The protection of your data is important to us!
We take the protection of personal data very seriously and strictly adhere to the rules of data protection laws.
1. name and contact details of the data controller and the company data protection officer
This data protection information applies to data processing by Berghotel Maibrunn GmbH & Co KG, responsible Anna Miedaner Address: Maibrunn 1, 94379 Sankt Englmar Phone: +49 (0)9965 8500, Fax: +49 (0)9965 850 100 info@berghotel-maibrunn.de www.berghotel-maibrunn.de 2. Collection and storage of personal data and the nature and purpose of their use a) When visiting the website When you visit our www.berghotel-maibrunn.de, the browser used on your device automatically sends information to the server of our website. This information is temporarily stored in a so-called log file. The following information is collected without any action on your part and stored until it is automatically deleted - IP address of the requesting computer, - date and time of access, - name and URL of the retrieved file, - website from which access is made (referrer URL), - browser used and, if applicable, the operating system of your computer and the name of your access provider. The aforementioned data is processed by us for the following purposes - ensuring a smooth connection to the website, - ensuring convenient use of our website, - evaluating system security and stability and - for other administrative purposes. The legal basis for data processing is Art. 6 para. 1 sentence 1 lit. f GDPR. Our legitimate interest follows from the data collection purposes listed above. Under no circumstances do we use the data collected for the purpose of drawing conclusions about your person. We also use cookies and analysis services when you visit our website. You can find more detailed explanations on this in sections 4 and 5 of this privacy policy. b) When registering for our newsletter If you have expressly consented in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR, we will use your e-mail address to send you our newsletter on a regular basis. To receive the newsletter, it is sufficient to provide an email address. In the guest club you will receive a newsletter every 8-12 weeks with current offers, a birthday letter or an evaluation e-mail after departure, for which we use your e-mail address, date of birth, first and last name and your preferred language. You can unsubscribe at any time, for example via a link at the end of each newsletter. Alternatively, you can also send your unsubscribe request by e-mail at any time.
c) Regular guest club (guest club) This website uses KunLeiSys guest club software (regular guest area). The provider is GASTROpoint GmbH, Pommernstraße 17, 83395 Freilassing, Germany. KunLeiSys Guest Club Software is a service used to organize and manage the Guest Club, offers, loyalty points, event e-mails and newsletter distribution.
You can register for the Guest Club on our website. We only use the data entered for the purpose of using the respective offer or service. The mandatory information requested during registration must be provided in full. Otherwise we will reject the registration. The data entered during registration is processed on the basis of your consent (Art. 6 para. 1 lit. a GDPR). You can withdraw your consent at any time free of charge. You can do this via the unsubscribe link in the email or by unsubscribing from the Guest Club.
The data you have stored with us for the purpose of the Guest Club will be stored by us until you unsubscribe and will be deleted from both our servers and the servers of GASTROpoint GmbH after you unsubscribe and delete your Guest Club account.
In the event of important changes, for example to the scope of the offer or technically necessary changes, we will use the e-mail address provided/stored during registration or in your profile to inform you in this way. Statutory retention periods remain unaffected. We have concluded a contract with GASTROpoint GmbH for commissioned data processing and fully implement the strict requirements of the German data protection authorities when using KunLeiSys Guest Club software.
