Deutsch English Français

Your data with us

The most important things first

These pages set a single, technically necessary cookie, embed no third-party services and do not analyse your behaviour. Everything you see here – images, fonts, menus – is loaded from our own server. Nothing is transmitted to Google, social networks or advertising networks.

The protection of your personal data is important to us. Below we explain in detail which data we collect, what we use it for, on what legal basis this is done, how long we keep it and what rights you have.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act is:

Gasthof Adler, owner Klaus-Peter Mayer
Schwedenstraße 17, 88682 Salem-Beuren, Germany
Phone +49 7554 323 · Fax +49 7554 97446
adler@adler-beuren.de

The controller is the body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

2. Data protection officer

We employ fewer than twenty people permanently engaged in the automated processing of personal data and are therefore not obliged to appoint a data protection officer. For all questions concerning data protection, please contact the address given above directly.

3. Definitions

We use the terms of the General Data Protection Regulation. Personal data is any information relating to an identified or identifiable person – such as name, address, telephone number, e-mail address or IP address. Processing is any operation performed on such data, i.e. collecting, storing, using, transmitting and erasing. Data subject is you, as the person whose data is processed.

4. Legal bases

We process personal data only where we are permitted to do so. The following may apply:

  • Consent pursuant to Article 6(1)(a) GDPR – if you have given us your consent.
  • Contract pursuant to Article 6(1)(b) GDPR – if we need your data to perform or initiate a contract with you, for example for a room booking or table reservation.
  • Legal obligation pursuant to Article 6(1)(c) GDPR – if a law obliges us to process, such as the Federal Registration Act or tax law.
  • Legitimate interest pursuant to Article 6(1)(f) GDPR – if our interest in processing prevails, for example in the secure operation of these pages. We weigh your interests in each case.

5. Accessing these pages and hosting

Each time you access one of our pages, your browser automatically transmits technical information which our hosting provider IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany, stores in log files:

  • IP address of the requesting device
  • date and time of access
  • name and address of the file retrieved
  • page from which the access was made
  • browser used and its version
  • operating system of the device
  • amount of data transferred and whether the retrieval was successful

This information is technically necessary so that the pages can be delivered at all. We also use it to detect faults, ensure the security of our systems and ward off abusive access. The legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in secure and trouble-free operation.

The log files are deleted after seven days at the latest. They are not merged with other data sets, and we draw no conclusions about individual persons from them. They are not evaluated for advertising purposes.

Our hosting provider processes this data exclusively on our behalf and is bound by our instructions. A data processing agreement pursuant to Article 28 GDPR is in place with them. The servers are located in Germany.

6. Encryption

These pages are transmitted in encrypted form (SSL or TLS). You can recognise this by the padlock in your browser’s address bar and by the address beginning with “https”. As long as encryption is active, the data you transmit to us cannot be read by third parties.

7. Cookies, analytics and external services

We set a single, technically necessary cookie (PHPSESSID). Until you close your browser it remembers which language you have chosen and protects the contact form against automated misuse. It contains only a random identifier and no personal data; we do not use it to track what you do on our pages. The legal basis for storing it on your device is Section 25 (2) No. 2 of the German TDDDG; no consent is required. In addition, your browser keeps in its session storage (sessionStorage) which on-screen hints you have already seen; this does not leave your device either. We use no analytics tools, no tracking pixels, no advertising networks and no social network buttons. No fonts, maps, videos or scripts are loaded from external servers; all components of these pages are on our own server. A consent banner is therefore not required.

Your browser may store parts of the page in its cache. This happens on your device; we have no access to it.

8. Excursion planner

On the “Salem & Lake Constance” page you can put together your own excursion plan. The destinations you select, the names of the days and your notes are stored exclusively in your browser’s local storage (localStorage) on your device. This information is not transmitted to us or to third parties; we have no access to it.

The storage serves solely to display your plan again on a later visit. It remains until you delete the plan via the “Clear plan” button or remove the website data in your browser. Consent is not required for this, as the storage is triggered by you and serves exclusively the function you requested (§ 25(2) no. 2 TDDDG).

The plan is printed via your browser’s print function. No data is transmitted to us in this process either.

9. Contacting us

If you call us, write to us or send an e-mail, we process the information you provide – usually name, telephone number or e-mail address and the content of your enquiry – in order to handle and answer it.

The legal basis is Article 6(1)(b) GDPR insofar as your enquiry serves to initiate or perform a contract, otherwise Article 6(1)(f) GDPR on the basis of our legitimate interest in responding.

We delete this information as soon as it is no longer required to achieve the purpose and no statutory retention obligations stand in the way. For mere enquiries without conclusion of a contract, this is usually the case after six months.

Please note that the transmission of unencrypted e-mails may have security gaps. For confidential information we ask you to call us or to send it by post.

10. Contact form

On our pages you can send us an enquiry via a form. The form is preset on each page to the relevant request; the e-mail to us notes which page the enquiry came from. In doing so we process the following information:

  • your request (room, table, celebration, coach tour or other)
  • your name
  • your e-mail address
  • your telephone number, if you provide it
  • depending on the page, further voluntary details about your request – such as preferred date, time, arrival and departure, number of people, room preference, occasion, catering wishes or your coach company
  • the text of your message
  • date and time of sending

Mandatory fields are request, name, e-mail address and message – without them we cannot answer your enquiry. All other fields are voluntary; they merely help us to give you a fitting answer right away.

The sole purpose of processing is to handle and answer your enquiry. The legal basis is your consent pursuant to Article 6(1)(a) GDPR, which you expressly give before sending, and Article 6(1)(b) GDPR insofar as your enquiry serves to initiate or perform a contract.

