Opens in a new tab

Privacy Policy

1. Introduction

Thank you for your interest in our website www.h24hotels.com (hereinafter “Website”). It is operated by H24 Hotel Management GmbH (hereinafter “H24 Hotels”) and offers you as a user (hereinafter “User”) the opportunity to find out about our hotel offers, room categories and locations, to make bookings and to get in touch with us.

The protection of your personal data is very important to us. We treat your data confidentially and in accordance with the applicable data protection laws, in particular the General Data Protection Regulation (GDPR). Below we inform you about the nature, scope and purpose of the processing of personal data and about your rights.

You can revoke any consent you have given at any time with effect for the future. If you have any questions about the processing of your data, please contact us.

Please note that changes in the law or changes to our internal processes may make it necessary to adapt this privacy policy. The current version can be viewed at any time at www.h24hotels.com/en/privacy-policy.

Further privacy notices:

In addition to this privacy policy for our website, you will find further information on the processing of personal data in the following areas:

These contain specific information on data processing outside the use of the website. Please refer to them separately if required.

2. Controller and scope

Controller within the meaning of the GDPR:

H24 Hotel Management GmbH
Herzbergstraße 139

10365 Berlin
Phone: +49 3338 914 1658
Email: [email protected]
Web: www.h24hotels.com

This privacy policy applies to the website www.h24hotels.com and to its subpages and subdomains operated by H24 Hotel Management GmbH.

3. Data protection officer

You can contact our data protection officer at: [email protected]

4. Principles of data processing

Personal data is any information relating to an identified or identifiable natural person, e.g. name, address, telephone number, IP address or usage behaviour. Data that has been anonymised or can only be attributed to a person with disproportionate effort is not considered personal data.

Your data is processed either on the basis of statutory provisions or on the basis of your consent. The data is deleted as soon as it is no longer required for the respective purpose and there are no statutory retention obligations to the contrary.

In this privacy policy we inform you in detail below about the individual processing operations, their purpose, legal basis and storage period.

5. Provision and use of the website

a. Hosting

This website is hosted externally. The personal data collected on this website is stored on the servers of the hosting provider named below. This includes in particular:

  • IP addresses
  • Contact requests
  • Meta and communication data
  • Contract data
  • Contact details
  • Names
  • Website access
  • Other data generated through the use of the website

Hosting is carried out for the purpose of fulfilling contracts with our potential and existing customers (Art. 6(1)(b) GDPR) and in the interest of a secure, fast and efficient provision of our online offering by a professional provider (Art. 6(1)(f) GDPR). If consent has been requested (e.g. via a cookie banner), processing is based exclusively on Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG (German Telecommunications Digital Services Data Protection Act). Consent can be revoked at any time.

Our host only processes your data to the extent necessary to fulfil its service obligations and follows our instructions in accordance with a data processing agreement required under data protection law (Art. 28 GDPR).

Hosting provider used:
IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany

The servers are located in a data centre in Germany (Berlin). We have concluded a data processing agreement with IONOS in accordance with Art. 28 GDPR.

b. Access data and log files

When you visit our website, we automatically collect certain personal data that your browser transmits to our server. This data is technically necessary for us to display the website to you and to ensure its stability and security:

  • IP address of the requesting computer
  • Date and time of access
  • Name and URL of the file accessed
  • Website from which access is made (referrer URL)
  • Browser used and, if applicable, the operating system of your computer
  • Name of your access provider

The data is stored temporarily in log files and automatically deleted after 30 days at the latest. This server log data is not merged with other data sources, nor is it evaluated in relation to individuals. The log files are used exclusively for technical analysis in the event of errors and to ensure the proper operation of the website.

Legal basis:

  • Art. 6(1)(f) GDPR: our legitimate interest in a secure and stable presentation of the website.

c. Cloudflare

We use the “Cloudflare” service. The provider is Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA (hereinafter “Cloudflare”).

Cloudflare offers a globally distributed content delivery network with DNS. Technically, the transfer of information between your browser and our website is routed through Cloudflare’s network. This enables Cloudflare to analyse the data traffic between your browser and our website and to act as a filter between our servers and potentially malicious data traffic from the internet. Cloudflare may also use cookies or other technologies to recognise internet users, but these are used solely for the purpose described here.

