Privacy Policy

This is an English translation of our German privacy policy, provided for your convenience. In the event of any discrepancy between the two versions, the German original is the legally binding text.

We, Hotel Möve garni, are the controller for this online offering and, as the provider of a teleservice, are required to inform you at the beginning of your visit to our online offering about the nature, scope and purposes of the collection and use of personal data in a precise, transparent, intelligible and easily accessible form, using clear and plain language. The content of this information must be available to you at all times. We are therefore obliged to inform you which personal data are collected or used. Personal data means any information relating to an identified or identifiable natural person.

We attach the greatest importance to the security of your data and to compliance with data protection legislation. The collection, processing and use of personal data is subject to the provisions of the European and national laws currently in force.

With the following privacy policy we would like to show you how we handle your personal data and how you can get in touch with us:

Hotel Möve garni
Auf der Mauer 21
D – 88131 Lindau/B
Telephone: +49 (0) 8382 / 275 895 0
Fax: +49 (0) 8382 / 275 895 0
Web: https://hotel-moeve-lindau.de
Email: info@hotel-moeve-lindau.de 


1. General

For ease of reading, our privacy policy does not differentiate by gender. In the interests of equal treatment, the corresponding terms apply to all genders.

The meaning of the terms used, such as “personal data” or its “processing”, can be found in Article 4 of the EU General Data Protection Regulation (GDPR).

The personal data of users processed within the scope of this online offering include inventory data (e.g. names and addresses of customers), contract data (e.g. services used, names of staff handling the matter, payment information), usage data (e.g. pages of our online offering visited, interest in our products) and content data (e.g. entries in the contact form).

“Users” here covers all categories of data subjects. These include, for example, our business partners, customers, prospective customers and other visitors to our online offering.

2. Specific

Privacy policy
We guarantee that we collect, process, store and use the data arising only in connection with handling your enquiries, as well as for internal purposes and in order to provide services or content requested by you. Privacy policy for this online offering and further information on the duty to inform pursuant to Art. 13 GDPR when collecting personal data from the data subject.

Legal bases for data processing

We process users’ personal data only in compliance with the relevant data protection provisions. This means that users’ data are processed only where there is a legal basis for doing so, that is,

in order to provide our contractual services (e.g. processing of orders) and online services, or where these are required by law,
where your consent has been given, and also
on the basis of our legitimate interests (i.e. an interest in the analysis, optimisation and economic operation and security of our online offering within the meaning of Art. 6 (1) (f) GDPR, in particular in measuring reach, creating profiles for advertising and marketing purposes and collecting access data and using third-party services).
We would be glad to show you where the above legal bases are set out in the GDPR:
Consent, Art. 6 (1) (a) and Art. 7 GDPR
Processing to fulfil our services and to carry out contractual measures, Art. 6 (1) (b) GDPR
Processing to fulfil our legal obligations, Art. 6 (1) (c) GDPR
Processing to safeguard our legitimate interests, Art. 6 (1) (f) GDPR

Transfer of data to third parties

Data are passed on to third parties only within the framework of the statutory requirements. We pass users’ data on to third parties only where this is necessary, for example, for contractual purposes, or on the basis of legitimate interests in the economic and effective operation of our business.

Where we engage subcontractors in order to provide our services, we take appropriate legal precautions and corresponding technical and organisational measures to ensure the protection of personal data in accordance with the relevant statutory provisions.

Transfer of data to a third country or an international organisation

Third countries are understood to mean countries in which the GDPR is not directly applicable law. In principle this covers all countries outside the EU or the European Economic Area.

No data are transferred to a third country or an international organisation without your consent or without a legal basis.

Retention period for your personal data

We adhere to the principles of data minimisation and data avoidance. This means that we store the data you provide to us only for as long as is necessary to fulfil the purposes stated above, or for as long as the various retention periods prescribed by law require. Once the relevant purpose ceases to apply, or after the corresponding periods have expired, your data are routinely blocked or erased in accordance with the statutory provisions.

We have drawn up an internal company policy to ensure that this is done.

