1. Controller
The controller responsible for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:
Nordsee-Hotel GmbH
Rheinstraße 63
27570 Bremerhaven
Germany
Phone: +4947362509980
Email: info@hotel-butjadingen.de
Represented by the managing directors:
Marija Krajnovic and Janina Strelow
2. General Information
The protection of your personal data is very important to us. We treat your personal data confidentially and in accordance with statutory data protection regulations, in particular the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and the Telecommunications Digital Services Data Protection Act (TDDDG).
Personal data means any information relating to an identified or identifiable natural person.
3. Accessing Our Website
When you visit our website, information is automatically processed by the hosting provider.
This includes in particular:
- IP address
- Date and time of access
- Browser type and browser version
- Operating system
- Referrer URL
- Pages accessed
- Amount of data transferred
- HTTP status code
This data is used exclusively to ensure the secure and trouble-free operation of the website and for IT security purposes.
The legal basis is Art. 6 para. 1 lit. f GDPR.
4. Hosting
Our website is hosted by the following service provider:
goneo Internet GmbH
Dresdener Straße 18
32423 Minden
Germany
Processing is carried out on the basis of a data processing agreement pursuant to Art. 28 GDPR.
5. SSL/TLS Encryption
For security reasons, our website uses SSL/TLS encryption. This protects transmitted data from access by unauthorized third parties.
6. Cookies
Our website uses technically necessary cookies.
If cookies are used beyond this that are not required for the operation of the website, they are used only with your consent via the cookie banner in place.
Legal bases:
- Art. 6 para. 1 lit. a GDPR
- Art. 6 para. 1 lit. f GDPR
- Section 25 TDDDG
7. Contact Form and Contacting Us
If you contact us via the contact form or by email, we process the data you provide.
This includes in particular:
- Name
- Personal data
- Email address
- Telephone number, if provided
- Content of your message
Processing is carried out exclusively for the purpose of handling your inquiry.
Legal basis:
Art. 6 para. 1 lit. b GDPR and Art. 6 para. 1 lit. f GDPR.
8. Bookings via Our Website
For direct bookings, we use the booking platform RoomRaccoon.
When making a booking, the following data in particular may be processed:
- Name
- Address
- Email address
- Telephone number
- Booking details
- Period of stay
- Room category
- Number of guests
- Special requests
- Payment information
- Invoice data
Processing is carried out for the performance of the accommodation contract.
Legal basis:
Art. 6 para. 1 lit. b GDPR.
9. Use of RoomRaccoon
For the management of our hotel operations, we use the cloud-based property management system (PMS) RoomRaccoon.
This includes in particular:
- Booking management
- Online booking engine
- Channel management
- Reservation management
- Guest management
- Communication with guests
- Online check-in
- Invoicing
- Payment processing
- Management of the stay
When using this system, personal data may be processed insofar as this is necessary for the performance of the accommodation contract.
Processing is carried out on the basis of Art. 6 para. 1 lit. b GDPR.
RoomRaccoon provides further information in its own privacy policy.
10. Bookings via Booking.com
If you book our accommodation via Booking.com, we receive the personal data required to carry out your stay from Booking.com.
This includes in particular:
- Name
- Contact details
- Booking information
- Stay details
- Payment status
- Messages
This data is processed exclusively for the purpose of carrying out your stay.
Booking.com also processes personal data under its own responsibility under data protection law.
Legal basis:
Art. 6 para. 1 lit. b GDPR.
11. Bookings via Airbnb
If your booking is made via Airbnb, we receive the personal data required for your stay from Airbnb.
This includes in particular:
- Name
- Contact details
- Stay details
- Booking information
- Messages
- Payment status
Processing is carried out exclusively for the performance of the accommodation contract.
Airbnb also processes personal data under its own responsibility under data protection law.
Legal basis:
Art. 6 para. 1 lit. b GDPR.
12. Payment Processing via Adyen
For online payments, we use the payment service provider Adyen.
When making a payment, the following data in particular may be processed:
- Name
- Payment information
- Invoice data
- Transaction data
- Booking reference
Processing is carried out exclusively for the purpose of processing the payment.
Legal basis:
Art. 6 para. 1 lit. b GDPR.
Adyen processes personal data in connection with payment processing in accordance with the applicable data protection provisions.
13. Digital Locking System NUKI
For digital access to our rooms, we use the electronic locking system NUKI.
Where necessary, the following data in particular may be processed:
- Name
- Room assignment
- Validity period of the digital key
- Technical access information
Processing is carried out exclusively for the purpose of carrying out your stay and managing access authorizations.
Legal basis:
Art. 6 para. 1 lit. b GDPR and Art. 6 para. 1 lit. f GDPR.
14. Google Maps
Google Maps is integrated into our website in order to display our location.
When the map is accessed, personal data, in particular your IP address, may be transmitted to Google.
Legal basis:
Art. 6 para. 1 lit. a GDPR.
15. Guest Wi-Fi
During your stay, we provide you with guest Wi-Fi.
In this context, technical connection data in particular may be processed insofar as this is necessary to provide the Wi-Fi, ensure network security, and fulfill legal obligations.
Legal basis:
Art. 6 para. 1 lit. b GDPR and Art. 6 para. 1 lit. f GDPR.
16. Statutory Retention Obligations
We store personal data only for as long as is necessary to fulfill statutory or contractual obligations.
In particular, tax and commercial law retention obligations apply.
After the expiry of the statutory periods, the data will be deleted unless there are further legal grounds for storage.
17. Recipients of Personal Data
Recipients of personal data may include in particular:
- Hosting service providers
- RoomRaccoon
- Adyen
- Booking.com
- Airbnb
- Employees
- IT service providers
- Tax advisors
- Authorities, where legally required
- Other bodies and persons connected with the operation of the business
Data is disclosed only to the extent necessary.
18. Your Rights
You have the following rights in particular:
- Right of access
- Right to rectification
- Right to deletion
- Right to restriction of processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent given, with effect for the future
To exercise your rights, simply send a message to:
19. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data.
20. Obligation to Provide Personal Data
The provision of personal data is partly required by law or contract, or necessary for the conclusion and performance of an accommodation contract.
Without this data, we may not be able to carry out your booking or your stay.
21. Automated Decision-Making
No exclusively automated decision-making, including profiling pursuant to Art. 22 GDPR, takes place.
22. Collection and Transmission of Data for the Guest Contribution
Where a guest contribution, spa tax, or tourist tax is payable on the basis of statutory or municipal regulations, we are obliged to collect the personal data required for this purpose from our guests and transmit it to the competent authority.
The data processed may include in particular:
- First and last name
- Address
- Date of birth
- Arrival and departure date
- Number of accompanying persons
- Information on possible discounts or exemptions
- Further information required under the applicable statutes
The data is collected as part of the booking or check-in process. The data is automatically transmitted via the reporting system SAS AVS used by us to the competent municipality for the assessment and administration of the guest contribution.
Processing is carried out to fulfill a legal obligation pursuant to Art. 6 para. 1 lit. c GDPR in conjunction with the applicable municipal regulations on the collection of the guest contribution and, where applicable, registration law provisions.
The provision of the data required for this purpose is legally mandatory. Without this information, we cannot comply with our legal obligations and may not be able to properly process the stay.
The data is stored only for as long as is necessary to fulfill the legal obligations and applicable retention periods.
23. Changes to This Privacy Policy
We reserve the right to amend this privacy policy if this becomes necessary due to legal changes or technical developments.
Version: July 2026