Privacy Policy
1. Data protection at a glance
General information
The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data by which you can be personally identified. For detailed information on data protection, please refer to the privacy policy set out below.
Data collection on this website
Who is responsible for data collection on this website? Data processing on this website is carried out by the website operator, whose contact details you can find in the section “Information on the controller”.
How do we collect your data? Your data is collected, on the one hand, when you provide it to us (e.g. entries in a contact or booking form). Other data (mainly technical data such as browser, operating system or time of access) is collected automatically or after your consent when you visit the website.
What do we use your data for? Some data is collected to ensure the website is provided without errors. Other data is used to process bookings and to communicate with you.
What rights do you have? You have the right at any time to obtain free information about the origin, recipients and purpose of your stored data, as well as a right to rectification or erasure. You can revoke a given consent at any time. Under certain circumstances you also have the right to restriction of processing and a right to lodge a complaint with the competent supervisory authority.
2. Hosting
External hosting
This website is hosted externally. The personal data collected on this website is stored on the servers of the host (in particular IP addresses, contact and booking requests, meta and communication data, contract data, contact data, names and website accesses).
External hosting is carried out for the purpose of fulfilling the contract with our potential and existing guests (Art. 6(1)(b) GDPR) and in the interest of secure, fast and efficient provision of our online offering (Art. 6(1)(f) GDPR). Where consent has been requested, processing is based exclusively on Art. 6(1)(a) GDPR and Section 25(1) TDDDG; consent may be revoked at any time.
We use the following host: goneo Internet GmbH, Dresdener Str. 18, 32423 Minden, Germany.
Data processing agreement
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. It ensures that our visitors’ personal data is processed only on our instructions and in compliance with the GDPR.
3. General information and mandatory notices
Data protection
The operators of this site take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy. Please note that data transmission over the internet (e.g. communication by e-mail) can have security gaps. Complete protection of data against access by third parties is not possible.
Information on the controller
The controller for data processing on this website is:
Ricardo Köhler, Ortsstraße 140, 02829 Markersdorf (Friedersdorf), Germany
Phone: +49 173 5127972 · E-mail: info@villa-matthias.com
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.
Storage period
Unless a more specific storage period is stated in this policy, your personal data remains with us until the purpose for processing no longer applies. If you make a legitimate request for erasure or revoke a consent, your data will be deleted unless we have other legally permissible grounds for storing it (e.g. tax or commercial retention periods).
Legal bases for processing
Where you have consented, we process your data on the basis of Art. 6(1)(a) or Art. 9(2)(a) GDPR. Where you have consented to the storage of cookies or access to your device, additionally on the basis of Section 25(1) TDDDG. For the performance of a contract or pre-contractual measures on the basis of Art. 6(1)(b) GDPR, for compliance with a legal obligation on the basis of Art. 6(1)(c) GDPR, and otherwise on the basis of our legitimate interest under Art. 6(1)(f) GDPR.
Recipients of personal data
We only pass on personal data to external parties where this is necessary for the performance of a contract, where we are legally obliged to do so, where we have a legitimate interest under Art. 6(1)(f) GDPR, or where another legal basis permits it. When using processors, data is passed on only on the basis of a valid data processing agreement.
Revocation, objection (Art. 21 GDPR) and right to complain
You may revoke a given consent at any time. Where processing is based on Art. 6(1)(e) or (f) GDPR, you have the right to object for reasons arising from your particular situation; in the case of direct marketing there is a general right to object. You also have the right to lodge a complaint with a supervisory authority.
Data portability, access, rectification, erasure and restriction
You have the right to receive data that we process automatically on the basis of your consent or in performance of a contract in a common, machine-readable format. You also have the right at any time to free information about your stored data, its origin, recipients and the purpose of processing, and, where applicable, a right to rectification, erasure or restriction of processing.
SSL / TLS encryption
For security reasons, this site uses SSL / TLS encryption. You can recognise an encrypted connection by “https://” in the address bar and the lock symbol in your browser.
Objection to advertising e-mails
We hereby object to the use of contact data published within the scope of the imprint obligation for sending advertising not expressly requested. We expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, e.g. spam e-mails.
4. Data collection on this website
Cookies
Our web pages use “cookies”. Necessary cookies are stored on the basis of Art. 6(1)(f) GDPR unless another legal basis is stated. Where consent has been requested, processing is based exclusively on that consent (Art. 6(1)(a) GDPR and Section 25(1) TDDDG); it may be revoked at any time.
Server log files
The provider automatically collects and stores information in server log files that your browser transmits: browser type and version, operating system, referrer URL, host name, time of the server request and IP address. This data is not merged with other data sources. Legal basis: Art. 6(1)(f) GDPR.
