The controller responsible for processing your personal data within the meaning of the General Data Protection Regulation (GDPR) is
Bright Sight GmbH, Virchowstrasse 17a, 90409 Nuremberg, Germany, commercial register Amtsgericht Nürnberg HRB 36664 (referred to below as „we"). Our legal representatives are named in the legal notice on the website of the relevant property.
1.2
This notice applies to the properties Astoria Apartments (Weidenkellerstraße 4, 90443 Nuremberg), Lorenz Apartments (Pfannenschmiedsgasse 4, 90402 Nuremberg) and Brunnen Apartments (Brunnengasse 47 and 42, 90402 Nuremberg).
1.3
Our Data Protection Officer is Daniel Schneiderbanger. You can reach him at the address above, marked for the attention of the Data Protection Officer, or through the contact form on the website of the relevant property.
1.4
This notice describes how we process data in connection with a booking and a stay. When you visit our websites, the privacy policy published there applies in addition; it covers cookies, audience measurement and contact forms.
2. Booking and Performance of the Stay
2.1
When you book with us, we process the details required for the accommodation contract: first and last name, address, e-mail address, telephone number, country, preferred language, dates of stay, number and age of travelling persons, services booked, special requests and details of the method of payment. If you indicate a business booking, we also process the company name and billing address.
2.2
The legal basis is Article 6(1)(b) GDPR, because the processing is necessary to perform the contract and to take steps prior to entering into it.
2.3
This data is stored in our property management system. The provider of that system processes it solely on our behalf and on the basis of a data processing agreement.
2.4
If you voluntarily provide information we do not need for the stay (such as the reason for your trip, preferences regarding the apartment, or a note about an intolerance), we process it in order to meet your request. The legal basis is Article 6(1)(b) GDPR; for health-related information it is solely your explicit consent under Article 9(2)(a) GDPR, which you may withdraw at any time with effect for the future.
2.5
You are not obliged to provide us with data. However, without the details listed in section 2.1 we cannot conclude or perform an accommodation contract, and without the details listed in section 6 we cannot comply with a statutory obligation.
3. Bookings Through Booking Platforms
3.1
If you book through a platform such as Booking.com, Airbnb or Expedia, we do not collect your data ourselves but receive it from that platform. What is transmitted is usually your name, the dates of stay, the service booked, the number of persons, the country, an e-mail address (often a forwarding address assigned by the platform) and, depending on the platform, a telephone number.
3.2
We process this data in order to perform the accommodation contract concluded with you. The legal basis is Article 6(1)(b) GDPR. This section also serves as our information under Article 14 GDPR regarding data not obtained from you directly.
3.3
The platforms are themselves responsible under data protection law for their own processing. The privacy notices of the relevant platform apply to the data you provide there and to communication within the platform.
3.4
To distribute availability and bookings between our system and the platforms we use a channel manager, and for bookings through individual platforms a specialised management service. Both process data on our behalf.
4. Payment Processing
4.1
We use payment service providers to process payments, to store and secure card details and to issue refunds. For older transactions and individual recurring settlements, a previously used provider may still be involved. The payment providers are connected through our property management system.
4.2
We process the method of payment, card details in tokenised form, the amount, the time, the booking reference and the result of the authorisation. Full card details are not available to us; they are processed and stored by the payment providers.
4.3
The legal basis is Article 6(1)(b) GDPR for processing the payment, Article 6(1)(c) GDPR for the statutory retention of accounting records, and Article 6(1)(f) GDPR for protecting against non-payment and for pursuing claims under the accommodation contract.
4.4
The payment providers process some data under their own responsibility, for instance to meet their own regulatory obligations and to prevent fraud. Details can be found in their privacy notices.
5. Arrival, Check-in and Access
5.1
Our properties operate without a permanently staffed reception. Before your arrival we send you the arrival information and the access details for the building and your apartment. For this we process your name, e-mail address, dates of stay and the apartment assigned to you. If we cannot reach you by e-mail, or if your arrival is imminent, we send the information by SMS to the telephone number you provided.
5.2
For automated dispatch we use an automation service and for SMS delivery a specialised messaging provider. Both process the necessary data on our behalf.
5.3
The legal basis is Article 6(1)(b) GDPR, because providing the access details is a necessary part of the accommodation service.
