Information on data processing according to Art. 13, 14 GDPR
We are pleased that you are visiting our homepage and thank you for your interest in our hotel. Dealing with the data of website visitors, but also of our customers and business partners, is a matter of trust. The trust placed in us is very important to us and therefore the significance and obligation to handle your data with care and to protect it from misuse.
To ensure that you feel safe and comfortable when visiting our website, we take the protection of your personal data and its confidential treatment very seriously. Therefore, we act in accordance with the applicable legal provisions on the protection of personal data and data security. With these notes on data protection, we would therefore like to inform you about when we store which data and how we use it - naturally in compliance with the applicable legislation.
THE MANDALA specifically follows the EU General Data Protection Regulation (GDPR) and the current Federal Data Protection Act (BDSG). When using the internet, we follow the Telemedia Act (TMG) and Telecommunications Telemedia Data Protection Act (TTDSG) of the Federal Republic of Germany to protect your personal data. In the following, we explain what information we collect during your visit to our website and how it is used. In the following, we explain what information we collect during your visit to our websites and how it is used. In addition, we would also like to inform you about how we store and use personal data that we have obtained via other channels.
The responsible person in the sense of the GDPR and other data protection regulations is the:
The Mandala Hotel GmbH
Potsdamer Str. 3
D-10785 Berlin
Tel.: +49 (0) 30 590 05 00 00
Mail: welcome@themandala.de
Name and address of the data protection officer
Andreas Thurmann
DataSolution LUD GmbH
Isarstr. 13
D-14974 Ludwigsfelde
Tel.: +49 (0) 3378202513
Mail: mail@hoteldatenschutz.de
Scope of the processing of personal data
As a matter of principle, we collect and use personal data of our users only insofar as this is necessary for the provision of a functional website as well as our contents and services. The collection and use of our users' personal data regularly only takes place with the user's consent. An exception applies in cases where it is not possible to obtain prior consent for actual reasons and the processing of the data is permitted by legal regulations.
Legal basis for the processing of personal data
Insofar as we obtain the consent of the data subject for processing operations of personal data, Art. 6 (1) lit. a GDPR serves as the legal basis. When processing personal data that is necessary for the performance of a contract to which the data subject is a party, Art. 6 (1) (b) GDPR serves as the legal basis. This also applies to processing operations that are necessary for the performance of pre-contractual measures. If processing of personal data is necessary to comply with a legal obligation (statutory provisions) to which our company is subject (e.g. federal registration laws), Art. 6 (1) c GDPR serves as the legal basis. If the processing is necessary to protect a legitimate interest of our company or a third party and the interests, fundamental rights and freedoms of the data subject do not outweigh the first-mentioned interest, Art. 6 (1) f GDPR serves as the legal basis for the processing.
Data deletion and storage period
The personal data of the data subject shall be deleted or blocked as soon as the purpose of the storage no longer applies. Storage may also take place if this has been provided for by the European or national legislator in Union regulations, laws or other provisions to which the person responsible is subject. The data will also be blocked or deleted if a storage period prescribed by the aforementioned standards expires, unless there is a necessity for the continued storage of the data for the conclusion or fulfilment of a contract.
Description and scope of data processing
Our website contains a contact form that can be used to contact us electronically. If you use this option, the data entered in the input mask will be transmitted to us and stored. These data are: First and last name, e-mail address and request.
Alternatively, it is possible to contact us via the e-mail address provided. In this case, the personal data transmitted with the e-mail will be stored.
Legal basis for data processing
The legal basis for the processing of the data is firstly our legitimate interest in the processing of data in the context of contacting the enquirer. If the contact is aimed at the conclusion of a contract, the additional legal basis for processing is in the context of a contractual relationship.
Purpose of the data processing
The processing of the personal data from the input mask serves us solely to process the contact. In the case of contact by e-mail, this also constitutes the necessary legitimate interest in processing the data. The data is used exclusively for processing the booking and for communication.
