Privacy Policy
Information on how personal data is processed on this website.
1. Controller
The controller responsible for data processing on this website is:
Kuppenheim Apartment
Jochen Schmid
Im Siegen 13
76456 Kuppenheim
Germany
Phone: +49 170 5280750
Email: service@kuppenheim-apartment.com
2. General information
We process personal data only to the extent necessary to operate this website, handle enquiries, prepare or carry out bookings and fulfil legal obligations.
Personal data means any information that can identify you personally, for example your name, contact details, message content, booking data or technical access data.
3. Hosting and server log files
This website is hosted by AD IT Systems GmbH, Kronenstraße 12, 90552 Röthenbach a.d. Pegnitz, Germany.
The hosting provider also supplies the technical infrastructure for email delivery and, as a processor, handles the sender, recipient and message data required for delivery.
When the website is accessed, technically necessary access data is processed by the web server. This may include the page or file accessed, date and time of access, transferred data volume, referrer URL, browser type and version, operating system and IP address in shortened or full form.
The processing is carried out to provide the website securely and reliably, to detect technical errors and to prevent misuse. The legal basis is Art. 6 para. 1 lit. f GDPR. Our legitimate interest is the secure and error-free operation of the website.
According to the technical data protection information of AD IT Systems, log files in managed hosting are generally stored for 7 days. Web server error logs are stored for 14 days and PHP error logs for 30 days, unless otherwise contractually configured.
4. Contact by phone, email, WhatsApp or contact form
If you contact us, we process the data you provide to handle your enquiry. This may include your name, email address, phone number, message content and any further voluntary information.
Depending on the content of the enquiry, processing is based on Art. 6 para. 1 lit. b GDPR if your enquiry relates to a booking or contract, or on Art. 6 para. 1 lit. f GDPR to answer general enquiries.
If you contact us via WhatsApp, you leave our website and use the WhatsApp service. Personal data may be processed by WhatsApp or Meta. Please use WhatsApp only if you agree to this data processing. Alternatively, you can contact us by phone or email.
5. Review form
If you use the “Leave a review” form to send feedback about your stay, we process the data you enter. This includes in particular your name or initials, email address, stay period, star rating and review text.
Processing is carried out to review and process your feedback and for possible publication on our website. The legal basis is your consent under Art. 6 para. 1 lit. a GDPR and our legitimate interest in guest feedback and quality assurance under Art. 6 para. 1 lit. f GDPR.
Reviews are not published automatically. Before publication, we check whether a stay actually took place. Your email address is not published. You can withdraw your consent to publication at any time with effect for the future.
6. Booking and our own booking system
For direct bookings, we use our own booking system within this website. We process the information you enter in the booking form, in particular your name, contact details, address, travel dates, number of guests, payment method and additional messages.
Processing is carried out to take pre-contractual steps and to handle the booking pursuant to Art. 6(1)(b) GDPR. Booking and payment data are stored in accordance with contract processing and statutory retention obligations.
Where an external payment provider such as PayPal or Mollie is enabled by the operator and you choose a payment method offered through that provider, the data required for payment is transferred to that provider. If no such method is selected, no data is transferred to an external payment provider.
6.1 Fellow travellers, tourist tax and statutory charges
A booking may also involve data about fellow travellers, in particular name, age group and, where required, nationality or exemption grounds. This data is used for occupancy planning, price calculation and, where applicable locally, the calculation and reporting of tourist tax or a comparable municipal charge.
6.2 Guest portal and arrival confirmation
A protected guest portal may be provided for confirmed bookings. Access is granted through a randomly generated token link that is valid only for the respective booking. Depending on the enabled modules, the portal may process arrival time, instructions, payment status, registration-form details and other stay data. Access tokens are revoked or replaced after the retention period defined in the published policy.
When an arrival confirmation is submitted, the time, IP address and browser/device identifier are logged to protect against misuse. These technical details are not used for advertising and are minimised or deleted under the retention policy.
6.3 Audit trail and system security
Security-relevant and administrative operations are recorded in an application-level, tamper-evident audit trail. A shortened IP address and a reduced browser/operating-system class may be stored. The audit trail serves access control, incident investigation, accountability and abuse prevention; no complete device profiles are created.
6.4 Registration form for foreign guests
If the digital registration module is enabled and a legally approved rule is configured, the information required for guests without German nationality under sections 29 and 30 of the German Federal Registration Act is processed. This may include the number of the valid identity document. The document is checked but not copied. Registration data is retained for one year from departure and then deleted within the configured deletion window unless a higher-ranking legal hold applies.
7. Cookies, local storage and external services
This website does not use analytics or marketing cookies.
A technically necessary item may be stored in your browser to save your selection in the cookie or service notice. This is used to remember your decision and avoid showing the notice again on every page view.
External content is loaded only when needed and after your consent. The booking system itself is part of the website; an enabled external payment provider is used only if you select a corresponding payment method.
8. Privacy-friendly reach statistics
To improve the content, we use our own privacy-friendly reach statistics. Only aggregated daily values for public pages are stored. We do not store IP addresses, complete user agents, cookies, URL parameters or personal profiles. Private areas such as the guest portal, offer links, admin area, API, calendar feeds and files are excluded from the statistics.
Where activated, the system records the public page viewed, the date, a device category, a shortened language setting and the referrer domain or access channel. Do Not Track and Global Privacy Control signals are respected.
The processing is based on Art. 6(1)(f) GDPR. Our legitimate interest is the technical and content-related optimisation of the website. The data is automatically deleted after the configured retention period.
We do not use external analytics or marketing services such as Google Analytics, Meta Pixel or comparable tracking services.
9. External fonts, maps and media
The current website project is designed so that no external fonts are loaded. Maps, videos or other external media should only be embedded if integrated in a privacy-compliant way and, where required, blocked in advance by a service notice.
10. Storage period
We store personal data only as long as necessary for the respective purpose or as required by statutory retention obligations.
Enquiries are deleted once they have been fully processed and no statutory retention obligations prevent deletion. Booking and billing data may be stored for longer due to tax and commercial-law retention obligations.
A published retention policy controls rule-based deletion and anonymisation. In particular, it provides for deletion of registration, communication, offer and access data and anonymisation of booking and review data that is no longer required. Invoices and payment records remain available to the extent required by statutory retention duties. Active legal holds may temporarily prevent deletion.
11. Your rights
Subject to the legal requirements, you have the following rights: access to your stored data, rectification of inaccurate data, erasure, restriction of processing, data portability, objection to certain processing operations and withdrawal of consent with effect for the future.
You can contact us at any time to exercise your rights.
12. Right to complain to a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates data protection law.
The competent authority is generally the supervisory authority of your usual place of residence, workplace or the place of the alleged infringement.
13. SSL/TLS encryption
For security reasons, this website should be delivered exclusively via encrypted HTTPS. You can recognise an encrypted connection by “https://” in your browser’s address bar.
14. Changes to this privacy policy
We reserve the right to adapt this privacy policy if the website, services used or legal requirements change.
Status: August 2026