- 1 Information about the collection of personal data
(1) Below, we provide you with information about the collection of personal data when using our website. Personal data means all data that relate directly to you, for example, your name, address, email addresses and user behaviour.
(2) The controller according to Art. 4 (7) EU General Data Protection Regulation (GDPR) is
Waldhotel Stuttgart GmbH
Telefon +49 711 185 72 0
Fax +49 711 185 72 400
Executive Management: John Sorensen, Sean Kevin Sorensen. Jörg Grede
Registered Office of the Company: Stuttgart
District Court of Stuttgart HRB 64 58
VAT ID no. DE 147 836 814
(see our Legal Notice).
You can contact our Data Protection Officer at
Am Wolfsberg 18
or by sending a letter to the above address and adding “Data Protection Officer”.
(3) When you contact us by e-mail or using a contact form, we will store the data notified by you (your e-mail address, your name and your telephone number, if applicable) to answer your questions. We will delete the data that arise in this context after its storage is no longer required, or limit the processing if there are statutory storage obligations.
(4) If we rely on commissioned service providers for individual functions of our offer or would like to use your data for advertising purposes, we will inform you in detail below about the respective transactions. In doing so, we will also state the specified criteria for the duration of storage.
- 2 Your rights
(1) With regard to your personal data, you have the following rights towards us:
– right of access;
– right to rectification or erasure;
– right to restriction of processing;
– right to objection to processing;
– right to data portability.
(2) You also have the right to lodge a complaint before data protection supervisory authorities concerning the processing of your personal data by us.
- 3 Collection of personal data when visiting our website
(1) In the case of merely informative use of the website, i.e. if you do not register or otherwise provide us with information, we will only collect the personal data that your browser transmits to our server. If you wish to view our website we will collect the following data, which is technically necessary for us so that we are able to display our website and ensure its stability and security (legal basis is art. 6, subsection 1, s. 1 (f), GDPR):
– IP address;
– date and time of the request;
– time zone difference to Greenwich Mean Time (GMT);
– contents of the request (specific page);
– access status/HTTP status code;
– the transferred data volume;
– website from which the request originates;
– operating system and its interface;
– language and version of the browser software.
(2) In addition to the aforementioned data, cookies will be saved on your computer when you use our website.
- a) Cookies
Cookies may contain data which enable the recognition of the device used. In some cases however, cookies only contain information on certain settings that cannot be related to individuals. However, cookies cannot directly identify a user.
A distinction is made between session cookies, which are deleted as soon as you close your browser and permanent cookies, which will be retained even after the session has ended. In terms of their function, cookies can be distinguished between:
- Essential cookies: These are strictly necessary in order to move around the website, use basic functions and guarantee the security of the website; they neither collect information about you for marketing purposes nor do they save which websites you have visited;
- Statistics: These collect information about how you use our website, which sites you visit and, e.g., whether errors occur when using the website; they do not collect any information which could identify you – all collected information is anonymous and is used exclusively to improve our website and to find out what interests our users;
- Marketing: These serve to offer the website user tailored advertising on the website or third-party offers and to measure the effectiveness of these offers; marketing cookies are stored for no more than 13 months;
- External media: These serve to improve the interactivity of our website with other services (e.g. social networks); sharing cookies are stored for no more than 13 months.
- 4 More functions and offers of our website
(1) Besides the use of our website for mere information purposes, we offer different services that you can use in case of interest. To do so, you usually have to specify more personal data that we will use to render the relevant service and to which the data processing principles specified above apply.
(2) To process your data, we sometimes make use of external service providers. These service providers have been carefully selected and commissioned by us, are bound by our instructions, and are checked at regular intervals.
(3) Apart from that, we may forward your personal data to third parties if we offer the participation in campaigns, competitions, contract conclusions or similar services together with partners. More detailed information will be provided when you specify your personal data or at the bottom, in the description of the offer.
