Data protection

Hotel St. Georg GmbH
Ghersburgstrasse 18
83043 Bad Aibling


Phone number: +49 8061/497-0
Fax: +49 8061/497-105
E-mail: hotel(at)sanktgeorg.com
Internet: www.sanktgeorg.com

Company: Hotel St. Georg GmbH
District court: HRB B 8883
Managing director: Johann Reif
Registered office: Bad Aibling
VAT registration number in accordance with § 27a
Tax office RosenheimVAT-ID-NO.: DE 165730504
Licensing authority: Rosenheim District Administration Office

Data protection officer: Norman Moll
Phone number: +49 8061/497-193
E-mail: empfangsleitung@sanktgeorg.com

Privacy policy

§ 1 Information on how personal data is collected

(1) In the following, we will inform you about how we collect personal data when you use our website. Personal data is all data that can be related to you personally, e.g. name, address, e-mail addresses, user behavior.

(2) The controller pursuant to Art. 4 (7) of the EU General Data Protection Regulation (GDPR) is

Hotel St. Georg GmbH
Ghersburgstrasse 18
83043 Bad Aibling
Phone number: +49 8061/497-0
Fax: +49 8061/497-105
E-mail: hotel@sanktgeorg.com
District courtTraunstein: HRB B 8883
Managing Director: Johann Reif

(see our imprint). You can contact our data protection officer at empfangsleitung@sanktgeorg.com or at our postal address, adding “the data protection officer”.

(3) When you contact us by email or using a contact form, we store the data you provide (your email address, possibly your name and your telephone number) in order to answer your questions. We delete the data collected in this context once it no longer needs to be stored, or we restrict the processing of it if there are statutory retention requirements.

(4) If we use contracted service providers for individual functions of our offer or would like to use your data for advertising purposes, we will inform you in detail about the respective processes as described below. We will also state the defined criteria for the storage period.

§ 2 Your rights:

(1) You have the following rights with respect to the personal data concerning you:

– Right of access,

– Right to rectification or erasure,

– Right to restriction of processing,

– Right to object to processing,

– Right to data portability.

(2) You also have the right to complain to a data protection supervisory authority about our processing of your personal data.

§ 3 Collection of personal data when visiting our website

(1) If you use our website for informational purposes only, i.e. if you do not register or otherwise provide us with information, we will only collect the personal data that your browser transmits to our server. If you wish to view our website, we collect the following data, which is technically necessary for us to display our website to you and to ensure stability and security (legal basis is Art. 6 para. 1 sentence 1 lit. f DS-GVO):

– IP adress

– Date and time of the request

– Time zone difference to Greenwich Mean Time (GMT)

– Content of the request (specific page)

– Access status/HTTP status code

– Amount of data transferred in each case

– Website from which the request comes

– Browser

– Operating system and its interface

– Language and version of the browser software.

(2) In addition to the aforementioned data, cookies are stored on your computer when you use our website. Cookies are small text files that are stored on your hard disk by the browser you are using and through which certain information flows to the place that sets the cookie (in this case, us). Cookies cannot execute programs or transmit viruses to your computer. They serve to make the internet offering more user-friendly and effective overall.

(3) Use of cookies:

a) This website uses the following types of cookies, the scope and functioning of which are explained below:

– Transient cookies (see b)

– Persistent cookies (see c).

b) Transient cookies are automatically deleted when you close your browser. These include, in particular, session cookies. These store a so-called session ID, which can be used to assign various requests from your browser to the common session. This enables your computer to be recognized when you return to our website. The session cookies are deleted when you log out or close your browser.

c) Persistent cookies are automatically deleted after a specified period, which may differ depending on the cookie. You can delete the cookies in your browser's security settings at any time.

d) You can configure your browser settings according to your preferences and, for example, refuse to accept third-party cookies or all cookies. Please note that if you do this, you may not be able to use all the features of this website.

§ 4 Further functions and offers on our website

(1) In addition to the use of our website for purely informational purposes, we offer various services that you can use if you are interested. To do so, you will generally need to provide additional personal data, which we use to provide the respective service and to which the aforementioned data processing principles apply.