d) When using our contact form For questions of any kind, we offer you the opportunity to contact us using a form provided on the website. It is necessary to provide a valid e-mail address so that we know who sent the request and can answer it. Further information can be provided voluntarily. Data processing for the purpose of contacting us is carried out in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR on the basis of your voluntarily given consent. The personal data collected by us for the use of the contact form will be automatically deleted after your request has been processed. 3. transfer of data Your personal data will not be transferred to third parties for purposes other than those listed below. We only pass on your personal data to third parties if: - you have given your express consent to this in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR, - the disclosure in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR is necessary for the assertion, exercise or defense of legal claims and there is no reason to assume that you have an overriding interest worthy of protection in not disclosing your data, - in the event that the disclosure in accordance with Art. 6 para. 1 sentence 1 lit. c GDPR, and - this is legally permissible and necessary for the processing of contractual relationships with you pursuant to Art. 6 para. 1 sentence 1 lit. B GDPR. 4. cookies We use cookies on our website. These are small files that your browser automatically creates and that are stored on your end device (laptop, tablet, smartphone, etc.) when you visit our website. Cookies do not cause any damage to your end device and do not contain any viruses, Trojans or other malware. Information is stored in the cookie that results in each case in connection with the specific end device used. However, this does not mean that we obtain direct knowledge of your identity. On the one hand, the use of cookies serves to make the use of our website more convenient for you. For example, we use so-called session cookies to recognize that you have already visited individual pages of our website. These are automatically deleted after you leave our site. In addition, we also use temporary cookies to optimize user-friendliness, which are stored on your end device for a specified period of time. If you visit our site again to use our services, it is automatically recognized that you have already visited us and which entries and settings you have made so that you do not have to enter them again. On the other hand, we use cookies to statistically record the use of our website and to evaluate it for the purpose of optimizing our offer for you (see section 5). These cookies enable us to automatically recognize that you have already visited our website when you visit it again. These cookies are automatically deleted after a defined period of time. The data processed by cookies is required for the purposes mentioned to protect our legitimate interests and those of third parties in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR. Most browsers accept cookies automatically. However, you can configure your browser so that no cookies are stored on your computer or a message always appears before a new cookie is created. However, completely deactivating cookies may mean that you cannot use all the functions of our website. 5. analysis tools a) Tracking tools The tracking measures listed below and used by us are carried out on the basis of Art. 6 para. 1 sentence 1 lit. f GDPR. With the tracking measures used, we want to ensure a needs-based design and the continuous optimization of our website. On the other hand, we use the tracking measures to statistically record the use of our website and to evaluate it for the purpose of optimizing our offer for you. These interests are to be regarded as legitimate within the meaning of the aforementioned provision. The respective data processing purposes and data categories can be found in the corresponding tracking tools. b) Google Analytics We use Google Analytics, a web analysis service of Google Inc(https://www.google.de/intl/de/about/)(1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; hereinafter referred to as "Google") for the purpose of designing and continuously optimizing our pages to meet your needs. In this context, pseudonymized user profiles are created and cookies (see section 4) are used. The information generated by the cookie about your use of this website, such as - browser type/version, - operating system used, - referrer URL (the previously visited page), - host name of the accessing computer (IP address), - time of the server request, is transmitted to a Google server in the USA and stored there. The information is used to evaluate the use of the website, to compile reports on website activity and to provide other services relating to website activity and internet usage for the purposes of market research and the needs-based design of this website. This information may also be transferred to third parties if this is required by law or if third parties process this data on our behalf. Under no circumstances will your IP address be merged with other Google data. The IP addresses are anonymized so that they cannot be assigned (IP masking). You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) and the processing of this data by Google by downloading and installing a browser add-on(https://tools.google.com/dlpage/gaoptout?hl=de).
Further information on data protection in connection with Google Analytics can be found in the Google Analytics help section(https://support.google.com/analytics/answer/6004245?hl=de). c) Google Adwords Conversion Tracking We also use Google Conversion Tracking to statistically record the use of our website and to evaluate it for the purpose of optimizing our website for you. Google Adwords places a cookie (see section 4) on your computer if you have reached our website via a Google ad. These cookies lose their validity after 30 days and are not used for personal identification. If the user visits certain pages of the Adwords customer's website and the cookie has not yet expired, Google and the customer can recognize that the user clicked on the ad and was redirected to this page. Each Adwords customer receives a different cookie. Cookies can therefore not be tracked via the websites of Adwords customers. The information collected using the conversion cookie is used to generate conversion statistics for Adwords customers who have opted for conversion tracking. Adwords customers learn the total number of users who clicked on their ad and were redirected to a page with a conversion tracking tag. However, they do not receive any information with which users can be personally identified. If you do not wish to participate in the tracking process, you can also refuse the setting of a cookie required for this - for example, by using a browser setting that generally deactivates the automatic setting of cookies. You can also deactivate cookies for conversion tracking by setting your browser to block cookies from the domain "www.googleadservices.com". Google's privacy policy on conversion tracking can be found here(https://services.google.com/sitestats/de.html).