5.4
Access to the building and the apartment is granted through an electronic locking system and time-limited access codes. For this purpose the system holds only the apartment and the period for which an access right applies. Your name, your contact details and your booking data are not stored in it.
5.5
The legal basis is Article 6(1)(b) GDPR, because granting the access right is part of the accommodation service. No monitoring of conduct or attendance takes place.
6. Reporting Obligation Under the German Federal Registration Act
6.1
We are required by law to fulfil specific reporting obligations when accommodating guests (Sections 29 and 30 of the German Federal Registration Act, Bundesmeldegesetz). For this purpose we process the dates of arrival and departure, first and last names, date of birth, nationality, address, the number of accompanying persons and your signature.
6.2
For guests who are not German nationals we also process the type of identity document presented, its number and the issuing state. We ask to see the document; we do not make a copy of it.
6.3
The legal basis is Article 6(1)(c) GDPR in conjunction with the provisions named above. Providing this data is required by law. Without it we are not permitted to accommodate you.
6.4
Registration forms are stored separately. Only those staff who need access in order to fulfil the reporting obligation have it. We provide information to security and law enforcement authorities to the extent that they are legally entitled to it.
7. Communication During and After Your Stay
7.1
We process your correspondence with us, whether by e-mail, through a booking platform, by telephone or by message, in order to deal with your request. For this we use a shared guest mailbox with a provider of e-mail and office services. The legal basis is Article 6(1)(b) GDPR, or Article 6(1)(f) GDPR for enquiries outside an existing contract, based on our legitimate interest in answering enquiries and keeping a record of the matter.
7.2
To run the properties we use an internal task management tool, where tasks relating to cleaning, maintenance and repairs are recorded by apartment. Guest names are not displayed there.
7.3
After your stay we may ask you for a review. The legal basis is Article 6(1)(f) GDPR, based on our legitimate interest in improving what we offer, and, where we contact you by e-mail, Section 7(3) of the German Act Against Unfair Competition (UWG). You may object to being contacted at any time, at no cost other than the transmission costs at base rates. For this we use a review management provider acting on our behalf.
7.4
For advertising by e-mail that goes beyond section 7.3, such as a newsletter, we process your data only with your consent under Article 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future, for example using the unsubscribe link in every message.
8. Invoices, Accounting and Tax
8.1
We issue invoices and process the data they contain in our accounting. For this we use accounting software and work with a tax advisory firm, which is responsible for its own processing under professional and data protection law.
8.2
The legal basis is Article 6(1)(b) GDPR for billing the service and Article 6(1)(c) GDPR in conjunction with the retention obligations under commercial and tax law (Section 147 of the German Fiscal Code, Section 257 of the German Commercial Code).
9. Video Surveillance
9.1
Video surveillance is in operation in the entrance and common areas of some properties. The apartments themselves and their immediate entrances are not monitored. The monitored areas are marked with signs on site.
9.2
The purpose is to protect people, to prevent and investigate criminal offences and damage to property, and to safeguard our property and that of our guests. The legal basis is Article 6(1)(f) GDPR.
9.3
Recordings are automatically deleted after 48 hours. A recording is kept for longer only where it is needed in an individual case to investigate a specific incident or to establish, exercise or defend legal claims. In that case the relevant sequence is secured separately and deleted as soon as the purpose no longer applies.
9.4
Only individuals expressly designated for this task have access to the recordings. Recordings are disclosed only to law enforcement authorities, insurers or injured parties, and only where this is necessary to investigate an incident and legally permitted.
10. Wi-Fi
10.1
We provide Wi-Fi at our properties. In operating the network, the network components process technical connection data, in particular the identifier of the connected device (MAC address), the time and duration of the connection and the access point used.
10.2
The purpose is to provide and operate the network, to detect and resolve faults and to prevent misuse. The legal basis is Article 6(1)(b) GDPR for providing the network and Article 6(1)(f) GDPR for its operation and security.
10.3
We do not analyse this data in order to trace the behaviour of individuals, and we do not create movement or usage profiles from it.
11. Recipients of Your Data
11.1
Within our company, access is given only to those individuals who need it for the relevant purpose, for example in guest services, property operations or accounting.