The use of Cloudflare is based on our legitimate interest in providing our website as error-free and securely as possible (Art. 6(1)(f) GDPR).

Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details and further information on security and data protection at Cloudflare can be found here: https://www.cloudflare.com/privacypolicy/.

The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards when data is processed in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/5666.

6. Reservations and bookings

On our website www.h24hotels.com we offer you the option of booking hotel rooms online. For this purpose we use the booking platform of HotelNetSolutions GmbH, Genthiner Straße 8, 10785 Berlin, Germany.

When you click on the “Book” button and select a location, you will be redirected to an external booking page on which the booking process for the respective location is integrated.

The technical processing of this booking is carried out on behalf of the operating company of the respective location by HotelNetSolutions GmbH as a processor in accordance with Art. 28 GDPR.

You will find the responsible operating company and its contact details in the legal notice of the respective booking page or in the booking confirmation you receive after your reservation.

In particular, the following personal data is processed during the booking process:

  • First and last name
  • Salutation and title, if applicable
  • Address (street, postcode, town, country)
  • Telephone number
  • Email address
  • Period of stay (arrival, departure)
  • Booked room category and additional services
  • Payment data (e.g. credit card data, payment status)
  • Company affiliation, if applicable
  • Individual comments, if applicable (e.g. allergies, requests)

Payment processing

Depending on the payment method selected, payment is processed via one of the following service providers:

  • Adyen N.V., Simon Carmiggeltstraat 6-50, 1011 DJ Amsterdam, Netherlands
  • PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg

Only the information required to carry out the payment is transmitted to these providers, including the booking amount, payment data and, if applicable, the IP address.

H24 Hotels itself does not store any complete payment information (e.g. credit card numbers) but only receives information on the payment status.

Processing is carried out exclusively for the performance of the contract on the basis of Art. 6(1)(b) GDPR.

The payment service providers act independently as controllers under data protection law. For further information on data processing, please refer to their respective privacy policies:

The data is processed to handle the booking, to carry out your stay and for invoicing.

Storage period

Your data will be deleted once the booking has been fully processed and the statutory retention periods have expired.
Typical retention periods:

  • 6 years for business correspondence (Section 257 German Commercial Code, HGB)
  • 10 years for tax-relevant documents (Section 147 German Fiscal Code, AO)

Legal bases for processing

  • Art. 6(1)(b) GDPR: to carry out pre-contractual measures and to fulfil the accommodation contract
  • Art. 6(1)(f) GDPR: our legitimate interest in efficient booking processing
  • Art. 6(1)(a) GDPR: if consent is given for optional information (e.g. allergies, requests) or for marketing purposes

Information on processing on our behalf

HotelNetSolutions GmbH acts on our behalf and processes your data exclusively in accordance with our instructions.
A corresponding data processing agreement in accordance with Art. 28 GDPR has been concluded.

The technical infrastructure of the booking pages is provided by HotelNetSolutions GmbH.
Responsibility under data protection law for the processing of your booking data lies with the operating company of the location you have selected.

H24 Hotel Management GmbH is responsible for the overall technical platform, but not for the independent processing of the booking data of individual locations.

Note on the privacy information

The respective controller provides the required privacy information directly within the booking form.
Please therefore take note of the information displayed there when making your booking.

7. Contact form, email contact and applications

If you contact us via a contact form on the website or by email, we process the personal data you provide in order to handle your enquiry.

In particular, the following data may be processed:

  • First and last name
  • Email address
  • Telephone number (if provided)
  • Content of your message
  • Date and time of transmission, if applicable
  • IP address (for forms)

The data is processed exclusively to handle and answer your enquiry. It will not be passed on to third parties without your express consent.

Legal bases for processing:

  • Art. 6(1)(b) GDPR: if the enquiry serves to carry out pre-contractual measures,
  • Art. 6(1)(f) GDPR: our legitimate interest in effective communication with users of the website.

Once your enquiry has been fully processed, the data will be deleted unless there are statutory retention obligations or you have expressly consented to further use.

Data transmitted via the contact form is encrypted using TLS. Please note that complete data security cannot be guaranteed when transmitting data by email. For confidential information we therefore recommend an alternative, secure form of transmission, e.g. by post or encrypted communication.

