Zur schönen Aussicht · Ferienhaus Königstein Check availability

Legal information

Privacy information

Information about the processing of personal data on this website.

Scope

This notice describes the processing of personal data on this website and in the associated booking and operational processes.

1. Controller

The controller is Sandro Fuchs, Ferienhaus “Zur schönen Aussicht”, Hermann-Schulze-Straße 12, 01824 Königstein, Germany, email: info@ferien-in-koenigstein.de, telephone: +49 35021 160005. You may use these details for any privacy enquiry.

2. Hosting and website access

The website and its database are hosted by IONOS. When the website is accessed, the hosting service processes connection data required for technical delivery, in particular the IP address, time, requested address, amount of data transferred, response status and browser/device information. This is used for secure delivery, fault analysis and protection against attacks. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is secure and reliable operation. For our webhosting contract concluded before 18 September 2025, IONOS makes webspace access logs available for a maximum of eight weeks; according to IONOS, IP addresses in those log files are anonymised.

3. Strictly necessary sessions and device access

We use strictly necessary session and security cookies for availability and booking functions. They enable the requested steps and protect your details. The legal bases are Article 6(1)(b) or (f) GDPR and section 25(2)(2) TDDDG.

4. Cloudflare Turnstile

We use Cloudflare Turnstile to protect the contact form and booking requests against automated abuse. Cloudflare processes information including the IP address, browser and connection characteristics, and the page visited. According to Cloudflare, form contents are not transmitted to Turnstile. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is protecting your details and our forms. This security access is strictly necessary under section 25(2)(2) TDDDG. Cloudflare may also process data outside the European Economic Area; see section 14 for the transfer mechanisms. Cloudflare Turnstile privacy information.

5. Contact enquiries

For a contact enquiry we process your name, email address, optional telephone number and message in order to respond and handle follow-up questions. The form sends the details to the operator’s central mailbox; it does not create an additional contact copy in the website database. The legal basis is Article 6(1)(b) GDPR for pre-contractual enquiries and otherwise Article 6(1)(f) GDPR, based on our legitimate interest in appropriate communication. Required fields are necessary to process the enquiry; without them the form cannot be submitted. Contact enquiries without a booking are deleted six months after processing is completed, unless a specific dispute or claim requires separate retention.

6. Booking requests and accommodation contracts

For requests, offers, bookings and stays we process title, names, contact details, travel dates, accommodation, number and composition of travellers, information about dogs, messages, address, contract status and the prices and terms applying to your booking. The legal basis is Article 6(1)(b) GDPR. Some data may also be required under statutory record-keeping and tax obligations pursuant to Article 6(1)(c) GDPR. No decision with legal or similarly significant effects is made solely by automated means; requests are reviewed by the operator. Finally rejected or unsuccessful requests are deleted after six months, except where a specific dispute or claim requires retention.

7. Traveller data, registration form and municipal guest tax

Before arrival we collect the actual travellers’ names and dates of birth and the booking address. Arrival, departure, address and birth dates are transferred to the municipal AVS system. There, the applicable guest tax is determined and the registration form to be signed by guests is created. Any calculation on our website is only provisional. For the guest-tax evidence needed later, we store the assessed amount, any exemption or reduction, a reference, the booking reference, stay dates and number of travellers separately from registration data; names, address and birth dates are not carried over to this evidence. Suitable documents supporting exemptions or reductions are checked but not stored. The legal basis is Article 6(1)(c) GDPR together with the applicable registration and municipal rules. Special registration data under the Federal Registration Act must be retained for one year from departure and destroyed within the following three months. Under Königstein’s 2026 guest-tax by-law, the municipal original registration form has a one-year period from arrival and must be destroyed within the following three months. Reusable traveller profiles are removed no later than three months after departure without deleting records required by law.

8. Prices, payments, cancellations and tax records

We process prices, payment status, incoming payments, payment references, refunds and cancellations for contract performance, bookkeeping and compliance with tax obligations. The legal bases are Article 6(1)(b) and (c) GDPR. Necessary booking and accounting vouchers are generally retained for eight years from the legally applicable start date; additional personal data is not retained wholesale. Other document classes may have different statutory periods.