The other personal data processed during the sending process serve to prevent misuse of the contact form and to ensure the security of our information technology systems.
Duration of storage
The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. For personal data sent by e-mail, this is the case when the respective conversation with the user has ended. The conversation is ended when the circumstances indicate that the matter in question has been conclusively clarified.
If the contact is a pre-contractual relationship (offer or reservation request), the transmitted data will also be stored in our hotel software and used to execute the contract. If there is no contractual relationship, we delete the data after one year at the end of the year.
Possibility of objection
You have the option to object to the processing of your data at any time. We have set up the e-mail address widerruf@themandala.de for this purpose. We would like to point out that in the event of an objection, the conversation cannot be continued or we cannot create any offers etc.
All personal data stored in the course of contacting us will be deleted in this case.
Description and scope of data processing
In order to be able to communicate with you better and to be able to answer questions about the online platform quickly, we use the chat function of LiveRate from the company LiveRate GmbH, Metzstraße 12, 81667 Munich, Germany on our website. The chat function of LiveRate is used as a communication medium and enables communication with website visitors. So-called chatbots can also be used here, which automatically answer standard questions. Within the chat, you have the option of entering your first and last name as well as your e-mail address. Otherwise, no personal data is stored.
Furthermore, you can use other messenger platforms (Facebook Messenger, Telegram) via LiveRate to send and receive messages. If you use Facebook Messenger, Facebook transmits to LiveRate, among other things, Facebook name, profile pictures, language and gender. If you use Telegram Messenger, your username and picture will be sent to LiveRate.
Legal basis for data processing
The legal basis for the processing is the common interest in data processing. We carry out the aforementioned processing for customer care and to increase our services.
You can also make a booking with us via the chat function of LiveRate. The data requested for the booking, e.g. e-mail address, name, address, are required for the initiation and conclusion of the contract. We process data for order processing, in particular we will forward payment data to your chosen payment service provider or our house bank. The legal basis for the processing is the contract or contract initiation relationship. To prevent unauthorised third parties from accessing your personal data, the ordering process on the website is encrypted using SSL/TLS technology.
Purpose of the data processing
The data is processed exclusively for the processing of the conversation.
Duration of storage
We delete the data accruing in this context after the processing is no longer necessary or we restrict the processing if there are statutory retention obligations.
In addition, as part of LiveRate, you are offered the opportunity to register to receive newsletters. The registration takes place via a registration link. If you have registered for the newsletter, our data processing will be carried out in accordance with the information on the point "Newsletter".
Possibility of objection
You have the option to object to the processing of your data at any time. We have set up the e-mail address widerruf@themandala.de for this purpose.
We would like to point out that in the event of an objection, the booking cannot be completed or the conversation cannot be continued.
Description and scope of data processing
Our website offers the option of purchasing vouchers. If a user takes advantage of this option, the data entered in the input mask is transmitted to us and stored. These data are: Salutation/title, first name, last name, e-mail address, address, voucher value, wishes, payment data, password for individual user account and, if applicable, date of birth and telephone number.
If you make a voucher purchase from our websites, this is done through the online ordering platform of INCERT eTourismus Gmbh & Co KG, Leonfeldner Straße 328, A-4040 Linz, Austria. All order data entered by you is transmitted in encrypted form. INCERT is committed to handling your transmitted data in accordance with data protection regulations. INCERT takes all organisational and technical measures to protect your data.
Legal basis for data processing
The legal basis for the processing of the data is the conclusion of a purchase contract.
Purpose of the data processing
The processing of the personal data from the input mask serves us solely to process the voucher purchase and to handle the payment transaction.
If there is a legitimate interest in obtaining information about the accessibility of natural persons who are commercially active and legal entities, and information about their creditworthiness, we can carry out an information request with IHD Gesellschaft für Kredit- und Forderungsmanagement mbH, Augustinusstr. 11 B, 50226 Frechen. You can find out more about this in IHD's data protection regulations.
