Rechtliches
Privacy Policy
1. Privacy at a glance
General notes
The following notes provide a simple overview of what happens to your personal data when you visit our website or send a room enquiry. Personal data is any data by which you can be personally identified. Detailed information can be found in the following sections.
2. Responsible body
Responsible for the data processing on this website is (Art. 4 Nr. 7 DSGVO):
Eugen Beimler
Landhaus Schend
Hauptstraße 9
54552 Immerath
Phone: +49 6573 306
E-mail: [email protected]
3. Data protection officer
Due to the size of our business, we are not obliged to appoint a data protection officer (§ 38 BDSG). For data protection matters, please contact directly the responsible body named under item 2.
4. Your rights
You have the right at any time to (Art. 15-22 DSGVO):
- obtain information about your personal data stored by us (Art. 15)
- have incorrect data corrected (Art. 16)
- request the erasure of your data (Art. 17)
- request the restriction of processing (Art. 18)
- request data portability (Art. 20)
- object to the processing (Art. 21)
- withdraw a consent given at any time (Art. 7 Abs. 3) — the lawfulness of the processing carried out up to the withdrawal remains unaffected
- lodge a complaint with a data protection supervisory authority (Art. 77)
Competent supervisory authority:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz
Hintere Bleiche 34, 55116 Mainz
www.datenschutz.rlp.de
5. General notes and mandatory information
Data protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations (DSGVO, BDSG, TDDDG) as well as this privacy policy.
SSL or TLS encryption
For security reasons and to protect the transmission of confidential content (e.g. booking enquiries), this site uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address bar of the browser shows “https://”.
Storage period
Unless a more specific storage period has been stated within this privacy policy, your personal data will remain with us until the purpose for the data processing no longer applies. Statutory retention obligations remain unaffected (in particular § 257 HGB, § 147 AO — up to 10 years for booking records).
Recipients / processors
A transfer of personal data to third parties takes place only insofar as this is necessary for the performance of the contract or a statutory obligation exists. Processors (Art. 28 DSGVO) — see item 6.
6. Processors and integrated services
a) Hosting & CDN
This website is operated on an infrastructure managed by our processor Conexa Digital, a brand of Merust Trust SL, CL Río Cervol 2, 46940 Manises (Valencia), Spain, NIF B72898414 — registered office within the EU, so no third-country transfer takes place in this respect. The delivery of the content additionally takes place via the Content Delivery Network of Cloudflare Inc. (101 Townsend St, San Francisco, CA 94107, USA). In doing so, Cloudflare collects server log data necessary for processing (in particular IP address, timestamp, browser type). Legal basis: Art. 6 Abs. 1 lit. f DSGVO (legitimate interest in secure and fast web hosting). Third-country transfer USA: based on EU standard data protection clauses (Art. 46 Abs. 2 lit. c DSGVO). Cloudflare is DPF-certified (Data Privacy Framework).
b) Booking enquiries — sending by e-mail
When you submit the enquiry form, the details you have entered (name, address, contact data, travel period, room request, message) are transmitted exclusively by e-mail to our reception, so that we can review your enquiry and reply to you personally. Storage in a booking database does not take place; there is no automatic availability check and no binding online booking. The technical e-mail dispatch takes place via the service Resend (see recipient list below). Legal basis: Art. 6 Abs. 1 lit. b DSGVO (pre-contractual measures).
c) E-mail sending & receiving — IONOS
E-mail correspondence to [email protected] is handled via the mail infrastructure of IONOS SE (Elgendorfer Str. 57, 56410 Montabaur). In doing so, IONOS collects data necessary for processing (sender, timestamp, e-mail content). Legal basis: Art. 6 Abs. 1 lit. b DSGVO (initiation of contract) or Art. 6 Abs. 1 lit. f DSGVO for other enquiries. Privacy IONOS: ionos.de/terms-gtc/terms-privacy
d) Map display — Google Maps
To display directions we embed Google Maps (provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; parent company Google LLC, USA). The map is loaded only after your express click (“load map”) — beforehand, no data is transmitted to Google. Upon loading, among other things your IP address and usage data are transmitted to Google, also to the USA. Legal basis: Art. 6 Abs. 1 lit. a DSGVO (consent by click). Google bases the USA transfer on the EU-US Data Privacy Framework or EU standard contractual clauses. The full address is shown as text next to it — you do not have to load the map.
On Google's role: Google does not process this data on our behalf but is — like us — independently responsible for it; Google expressly places Maps under its “Controller-Controller Data Protection Terms”. Google therefore also uses the data for its own purposes. Consequently there is no data processing agreement under Art. 28 GDPR for Google Maps. What Google does with the data is set out in the Google Privacy Policy.
e) Reach measurement — Cloudflare Web Analytics
To understand which pages interest our guests we use Cloudflare Web Analytics (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA). Recorded are the page called up, referrer, approximate region of origin, device type and loading time.
This service sets no cookies and reads nothing from your device. No fingerprinting takes place, no profile is built about you and you are not recognised across several websites. Because no information is stored on your device or retrieved from it, no consent is required under § 25 Abs. 1 TDDDG for this service — it therefore runs regardless of how you decide on the consent notice. Legal basis: Art. 6 Abs. 1 lit. f DSGVO (legitimate interest in a needs-based design of our offer). You may object to this processing at any time under Art. 21 DSGVO — an informal message to [email protected] suffices. USA transfer: EU standard contractual clauses, Cloudflare is DPF-certified.
f) Session analysis — Microsoft Clarity (only with your consent)
If you agree in the notice at the bottom of the page, we use Microsoft Clarity (Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland). The service shows us, via heatmaps and recorded session flows, which areas of a page are viewed and clicked and where visitors drop off. Mouse movements, clicks, scrolling and page changes are recorded; cookies are set in the process (including _clck, _clsk).