Your information is not stored in a database on the server. It is transmitted directly as an e-mail to our mailbox and treated there like an ordinary letter. The e-mail is sent via our hosting provider’s server, which acts exclusively on our instructions. It is not passed on to any other third parties.

To protect against automatically sent spam, the form contains a field that is invisible to you and checks how much time has elapsed between opening and sending. No third-party service is used for this, only the technically necessary session cookie described above is used for this and no profile of you is created.

We delete your message as soon as it is no longer required to achieve the purpose and no statutory retention obligations stand in the way – for enquiries without conclusion of a contract, usually after six months.

You may withdraw your consent at any time without formality, for example with a short message to adler@adler-beuren.de. The lawfulness of processing carried out before withdrawal remains unaffected.

11. Table reservations and room bookings

For a table reservation we need your name, a callback number, date, time and number of people. For a room booking, additionally your address, arrival and departure dates and the number of travellers. We process this information to confirm your booking, prepare your stay and invoice it. The legal basis is Article 6(1)(b) GDPR.

Online room bookings are made via the booking system of our service provider SiteMinder (direct-book.com). We receive the information you enter there in order to perform the contract; the legal basis is Article 6(1)(b) GDPR. SiteMinder’s privacy policy additionally applies to processing on the booking system’s side.

The “Order a voucher” button takes you to the voucher shop of the provider Yovite (yovite.com), which opens in a new window. Simply clicking it transmits no data from our site; you only enter your details on the provider’s site. Yovite handles the sale and payment of vouchers on its own responsibility; Yovite’s privacy policy applies to this processing.

If you voluntarily tell us about special wishes – such as intolerances or the need for accessible access – we process them exclusively to fulfil your wish and delete them after your stay. The legal basis is your consent pursuant to Article 6(1)(a) and, insofar as health information is concerned, Article 9(2)(a) GDPR. You may withdraw this consent at any time.

12. Registration form for hotel guests

As an accommodation business we are legally obliged to have our guests complete and sign a registration form. This records name, date of birth, address, nationality, number of accompanying persons, arrival and departure dates and, for foreign guests, identity document details.

The legal basis is Article 6(1)(c) GDPR in conjunction with §§ 29 to 30 of the German Federal Registration Act. We keep the registration forms for one year and then destroy them. During this period we may grant competent authorities access on request; no further disclosure takes place.

13. Recipients of your data

As a rule we do not pass your data on to third parties. Transmission takes place only in the following cases:

  • to our hosting provider IONOS SE (Montabaur, Germany), which provides the pages for us and acts exclusively on our instructions
  • to the operator of our online booking system (SiteMinder), insofar as you book a room online
  • to the voucher provider Yovite, which handles the sale and payment of vouchers
  • to our tax advisor and, in the course of an audit, to the tax office, insofar as invoices and booking records are concerned
  • to registration authorities, insofar as the Federal Registration Act provides for this
  • to law enforcement and other authorities, insofar as we are legally obliged to provide information

No transfer to countries outside the European Union or to international organisations takes place. Your data is not sold and not passed on to third parties for advertising purposes.

14. Retention period

We store personal data only for as long as is necessary for the respective purpose or as long as statutory retention obligations exist. In detail:

  • server log files: seven days
  • enquiries without conclusion of a contract: six months
  • messages from the contact form: six months, unless a contract is concluded
  • registration forms: one year
  • invoices, booking records and commercial correspondence: six or ten years respectively under commercial and tax law

After these periods expire, the data is deleted or destroyed.

15. Obligation to provide data

You do not have to provide any data merely to visit these pages. If you wish to reserve a table or book a room, we need the information required for this; without it we cannot conclude the contract. The information on the registration form is required by law.

16. No automated decision-making

No automated decision-making, including profiling, pursuant to Article 22 GDPR takes place. We do not assess you by machine and do not create usage profiles.

17. Your rights

You have the following rights towards us:

  • Access pursuant to Article 15 GDPR as to whether and which data we process about you, for what purposes, for how long and to whom we may disclose it
  • Rectification pursuant to Article 16 GDPR of inaccurate or incomplete information
  • Erasure pursuant to Article 17 GDPR, insofar as no retention obligation stands in the way
  • Restriction of processing pursuant to Article 18 GDPR
  • Data portability pursuant to Article 20 GDPR, i.e. provision in a common, machine-readable format
  • Objection pursuant to Article 21 GDPR to processing that we base on a legitimate interest
  • Withdrawal of consent given, pursuant to Article 7(3) GDPR, with effect for the future

An informal message to the address given above is sufficient. Exercising these rights costs you nothing.

18. Right to object

Insofar as we process data on the basis of a legitimate interest pursuant to Article 6(1)(f) GDPR, you have the right to object at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds which override your interests, or the processing serves to assert or defend legal claims.

19. Complaint to the supervisory authority

If you believe that we are not processing your data lawfully, you may lodge a complaint with a data protection supervisory authority. The authority responsible for us is:

The State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg
Lautenschlagerstraße 20, 70173 Stuttgart, Germany
Phone +49 711 615541-0

The right to lodge a complaint exists without prejudice to any other administrative or judicial remedy.

20. Data security

We take technical and organisational measures to protect your data against loss, destruction, alteration and unauthorised access. These include the encrypted transmission of these pages, restricted access to documents and regular updating of the software used. We adapt our measures to technical developments.

21. Changes to this policy

We adapt this policy as soon as our services or the legal situation change – for example if online booking or a route map is added later. The version available here applies in each case.