9. Email communications

We send emails about enquiries, offers, payments, cancellations, traveller details and arrival through IONOS. After a completed stay, we may send one brief request for feedback. This email may contain a link to Google reviews; a connection to Google is established only if you open it. We do not assume marketing consent for this request. We store the details needed for communication and proof of delivery, in particular recipient, subject, message content, time and delivery status. This supports contract performance, follow-up and traceable communication. The legal bases are Article 6(1)(b), (c) and, for delivery and security evidence and the one-off feedback request, (f) GDPR. Necessary business and contractual correspondence is retained for six years according to its document class; purely technical delivery errors are deleted after 30 days.

10. Arrival documents and access code

For confirmed stays we send appropriate arrival information and documents. An individual access code is processed only for arrival and the stay. The legal basis is Article 6(1)(b) GDPR. The code is scheduled for deletion seven days after departure; if evidence is required for a specific security incident, only the necessary evidence is kept separately protected.

11. Availability calendars

To prevent double bookings, we use Google Calendar to manage occupancy. From other calendar entries, we retain only the periods and occupancy details needed for availability, not descriptive content. For confirmed website bookings, we transfer the booking number, booker’s first and last name, accommodation and period to Google. Email addresses, payment details and guest messages are not transferred. The legal bases are Article 6(1)(b) and (f) GDPR; our legitimate interest is reliable availability. Guests do not connect directly to Google Calendar.

12. Security and operational logs

To prevent abuse and resolve faults, we process necessary access and security data, such as IP addresses, timestamps and error information. Public form-attempt records are removed after one day. Security data is generally retained for 90 days, full IP addresses contained in it for 30 days and other necessary operational data for no more than 180 days. The legal basis is Article 6(1)(f) GDPR; our legitimate interests are access protection, fault detection and evidence of security-relevant actions.

13. Recipients

Only the operator and necessary service providers receive access to the extent required: IONOS for hosting and email delivery; Cloudflare Turnstile to protect public forms; Google for occupancy management and voluntarily opened reviews; and Microsoft OneDrive for backup copies. Authorities receive data only where required by law, in particular for registration and guest-tax purposes. External map, review or tourism websites are contacted only when you deliberately follow a link. We use no analytics, advertising or social-media pixels or externally loaded fonts.

14. International transfers

IONOS processing is governed by the hosting and mail contract in use. With Cloudflare Turnstile, Google and Microsoft OneDrive, processing by group companies or subprocessors outside the European Economic Area cannot be ruled out. Cloudflare's current data-processing addendum provides for the EU-U.S. Data Privacy Framework for applicable transfers and, in addition, EU Standard Contractual Clauses (SCCs). For details of Google's processing when you voluntarily open a review link, see Google's privacy information.

15. Retention and deletion

Personal data is deleted or irreversibly anonymised according to its purpose; specific statutory evidence duties or disputes may require longer, purpose-bound retention. Necessary booking and accounting vouchers are kept for eight years, and necessary business and contractual correspondence for six years. Contact enquiries without booking and finally rejected requests are deleted after six months, technical mail errors after 30 days and past calendar events after 24 months unless a specific evidence reason applies. Access codes are scheduled for deletion seven days after departure. Reusable traveller profiles are removed no later than three months after departure. Federal registration data is retained for one year from departure and destroyed within the following three months; the municipal original for one year from arrival and destroyed within the following three months. Longer guest-tax evidence is reduced to the necessary minimal record. The periods for access and security data are set out in section 12. Backup copies follow a separate, limited retention plan; the deletion periods apply again after a restore.

16. Your rights

Subject to the statutory conditions, you have rights of access, rectification, erasure, restriction, data portability and objection to processing based on legitimate interests. Consent may be withdrawn for the future; however, the core processing described here is based primarily on contract, legal obligation or legitimate interests. Statutory retention duties may prevent immediate erasure. To exercise your rights, contact the controller using the details above.

17. Right to lodge a complaint

You have the right to lodge a complaint with a data-protection supervisory authority. For a non-public controller established in Saxony, the Saxon Data Protection and Transparency Commissioner, Maternistraße 17, 01067 Dresden, Germany, will generally be competent Lodge a complaint with the Saxon supervisory authority.

18. Date and changes

Date: 23 September 2026. This notice will be updated if the law, service providers or functions change.