Applications

You can apply to us via the application form on our website. In doing so, we process the information you send us, in particular your name, contact details, cover letter, CV and references. The data is stored on our server and forwarded to the persons responsible for the application process. It is used exclusively to carry out the application process.

The legal basis is Art. 6(1)(b) GDPR (initiation of an employment relationship). If you are hired, the data will be transferred to your personnel file. Otherwise, we will delete your application documents no later than six months after the end of the application process, unless you have expressly consented to longer storage, for example for a talent pool.

8. Live chat

On our website we provide a live chat function that allows you to communicate with our team in real time. The live chat is provided by the service provider chatlyn, Renngasse 4 R4-4, 1010 Vienna, Austria.

When you use the live chat, the following personal data is processed:

  • Content of the chat messages
  • Date and time of the chat
  • IP address
  • Browser and device type used
  • Your email address or name, if provided voluntarily

This data is processed exclusively for the purpose of answering your enquiries and communicating with you.

Legal bases for processing:

The chat widget is only loaded if you have given your consent in our cookie banner. The legal basis is your consent in accordance with Art. 6(1)(a) GDPR and Section 25(1) TDDDG, which you can revoke at any time via the privacy settings. Insofar as your enquiry serves to prepare a contract, such as a booking, processing is additionally based on Art. 6(1)(b) GDPR.

So that a conversation that has been started can be continued, chatlyn stores an identifier in your browser (cookie “cw_conversation”, storage period up to 1 year). The data is stored on servers in Frankfurt am Main, Germany. chatlyn uses sub-processors, including OpenAI and Zapier, which are based in the USA. The transfer to the USA is safeguarded by standard contractual clauses of the EU Commission.

chatlyn is a processor within the meaning of Art. 28 GDPR.

9. Cookies and consent management

Our website uses so-called “cookies” and similar technologies (e.g. pixels, web storage) to provide certain functions, to analyse usage and, where applicable, to display personalised content.

General information on cookies:

Cookies are small data packets that are stored on your device either temporarily for the duration of a session (session cookies) or permanently (persistent cookies). Session cookies are deleted automatically at the end of your visit. Persistent cookies remain on your device until you delete them manually or your browser does so automatically.

Cookies can either be set by us (first-party cookies) or originate from third-party companies (third-party cookies). The latter enable, for example, the integration of external services such as payment providers or analysis tools.

Types of cookies:

  • Technically necessary cookies: required for the operation of the website (e.g. language selection, security, shopping cart function)
  • Statistics cookies: help us to understand how our website is used
  • Marketing cookies: enable the display of interest-based advertising
  • Functional cookies: enable embedded content such as maps, videos and the live chat

Legal bases for processing:

  • Art. 6(1)(f) GDPR for technically necessary cookies: legitimate interest in a functioning website
  • Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG for all non-necessary cookies: consent via the cookie banner

Your settings:

You can manage your cookie settings via our cookie banner (consent tool). In addition, your browser allows you to control cookies individually, delete them or prevent them from being set altogether. If cookies are deactivated, the functionality of our website may be restricted.

Use of Real Cookie Banner:

Our website uses the consent technology of Real Cookie Banner to obtain your consent to the storage of certain cookies on your device or to the use of certain technologies and to document this in compliance with data protection law. The provider of this technology is devowl.io GmbH, Tannet 12, 94539 Grafling, Germany (hereinafter “Real Cookie Banner”).

Real Cookie Banner is installed locally on our servers, so no connection is established to the servers of the provider of Real Cookie Banner. Real Cookie Banner stores a cookie in your browser in order to be able to assign the consents you have given or their revocation to you. The data collected in this way is stored until you ask us to delete it, delete the Real Cookie Banner cookie yourself or the purpose for storing the data no longer applies. Mandatory statutory retention obligations remain unaffected.

Real Cookie Banner is used to obtain the legally required consent for the use of cookies. The legal basis for this is Art. 6(1)(c) GDPR.

For Google services we use Google Consent Mode. Our cookie banner informs the Google services which purposes you have consented to. Google then only stores cookies and processes data to the extent of your consent.

10. Tracking and analysis tools

In order to better understand user behaviour on our website and to continuously improve our offering, we use tracking and analysis tools. These tools help us to statistically evaluate, for example, the number of visits, time spent on the website, pages accessed or navigation on the website.

a. Google Tag Manager

We use Google Tag Manager, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Tag Manager is used exclusively to manage and integrate tracking tools and other services. Google Tag Manager itself does not process any personal data. However, your IP address may be collected and transmitted to Google servers in the USA.