(4) If our service providers or partners have their registered office in a state outside the European Economic Area (EEA), we will inform you on the consequences thereof in the description of the offer.
(5) Tools from companies based in the USA are integrated on our website. When these tools are active, your personal data can be passed on to the US servers of the respective companies. We would like to point out that the USA is not a safe third country within the meaning of EU data protection law. US companies are obliged to surrender personal data to security authorities without you as the person concerned being able to take legal action against this. It cannot therefore be ruled out that US authorities (e.g. secret services) process, evaluate and permanently store your data on US servers for monitoring purposes. We have no influence on these processing activities.
- 5 Objection to or Withdrawal of Your Consent to the Processing of Your Data
(1) If you have provided us with a consent to the processing of your data, you may withdraw that consent at any time. Such a withdrawal affects the legitimacy of the processing of your personal data following your declaration of such a withdrawal.
(2) Where we justify the processing of your personal data on the basis of a weighing of interests, you may submit an objection to the processing. This is particularly relevant to cases in which the processing is not necessary for fulfilling a contract with you, which we will clarify in each case in the following description of the functions. When exerting such right to objection, we ask you to explain the reasons why we should not process your personal data as it is done by us. In case of your justified objection, we will check the facts and either discontinue the data processing and/or adjust it or give you our compelling legitimate grounds based on which we will continue the processing.
(3) It goes without saying that you can object to the processing of your personal data for marketing and data analysis purposes at any time. You can notify us of your objection to processing for advertising purposes via the following contact details: firstname.lastname@example.org.
- 6 Newsletter
(1) You can consent to subscribe to our newsletter, which will provide you with information about our current interesting offers. The advertised products and services are named in the declaration of consent.
(2) For the registration for our newsletter, we use the so-called double opt-in procedure. This means that after your registration, we will send an e-mail to the specified e-mail address in which we ask you to confirm that you want to receive the newsletter. Furthermore, we will always store the IP addresses used and the time of the registration and confirmation. This serves as a means of proof of your subscription and, if applicable, to solve any potential misuse of your personal data.
(3) The only information required for sending the newsletter is your email address. More, separately marked data can be specified voluntarily and will only be used to address you personally. After your confirmation, we will store your email address for the purpose of sending the newsletter. The legal basis is Article 6(1) clause 1 point a) of GDPR.
(4) You can withdraw your consent to receive the newsletter and unsubscribe at any time. You can withdraw your consent by clicking on the link provided in newsletter emails, by sending an email to email@example.com or by sending a message to the contact data stated in the legal notice.
(5) We point out that when dispatching the newsletter, we will analyse your user behaviour. For these analyses, emails contain so-called web beacons and/or tracking pixels creating one-pixel image files which are stored on our website. In this regard, we also connect data indicated under art. 3 and web beacon data to your email address and an individual ID to create user profiles and to tailor newsletters to your individual interests. In this context, we collect data about when you read the newsletter and which links to click on and to make assumptions as to your personal interests. We then connect this data to your activities on our website.
You may object to tracking at any time by clicking on the separate link provided in each email or by contacting us in any other way indicated above. Information will be stored for as long as you subscribed to the newsletter. After subscription, we store data only for statistical purposes and on an anonymised basis. Tracking is also prevented if your default standard email program settings block the display of images. In this case, newsletters are not fully displayed and you may not be able to use all the functions. If you decide to have images manually displayed, the above tracking activities will be performed.
- 7 Use of Google Analytics and Google Search Console
(1) This website uses Google Analytics and Google Search Console, two web analysis services provided by Google Inc. (“Google”). Google Analytics uses so-called “cookies”, that are text files that are stored on your computer and which enable an analysis of how you use our website. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the US and stored there. In the event of the activation of the IP anonymisation on this website, your IP address will be shortened beforehand by Google within member states of the European Union or in other signatory states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the US and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on the website activities, and to provide other services relating to the use of the website and the Internet to the website operator. Search Console makes it possible to access different reports and configure websites.