Duration of storage
The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. In the case of a contractual relationship, we will delete the data received as soon as national, commercial law, statutory or contractual retention requirements have been fulfilled.
Possibility of objection
The user has the option to object to the processing of his or her personal data at any time. We have set up the e-mail address widerruf@themandala.de for this purpose.
Description and scope of data processing
For the support, advice and advertising of corporate customers, we collect and use the contact person, telephone number and postal address in addition to the business partner or potential business partner. We obtain the information from various sources, either through an enquiry (e-mail or telephone), but also via events, trade fairs, business cards that our sales staff receive, etc.
Legal basis for data processing
The legal basis for processing the data is our legitimate interest in data processing. If the contact is aimed at the conclusion of a contract, the additional legal basis for the processing is the contractual relationship.
To increase our services, we manage all data received in the CRM module of our central hotel software within THE MANDALA. The responsible entity is the hotel with which a business contact exists. Central services such as sales, banqueting, reservations and marketing access this data. The legal basis for processing the data is our legitimate interest in data processing within the framework of central administration and use of the data of our customers and business partners within the hotel group.
Purpose of the data processing
We use this contact data exclusively for our own purposes and for the needs-based design of our own sales activities.
Duration of storage
In principle, no deletion period is foreseen. However, if our sales department has not had any contact with the company contact within 3 years, the sales department will decide whether the contact person of the company contact will be deleted.
If the contact is a pre-contractual relationship (offer, booking or reservation request), the transmitted data will also be stored in our hotel software and used to execute the contract. If there is no contractual relationship, we delete the data after one year at the end of the year.
Possibility of objection
As the contact person of a company contact, you have the option to object to the processing of your data at any time. We have set up the e-mail address widerruf@themandala.de for this purpose. All personal data of the contact person that has been stored for the business partner will be deleted in this case.
Description and scope of data processing
Each time our website is accessed, our system automatically collects data and information from the computer system of the accessing computer. The following data is collected:
The data is also stored in the log files of our system. This data is not stored together with other personal data of the user. Personal user profiles cannot be formed. The stored data is only evaluated for statistical purposes.
Legal basis for data processing
The legal basis for the temporary storage of the data and the log files is the processing to protect our legitimate interest.
Purpose of the data processing
The temporary storage of the IP address by the system is necessary to enable delivery of the website to the user's computer. For this purpose, the user's IP address must remain stored for the duration of the session.
The storage in log files is done to ensure the functionality of the website. In addition, we use the data to optimise the website and to ensure the security of our information technology systems. An evaluation of the data for marketing purposes does not take place in this context.
Our legitimate interest in data processing also lies in these purposes.
Duration of storage
The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. In the case of the collection of data for the provision of the website, this is the case when the respective session has ended.
In the case of storage of data in log files, this is the case after seven days at the latest. Storage beyond this period is possible. In this case, the IP addresses of the users are deleted or alienated so that an assignment of the calling client is no longer possible.
Possibility of objection and removal
The collection of data for the provision of the website and the storage of the data in log files is absolutely necessary for the operation of the website. Consequently, there is no possibility for the user to object.
Facebook
Our website uses social plugins ("plugins") of the social network facebook.com, which is operated by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA ("Facebook").
The plugins are marked with a corresponding logo. When you call up a web page of our website that contains such a plugin, your browser establishes a direct connection with the Facebook servers if the plugin is activated. The content of the plugin is transmitted by Facebook directly to your browser, which then integrates it into the website. By integrating the plugin, Facebook receives the information that you have accessed the corresponding page of our website. If you are logged in to Facebook, Facebook can assign the visit to your Facebook account. If you interact with the plugins or post a comment, the corresponding information is transmitted directly from your browser to Facebook and stored there. For the purpose and scope of the data collection and the further processing and use of the data by Facebook, as well as your rights in this regard and setting options for protecting your privacy, please refer to Facebook's privacy policy. If you do not want Facebook to collect data about you via our website, you must log out of Facebook before visiting our website.
