Privacy Policy
Hotel Bavaria Oberstaufen
1. Data Controller
Hotel Bavaria Schneider GmbH
Isnyer Straße 2, 87534 Oberstaufen, Germany
Represented by the managing directors Markus Schneider and Brigitte Schneider
Phone: +49 8386 93250
Email: info@bavaria-oberstaufen.de
The controller within the meaning of the General Data Protection Regulation is Hotel Bavaria Schneider GmbH. We are not required to appoint a data protection officer; please address data protection enquiries to the contact above.
2. General Information on Data Processing
The protection of your personal data is very important to us. We process personal data exclusively within the framework of the applicable data protection laws, in particular:
General Data Protection Regulation (GDPR)
German Federal Data Protection Act (BDSG)
Telecommunications and Digital Services Data Protection Act (TDDDG)
This privacy policy provides information about what data we collect, how we use it, and what rights you have.
To secure your data, we use appropriate technical and organizational measures (TOMs) to protect it from loss, misuse, or unauthorized access.
3. Purposes and Legal Bases of Processing
We only process personal data when permitted. This includes, in particular, the following purposes:
Operation, maintenance, and security of our website
Communication with guests, prospective customers, and partners
Processing of bookings, handling of the stay, and billing
Fulfillment of legal obligations (e.g., registration law, tax law)
Marketing, analysis, and advertising purposes (only with consent)
Safeguarding legitimate interests (e.g., IT security, service optimization)
Legal bases according to Art. 6 (1) GDPR:
lit. a – Consent
lit. b – Contract / pre-contractual steps
lit. c – Legal obligation
lit. f – Legitimate interest
4. Website hosting
Our website is delivered by:
Netlify, Inc., 512 2nd Street, Suite 200, San Francisco, CA 94107, USA
Purpose: hosting, delivery and operation of the website.
Data processed: IP address, time of access, file requested, volume of data transferred, browser and operating system details, referrer.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in secure and reliable operation).
Transfer to the USA: safeguarded by Standard Contractual Clauses; Netlify is certified under the EU-US Data Privacy Framework.
More information: https://www.netlify.com/privacy
5. Consent management
Your decision on cookies and analytics is managed without any external service provider.
Storage: exclusively local in your browser (localStorage, key “hb-consent-v1”). No data is transmitted to us or to third parties.
Content: the categories you selected and the time of your decision.
Withdrawal: at any time via “Cookie settings” in the footer of every page. It takes effect immediately; analytics already running is switched off at once.
Legal basis: Section 25 (2) no. 2 TDDDG (technically necessary storage), Art. 6 (1) (c) GDPR (proof of consent).
6. Security and Encryption
Our website uses SSL/TLS encryption (HTTPS).
Server logs (IP address, timestamp, browser data, referrer) are used for security, error analysis, and system maintenance.
Legal basis: Art. 6 (1) (f) GDPR.
7. Web analytics (Google Analytics 4)
Provider: Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland
Data: usage data, truncated IP address, device and browser details, pages viewed.
Purpose: statistical evaluation of website use.
Legal basis: consent (Art. 6 (1) (a) GDPR, Section 25 (1) TDDDG).
Measurement only starts once you have enabled the “Statistics” category in the cookie notice. Without that consent, no Google script is loaded.
Transfer to the USA: safeguarded by Standard Contractual Clauses.
More information: https://policies.google.com/privacy
8. Maps (Google Maps)
Provider: Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland
The map on our website is only loaded after you have explicitly activated it (two-click solution). Before that, no connection to Google is established.
Data: IP address, device and browser details, location context of the map sections requested.
Purpose: directions and presentation of our location.
Legal basis: consent (Art. 6 (1) (a) GDPR).
More information: https://policies.google.com/privacy
9. Contact form
If you write to us using the form, we process the details you provide (name, email address, message, optionally phone number and travel dates) in order to answer your enquiry.
Submissions are handled by the form service of our host, Netlify, Inc.
Legal basis: Art. 6 (1) (b) GDPR for enquiries relating to a booking, otherwise Art. 6 (1) (f) GDPR (legitimate interest in responding).
Storage period: until your enquiry has been dealt with, beyond that only where statutory retention periods apply.
10. Fonts
The fonts used are served from our own server.
No connection is made to Google Fonts, Adobe Fonts or any other external provider; your IP address is not transmitted to third parties.
11. Booking and Guest Management Systems
11.1 Online Booking & Channel Management (DIRS21 / DIRS Channelmanager)
We use DIRS21 and the DIRS Channelmanager to process online bookings and synchronize availabilities.
Data processed: Name, contact details, stay data, payment information, booking details.
Purpose: Execution and management of bookings.
Legal basis: Art. 6 (1) (b) GDPR.
More info: https://www.dirs21.de/datenschutz (Link is in German)
11.2 Property Management System (PMS)
We use a Property Management System to manage the processes related to your stay.
Data processed: Guest master data, reservation data, billing data, payment information, communication, check-in/check-out, log data.
Purpose: Fulfillment of the accommodation contract, billing, guest services, statutory documentation obligations.
Legal bases: Art. 6 (1) (b) GDPR, Art. 6 (1) (c) GDPR
11.3 Guest Registration System (Germany)
We transmit legally required registration data in accordance with the German Federal Registration Act (BMG).
Data: Name, address, date of birth, nationality, travel dates, number of accompanying persons.
Recipients: Registration authority of the municipality of Oberstaufen, and tourist organizations if applicable.
Legal basis: Art. 6 (1) (c) GDPR.
12. Recipients of Data
Recipients may include:
Processors (Netlify as host, DIRS21 for bookings, provider of our property management system)
Legal bodies and authorities
Payment service providers
IT and support service providers
All processors are contractually bound according to Art. 28 GDPR.
13. Storage Period & Deletion
We store personal data only as long as it is necessary for the fulfillment of the purposes or as required by law.
Typical periods in Germany:
Accounting records: 10 years
Registration data: according to BMG
Technical server logs: max. 6 months
After the period expires, the data is deleted or anonymized.
14. Rights of the Data Subject
You have the right to:
Access (Art. 15 GDPR)
Rectification (Art. 16 GDPR)
Erasure (Art. 17 GDPR)
Restriction of processing (Art. 18 GDPR)
Data portability (Art. 20 GDPR)
Object (Art. 21 GDPR)
Withdraw your consent (Art. 7 (3) GDPR)
Contact: info@bavaria-oberstaufen.de
15. Right to Lodge a Complaint
The competent supervisory authority is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 27
91522 Ansbach, Germany
Web: https://www.lda.bayern.de
16. Changes to this Privacy Policy
We reserve the right to update this privacy policy if legal, technical, or organizational changes make it necessary.