(2) The IP address transmitted in the scope of Google Analytics and Search Console will not be merged with other data provided by Google.
(3) You can prevent the storage of cookies by setting your browser software accordingly; however, please note that if you do this, you may not be able to use all the features of this website to their fullest extent, however. You may also prevent the collection by Google of the data generated by the cookie and related to your use of the website (including your IP address) as well as the processing of this data by Google by downloading and installing the browser plug-in available under the following link: http://tools.google.com/dlpage/gaoptout?hl=en.
(4) This website uses Google Analytics with the extension “_anonymizeIp ()”. As a result, IP addresses are processed in shortened form, thereby excluding the possibility of personal identification. Insofar as the data collected about your person is assigned a personal reference, it will be immediately excluded, and the personal data will be deleted immediately.
(5) We use Google Analytics to analyse and make regular improvements to the use of our website. With the statistics that we obtain, we can improve our offer and make it more interesting for you as the user. For the exceptional cases in which personal data is transferred to the USA, Google has agreed to comply with the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework . The legal basis for the use of Google Analytics is point (f) of Art. 6(1) s. 1 GDPR.
(7) This website uses Google Analytics also for cross-device analyses of streams of visitors based on user IDs. In your user account (“My Data”, “Personal Data”), you can deactivate cross-device use analyses.
- 8 Integration of Google Maps
(1) On this website, we use Google Maps. This allows us to show you interactive maps as part of the website and enables the convenient use of the map function.
(2) When you visit the website, Google receives information that you have accessed the relevant sub-page of our website. The data stated under § 3 of this declaration will also be transmitted. This will occur regardless of whether Google provides a user account into which you are logged in, or no user account exists. If you are logged in to Google, your data will be assigned directly to your account. If you do not want the data to be assigned to your Google profile, you must log out before activating the button. Google will store your data as user profiles and use it for the purposes of advertising, market research and/or the custom configuration of its website. Data (including the data of users who are not logged in) are evaluated in this way to provide custom advertising and to inform other users of the social network about your use of our website. You have the right to object to the creation of such user profiles; if you intend to exercise this right, please contact Google.
- 9 Use of Google Adwords Conversion
(1) We use Google AdWords to raise awareness of our attractive offers by placing advertisements (so-called ad words) on external website. In relation to advertising campaign data, we can determine the success of single advertising activities. This way, we pursue the interest to display to you advertisements to make our website more interesting for you and to provide for fair advertising cost calculation.
(2) These advertisements are provided by Google via so-called “Ad Servers”. For this purpose, we use ad server cookies to measure certain success parameters, such as the display of advertisements and the number of user clicks. If you access our website via a Google advertisement, Google AdWords places a cookie on your computer. Generally, these cookies are valid only for 30 days and they are not intended to personally identify you. In addition to this cookie, your browser stores other analysis values, such as the unique cookie ID, the number of ad impressions per placement (frequency), the last impression (relevant for post-view conversions) and opt-out information (notice that users no longer want to be contacted).
(3) These cookies enable Google to recognise your internet browser. If users visit certain pages on an Adwords customer’s website and if the cookie stored on the user’s computer has not yet expired, Google and the customer are able to see that the user has clicked on the advertisement and was referred to this page. Every AdWords customer is assigned a different cookie. Cookies cannot therefore be tracked via the websites of AdWords customers. We ourselves to not collect and process any personal data relating to the above advertising activities. Instead, we only receive statistical evaluations from Google based on which we can see which of our advertising activities are particularly effective. We do not receive any other data from employing the advertising media and, in particular, we are unable to identify users based on this information.