You can find more information on this in Facebook's privacy policy. If you do not want Facebook to link your visit to our website with your Facebook user account, please log out of your Facebook account.
Facebook fan page
On our Facebook fan page at: https://www.facebook.com/onospaberlin/ we use plugins from the provider Facebook.com, which are provided by the company Facebook Inc., 1601 S. California Avenue, Palo Alto, CA 94304 in the USA. By using the fan page, data is forwarded to the Facebook servers, which contain information about your visits to our fan page. For logged-in Facebook users, this means that the usage data is assigned to their personal Facebook account. As soon as you actively use the Facebook plugin as a logged-in Facebook user (e.g. by clicking the "Like" button or using the comment function), this data is transferred to your Facebook account and published. You can only avoid this by logging out of your Facebook account beforehand.
We do not know exactly what data Facebook stores and uses. As a user of the fan page, you must therefore expect that Facebook also stores your actions on the fan page without gaps.
Otherwise, the General Terms of Use of Facebook Ireland Limited, Hanover Reach, 5-7 Hanover Quay, Dublin 2, Ireland apply. With regard to data protection on Facebook, please note the following data protection information of Facebook Ireland Limited.
The legal basis for this data processing is Art. 6 para. 1 lit. a, f) GDPR.
Every person depicted as well as other third parties have the possibility to object to the publication of their personal data (photos) at any time. We have set up the e-mail address widerruf@themandala.de for this purpose. The right to object applies in particular to the publication of images for the future.
It can always happen that we accidentally publish pictures of people where no consent has been given. If publication is not desired, we will immediately do everything possible to comply with your right. In the case of group pictures, we reserve the right to distort faces.
The "Instagram button" is used on this website. When you access this website, your browser establishes a connection to servers of the social network Instagram, offered by Instagram Inc, 1601 Willow Road, Menlo Park, CA, 94025, USA.
When you visit our pages on https://www.instagram.com/ono.spa/, a direct connection is established between your browser and the Instagram server. Instagram thereby receives the information that you have visited our site with your IP address. If you click the Instagram button while you are logged into your Instagram account, you can link the content of our pages on your Instagram profile. This allows Instagram to associate the visit to our pages with your user account. We would like to point out that we, as the provider of the pages, have no knowledge of the content of the transmitted data or its use by Instagram.
For more information, please see Instagram's privacy policy.
Instagram API
We use Instagram API from Instagram, Inc., 1 Hacker Way, Menlo Park, CA 94025, USA, to access additional services and data from Instagram, Inc. This involves a transfer of your IP address to Instagram, Inc. Please note that there is a separate section in this privacy policy for each additional service we use from Instagram, Inc.
Purpose and legal basis
The use of Instagram API is based on your consent.
Duration of storage
The concrete storage period of the processed data cannot be influenced by us, but is determined by Instagram, Inc. Further information can be found in the privacy policy for Instagram API.
YouTube Video
We have integrated YouTube Video on our website. YouTube Video is a component of the video platform of YouTube, LLC, on which users can upload content, share it over the internet and receive detailed statistics.
YouTube Video allows us to integrate content from the platform into our website.
YouTube Video uses cookies and other browser technologies to analyse user behaviour, recognise users and create user profiles. This information is used, among other things, to analyse the activity of the content listened to and to create reports. If a user is registered with YouTube, LLC, YouTube Video can associate the videos played with the profile.
When you access this content, you establish a connection to servers of YouTube, LLC, whereby your IP address and possibly browser data such as your user agent are transmitted.
The use of the service is based on our legitimate interests, i.e. interest in a platform-independent provision of content.
The concrete storage period of the processed data cannot be influenced by us, but is determined by YouTube, LLC. Further information can be found in the privacy policy for YouTube Video.
We use Crazy Egg from Crazy Egg, Inc. to carry out so-called A/B tests on our online offer. This involves simultaneously publishing different versions of our online offer and measuring which of these versions is more user-friendly. When testing the versions, data such as the operating system used, the user agent of the browser and the time of the call can be collected in order to measure the success of the version.