(2) In some cases, we use external service providers to process your data. These have been carefully selected and commissioned by us, are bound by our instructions and are regularly monitored.

(3) Furthermore, we may disclose your personal data to third parties if we offer participation in promotions, competitions, the conclusion of contracts or similar services together with partners. You will receive more detailed information about this when you provide your personal data or at the bottom of the description of the offer.

(4) If our service providers or partners are based in a country outside the European Economic Area (EEA), we will inform you of the consequences of this in the description of the offer.

§ 5 Objection to or revocation of consent to the processing of your data

(1) If you have given your consent to the processing of your data, you can revoke it at any time. Such a revocation influences the permissibility of the processing of your personal data after you have given it to us.

(2) Insofar as we base the processing of your personal data on the weighing of interests, you may object to the processing. This is the case if the processing is not necessary, in particular, for the fulfillment of a contract with you, which we describe in the following description of the functions. When exercising such an objection, we ask you to explain the reasons why we should not process your personal data as we have done. If your objection is justified, we will review the situation and either discontinue or adjust the data processing, or point out to you our compelling legitimate grounds for continuing the processing.

(3) Of course, you can object to the processing of your personal data for advertising and data analysis purposes at any time. You can inform us of your objection to advertising using the following contact details: hotel@sanktgeorg.com.

§ 6 Newsletter

(1) With your consent, you can subscribe to our newsletter, in which we inform you about our current interesting offers. The advertised goods and services are named in the declaration of consent.

(2) We use the so-called double-opt-in procedure for registering for our newsletter. This means that after you register, we will send an e-mail to the e-mail address you provided, asking you to confirm that you wish to receive the newsletter. In addition, we store the IP addresses you use and the times of registration and confirmation. The purpose of this procedure is to be able to verify your registration and, if necessary, to clarify any possible misuse of your personal data.

(3) The only information required for sending the newsletter is your email address. The provision of further, separately marked data is voluntary and is used to address you personally. After your confirmation, we store your email address for the purpose of sending you the newsletter. The legal basis for this is Art. 6 (1) 1 lit. a GDPR.

(4) You can revoke your consent to receive the newsletter and unsubscribe from the newsletter at any time. You can declare your revocation by clicking on the link provided in each newsletter e-mail, by e-mail to hotel@sanktgeorg.com or by sending a message to the contact details given in the imprint.

(5) We would like to point out that we evaluate your user behavior when sending the newsletter. For this evaluation, the sent e-mails contain so-called web beacons or tracking pixels, which represent one-pixel image files stored on our website. For the evaluations, we link the data mentioned in § 3 and the web beacons with your e-mail address and an individual ID. We use the data obtained in this way to create a user profile in order to tailor the newsletter to your individual interests. In doing so, we record when you read our newsletters and which links you click on in them, and from this we deduce your personal interests. We link this data to the actions you take on our website.

You can opt out of this tracking at any time by clicking on the separate link provided in each e-mail or by notifying us through another contact channel. The information is stored for as long as you are subscribed to the newsletter. After you unsubscribe, we store the data in a purely statistical and anonymous form.

§ 7 Use of Google Analytics

(1) This website uses Google Analytics, a web analysis service provided by Google, Inc. (“Google”). Google Analytics uses “cookies”, which are text files placed on your computer, to help the website analyze how users use the site. The information generated by the cookie about your use of the website (including your IP address) will be transmitted to and stored by Google on servers in the United States. However, if IP anonymization is activated on this website, your IP address will be shortened by Google in advance within member states of the European Union or in other states that are party to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be sent to a Google server in the US and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity and to provide other services relating to website activity and internet usage for the website operator.

(2) The IP address transmitted by your browser as part of Google Analytics is not merged with other Google data.

(3) You can prevent cookies from being stored by selecting the appropriate settings in your browser software; however, we would like to point out that in this case you may not be able to use all the functions of this website to their full extent. You can also prevent the data generated by cookies about your use of the website (incl. your IP address) from being passed to Google, and the processing of these data by Google, by downloading and installing the browser plugin available at the following link: tools.google.com/dlpage/gaoptout.