(4) Due to the marketing tools employed, your browser automatically establishes a direct connection to Google servers. We have no influence on the scope and the further use of data which Google collects through these tools and we provide information to you according to the state of knowledge: By including AdWords Conversion, Google is informed that you accessed the relevant part of our internet presence or that you clicked on our advertisement. If you are registered with a Google service, Google can allocate your visit to your account. Even if not registered with and/or logged on to Google, it is possible that the service provider has access to and stores your IP address.
(5) There are different ways to prevent tracking activities: a) adequate changes to your browser software settings, particularly the blocking of third-party cookies, leads to third-party advertisements no longer being shown to you; b) conversion tracking cookies de-activation by changing your browser settings in a way that “www.googleadservices.com” cookies are blocked (https://www.google.de/settings/ads), whereby these settings will be deleted if you delete your cookies; c) de-activation of interest-based advertisements from providers related to the “About Ads” self-regulation campaign (http://www.aboutads.info/choices), whereby these settings will be deleted if you delete your settings; and d) permanent de-activation in your browser (Firefox, Internet Explorer or Google Chrome) at http://www.google.com/settings/ads/plugin. Please note that in this case you may not be able to use all the features of the offer to their full extent.
- 10 Remarketing
In addition to AdWords Conversion, we use Google Remarketing, a process which we use to contact you again. Based on this application, we are able to display to you our advertisements on other website if you continue to use the internet. This takes place by means of cookies stored in your browser via which your use behaviour is collected and evaluated by Google when you visit different websites. This way, Google is able to determine that you accessed our website. According to Google’s own information, they will not merge data from remarketing activities with your personal data possibly stored by them. They particularly say that they apply pseudonymisation when it comes to remarketing.
- 11 DoubleClick by Google
(2) Due to the marketing tools employed, your browser automatically establishes a direct connection to Google servers. We have no influence on the scope and the further use of data which Google collects through these tools and we provide information to you according to the state of knowledge: By including DoubleClick, Google is informed that you accessed the relevant part of our internet presence or that you clicked on our advertisement. If you are registered with a Google service, Google can allocate your visit to your account. Even if not registered with and/or logged on to Google, it is possible that the service provider has access to and stores your IP address.
(3) There are different ways to prevent tracking activities: a) adequate changes to your browser software settings, particularly the blocking of third-party cookies, leads to third-party advertisements no longer being shown to you; b) conversion tracking cookies de-activation by changing your browser settings in a way that “www.googleadservices.com” cookies are blocked (https://www.google.de/settings/ads), whereby these settings will be deleted if you delete your cookies; c) de-activation of interest-based advertisements from providers related to the “About Ads” self-regulation campaign (http://www.aboutads.info/choices), whereby these settings will be deleted if you delete your settings; and d) permanent de-activation in your browser (Firefox, Internet Explorer or Google Chrome) at http://www.google.com/settings/ads/plugin. Please note that in this case you may not be able to use all the features of the offer to their full extent.
(4) The legal basis for the processing of your data is Art. 6(1) sent. 1 point (f) of the GDPR. For more information on DoubleClick by Google, please go to https://www.google.de/doubleclick and http://support.google.com/adsense/answer/2839090; general information on data protection with Google is available at https://www.google. de/lint/de/policies/privacy. As an alternative, you can also go to the Network Advertising Initiative (NAI) website at http://www.networkadvertising.org. Google has agreed to comply with the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework.
- 12 Facebook, Google+, Tripadvisor, Sofort-Gutschein
(1) Our website includes links to the above services. We will not transfer your personal data for these purposes. Our website does not use social plug-ins which means that no data will be transferred to these services, unless you expressly follow the links.
(2) If you do follow the links, your browser establishes a connection to the relevant social network or service transmitting data, such as your IP address, so that your visit to your website can be allocated to your user account. You can prevent these allocations by simply logging off of the relevant user account.
- 13 Online reservations
(1) For you to be able to easily make online bookings, we use the Hotelnetsolutions, Fidelio (Fidelio Suite 8 by Oracle Hospitality) and MeetingMarket booking systems.