Web tracking technologies are used to associate the above data with the version of our online offering being tested.
Purpose and legal basis
The use of Crazy Egg is based on your consent to optimise our online offer.
Duration of storage
The specific storage period of the processed data cannot be influenced by us, but is determined by Crazy Egg, Inc. Further information can be found in the data protection declaration for Crazy Egg.
We use Cognito Forms CDN to properly deliver the content of our website. Cognito Forms CDN is a service of Cognito LLC, which acts as a content delivery network (CDN) on our website to ensure the functionality of other services of Cognito LLC. For said services you will find a separate section in this privacy policy. This section only deals with the use of the CDN.
A CDN helps to provide content of our online offer, in particular files such as graphics or scripts, more quickly with the help of regionally or internationally distributed servers. When you access this content, you establish a connection to servers of Cognito LLC, 929 Gervais Street, Suite D Columbia, SC 29201, United States, whereby your IP address and possibly browser data such as your user agent are transmitted. This data is processed exclusively for the above-mentioned purposes and to maintain the security and functionality of Cognito Forms CDN.
Purpose and legal basis
The use of the Content Delivery Network is based on our legitimate interests, i.e. interest in a secure and efficient provision and optimisation of our online offer.
Duration of storage
The concrete storage period of the processed data cannot be influenced by us, but is determined by Cognito LLC. Further information can be found in the privacy policy for Cognito Forms CDN.
We have integrated components of the MailChimp service on our website. MailChimp is a service of The Rocket Science Group, LLC and offers marketing automation for companies.
MailChimp is used to store and transfer data entered in forms using cookies, to send marketing emails and automated messages and to create targeted campaigns.
In addition, MailChimp offers us the possibility to analyse whether the emails sent have been opened, how many users have received an email and whether users have unsubscribed from the newsletter after receiving an email.
In this case, your data will be passed on to the operator of MailChimp, The Rocket Science Group, LLC, 675 Ponce de Leon Ave NE Suite 5000 Atlanta, GA 30308, United States.
Purpose and legal basis
We process your data with the help of MailChimp for the purpose of optimising our website and for marketing purposes based on your consent.
Duration of storage
The specific storage period of the processed data cannot be influenced by us, but is determined by The Rocket Science Group, LLC. Further information can be found in the privacy policy for MailChimp.
This service is mainly aimed at adults. We do not currently market any specific areas for children. Accordingly, we do not knowingly collect age-identifying information, nor do we knowingly collect personal information from children under the age of 16. However, we caution all visitors to our website under the age of 16 not to disclose or provide any personally identifiable information through our service. In the event that we discover that a child under the age of 16 has provided us with personal information, we will delete the child's personal information from our files to the extent technically feasible.
If your personal data is processed, you are a data subject within the meaning of the GDPR and you have the following rights vis-à-vis the controller:
You have the right to revoke your declaration of consent under data protection law at any time. The revocation of consent does not affect the lawfulness of the processing carried out on the basis of the consent until the revocation. For this purpose, we have set up the e-mail address widerruf@themandala.de.
As a data subject, without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence or of the place of the alleged infringement, if you consider that the processing of personal data relating to you infringes data protection.
The supervisory authority to which the complaint is submitted will inform you of the status and outcome of your complaint, including the possibility of a judicial remedy.
You can find more information on the website of the Federal Commissioner for Data Protection and Freedom of Information. Follow the link.
We use technical and organisational security measures in accordance with Art. 32 GDPR to protect your data managed by us against accidental or intentional manipulation, loss, destruction or against access by unauthorised persons. Our security measures are continuously improved in line with technological developments. Access is only possible for a few authorised persons and persons who are obliged to provide special data protection and who are involved in the technical, administrative or editorial care of data.
We reserve the right to change, update or amend this privacy notice at any time. Any revised information on data processing will only apply to personal data collected or modified after the effective date.
Status | February 2022