Privacy policy
Privacy at a glance
The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data with which you can be personally identified. Detailed information on the subject of data protection can be found in this privacy policy.
Who is responsible for the data collection on this website?
Data processing on this website is carried out by the website operator. Their contact details can be found in the „Notice Concerning the Controller“ section of this privacy policy.
How do we collect your data?
Your data is collected, on the one hand, by you providing it to us, e.g. by entering it into a contact form. Other data is recorded automatically by our IT systems when you visit the website (e.g. internet browser, operating system or time of the page view).
What do we use your data for?
Part of the data is collected to ensure the error-free provision of the website. Other data can be used to analyse user behaviour.
What rights do you have regarding your data?
You have the right at any time to obtain free information about the origin, recipient and purpose of your stored personal data, as well as a right to rectification or erasure of this data. We explain further rights below.
External hosting
This website is hosted by an external service provider (host):
We host our website with Mittwald CM Service GmbH & Co. KG, Königsberger Straße 4–6, 32339 Espelkamp (hereinafter referred to as „Mittwald"). When you visit our website, Mittwald collects various log files including your IP addresses. For details, please refer to Mittwald's privacy policy: https://www.mittwald.de/datenschutz
The use of Mittwald is based on Article 6(1)(f) of the GDPR. We have a legitimate interest in ensuring our website is displayed as reliably as possible. If corresponding consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG; consent may be revoked at any time.
We have concluded a data processing agreement (DPA) with the hoster.
General notes and mandatory information
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
When you use this website, various personal data are collected. Personal data is data with which you can be personally identified. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this happens.
Please note that data transmission over the internet (e.g. communication by email) may be subject to security vulnerabilities. It is not possible to protect data completely against access by third parties.
Note on the responsible party
The party responsible for data processing on this website is:
Hotel & Restaurant Seeblick
Strunwai 13
25946 Norddorf (Amrum)
Telephone: +49 4682 92 10
Email: mail@seeblicker.de
Responsible: Nicole Hesse e.K.
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data (e.g. names, email addresses, etc.).
Retention period
Unless a more specific storage period has been specified within this privacy policy, your personal data will remain with us until the purpose for data processing ceases to apply. If you assert a justified request for deletion or revoke your consent to data processing, your data will be deleted, provided we have no other legally permissible reasons for storing your personal data (e.g. retention periods under tax or commercial law); in the latter case, the deletion will take place after these reasons cease to apply.
Withdrawal of your consent to data processing
Many data processing operations are only possible with your explicit consent. You can revoke consent that has already been given at any time. The legality of the data processing carried out up to the revocation remains unaffected by the revocation.
Right to object to data collection in special cases and to direct marketing (Art. 21 GDPR)
IF PROCESSING IS BASED ON ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT TO OBJECT, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, AT ANY TIME TO PROCESSING OF PERSONAL DATA CONCERNING YOU; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR AFFECTED PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21(1) GDPR).
IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR SUCH MARKETING; THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS ASSOCIATED WITH SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION PURSUANT TO ART. 21 PARA. 2 GDPR).
Right to lodge a complaint with the competent supervisory authority
In the event of infringements of the GDPR, data subjects shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or place of the alleged infringement. The right to lodge a complaint shall be without prejudice to any other administrative or judicial remedy.
SSL or TLS encryption
For reasons of security and to protect the transmission of confidential content, such as orders or enquiries that you send to us as the site operator, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address bar of the browser changes from „http://“ to „https://“ and by the lock symbol in your browser bar.
When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Access, erasure and rectification
In accordance with the applicable statutory provisions, you have the right at any time to free-of-charge information about your stored personal data, their origin and recipients, and the purpose of the data processing, and, where applicable, a right to the rectification or erasure of this data. You can contact us at any time regarding this matter or if you have any further questions on the subject of personal data.
Right to restriction of processing
You have the right to request the restriction of the processing of your personal data. You can contact us at any time for this purpose. The right to restriction of processing applies in the following cases:
– If you contest the accuracy of your personal data stored by us, we generally need time to verify this. For the duration of the verification, you have the right to request the restriction of the processing of your personal data.