Contacting SoftTec GmbH

If you contact us by email, telephone, fax, contact form, etc., you consent to electronic communication. Personal data are collected when you contact us. Which data are collected in the case of a contact form can be seen from the respective contact form. Your data are transmitted securely (SSL-encrypted). The information you provide is stored solely for the purpose of processing the enquiry and for any follow-up questions.

We would be glad to set out the legal bases for this:
Processing to fulfil our services and to carry out contractual measures, Art. 6 (1) (b) GDPR
Processing to safeguard our legitimate interests, Art. 6 (1) (f) GDPR

We use software for maintaining customer data (a CRM system) or comparable software on the basis of our legitimate interests (efficient and rapid handling of user enquiries).

We would like to point out that emails can be read or altered without authorisation and unnoticed while in transit. We would further point out that we use software to filter unwanted emails (a spam filter). Emails may be rejected by the spam filter if certain characteristics have caused them to be wrongly identified as spam.

What rights do you have?

Right of access
You have the right to obtain information about the data stored about you free of charge. On request we will inform you in writing, in accordance with applicable law, which personal data we have stored about you. This also includes the origin and the recipients of your data as well as the purpose of the data processing.

Right to rectification
You have the right to have the data we hold about you rectified if they are inaccurate. You may also request a restriction of processing, for example where you contest the accuracy of your personal data.

Right to blocking
You may also have your data blocked. So that a blocking of your data can be taken into account at all times, these data must be retained in a blocking file for verification purposes.

Right to erasure
You may also request the erasure of your personal data, provided that no statutory retention obligations apply. Where such an obligation exists, we will block your data on request. Where the relevant statutory conditions are met, we will erase your personal data even without a corresponding request from you.

Right to data portability
You are entitled to require us to provide the personal data transmitted to us in a format which permits transmission to another body.

Right to lodge a complaint with a supervisory authority
You have the option of lodging a complaint with one of the data protection supervisory authorities.

Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 27, D-91522 Ansbach
Telephone: +49 981 53-1300
Fax: +49 981 53-981300

You can open the complaint form of the Bavarian State Office for Data Protection Supervision via the following link: https://www.lda.bayern.de/de/beschwerde.html

Right to object
You have the option at any time of withdrawing your consent to the use of your data for internal purposes with effect for the future. To do so it is sufficient to send an email to info@softtec.de . However, such a withdrawal does not affect the lawfulness of the processing operations carried out by us up to that point. This does not affect data processing on the basis of any other legal grounds, such as the initiation of a contract (see above).

Protection of your personal data

We take contractual, organisational and technical security measures in line with the state of the art in order to ensure that the provisions of the data protection laws are complied with and thereby to protect the data processed by us against accidental or deliberate manipulation, loss, destruction or access by unauthorised persons.

The security measures include in particular the encrypted transmission of data between your browser and our server. A 128-bit SSL (AES 128) encryption technique is used for this. This includes your IP address.

In doing so, your personal data are protected within the framework of the following points (extract):

Preserving the confidentiality of your personal data
In order to preserve the confidentiality of the personal data stored with us, we have taken various measures relating to physical access, system access and data access control.
Preserving the integrity of your personal data
In order to preserve the integrity of the personal data stored with us, we have taken various measures relating to transfer control and input control.
Preserving the availability of your personal data
In order to preserve the availability of the personal data stored with us, we have taken various measures relating to job control and availability control.

The security measures in use are continuously improved in line with technological developments. Despite these precautions, because of the insecure nature of the internet we cannot guarantee the security of your data transmission to our online offering. Any transmission of data by you to our online offering is therefore at your own risk.

Protection of minors

Persons who have not yet reached the age of 16 may not transmit any personal data to us without the consent of their parents or guardians. Persons who have not yet reached the age of 16 may provide us with personal information only where the express consent of their parents or guardians has been given, or where the persons have reached the age of 16 or are older. These data are processed in accordance with this privacy policy.

Protection of persons under the age of majority

Persons who have not yet reached the age of 18 may not transmit any personal data to us without the consent of their parents or guardians. Persons who have not yet reached the age of 18 may provide us with personal information only where the express consent of their parents or guardians has been given. These data are processed in accordance with this privacy policy.

