Privacy policy
Privacy Policy The protection of your personal data is very important to us. We handle your data confidentially and in accordance with the legal data protection regulations, in particular the EU General Data Protection Regulation (GDPR). Below we inform you about which personal data we collect as part of our rental services and how we handle this data.
1. Controller Rennsteigscheune
– Holiday and Worker Apartments Flurstraße 3, 96361 Steinbach am Wald, Germany 📧 Email: rennsteigscheune@kanzlei-neubauer.de 📞 Phone: +49 177 197153 or +49 1522 4560809 Contact Person: Jacqueline Neubauer
2. What Data Do We Collect?
We only collect data that is necessary to process and manage your booking: Name, address, phone number, email address Booking details (period, number of persons, apartment) Payment information (e.g., IBAN for bank transfers) ID data, if legally required (e.g., for direct bookings) Communication data from emails, WhatsApp, or online forms Technical data when visiting our website (IP address, browser type, operating system – see Section 9)
3. Purpose of Data
Processing We process your data for the following purposes: To manage your booking (contract fulfillment) To create and send invoices To communicate with you before, during, and after your stay To comply with legal retention obligations To handle cancellations, damages, or inquiries To ensure the technical security and optimization of our website
4. Legal Bases
The data processing is based on the following legal grounds: Art. 6 (1) lit. b GDPR – for contract fulfillment (e.g., bookings) Art. 6 (1) lit. c GDPR – to comply with legal obligations (e.g., invoice retention) Art. 6 (1) lit. f GDPR – for legitimate interests (e.g., communication, IT security)
5. Disclosure of Your Data
Your data will not be shared with third parties, except: With legally obligated authorities (e.g., tax office) With service providers such as tax consultants, web hosting providers, who are bound by confidentiality If booking via platforms like Booking.com, Airbnb, etc., data processing is handled directly by these providers If you use WhatsApp, data is transmitted to WhatsApp LLC (Meta Platforms Inc., USA) We have data processing agreements with all service providers in accordance with Art. 28 GDPR.
6. Data Retention
Period Your data is stored only as long as necessary or legally required: Booking data and invoices: 10 years Email correspondence: max. 3 years WhatsApp communication: regularly deleted Server log files: max. 7 days
7. Your Rights Under GDPR,
you have the following rights at any time:
Right to access (Art. 15 GDPR)
Right to rectification (Art. 16 GDPR)
Right to erasure (Art. 17 GDPR)
Right to restriction of processing (Art. 18 GDPR)
Right to data portability (Art. 20 GDPR)
Right to object (Art. 21 GDPR)
Please contact us by email if you wish to exercise any of these rights.
8. Security
We process your data according to the latest technical standards. We use technical and organizational security measures: Data transmission via our website is SSL-encrypted. Data is stored only on secure devices. Access (e.g., to email accounts) is password-protected. Regular security updates on all systems.
9. Use of Cookies & Website Tools
When you visit our website, the following applies: Only technically necessary cookies are used. No tracking or analytics tools are used (e.g., Google Analytics). External booking platforms (e.g., Booking.com) have their own privacy policies. Our web hosting is provided by [Name of Hosting Provider], who is contractually bound as a data processor according to Art. 28 GDPR. Server Log Files: When visiting the website, technical information is automatically collected (e.g., IP address, browser type, time). This data is used for security purposes and is not combined with other data sources.
10. Use of WhatsApp
If you contact us via WhatsApp, please note that data is transmitted to WhatsApp LLC (Meta), which may also transfer data to the USA. We only use WhatsApp if you expressly request it. Alternatively, you can contact us at any time via email.
11. Data Protection for Children
Our services are not directed at children under 16. We only process data of minors if parental consent is provided.
12. Right to Lodge a Complaint with a Supervisory Authority
If you believe your data has been processed unlawfully, you can lodge a complaint with the relevant data protection authority: Bavarian State Office for Data Protection Supervision (BayLDA) Promenade 27, 91522 Ansbach, Germany Phone: +49 981 53 1300 Website: www.lda.bayern.de