Contact form
If you send us enquiries via the contact form, your details will be stored for the purpose of processing the enquiry and any follow-up questions. For our forms we use “JetFormBuilder” (Crocoblock, ZGRUPOWANA Sp. z o.o., Rzeszów, Poland). The form data is stored exclusively on our own server (goneo); no transmission to Crocoblock takes place. Legal basis: Art. 6(1)(b) GDPR, otherwise Art. 6(1)(f) GDPR or your consent (Art. 6(1)(a) GDPR).
Enquiry by e-mail or telephone
If you contact us by e-mail or telephone, your enquiry including the resulting personal data will be stored and processed for the purpose of handling your request and will not be passed on without your consent. Legal basis: Art. 6(1)(b) GDPR, otherwise Art. 6(1)(f) GDPR or your consent (Art. 6(1)(a) GDPR).
Bookings (online booking system)
For booking our holiday accommodation we use the booking system “HBook” (provider: Maestrel). When you make a booking or booking request, we process the data you provide – in particular name, address, e-mail, telephone number, arrival and departure dates, number of guests and any further details – in order to handle the booking and fulfil the accommodation contract. Booking data is stored on our own server (goneo). Legal basis: Art. 6(1)(b) GDPR. Mandatory statutory retention periods remain unaffected. If payment is made online, payment data is transmitted to the respective payment provider (see following section).
Payment providers
Stripe: We offer payment via Stripe. Provider: Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. When paying with Stripe, the payment data you enter (e.g. name, amount, bank/credit card details) is transmitted to Stripe. Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR; where consent is requested, Art. 6(1)(a) GDPR. Any transfer to the USA is based on the EU Commission’s standard contractual clauses. Details: https://stripe.com/privacy.
PayPal: We also offer payment via PayPal. Provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. When paying with PayPal, the payment data you enter is transmitted to PayPal. Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR; where consent is requested, Art. 6(1)(a) GDPR. Details: https://www.paypal.com/uk/webapps/mpp/ua/privacy-full.
5. Cookie consent
Complianz
We use a consent management platform that creates a cookie pop-up, scans scripts and cookies and obtains and documents your consent. The tool used is “Complianz”; provider: Complianz BV, Kalmarweg 14-5, 9723 JG Groningen (Netherlands). Legal basis for use: our legitimate interest in a legally compliant operation (Art. 6(1)(f) GDPR). More: https://complianz.io/legal/privacy-statement/.
6. Security
Security Optimizer
To protect our website we use the security plugin “Security Optimizer” (provider: SiteGround). It serves to protect against unauthorised access and attacks (e.g. login protection). Security-relevant data such as IP addresses may be processed. Legal basis: our legitimate interest in secure operation (Art. 6(1)(f) GDPR).
7. Cloudflare Turnstile
Cloudflare Turnstile
To protect our contact form against automated requests (spam, bots) we use “Turnstile” from Cloudflare Germany GmbH, Rosental 7, c/o Mindspace, 80331 Munich (parent company: Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA). Turnstile analyses technical characteristics of your device and browser; in doing so, your IP address, browser and operating system information, language settings, screen resolution, mouse movements and keyboard inputs and a timestamp are transmitted to Cloudflare. Legal basis: Art. 6(1)(f) GDPR. The transfer to the USA is based on the EU Commission’s standard contractual clauses: https://www.cloudflare.com/cloudflare-customer-scc/. More: https://www.cloudflare.com/privacypolicy/.
8. Google Maps
Google Maps
This website uses the map service Google Maps, e.g. to show our location and directions. Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Maps is only loaded after you have consented via our consent banner (Complianz). Use of the functions requires processing of your IP address; this information is usually transferred to a Google server in the USA and stored there. Legal basis: your consent (Art. 6(1)(a) GDPR and Section 25(1) TDDDG); it may be revoked at any time. The transfer to the USA is based on the EU Commission’s standard contractual clauses. More: https://policies.google.com/privacy.
9. Reviews (Airbnb)
Airbnb reviews
To display guest reviews we embed Airbnb reviews using the widget “Widgets für Airbnb Bewertungen” (provider: Trustindex.io) and “WP Airbnb Review Slider” (provider: LJ Apps). When you access a page with an embedded Trustindex widget, data (e.g. IP address) may be transmitted to Trustindex or Airbnb. “WP Airbnb Review Slider” stores reviews locally in our database and loads them without a further third-party request. Embedding is based on your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG) where requested, otherwise on our legitimate interest in an appealing presentation (Art. 6(1)(f) GDPR).