Cookies

We use cookies. Cookies are small text files which are stored locally in the cache of your internet browser. Cookies make it possible to recognise the internet browser. The files are used to help the browser navigate through the online offering and to make full use of all its functions.

Our online offering uses: browser cookies

Control of cookies by the user

Browser cookies: you can set all browsers so that cookies are accepted only on request. It is also possible to set them so that only cookies from the pages currently being visited are accepted. All browsers offer functions which allow cookies to be deleted selectively. The acceptance of cookies can also be switched off generally, although restrictions on the ease of use of this online offering may then have to be accepted.

Use of first-party cookies (Google Analytics cookie)

Google Analytics cookies record:

Unique users – Google Analytics cookies record and group your data. All activities during a visit are combined. By setting Google Analytics cookies, a distinction is made between users and unique users.
User activities – Google Analytics cookies also store data about the start and end time of a visit to the online offering and how many pages you have viewed. When the browser is closed, or after a prolonged period of user inactivity (30 minutes by default), the user session is ended and the cookie records the visit as finished. The date and time of the first visit are also recorded. The total number of visits per unique user is likewise logged. External link: http://www.google.com/analytics/terms/de.html

You can prevent the collection of the data generated by the cookie and relating to your use of the online offering (including your IP address) by Google, and the processing of these data by Google, by downloading and installing the following link in the browser plug-in:

External link: http://tools.google.com/dlpage/gaoptout?hl=de.

Further information can be found under the heading “Google Analytics / Universal Analytics web analytics service”.

Use of third-party cookies

In our online offering, third parties set [further] cookies (third-party cookies) through the inclusion of editorial texts or advertising. Third parties are also subject to strict data protection requirements regarding the attributability of personal data.

Lifespan of the cookies used

Cookies are managed by the web server of our online offering. This online offering uses:

[Transient cookies / session cookies (single usage session)

Lifespan: until this online offering is closed] [Persistent cookie (permanent browser identification)

Lifespan: 30 days]

Disabling or removing cookies (opt-out)

Every web browser offers ways to restrict and delete cookies. You can find further information on this on the following websites:

Internet Explorer:

http://windows.microsoft.com/en-GB/windows7/How-to-manage-cookies-in-Internet-Explorer-9

Firefox:

https://support.mozilla.org/en-US/kb/cookies-information-websites-store-on-your-computer?redirectlocale=en-US&redirectslug=Cookies

Google Chrome:

https://support.google.com/chrome/answer/95647?hl=en

Safari:

https://support.apple.com/de-de/HT201265

Google Analytics / Universal Analytics web analytics service

We use Google Analytics, a web analytics service provided by Google Inc. (“Google”). Google Analytics uses “cookies”, text files which are stored on your computer and which enable an analysis of your use of the online offering. The information generated by the cookie about your use of this online offering is generally transmitted to a Google server in the USA and stored there. A transfer of data to a third country therefore takes place. In this connection it is ensured that appropriate and adequate safeguards are in place and that enforceable rights and effective legal remedies are available to you.

You can obtain a copy of the appropriate safeguards via the following links:

Privacy Shield: https://www.privacyshield.gov/list
Standard contractual clauses:

http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:L:2010:039:0005:0018:DE:PDF

Where IP anonymisation is activated in our online offering, however, your IP address will first be truncated by Google within member states of the European Union or in other states party to the Agreement on the European Economic Area.

Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there. On our behalf, Google will use this information to evaluate your use of the online offering, to compile reports on the activity of the online offering and to provide us with further services connected with the use of the online offering and internet usage. The IP address transmitted by your browser within the scope of Google Analytics is not merged with other data held by Google. You can prevent the storage of cookies by adjusting the settings of your browser software accordingly. We would point out, however, that in this case you may not be able to make full use of all the functions of this online offering.

We would point out that this online offering uses Google Analytics with the “_anonymizeIp()” extension and that IP addresses are therefore processed only in truncated form, in order to rule out direct attributability to a person.

We also use Google Analytics reports to record demographic characteristics and interests.