– If the processing of your personal data was/is unlawful, you may request the restriction of data processing instead of erasure.
– If we no longer require your personal data, but you need them for the exercise, defence or establishment of legal claims, you have the right to request the restriction of the processing of your personal data instead of erasure.
– If you have lodged an objection pursuant to Art. 21(1) GDPR, a balancing of your interests against ours must be carried out. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.
If you have restricted the processing of your personal data, such data may – with the exception of storage – only be processed with your consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or a Member State.
Objection to promotional emails
The use of contact details published in the context of the imprint obligation for sending unsolicited advertising and information materials is hereby objected to. The operators of the pages expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, such as spam emails.
server log files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
– Browser type and browser version
– operating system used
– Referrer URL
– Hostname of the accessing computer
– Server request time
– IP address
These data will not be merged with other data sources. The collection of these data is based on Article 6(1)(f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimisation of their website – for this purpose, the server log files must be collected.
Enquiry by email, telephone or fax
If you contact us by email, telephone or fax, your enquiry, including all personal data resulting therefrom (name, enquiry), will be stored and processed by us for the purpose of handling your request. We will not pass on these data without your consent.
The processing of this data is based on Art. 6(1)(b) GDPR if your request is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of enquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) if this has been requested.
The data you sent to us via contact enquiries will remain with us until you ask us to delete it, revoke your consent for storage, or the purpose for data storage no longer applies (e.g. after your request has been processed). Mandatory statutory provisions – in particular statutory retention periods – remain unaffected.
Applications
We offer you the opportunity to apply to us (e.g. by email or for job vacancies on this website). Below, we inform you about the scope, purpose and use of your personal data collected as part of the application process.
If you send us an application, we will process your associated personal data (e.g. contact and communication data, application documents, notes taken during job interviews) to the extent necessary to decide on the establishment of an employment relationship. The legal basis for this is Section 26 of the Federal Data Protection Act (BDSG) (initiation of an employment relationship), Article 6(1)(b) of the GDPR (general initiation of a contract) and – if you have given your consent – Article 6(1)(a) of the GDPR. Consent may be revoked at any time. Within our company, your personal data will be passed on exclusively to persons involved in the processing of your application.
If the application is successful, the data you have submitted will be stored for the purpose of carrying out the employment relationship. If you are not offered a position, the application documents will be deleted no later than six months after notification of the rejection decision, provided that no other legitimate interests prevent deletion or you have consented to a longer period of storage.
Google Web Fonts (local hosting)
For the uniform display of fonts, we use Google Fonts, which are hosted locally. No personal data is transmitted to Google in the process.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a uniform and appealing presentation of our online offering).
Burst Statistics
This website uses the analytics tool Burst Statistics by the developers of Really Simple Plugins. Burst Statistics enables privacy-friendly analysis of the use of this website. No personal data is stored or passed on to third parties in the process. IP addresses are anonymised and are not stored permanently.
Processing is carried out on the basis of Article 6(1)(f) GDPR (legitimate interest in analysing user behaviour to optimise the online offering). Since the data is anonymous, traditional tracking is not possible.
Processing of customer data (customer and contract data)
We collect, process and use personal data only to the extent that it is necessary for the establishment, content design or modification of the legal relationship (master data). This is done on the basis of Art. 6 para. 1 lit. b GDPR, which permits the processing of data for the performance of a contract or pre-contractual measures. We only collect, process and use personal data regarding the use of this website (usage data) to the extent necessary to enable the user to use the service or to bill for it.
The collected customer data will be deleted after completion of the order or termination of the business relationship. Statutory retention periods remain unaffected.
YouTube (enhanced privacy mode)
This website embeds videos from the YouTube platform. The operator is Google Ireland Limited („Google“), Gordon House, Barrow Street, Dublin 4, Ireland. We use YouTube in the enhanced privacy mode. According to YouTube, this mode means that YouTube does not store any information about visitors to this website before they watch the video.