Further information on international data transfers can be found in the section “Data transfers to third countries / USA”.

It is used on the basis of Art. 6(1)(f) GDPR, our legitimate interest in the simple integration of tools. If consent has been requested, processing is based exclusively on Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG. Consent can be revoked at any time.

Google is certified under the EU-US Data Privacy Framework (DPF):

https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active

b. Google Analytics

This website uses Google Analytics to analyse user behaviour. The provider is also Google Ireland Limited, Dublin, Ireland.

Among other things, Google Analytics collects the following information:

  • Page views and time spent on pages
  • Origin of the user (referrer)
  • Operating system and device used
  • Mouse movements, clicks and scrolling behaviour

Google uses cookies and other technologies (e.g. device fingerprinting) to recognise users. Google also uses modelling approaches and machine learning to evaluate usage behaviour.

The information is usually transmitted to servers in the USA. The transfer is based on the standard contractual clauses of the EU Commission. Google is also DPF certified.

Further information on international data transfers can be found in the section “Data transfers to third countries / USA”.

Legal basis:

  • Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG: your consent via the cookie banner.

Right to object:

You can prevent the collection of your data by Google Analytics at any time:

Further information:

https://support.google.com/analytics/answer/6004245?hl=en

https://privacy.google.com/businesses/controllerterms/mccs/

https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active

c. Google Ads

The website operator uses Google Ads. Google Ads is an online advertising programme of Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Ads enables us to display advertisements in the Google search engine or on third-party websites when the user enters certain search terms on Google (keyword targeting). Targeted advertisements can also be displayed on the basis of user data available to Google (e.g. location data and interests) (target group targeting). As the website operator, we can evaluate this data quantitatively, for example by analysing which search terms led to our advertisements being displayed and how many advertisements led to corresponding clicks.

We also use Google Ads conversion tracking to find out whether visitors make a booking or an enquiry after clicking on one of our ads, as well as remarketing to show visitors to our website suitable ads on other websites. Google sets cookies for this purpose. Google Ads is only loaded if you have consented to the Marketing category in the cookie banner.

This service is used on the basis of your consent in accordance with Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent can be revoked at any time.

Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://policies.google.com/privacy/frameworks and https://business.safety.google/controllerterms/.

The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards when data is processed in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.

11. Plugins and tools

General note on embedded content

Please note: Simply loading embedded content (e.g. map services, social media feeds or plugins) can result in technical information being transmitted to third-party platforms, even without any action on your part. This includes in particular your IP address, device type, browser used and, where applicable, cookies. This data processing is the sole responsibility of the respective platform operator under data protection law.
For further information, please refer to the sections on the individual services.

a. Google Fonts (local hosting)

Our website uses so-called Google Fonts, provided by Google, for the uniform display of fonts. The Google Fonts are installed locally on our server. No connection to Google servers is established in the process.

Further information on Google Fonts can be found at: https://developers.google.com/fonts/faq

Google’s privacy policy:

https://policies.google.com/privacy?hl=en

b. Google Maps

This website uses the map service Google Maps. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

To use the functions of Google Maps, it is necessary to store your IP address. This is usually transferred to a Google server in the USA. If Google Maps is activated, Google may also load Google Fonts for the purpose of displaying fonts uniformly.

Further information on international data transfers can be found in the section “Data transfers to third countries / USA”.

Legal bases:

  • Art. 6(1)(f) GDPR: legitimate interest in an appealing presentation of our online offering and in making our locations easy to find
  • Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG: if consent has been given for loading content

Google is certified under the EU-US Data Privacy Framework. Further information:

https://privacy.google.com/businesses/gdprcontrollerterms

https://policies.google.com/privacy?hl=en

https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active

The general information on embedded content applies (see above).

c. Vimeo

This website uses plugins of the video portal Vimeo. The provider is Vimeo Inc., 555 West 18th Street, New York, New York 10011, USA.

When you visit one of our pages featuring a Vimeo video, a connection to the Vimeo servers is established. The Vimeo server is informed which of our pages you have visited. Vimeo also obtains your IP address. This also applies if you are not logged in to Vimeo or do not have a Vimeo account. The information collected by Vimeo is transmitted to the Vimeo server in the USA.