The data we send which are linked to cookies, user identifiers (e.g. user ID) or advertising IDs are automatically deleted after 14 months. Data whose retention period has been reached are deleted automatically once a month. More detailed information on the terms of use and data protection can be found at https://www.google.com/analytics/terms/de.html or at https://policies.google.com/?hl=de

In addition, you can prevent the collection of the data generated by the cookie and relating to your use of the online offering (including your IP address) by Google, and the processing of these data by Google, by downloading and installing a browser plug-in via the following link: http://tools.google.com/dlpage/gaoptout?hl=de.

As an alternative to the browser plug-in, or within browsers on mobile devices, the following link can be used to set an opt-out cookie which will prevent collection by Google Analytics within this online offering in future (this opt-out cookie works only in this browser and only for this domain; if you delete the cookies in this browser, click the link again):

Disable Google Analytics


Use of Google Maps

We use Google Maps to display maps and to create directions. Google Maps is operated by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. By using this online offering you consent to the collection, processing and use by Google, one of its agents or third-party providers of the automatically collected data and of the data entered by you (including your IP address). The terms of use for Google Maps can be found at the following link:

https://www.google.de/intl/de/policies/terms/regional.html

Detailed information on transparency and choices, as well as the privacy provisions, can be found in the privacy centre of google.de: https://www.google.de/intl/de/policies/privacy/?fg=1

Use of Facebook plugins

Plugins of the social network Facebook (Facebook Inc., 1601 Willow Road, Menlo Park, California, 94025, USA) are integrated into our pages. You can recognise the Facebook plugins by the Facebook logo or the “Like” button on our page. An overview of the Facebook plugins can be found here: http://developers.facebook.com/docs/plugins/.

When you visit our pages, the plugin establishes a direct connection between your browser and the Facebook server. Facebook thereby receives the information that you have visited our page with your IP address. If you click the Facebook “Like” button while you are logged into your Facebook account, you can link the content of our pages to your Facebook profile. This enables Facebook to associate your visit to our pages with your user account. We would point out that, as the provider of these pages, we receive no knowledge of the content of the data transmitted or of its use by Facebook. Further information on this can be found in Facebook’s privacy policy at http://de-de.facebook.com/policy.php

If you do not wish Facebook to be able to associate your visit to our pages with your Facebook user account, please log out of your Facebook user account.

Newsletter

When you subscribe to our email newsletter, personal data are collected. We use these data for our own advertising purposes in the form of your email newsletter, provided that you have expressly consented to this as set out below:

“Yes, I would like to subscribe to the newsletter! I accept the privacy policy.”

You can unsubscribe from the newsletter at any time via the link provided for that purpose in the newsletter, or by sending us a corresponding message, email info@hotel-moeve-lindau.de . Once you have unsubscribed, your email address will be deleted from our newsletter distribution list without delay and added to a blocking file to ensure that the withdrawal is observed.

With newsletter tracking, user behaviour is recorded in pseudonymised form. This involves the following pseudonymised data: recipients, recipients less bounces, recipients in queue, recipients skipped, unique unsubscribe rate, unique unsubscribes, bounce rate, bounces (including hard and soft bounces), unique open rate, unique opens, open rate, opens, unique click rate, unique clicks, click rate, clicks, effective unique click rate, clicks for the segmentation of target groups.

For the delivery of the newsletter we work with an external service provider, rapidmail GmbH, Augustinerplatz 2, 79098 Freiburg i. Br. Your personal data are forwarded to rapidmail GmbH for the purpose of sending the newsletter and are processed by them exclusively in accordance with our instructions.

Newsletter tracking: provided that you have previously given your express consent, newsletter tracking (also known as web beacons or tracking pixels) is used. When the newsletter is delivered, the external server can then record certain data about the recipient, for example the time of retrieval, the IP address or details of the email program (client) used. The name of the image file is individualised for each mail recipient by appending a unique ID. The mail sender records which ID belongs to which email address and can thus determine, when the image is retrieved, which newsletter recipient has just opened the email.