As soon as you start a video, a connection to the YouTube servers is established. This informs the YouTube server which of our pages you have visited. YouTube is used in the interest of an appealing presentation of our online offerings (Art. 6 para. 1 lit. f GDPR). If corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TDDDG; the consent can be revoked at any time.
For further information, please refer to YouTube's privacy policy: https://policies.google.com/privacy
Online booking and voucher shop (SoftTec / hotline)
For online booking of rooms and holiday apartments as well as the purchase of vouchers, we use the „hotline" hotel software provided by SoftTec GmbH, Hindelanger Straße 35, 87527 Sonthofen (hereinafter referred to as „SoftTec"). The booking engine and voucher shop are provided under the domain hotels-online-buchen.de; when you click on „Check availability", „Book now" or „Buy voucher", you will be redirected to this platform. SoftTec's privacy policy: https://hotlinesoftware.de/datenschutz/
During the booking process or the purchase of a voucher, the data entered by you will be processed, in particular your name, address, email address, telephone number, travel dates, number and age of fellow travellers, payment details and, where applicable, special requests. The data will be transmitted to us and stored in our hotel system in order to process your booking, contact you and handle the contract. Payment details are processed via the payment service provider.
The legal basis is Article 6(1)(b) of the GDPR (performance of a contract or steps prior to entering into a contract). The data is stored for as long as is necessary for the performance of the contract; in addition, retention periods under commercial and tax law apply (usually 10 years). Your booking data is transmitted to the relevant authorities within the scope of statutory reporting obligations (accommodation statistics, visitor's tax).
Chatbot (SoftTec, powered by Chatbase)
On our website, we offer a chatbot that automatically answers your questions relating to the hotel, restaurant and spa. The provider is SoftTec GmbH, Hindelanger Straße 35, 87527 Sonthofen, Germany (hereinafter referred to as „SoftTec"). Technically, the chatbot is based on the Chatbase platform provided by Chatbase Inc., 2261 Market Street STE 85690, San Francisco, CA 94114, USA.
When you visit our website, the chatbot script is loaded from SoftTec's servers; for technical reasons, your IP address is transmitted in the process. Further processing only takes place if you actively open and use the chat. Your entered messages, the conversation history, the time of use and technical data (IP address, browser information) are then processed in order to answer your questions. The answers are generated using AI language models. To continue the conversation, the chatbot may save information in your browser (local storage).
Please do not enter sensitive data such as payment or health information in the chat. For binding bookings and reservations, please use our booking engine or contact us directly.
The legal basis for providing the chatbot is Article 6(1)(f) of the GDPR. Our legitimate interest lies in enabling you to receive quick answers to questions about your stay at any time and in relieving the burden on our reception desk. The processing of your chat entries is based on Article 6(1)(b) of the GDPR (responding to your enquiry). You can object to the processing at any time by not using the chatbot or by contacting us via email at mail@seeblicker.de; you can also obtain all information by telephone or email.
Data processing by Chatbase takes place in the USA. The transfer is safeguarded by standard contractual clauses of the EU Commission (Data Processing Agreement: https://www.chatbase.co/legal/dpa). Chat histories are deleted after [period – please check with SoftTec]. Further information: https://hotlinesoftware.de/datenschutz/ and https://www.chatbase.co/legal/privacy
We have concluded a data processing agreement with SoftTec.
Table reservation, menus and online ordering (gastronovi)
For online table reservation, the display of our menus, and the online ordering of food for collection, we use the software provided by gastronovi GmbH, Buschhöhe 2, 28357 Bremen, Germany (hereinafter referred to as „gastronovi"). The relevant modules are integrated into our website as external content; when loaded, a connection is established with gastronovi's servers and your IP address is transmitted.
When making a table reservation, we process the data you enter (name, email address, telephone number, date, time, number of people, and any notes) in order to confirm and carry out the reservation. In the case of an online order, we also process the order data and payment information via the payment service provider integrated into gastronovi [add provider].
