1. Controller
The controller responsible for data processing on this website is:
Chalet Moos, Inhaber Vitalii Konyk, Bergleweg 1, 79682 Todtmoos
Email: info@chalet-todtmoos.de · Phone: +49 (0)7674 224
2. Your rights as a data subject
You have the right at any time to information (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing (Art. 21). You may also lodge a complaint with a data protection supervisory authority. The competent authority is the State Commissioner for Data Protection of Baden-Württemberg.
3. Accessing our website (server log files)
When you visit the website, information that your browser transmits is collected automatically (server log files): IP address, date and time, the page accessed, browser type and operating system. The legal basis is our legitimate interest in secure and stable operation (Art. 6(1)(f) GDPR). The data are deleted automatically after 7 days at the latest.
4. Contact and booking enquiries
If you contact us via the contact form, by email or by phone, we process the data you provide (e.g. name, email, message, room preference) in order to handle your enquiry and any possible booking. The legal basis is Art. 6(1)(b) (steps prior to entering into a contract) or (f) GDPR. The data are deleted as soon as they are no longer required and no statutory retention obligations prevent this.
Note: Your message from the contact form is transmitted to our server and stored there so that the host can read it and reply to you. We store your name, e-mail address, optionally your phone number, your message and our replies. The data is deleted automatically after 180 days at the latest and is not passed on to third parties.
5. Hosting
This website is hosted by a service provider: Hostinger International Ltd. (registered in Kaunas, Lithuania); the servers are located in a data centre in Frankfurt am Main, Germany. On our behalf, the host processes data that arise when the website is visited (see server log files). The basis is a data processing agreement (Art. 28 GDPR).
6. Map display (OpenStreetMap)
To show our location, we embed map material from OpenStreetMap (OpenStreetMap Foundation, St John's Innovation Centre, Cowley Road, Cambridge, CB4 0WS, UK). The map is loaded only after you click: as long as you do not press the “Load map” button, no data is transmitted to OpenStreetMap. Once you click, your IP address is transmitted to OpenStreetMap. The legal basis is your consent (Art. 6(1)(a) GDPR), which you give by clicking. Privacy information: wiki.osmfoundation.org/wiki/Privacy_Policy.
7. Fonts
This website uses fonts embedded locally on our server (self-hosted). No connection to Google servers is made and no data (in particular no IP address) is transmitted to Google.
8. Payment processing
For online payments we use the payment service provider Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland). To pay, you are redirected to a page operated by Stripe. You enter your payment details directly with Stripe — card data never reaches our server and is not stored by us. What we transmit to Stripe is solely the booking data: room, travel period, number of nights, amount and an internal booking reference. The contact details you enter with Stripe (name, e-mail address, telephone number where applicable) are passed back to us afterwards so that we can process your booking. The legal basis is performance of the accommodation contract (Art. 6 (1) (b) GDPR). Stripe acts partly as a processor on our behalf and partly as an independent controller in order to meet its own legal obligations; any transfer to third countries takes place on the basis of the EU standard contractual clauses. Details: stripe.com/de/privacy.
9. E-mail processing and booking management
We manage enquiries and bookings in our own booking system on our server. Replies you send us by e-mail are automatically attached to the corresponding enquiry; for this purpose the system checks our mailbox at short intervals and processes only messages relating to an existing enquiry. The legal basis is the performance or initiation of the accommodation contract (Art. 6(1)(b) GDPR). Retention of booking data: uncompleted booking requests are deleted after 1 day, declined or cancelled requests after 30 days, completed bookings no later than 90 days after departure. The host additionally receives a brief technical notification about new requests via messenger; it contains no names and no contact details — only an internal reference number.
10. Data backups
To protect against data loss, we create daily automatic backup copies of the booking system (including enquiries and correspondence). Backups are transferred in encrypted form and additionally stored in a cloud storage service (Google Drive, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland), where they are automatically deleted after no more than 14 days. The legal basis is our legitimate interest in the security and recoverability of our systems (Art. 6(1)(f) GDPR).
11. Visitor measurement
We want to know how often our pages are viewed. For this we use Umami, software that we run on our own server. No cookies are set and no personal data is stored: your IP address is processed solely to determine the country and is not stored. We only record the page viewed, the referring page, device type, browser and country. Individual visitors are not recognised and no cross-site tracking takes place. The data does not leave our server and is not passed on to third parties. The legal basis is our legitimate interest in designing our offering to suit demand (Art. 6 (1) (f) GDPR). Consent is not required because no access to your device takes place (§ 25 (2) TDDDG).
12. Cookies
This website sets no cookies — neither technically necessary ones nor tracking or marketing cookies. Page views are measured without cookies (see “Visitor measurement”). A cookie banner is therefore not required.
13. SSL/TLS encryption
For security reasons, this site uses SSL/TLS encryption. You can recognise an encrypted connection by the "https://" in your browser's address bar.
14. Changes
We will update this privacy policy whenever changes to the website or legal requirements make it necessary.