11.2
Outside our company we disclose data to the following categories of recipient:
a)
Service providers processing on our behalf and on our instructions (processing under Article 28 GDPR), in particular the providers of our property management system, channel manager, guest and access technology, communication and automation services, review platform, and IT, hosting and maintenance providers.
b)
Payment service providers and credit institutions, for the processing of payments.
c)
Tax advisors and auditors, within the scope of their statutory duties.
d)
Public authorities, where we are legally obliged or entitled to provide information, in particular under the reporting obligation.
e)
Lawyers, courts, insurers and debt collection providers, where this is necessary to establish or defend legal claims.
f)
Booking platforms, where the booking was made through them and communication runs through their system.
11.3
We will tell you on request which companies fall within these categories. We do not name them publicly, because the systems we use also serve the security of our properties and our guests.
11.4
We do not sell your data and do not pass it on for third-party advertising purposes.
12. Processing Outside the European Union
12.1
Some of the service providers we use are based outside the European Economic Area, or use sub-processors there, in particular in the United States.
12.2
A transfer takes place only where the requirements of Articles 44 et seq. GDPR are met, that is on the basis of an adequacy decision of the European Commission, such as the EU-US Data Privacy Framework for recipients certified under it, or on the basis of the European Commission's standard contractual clauses under Article 46(2)(c) GDPR together with supplementary safeguards.
12.3
Despite these safeguards, access by state authorities in third countries cannot be entirely ruled out and the level of protection may not correspond in every respect to that within the European Union. We will provide you with a copy of the relevant safeguards on request.
13. Retention Periods
13.1
We store personal data only for as long as it is needed for the relevant purpose or as long as we are legally required to retain it. After that it is deleted or anonymised. The following periods apply:
Data
Period
Booking and stay data
3 years from the end of the year in which the stay ended
Invoices, payment records and accounting documents
8 years from the end of the year of issue (Section 147 AO, Section 257 HGB)
Registration forms
1 year, then destroyed within 3 months (Section 30(4) BMG)
Video recordings
48 hours, then automatically deleted
Guest correspondence
3 years from the end of the year in which the matter was closed
Data used for newsletter dispatch
until consent is withdrawn
13.2
The three-year period corresponds to the standard limitation period under Sections 195 and 199 of the German Civil Code and serves to defend against and pursue claims under the accommodation contract. Where data has to be kept longer to meet a statutory retention obligation, it is blocked for all other purposes and held solely to meet that obligation.
14. Your Rights
14.1
You have the right to obtain information about the data we hold about you (Article 15 GDPR), to have inaccurate data corrected (Article 16 GDPR), to erasure (Article 17 GDPR), to restriction of processing (Article 18 GDPR) and to data portability (Article 20 GDPR).
14.2
Right to object: You have the right, on grounds relating to your particular situation, to object at any time to processing that we base on Article 6(1)(f) GDPR (Article 21(1) GDPR). We will then stop processing the data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless the processing serves to establish, exercise or defend legal claims.
14.3
Objection to direct marketing: You may object at any time, without giving reasons, to the processing of your data for direct marketing purposes (Article 21(2) GDPR). We will then no longer use your data for that purpose.
14.4
Where you have consented to processing, you may withdraw your consent at any time with effect for the future (Article 7(3) GDPR). This does not affect the lawfulness of processing carried out before the withdrawal.
14.5
A message to the contact details given in section 1 is sufficient to exercise your rights. We will respond without undue delay and at the latest within one month. Where there is doubt about your identity, we may request additional information to confirm it.
15. Right to Lodge a Complaint
15.1
Without prejudice to any other remedy, you have the right to lodge a complaint with a data protection supervisory authority (Article 77 GDPR), in particular in the Member State of your residence, place of work or the place of the alleged infringement.
15.2
The authority responsible for us is the Bavarian Data Protection Authority, Bayerisches Landesamt für Datenschutzaufsicht, Promenade 18, 91522 Ansbach, Germany.
16. No Automated Decision-Making, and Changes to This Notice
16.1
Automated decision-making, including profiling, within the meaning of Article 22 GDPR does not take place.
16.2
We update this notice when our processing or the legal requirements change. The version available on our websites applies. The current version date is shown above.