The legal basis is Art. 6 para. 1 lit. b GDPR (performance of a contract). The integration of the modules is based on our legitimate interest in providing a user-friendly reservation and ordering option (Art. 6 para. 1 lit. f GDPR). Reservation data will be deleted `[add time period, e.g. 12 months]` after the reservation date; order data is subject to statutory retention periods.
Further information: https://www.gastronovi.com/datenschutz/ and specifically regarding the reservation services: https://www.gastronovi.com/datenschutz/datenschutz-reservierungsdienste/
Customer reviews (Customer Alliance)
We use the service of CA Customer Alliance GmbH, Hausvogteiplatz 12, 10117 Berlin (hereinafter „Customer Alliance"), to collect and display guest reviews. On our website, we link to our review profile on Customer Alliance `[and/or: embed a review widget – when the widget loads, a connection to Customer Alliance's servers is established and your IP address is transmitted]`.
After your stay, you will receive an email from us via Customer Alliance requesting a review. For this purpose, we transmit your name, email address and stay details to Customer Alliance. The review request is sent on the basis of Art. 6 (1) (f) GDPR (legitimate interest in quality assurance and customer retention). You can object to receiving review requests at any time, e.g. by email to mail@seeblicker.de.
Further information: https://www.customer-alliance.com/en/privacy-policy/ · Provider's privacy contact: dataprotection@customer-alliance.com
3D virtual tours (Matterport)
On our website, we integrate virtual 3D tours of rooms, holiday apartments and the spa. The provider is Matterport, Inc., 352 East Java Drive, Sunnyvale, CA 94089, USA.
When loading a tour, a connection is established with Matterport's servers. In the process, your IP address, browser information, and usage data (e.g. time spent, interactions) are transmitted to Matterport; Matterport may set cookies. We have no control over the further processing by Matterport.
The legal basis is your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG; this consent can be revoked at any time via the cookie settings. Data transmission to the USA is based on standard contractual clauses of the European Commission. Further information: https://matterport.com/privacy-policy · Contact: privacy@matterport.com
Communication via WhatsApp
For fast communication with our reception and for orders from our takeaway kitchen, we offer you the option of contacting us via WhatsApp. The provider is WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. We use `[WhatsApp Business App / WhatsApp Business Platform]`.
If you contact us via WhatsApp, we will process your telephone number, profile name, message content and the time of communication in order to process your enquiry or order. In the process, WhatsApp receives communication metadata (not the end-to-end encrypted content) and may transfer this data – including to third countries, in particular the USA. Your address book is not synchronised with WhatsApp by us.
Communication is initiated by you; the legal basis is Art. 6 para. 1 lit. b GDPR (processing of enquiries and orders) or Art. 6 para. 1 lit. f GDPR (legitimate interest in rapid, straightforward communication). If you do not wish to use WhatsApp, you can reach us at any time by telephone or email. We delete chat histories as soon as your enquiry has been concluded, provided there are no statutory retention obligations. Further information: https://www.whatsapp.com/legal/privacy-policy-eea
Applications (Pentacode)
For advertising job vacancies and receiving online applications, we use the application portal of Pentacode AG, Lindwurmstraße 147, 80337 Munich, Germany (hereinafter referred to as „Pentacode"). When you click on „Apply now", you will be redirected to the portal (jobs.pentacode.app). The application data entered by you there (name, contact details, curriculum vitae, certificates, cover letter) will be processed on our behalf and transmitted to us for the purpose of conducting the application process. Further information: https://pentacode.app/datenschutz/
The legal basis is Section 26 of the Federal Data Protection Act (BDSG) and Article 6(1)(b) of the GDPR (decision on the establishment of an employment relationship). In the event of a rejection, applicant data will be deleted no later than 6 months after the completion of the procedure, unless you have consented to a longer storage period (applicant pool). Applications by email to mail@seeblicker.de are also possible; please note that unencrypted emails can be intercepted during transmission.
Language version (optional, for clarification)
Our website is available in German and English. Language switching takes place via the URL (e.g. `/en/`) without storing cookies or personal data.