(4) This website uses Google Analytics with the extension “_anonymizeIp()”. This means that IP addresses are further processed in a shortened form, thus excluding the possibility of personal references. Insofar as the data collected about you is personally identifiable, this is therefore immediately excluded and the personal data is thus promptly deleted.

(5) We use Google Analytics to analyze and regularly improve the use of our website. The statistics obtained enable us to improve our services and make them more interesting for you as a user. For the exceptional cases in which personal data is transferred to the United States, Google has submitted to the EU-US Privacy Shield, www.privacyshield.gov/EU-US-Framework. The legal basis for the use of Google Analytics is Art. 6 para. 1 sentence 1 lit. f DS-GVO.

(6) Third-party information: Google Dublin, Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, Fax: +353 (1) 436 1001. User conditions: www.google.com/analytics/terms/de. html, data protection overview: www.google.com/intl/de/analytics/learn/privacy.html, and data protection declaration: http://www.google.de/intl/de/policies/privacy.

§ 8Facebook, Google+, Xing

(1) Our website provides links to the above services. We do not transfer your personal data. We do not use social plugins on our site, i.e. if you do not explicitly follow the corresponding links, no data will be transferred to the above services.

(2) If you follow these links, your browser will establish a connection to the corresponding social network or service. In doing so, data, e.g. your IP address, will be transmitted so that they can assign your visit to our site to your user account, if one exists. You can prevent this assignment by logging out of your corresponding user account.

§ 9 Inclusion of YouTube videos

(1) We have included YouTube videos in our online offering. These are stored on www.YouTube.com and can be played directly from our website. These are all embedded in “privacy-enhanced mode”, i.e. no data about you as a user is transmitted to YouTube if you do not play the videos. Only when you play the videos will the data mentioned in paragraph 2 be transmitted. We have no influence over this data transmission.

(2) When you visit the website, YouTube receives the information that you have accessed the corresponding subpage of our website. In addition, the data mentioned in § 3 of this declaration will be transmitted. This occurs regardless of whether YouTube provides a user account that you are logged in to or whether no user account exists. If you are logged in to Google, your information will be directly associated with your account. If you do not want this information to be associated with your YouTube profile, you must log out before activating the button. YouTube stores your data as user profiles and uses them for the purposes of advertising, market research and/or demand-oriented design of its website. Such an evaluation is carried out in particular (even for users who are not logged in) to provide demand-oriented advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles, but you must contact YouTube to exercise this right.

(3) Further information on the purpose and scope of data collection and processing by YouTube can be found in the privacy policy. You can also find more information about your rights and the settings options for protecting your privacy there: www.google.de/intl/de/policies/privacy. Google also processes your personal data in the United States and has submitted to the EU-US Privacy Shield, www.privacyshield.gov/EU-US-Framework 


§ 10 Inclusion of Google Maps

(1) We use the Google Maps service on this website. This allows us to display interactive maps directly on the website and enables you to use the map function conveniently.

(2) When you visit the website, Google receives the information that you have accessed the corresponding subpage of our website. In addition, the data mentioned in § 3 of this declaration will be transmitted. This occurs regardless of whether Google provides a user account that you are logged in to or whether there is no user account. If you are logged in to Google, your information will be directly associated with your account. If you do not want this information to be associated with your Google profile, you must log out before activating the button. Google stores your data as user profiles and uses them for the purposes of advertising, market research and/or demand-oriented design of its website. Such an evaluation is carried out in particular (even for users who are not logged in) to provide demand-oriented advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles, but you must contact Google to exercise this right.

(3) Further information on the purpose and scope of the data collection and its processing by the plug-in provider can be found in the provider's data protection declarations. You can also find more information about your rights and the settings you can use to protect your privacy: www.google.de/intl/de/policies/privacy. Google also processes your personal data in the United States and is subject to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework

§ 11 Use of Google Adwords Conversion

(1) We use the Google Adwords service to draw attention to our attractive offers with the help of advertising material (so-called Google Adwords) on external websites. We can determine how successful the individual advertising measures are in relation to the data from the advertising campaigns. Our aim is to show you advertising that is of interest to you, to make our website more interesting for you and to achieve a fair calculation of advertising costs.