Further information on how Google processes your data: https: //policies.google.com/technologies/partner-sites 6. Social media plug-ins We use social plug-ins from the social networks Facebook, Twitter and Instagram on our website on the basis of Art. 6 para. 1 sentence 1 lit. f GDPR in order to make our law firm better known. The underlying advertising purpose is to be regarded as a legitimate interest within the meaning of the GDPR. Responsibility for data protection-compliant operation must be guaranteed by the respective provider. We integrate these plug-ins using the so-called two-click method in order to protect visitors to our website in the best possible way. a) Facebook Social media plug-ins from Facebook are used on our website in order to make their use more personal. We use the "LIKE" or "SHARE" button for this purpose. This is an offer from Facebook. When you visit a page on our website that contains such a plugin, your browser establishes a direct connection with the Facebook servers. The content of the plugin is transmitted by Facebook directly to your browser, which integrates it into the website. By integrating the plugins, Facebook receives the information that your browser has accessed the corresponding page of our website, even if you do not have a Facebook account or are not currently logged in to Facebook. This information (including your IP address) is transmitted directly from your browser to a Facebook server in the USA and stored there. If you are logged in to Facebook, Facebook can assign your visit to our website directly to your Facebook account. If you interact with the plugins, for example by clicking the "LIKE" or "SHARE" button, the corresponding information is also transmitted directly to a Facebook server and stored there. The information is also published on Facebook and displayed to your Facebook friends. Facebook can use this information for the purposes of advertising, market research and the needs-based design of Facebook pages. For this purpose, Facebook creates usage, interest and relationship profiles, e.g. to evaluate your use of our website with regard to the advertisements displayed to you on Facebook, to inform other Facebook users about your activities on our website and to provide other services associated with the use of Facebook. If you do not want Facebook to assign the data collected via our website to your Facebook account, you must log out of Facebook before visiting our website. The purpose and scope of the data collection and the further processing and use of the data by Facebook as well as your rights in this regard and setting options to protect your privacy can be found in Facebook's data protection information(https://www.facebook.com/about/privacy/). b) Twitter Plugins of the short message network of Twitter Inc (Twitter) are integrated on our website. You can recognize the Twitter plugins (tweet button) by the Twitter logo on our site. You can find an overview of tweet buttons here (https://about.twitter.com/resources/buttons). When you visit a page on our website that contains such a plugin, a direct connection is established between your browser and the Twitter server. Twitter then receives the information that you have visited our site with your IP address. If you click on the Twitter "tweet button" while you are logged into your Twitter account, you can link the content of our pages to your Twitter profile. This allows Twitter to associate your visit to our website with your user account. We would like to point out that, as the provider of the pages, we have no knowledge of the content of the transmitted data or its use by Twitter. If you do not want Twitter to be able to associate your visit to our pages, please log out of your Twitter user account. Further information on this can be found in Twitter's privacy policy (https://twitter.com/privacy). c) Instagram Our website also uses social plugins ("plugins") from Instagram, which is operated by Instagram LLC, 1601 Willow Road, Menlo Park, CA 94025, USA ("Instagram"). The plugins are marked with an Instagram logo, for example in the form of an "Instagram camera". When you access a page on our website that contains such a plugin, your browser establishes a direct connection to Instagram's servers. The content of the plugin is transmitted by Instagram directly to your browser and integrated into the page. Through this integration, Instagram receives the information that your browser has accessed the corresponding page of our website, even if you do not have an Instagram profile or are not currently logged in to Instagram. This information (including your IP address) is transmitted directly from your browser to an Instagram server in the USA and stored there. If you are logged in to Instagram, Instagram can directly associate your visit to our website with your Instagram account. If you interact with the plugins, for example by clicking the "Instagram" button, this information is also transmitted directly to an Instagram server and stored there. The information is also published on your Instagram account and displayed to your contacts there. If you do not want Instagram to assign the data collected via our website directly to your Instagram account, you must log out of Instagram before visiting our website. Further information can be found in Instagram's privacy policy(https://help.instagram.com/155833707900388).