If you are logged in to your Vimeo account, you enable Vimeo to assign your surfing behaviour directly to your personal profile. You can prevent this by logging out of your Vimeo account.

Vimeo uses cookies or comparable recognition technologies (e.g. device fingerprinting) to recognise website visitors. Vimeo is used in the interest of an appealing presentation of our online offering. This constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR. If consent has been requested, processing is based exclusively on Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user’s device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.

According to Vimeo, data transfer to the USA is based on the standard contractual clauses of the EU Commission and on “legitimate business interests”. Details can be found here:
https://vimeo.com/privacy.

Further information on the handling of user data can be found in Vimeo’s privacy policy at: https://vimeo.com/privacy.

The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards when data is processed in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information can be obtained from the provider at the following link:
https://www.dataprivacyframework.gov/participant/5711.

d. Meta Pixel (formerly Facebook Pixel)

This website uses Meta’s visitor action pixel for conversion measurement. The provider of this service is Meta Platforms Ireland Limited, Merrion Road Dublin 4, Dublin, D04 X2K5, Ireland. According to Meta, however, the data collected is also transferred to the USA and other third countries.

This allows the behaviour of page visitors to be tracked after they have been redirected to the provider’s website by clicking on a Meta advertisement. This enables the effectiveness of Meta advertisements to be evaluated for statistical and market research purposes and future advertising measures to be optimised.

The data collected is anonymous for us as the operator of this website; we cannot draw any conclusions about the identity of the users. However, the data is stored and processed by Meta, so that a connection to the respective user profile on Facebook or Instagram is possible and Meta can use the data for its own advertising purposes in accordance with the Meta data usage policy (https://www.facebook.com/about/privacy/). This enables Meta to place advertisements on Facebook or Instagram pages and other advertising channels. We as the site operator have no influence on this use of the data.

This service is used on the basis of your consent in accordance with Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent can be revoked at any time.

We use the advanced matching function within the Meta Pixel.

Advanced matching enables us to transmit various types of data (e.g. place of residence, federal state, postcode, hashed email addresses, names, gender, date of birth or telephone number) of our customers and prospective customers that we collect via our website to Meta. This allows us to tailor our advertising campaigns on Facebook and Instagram even more precisely to people who are interested in our offers. Advanced matching also improves the attribution of website conversions and extends custom audiences.

Insofar as personal data is collected on our website with the help of the tool described here and forwarded to Meta, we and Meta Platforms Ireland Limited, Merrion Road Dublin 4, Dublin, D04 X2K5, Ireland are jointly responsible for this data processing (Art. 26 GDPR). The joint responsibility is limited exclusively to the collection of the data and its transfer to Meta. The processing by Meta that takes place after the transfer is not part of the joint responsibility. The obligations incumbent on us jointly have been set out in a joint processing agreement. The wording of the agreement can be found at:
https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing the privacy information when using the Meta tool and for the secure implementation of the tool on our website in terms of data protection law. Meta is responsible for the data security of Meta products. You can assert data subject rights (e.g. requests for information) regarding the data processed by Facebook or Instagram directly with Meta. If you assert data subject rights with us, we are obliged to forward them to Meta.

Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here:
https://www.facebook.com/legal/EU_data_transfer_addendum and https://www.facebook.com/help/566994660333381.

Further information on protecting your privacy can be found in Meta’s privacy policy:
https://www.facebook.com/about/privacy/.

You can also deactivate the remarketing function “Custom Audiences” in the ad settings section at https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen. To do this, you must be logged in to Facebook.

If you do not have a Facebook or Instagram account, you can deactivate usage-based advertising by Meta on the website of the European Interactive Digital Advertising Alliance:
https://www.youronlinechoices.com/uk/your-ad-choices/.

The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards when data is processed in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information can be obtained from the provider at the following link:
https://www.dataprivacyframework.gov/participant/4452.

e. Links to social networks

At the bottom of the page you will find simple links to our profiles on Instagram and TikTok. No data is transmitted through these links themselves. Only when you click on a link do you leave our website, and the privacy policy of the respective network applies.
Privacy at Instagram: https://privacycenter.instagram.com/policy
Privacy at TikTok: https://www.tiktok.com/legal/page/eea/privacy-policy/

f. OpenStreetMap

We use the map service of OpenStreetMap (OSM).

