic Area, this is carried out in accordance with the requirements of Arts. 44 et seq. GDPR.
10. Hotel Management and Online Check-in via 3RPMS
We use the 3RPMS hotel management system to manage reservations and guest stays and to carry out our online check-in. In this context, we process in particular master and contact data, reservation and stay information and the data required for online check-in and, where applicable, to comply with statutory registration obligations. The legal basis is Art. 6(1)(b) GDPR and, where legal obligations apply, Art. 6(1)(c) GDPR.
11. Statutory Registration Data
Where statutory registration obligations apply to accommodation providers, we process the data required by law on the basis of Art. 6(1)(c) GDPR. Data collected solely on the basis of these specific registration obligations is retained in accordance with the applicable statutory requirements and subsequently deleted or destroyed.
12. Video Surveillance
To protect our guests and employees, safeguard our property and house rights, and prevent and investigate criminal offences, certain publicly accessible areas of the hotel are monitored by video surveillance. Guest rooms are not subject to video surveillance. The legal basis is Art. 6(1)(f) GDPR. Video recordings are generally stored for seven days and then automatically deleted unless they are required for a longer period in connection with a specific incident for the preservation of evidence or for the establishment, exercise or defence of legal claims.
13. Recipients and Service Providers
To operate the hotel, we use external service providers and technical systems. These include in particular VIATO for the online booking process, Stripe for payment and credit card processing and 3RPMS for hotel management and online check-in. Personal data is disclosed only where this is necessary for the respective purpose, required by law or otherwise permitted by a legal basis. Where service providers process personal data on our behalf, we comply with the requirements of Art. 28 GDPR.
14. Transfers to Third Countries
Where personal data is processed outside the European Union or the European Economic Area in connection with the services we use, transfers take place only in accordance with the requirements of Arts. 44 et seq. GDPR, in particular on the basis of an adequacy decision or appropriate safeguards.
15. Retention Periods
We retain personal data only for as long as necessary for the relevant processing purpose or for as long as statutory retention obligations apply. Documents relevant under tax and commercial law are retained in accordance with the applicable statutory retention periods. Data may also be retained for as long as necessary to establish, exercise or defend legal claims. Once the processing purpose no longer applies and statutory retention periods have expired, the data is deleted unless another legal basis permits continued retention.
16. Rights of Data Subjects
Subject to the statutory requirements, you have in particular the right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR) and data portability (Art. 20 GDPR). Consent that has been given may be withdrawn at any time with effect for the future pursuant to Art. 7(3) GDPR.
16.1 Right to Object under Art. 21 GDPR
Where the processing of your personal data is based on Art. 6(1)(f) GDPR, you have the right to object at any time, on grounds relating to your particular situation, to such processing. We will then no longer process the relevant data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or unless the processing serves the establishment, exercise or defence of legal claims. You may object to processing for direct marketing purposes at any time without giving reasons.
17. Right to Lodge a Complaint with the Data Protection Supervisory Authority
Pursuant to Art. 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes data protection law.
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach
Germany
www.lda.bayern.de
18. Updates to this Privacy Policy
We reserve the right to amend this Privacy Policy if legal requirements, our services or the technical systems we use change. The current version published on our website shall apply.
Last updated: August 2026