Changes to our privacy provisions

We reserve the right to adapt our privacy policy from time to time so that it always complies with current legal requirements, or in order to reflect changes to our services in the privacy policy. This might concern, for example, the introduction of new services. The new privacy policy will then apply to your next visit.

Trade mark protection

Every company name or trade mark mentioned here is the property of the respective company. Brands and names are mentioned for purely informational purposes.

3. Russia-specific provisions

The following applies to users resident in the Russian Federation:

The foregoing services of our online offering are not intended for citizens of the Russian Federation who are resident in Russia.

If you are a Russian citizen resident in Russia, you are hereby expressly informed that any personal data which you provide to us via this online offering are subject solely to your own risk and your own responsibility. You further agree that you will not hold us responsible for any failure to comply with the laws of the Russian Federation.

Social media

Hotel Möve garni has a social media presence on Facebook (https://www.facebook.com/hotelmoevegarni/). Data are processed as a result.

You can find Facebook’s privacy policy here: https://www.facebook.com/policy.php

Encryption in accordance with the Advanced Encryption Standard (AES)

All data traffic takes place via SSL encryption with up to 256 bits. Beforehand, the data have been checked by a firewall and a virus scanner.

We have placed particular importance on the security of your customers’ credit card data.
As required by the credit card industry, this is ensured by the interaction of three different servers:
One server (the data server) contains exclusively credit card data, which have previously been encrypted in accordance with the Advanced Encryption Standard (AES). AES is the first publicly available encryption algorithm approved in the USA for government documents of the highest level of secrecy.
A second server (the key server) manages exclusively the keys used to encrypt the credit card data. A different key is available for each hotel.
Both servers are sealed off from the outside world: they can communicate exclusively with the third server, the web server.
The web server sends the credit card data to the data server, which fetches the key from the key server, encrypts the data and then stores them.

The security measures required by the credit card industry have also been taken for the retrieval of the data:
Using the “Data protection” function, the hotel proprietor registers once as the data protection administrator. They choose their own password and thereby ensure that only they know it.

They can then in turn designate members of staff who are likewise authorised to retrieve credit card data.
Both the data protection administrator and authorised members of staff must authenticate themselves with a personal password each time credit card data are retrieved.

Personal passwords are valid for 90 days and must then be renewed. Reusing the same password is not possible. Passwords which have not been used for 90 days are deleted automatically.

The fact that each hotel has a different encryption key, and that only the hotel’s data protection administrator can authorise further persons, ensures that even employees of our company have no way of viewing your customers’ credit card data.


Your data on real servers – no cloud

We know exactly where our (your) data are – because we do not store data in a cloud for reasons of cost.
Our servers are located in Düsseldorf, in a data centre in the Connecta Parc.

Physical access to the data centre is possible only for authorised persons.
Identity is verified by means of RFID readers and a biometric hand scanner, so that only authorised persons are granted access to the data centre.

The entire data centre is monitored by camera around the clock.
The cameras are located both at all entrances to the data centre and in the colocation areas themselves. All recordings are stored and archived long-term over a predefined period.

The data centre is equipped with an alarm system.
This secures in particular all entrance areas, as well as especially critical zones, against unauthorised access.
The entire data centre also has a modern early fire detection system which detects a possible fire at an early stage both above and below the raised floor and initiates the appropriate measures. Both systems are connected to a local security service and are monitored remotely.

To ensure a permanent power supply, particular importance has also been attached to a high degree of availability and redundancy in the energy supply.

The electricity (100% green power from hydroelectric sources) is permanently buffered by redundant UPS systems, which compensate not only for complete power failures but also for fluctuations in the energy supplier’s network.
An emergency generator is available for longer power failures and supplies up to 100% of the power when required. Appropriate control mechanisms ensure that components with high starting currents, such as motor loads and rectifiers, are started one after another.
The generator has a start-up time of about 30 seconds and is checked and tested once a month for correct operation. The fuel supply is designed for continuous operation of the emergency generator. Refuelling during operation is also possible, so that longer outages can be bridged.

Inbound Marketing & Webmaster:

Orbit Publishers – Inbound Marketing Mexico

Do you have further questions about data security? We are available to answer your questions at any time.