Your data will be collected, processed and used only
- for establishing, performing and processing the contract relationship based on the reservation, and
- for possible pre- and post-stay mailing
In certain cases, our website also uses technologies from our partnering companies, Expedia, Inc. and meetago GmbH, to efficiently process your queries/bookings.
These companies ensure that your data is processed and used for consultancy, advertising and market research purposes only if you expressly consented to this. You may object to our partnering companies using your data any time.
(2) If you would like to book an overnight stay on-line, it is absolutely necessary for contract conclusion that you provide us with the personal data we require to process your order. When processing the contracts, the necessary mandatory fields are marked to indicate this, other information can be given voluntarily. We use the data provided by you to process your order. We can also pass on your payment data to our bank. The legal basis here is art. 6(1) sent. 1 lit. b of the GDPR.
(3) Due to stipulations under commercial and tax law, we are obliged to retain your address, payment and order data for ten years. Nevertheless, we restrict processing after two years, i.e. your data will be used only for compliance with the legal obligations.
- 14 Video Surveillance Scope and Purpose
(1) On the WALDHOTEL STUTTGART premises, we have video surveillance pursuant to the law, in particular the German Federal Data Protection Act [Bundesdatenschutzgesetz] (BDSG new version) and the EU General Data Protection Regulation (GDPR).
(2) Video surveillance is admissible to the extent this is required for the interests of WALDHOTEL STUTTGART and no legitimate interests of the guests are contrary to this.
(3) Data subjects will always be informed about existing video surveillance and they will see which camera is operating.
(4) There is also a clearly visible information sign attached in a way that it is visible to the data subjects prior to entering the video surveillance area. This information sign also indicates the name of the person overseeing video surveillance activities and his contact data to obtain information about video surveillance cameras.
(5) Compliance with the data subjects’ rights in terms of art. 14 through 21 of the GDPR is guaranteed.
(6) The legal basis of processing your data is art. 6(1) sent. 1 lit. f) of the GDPR (art. 13(1) lit. d) of the GDPR).
- 15 Contact form
(1) You have the possibility to contact us via the contact form. Personal Data is expressly provided on a strictly voluntary basis and will be processed on a confidential basis and for purposes pursuant to valid data protection provisions. We will not transfer the data to third parties outside our company.
(2) Due to stipulations under commercial and tax law, we are obliged to retain your address, payment and order data for ten years. Nevertheless, we restrict processing after two years, i.e. your data will be used only for compliance with the legal obligations.
- 16 Security
WALDHOTEL STUTTGART applies technical and organisational security measures to protect your data from accidental or intentional manipulation, loss, destruction and access by unauthorised individuals. These security measures are subject to continuous improvement according to technological developments. Also, all our employees and vicarious agents are subject to data secrecy in terms of the German Data Protection Act [Datenschutzgesetz].
- 17 “TrustYou” email marketing service
In Waldhotel Stuttgart, we use TrustYou for the dispatch of newsletters. The service is provided by TrustYou GmbH, Munich Center of Technology, Agnes-Pockels-Bogen 1, 80992 Munich. TrustYou is a service that allows for organising and analysing the dispatch of newsletters. Data you provided for subscription (e.g. email address) is stored on TrustYou servers within the European Union.
Our newsletters dispatched with TrustYou give us the possibility to analyse the behaviour of the newsletter recipient. It can, for example, be analysed how many recipients opened the newsletter message and how often which link in the newsletter was clicked. The so-called conversion tracking also allows for the analysis whether a pre-defined action (e.g. purchase of a product on our website) was completed after clicking the link in the newsletter.
You can object to the processing at any time with effect for the future by clicking the Unsubscribe link at the end of the newsletter. Thus, the processing for the receipt of the newsletter and for the statistical analyses ends at the same time. Separate objection to the dispatch via TrustYou or the statistical evaluation is not possible.
Last update: October 2018