Your input is not transmitted in plain text: masking is enabled, so input fields and text content are made unrecognisable before the data leaves our system. We therefore see where people act on a page, not what they typed.
Important note on Microsoft's role: Unlike the providers listed under a) to e), Microsoft does not process this data solely on our behalf but is independently responsible for it. Microsoft therefore also uses the data for its own purposes, including improving its own products and advertising purposes. Consequently there is no data processing agreement under Art. 28 GDPR for Clarity. What Microsoft does with the data is set out in the Microsoft Privacy Statement.
The legal basis is exclusively your consent (Art. 6 Abs. 1 lit. a DSGVO; § 25 Abs. 1 TDDDG). Without consent Clarity is not loaded — not a single request goes to Microsoft. You can withdraw your consent at any time with effect for the future via “Analytics settings” in the footer. USA transfer: standard contractual clauses, supplemented by the EU-US Data Privacy Framework.
7. Data collection on this website
Cookies and local storage
Our web pages use so-called “cookies” and similar storage techniques (localStorage). Specifically, we store:
-
Theme preference (
theme, localStorage) — stores whether you display the site light or dark. Legal basis: § 25 Abs. 2 Nr. 2 TDDDG (technically necessary for the display you have chosen). -
Accessibility comfort (
schend_a11y_v1, localStorage) — stores your settings for font size, contrast and reduced motion. Legal basis: § 25 Abs. 2 Nr. 2 TDDDG.
Without your consent we set no analytics cookies — neither our own nor third-party ones. Only if you expressly agree in the notice at the bottom of the page does Microsoft Clarity come into play (item 6 f); that service sets cookies of its own. If you do not agree, only the comfort settings listed above and the cookie-free reach measurement via Cloudflare Web Analytics (item 6 e) remain, for which no consent is required. You can withdraw your consent at any time via “Analytics settings” in the footer. You can adjust your browser settings so that cookies / localStorage are completely blocked — however, this may limit the function of the website (e.g. your theme and comfort settings will be lost).
Server log files
Our hosting provider (see item 6 a) automatically collects and stores information in so-called server log files, which your browser automatically transmits:
- browser type and browser version
- operating system used
- referrer URL
- host name of the accessing computer
- time of the server request
- IP address (truncated after processing)
A merging of this data with other data sources is not carried out. Legal basis: Art. 6 Abs. 1 lit. f DSGVO (legitimate interest in operational security). We do not operate a web server of our own and keep no server log files ourselves; the processing lies with the hosting provider, who processes the data according to its own retention periods for operational and attack security and does not make it available to us.
Room enquiry / booking form
Via the booking form we collect the following data:
- name (first and last name)
- address (street, postal code/city)
- e-mail address
- telephone number
- arrival and departure date
- desired room / package and number of persons
- catering & extras (e.g. half board, cot, travelling with a dog)
- any special requests (free text)
Purpose: processing of your enquiry, initiation of contract, room reservation
and communication regarding your stay.
Legal basis: Art. 6 Abs. 1 lit. b DSGVO (initiation and
performance of contract).
Storage period: Until the complete handling of the enquiry / the
stay. Booking-relevant records (invoices) are retained pursuant to § 257 HGB / § 147 AO for up to
10 years.
Recipients / processors:
- Cloudflare, Inc. — hosting and delivery of the website as well as operation of the enquiry endpoint (server region EU), see item 6 a.
- Resend (Plus Five Five, Inc., USA; dispatch via EU region) — technical dispatch of your enquiry by e-mail to our reception as well as an automatic confirmation of receipt to your own e-mail address. The enquiry data you entered in the form are transmitted. USA transfer based on EU standard contractual clauses.
- Conexa Digital, a brand of Merust Trust SL, CL Río Cervol 2, 46940 Manises (Valencia), Spain, NIF B72898414 — technical service provider for operation and maintenance of the website. The acceptance or rejection of your enquiry is decided exclusively by a human.
Data processing agreements pursuant to Art. 28 DSGVO exist with all the named service providers. No disclosure to other third parties takes place.
Enquiry by e-mail, telephone or fax
If you contact us by e-mail ([email protected]), telephone (+49 6573 306) or fax (+49 6573 99815), your enquiry including all personal data resulting from it (name, content of the enquiry, contact data) is stored with us for the purpose of processing. Legal basis: Art. 6 Abs. 1 lit. b DSGVO in the case of initiation of contract, otherwise Art. 6 Abs. 1 lit. f DSGVO (legitimate interest in prompt processing). Data is not disclosed without your consent.
8. Registration obligation for overnight stays
Pursuant to the Federal Registration Act (BMG) we are obliged, in the case of foreign guests, to collect extended registration data (§§ 29 und 30 BMG). For German nationals the registration form obligation no longer applies since 01.01.2025. The collected data is retained one year after departure and subsequently deleted. Legal basis: Art. 6 Abs. 1 lit. c DSGVO (legal obligation).
9. No automated decision-making
A solely automated decision within the meaning of Art. 22 DSGVO (decision without human involvement having legal effect concerning you) does not take place. You are looked after exclusively by human processing.
10. Currency of this privacy policy
We reserve the right to adapt this privacy policy should legal requirements or our processing activities change. The respectively current version can be found at all times on this page. Material changes will additionally be announced on the home page.
Last updated: June 2026