7. purchase of a voucher via this website 1. description and scope of data processing On our website there is the possibility to buy vouchers. If a user makes use of this option, the data entered in the input mask will be transmitted to us and stored. These data are Title, first name, surname, address, e-mail address, telephone, voucher value, personalization of the voucher, shipping options/alternative delivery address, payment method. If you order a voucher from our website, this is done via the online ordering platform of websLINE Internet- & Marketing GmbH, Sägewerkstrasse 24, 83395 Freilassing, Germany. All order data entered by you is transmitted in encrypted form. websLINE has undertaken to handle your transmitted data in accordance with data protection regulations. websLINE takes all organizational and technical measures to protect your data. The data will not be passed on to third parties in this context. The data will be used exclusively for processing the booking and for communication.
2. legal basis for data processing The legal basis for the processing of the data is the conclusion of a purchase contract with the user.
3. purpose of data processing The processing of personal data from the input mask serves us solely to process the voucher purchase and to process payment transactions.
4. duration of storage The data will be deleted as soon as it is no longer required for the purpose for which it was collected. In the case of a contractual relationship, we will delete the data received as soon as national, commercial, statutory or contractual retention requirements have been met.
5. right of objection and removal The user has the possibility to object to the processing of his personal data at any time.
7. rights of data subjects You have the right: - in accordance with Art. 15 GDPR, to request information about your personal data processed by us. In particular, you can request information about the purposes of processing, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right of appeal, the origin of your data if it has not been collected by us, as well as the existence of automated decision-making including profiling and, if applicable, meaningful information on its details; - in accordance with Art. 16 GDPR, to demand the immediate correction of incorrect or incomplete personal data stored by us; - in accordance with Art. 17 GDPR, to demand the deletion of your personal data stored by us, unless the processing is necessary to exercise the right to freedom of expression and information, to fulfill a legal obligation, for reasons of public interest or to assert, exercise or defend legal claims; - in accordance with Art. 18 GDPR, to demand the restriction of the processing of your personal data if the accuracy of the data is contested by you, the processing is unlawful but you oppose the erasure of the data and we no longer need the data, but you require it for the establishment, exercise or defense of legal claims or you have objected to processing pursuant to Art. 21 GDPR to object to the processing; - in accordance with Art. 20 GDPR, to receive your personal data that you have provided to us in a structured, commonly used and machine-readable format or to request that it be transmitted to another controller; - in accordance with Art. 7 para. 3 GDPR, to withdraw your consent to us at any time. This means that we may no longer continue the data processing based on this consent in the future and - to lodge a complaint with a supervisory authority in accordance with Art. 77 GDPR. As a rule, you can contact the supervisory authority of your usual place of residence or workplace or our registered office. 8. right to object If your personal data are processed on the basis of legitimate interests pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR, you have the right to object to the processing of your personal data pursuant to Art. 21 GDPR, provided that there are reasons for this arising from your particular situation or the objection is directed against direct advertising. In the latter case, you have a general right to object, which will be implemented by us without specifying a particular situation. If you wish to make use of your right of revocation or objection, simply send an e-mail to: info@berghotel-maibrunn.de a fax to: +49 (0)9965 850 100 or by post to our address: Maibrunn 1, 94379 Sankt Englmar 9 . Up-to-dateness and amendment of this privacy policy This privacy policy is currently valid and was last updated in May 2018. It may become necessary to amend this privacy policy as a result of the further development of our website and offers on it or due to changes in legal or official requirements. You can access and print out the current privacy policy at any time on the website at www.berghotel-maibrunn.de/datenschutzerklaerung/. If you have any questions, comments or requests regarding the collection, processing and use of your personal data by us, please also contact us at any time at the contact address Berghotel Maibrunn, Maibrunn 1, 94379 Sankt Englmar.