(2) These advertising materials are delivered by Google through so-called “ad servers”. For this purpose, we use ad server cookies, which allow certain parameters to be measured for measuring success, such as the display of ads or clicks by users. If you access our website via a Google ad, Google Adwords stores a cookie on your PC. These cookies usually lose their validity after 30 days and are not intended to identify you personally. The unique cookie ID, number of ad impressions per placement (frequency), last impression (relevant for post-view conversions) and opt-out information (marker that the user no longer wishes to be addressed) are usually stored as analysis values for this cookie.

(3) These cookies enable Google to recognize your internet browser. If a user visits certain pages of an Adwords customer's website and the cookie stored on his computer has not yet expired, Google and the customer can recognize that the user clicked on the ad and was redirected to this page. A different cookie is assigned to each Adwords customer. This means that cookies cannot be tracked across the websites of Adwords customers. We ourselves do not collect or process any personal data in the aforementioned advertising measures. We only receive statistical evaluations from Google. Based on these evaluations, we can see which of the advertising measures used are particularly effective. We do not receive any further data from the use of the advertising material; in particular, we cannot identify users on the basis of this information.

(4) Based on the marketing tools used, your browser automatically establishes a direct connection with the Google server. We have no influence on the extent and further use of the data collected by Google through the use of this tool and therefore inform you according to our level of knowledge: Through the integration of AdWords Conversion, Google receives the information that you have accessed the corresponding part of our website or clicked on one of our ads. If you are registered with a Google service, Google can assign the visit to your account. Even if you are not registered with Google or are not logged in, there is a possibility that the provider may obtain and store your IP address.

(5) You can prevent participation in this tracking process in various ways: a) by adjusting your browser software accordingly; in particular, suppressing third-party cookies will prevent you from receiving ads from third-party providers; b) by disabling cookies for conversion tracking by setting your browser to block cookies from the domain “www.googleadservices. com” are blocked, https://www.google.de/settings/ads, although this setting will be deleted if you delete your cookies; c) by disabling the interest-based ads of the providers that are part of the ‘About Ads’ self-regulation campaign via the link www.aboutads. info/choices, although this setting will be deleted if you delete your cookies; d) by permanently disabling it in your Firefox, Internet Explorer or Google Chrome browser under the link www.google.com/settings/ads/plugin. We would like to point out that in this case you may not be able to use all the functions of this offer to their full extent.

(6) The legal basis for the processing of your data is Art. 6 (1) sentence 1 point (f) GDPR. Further information on data protection at Google can be found here: www.google.com/intl/de/policies/privacy and services.google.com/sitestats/de.html. Alternatively, you can visit the website of the Network Advertising Initiative (NAI) at www.networkadvertising.org. Google has submitted to the EU-US Privacy Shield, www.privacyshield.gov/EU-US-Framework

§ 12 Remarketing

In addition to Adwords Conversion, we use the Google Remarketing application. This is a process by which we would like to address you again. This application allows us to display our advertisements to you as you continue to use the internet after visiting our website. This is done by means of cookies stored in your browser, which are used by Google to record and evaluate your usage behavior when you visit various websites. This enables Google to determine that you have previously visited our website. According to Google, the data collected in the course of remarketing is not merged with any of your personal data that may be stored by Google. In particular, Google states that pseudonymization is used for remarketing.

§ 13 Facebook Custom Audiences

(1) Furthermore, the website uses the remarketing function “Custom Audiences” from Facebook Inc. (“Facebook”). This allows users of the website to be shown interest-based ads (“Facebook Ads”) when they visit the social network Facebook or other websites that also use the process. In doing so, we pursue the interest of showing you advertising that is of interest to you in order to make our website more interesting to you.

(2) Based on the marketing tools used, your browser automatically establishes a direct connection with the Facebook server. We have no influence on the extent and further use of the data collected by Facebook through the use of this tool and therefore inform you according to our level of knowledge: Through the integration of Facebook Custom Audiences, Facebook receives the information that you have accessed the corresponding website of our Internet presence or clicked on an ad from us. If you are registered with a Facebook service, Facebook can assign the visit to your account. Even if you are not registered with Facebook or are not logged in, it is possible that the provider will obtain and store your IP address and other identifying information.

(3) You can deactivate the “Facebook Custom Audiences” function at https://www.facebook.com/settings/?tab=ads#_.

(4) The legal basis for the processing of your data is Art. 6 (1) sentence 1 point f GDPR. Further information on data processing by Facebook is available at www.facebook.com/about/privacy

§ 14 A/B testing

(1) This website also carries out analyses of user behavior using a so-called A/B test. This allows us to display our websites with slightly varied content, depending on a profile assignment that has taken place. This enables us to analyze our offer, improve it regularly and make it more interesting for you as a user. The legal basis for the A/B test is Art. 6 para. 1 sentence 1 lit. f DS-GVO.

(2) For this analysis, cookies (see § 3 for more details) are stored on your computer. The information collected in this way is stored by the controller on its server in the United States. You can prevent the analysis by deleting existing cookies and by preventing the storage of cookies. If you prevent the storage of cookies, we would like to point out that you may not be able to use all of the features of our website. You can prevent cookies from being stored by adjusting your browser settings.

(3) Before the analyses are carried out, the IP addresses are further processed in abbreviated form, thus excluding the possibility of direct personal reference. The IP address transmitted by your browser is not merged with other data collected by us.

(4) The service providers for the analyses are

You can prevent the data generated by cookies about your use of the website (incl. your IP address) from being passed to Google, and the processing of these data by Google, by downloading and installing the browser plugin available at the following link: http://tools.google.com/dlpage/gaoptout?hl=de

You can also prevent data collection by Google Analytics / Google Optimize by clicking on the following link. This sets an opt-out cookie that prevents the future collection of your data when you visit this website:

Hier klicken

§ 15 Online reservation

(1) We use the Hotelnetsolutions booking engine (HotelNetSolutions GmbH, Genthiner Str. 8, 10785 Berlin) to enable you to conveniently book your stay with us online. Your data will be collected, processed and used exclusively for the purpose of establishing, implementing and processing the contractual relationship established with the reservation.

(2) If you wish to book an overnight stay with us online, it is necessary for the conclusion of the contract that you provide us with the personal data that we require for the processing of your order. Mandatory information required for the performance of the contract is marked separately; any further information is provided voluntarily. We process the data you provide in order to process your order. For this purpose, we may pass on your payment data to our principal bank. The legal basis for this is Art. 6 (1) sentence 1 point b GDPR.

(3) It is possible to create a corporate customer account that allows us to store your data for later bookings. When you create an account, the data you provide will be stored until you request its deletion.

We may also process the data you provide to inform you about other interesting products in our portfolio or to send you e-mails with technical information.

(4) We are obliged by commercial and tax law to store your address, payment and order data for a period of ten years. However, after two years we will restrict the processing of this data, i.e. your data will only be used to comply with legal obligations.

§ 16 Contact form

You can use our contact form to get in touch with us. The input of data is explicitly on a voluntary basis. The personal data provided will be treated confidentially and used for the intended purpose in accordance with the applicable data protection regulations. The data will not be passed on to third parties outside our company.

§ 17 Security

The HOTEL ST. GEORG uses technical and organizational security measures in order to protect the data provided by you against accidental or intentional manipulation, loss, destruction or against access by unauthorized persons. These security measures are continuously improved in line with technological progress. In addition, all employees and agents are bound to the data secrecy of the Federal Data Protection Act.

§ 18 Changes to this data protection declaration

The HOTEL ST. GEORG reserves the right to change this data protection declaration. The current version of the data protection declaration is always available on the HOTEL ST. GEORG website at www.sanktgeorg.com/datenschutz/

As of: May 2018

Your HOTEL ST. GEORG