We integrate the map material of OpenStreetMap on the server of the OpenStreetMap Foundation, St John’s Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom. The United Kingdom is considered a safe third country under data protection law. This means that the United Kingdom has a level of data protection that corresponds to the level of data protection in the European Union. When you use OpenStreetMap maps, a connection to the servers of the OpenStreetMap Foundation is established.
In the process, your IP address and other information about your behaviour on this website may be forwarded to the OSMF. For this purpose, OpenStreetMap may store cookies in your browser or use comparable recognition technologies.

OpenStreetMap is used in the interest of an appealing presentation of our online offering and to make the locations we indicate on the website easy to find. This constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR. If consent has been requested, processing is based exclusively on Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user’s device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.

Note on external content:

Embedding social media content and map services may result in third-party providers collecting data from you, even if you do not actively interact with the plugin. These data transfers are the sole responsibility of the respective providers. H24 Hotels has no influence on the scope, content or storage period of data processing by third-party platforms.

12. Links to external providers

In our online magazine at https://h24hotels.com/magazin/ (in German) we occasionally link to content and offers from third-party providers (e.g. external articles, recommendations or partner sites). When you click on such links, you leave our website. From this point on, data is processed by the respective third-party provider, over which we have no influence.

Please note that only the privacy policies of the respective third-party providers apply to this external content. We recommend that you find out there how your personal data is handled.

13. Newsletter

If you subscribe to our newsletter, we use your email address to regularly send you information about offers, news and relevant content relating to H24 Hotels.

For sending we use a double opt-in procedure that complies with data protection law: after registering, you will receive an email with a confirmation link. Your registration only becomes effective once you have clicked on this link. Your consent is logged in the process.

Data processed:

  • Email address
  • IP address at the time of registration
  • Date and time of registration and confirmation

Legal basis:

  • Art. 6(1)(a) GDPR: your express consent

You can revoke your consent at any time with effect for the future, e.g. via the unsubscribe link in the newsletter or by notifying us directly.

For sending we use a specialised service provider with whom a data processing agreement in accordance with Art. 28 GDPR has been concluded. Data is processed exclusively within the EU.

14. Data transfers to third countries / USA

This section supplements the information in the sections on Google, Meta, Vimeo, Cloudflare and other US service providers.

Some of the services used on our website are provided by companies based outside the European Union or the European Economic Area, in particular in the USA (e.g. Google, Meta). The use of these services may therefore involve the transfer of personal data to so-called third countries.

Since 10 July 2023, there has been an adequacy decision by the European Commission for the USA under the EU-U.S. Data Privacy Framework (DPF). Companies such as Google and Meta have joined this framework and thus offer an adequate level of data protection within the meaning of Art. 45 GDPR.

Data is therefore transferred to these certified providers on the basis of this adequacy decision. Information on certification can be found at:

https://www.dataprivacyframework.gov/s/participant-search

If a provider is not certified, we base the transfer on standard contractual clauses of the EU Commission in accordance with Art. 46(2)(c) GDPR, supplemented by additional safeguards (e.g. encryption, pseudonymisation), in order to ensure an adequate level of protection.

15. Your rights as a data subject

As a data subject within the meaning of the GDPR, you have the following rights in connection with the processing of your personal data by us:

Access (Art. 15 GDPR):

You have the right to request information as to whether and which personal data we process about you. This includes, among other things, information on the purposes of processing, the categories of personal data, the recipients and the planned storage period.

Rectification (Art. 16 GDPR):

You have the right to request the immediate rectification of inaccurate personal data or the completion of incomplete personal data.

Erasure (Art. 17 GDPR):

You have the right to request the erasure of your personal data, provided that there are no statutory retention obligations or other legitimate grounds preventing erasure.

Restriction of processing (Art. 18 GDPR):

You can request the restriction of the processing of your personal data if, for example, you dispute the accuracy of the data or the processing is unlawful.

Data portability (Art. 20 GDPR):

You have the right to receive your personal data in a structured, commonly used and machine-readable format or to request its transfer to another controller.

Objection (Art. 21 GDPR):

If we process your data on the basis of a legitimate interest, you have the right to object to the processing on grounds relating to your particular situation.

Revocation of consent (Art. 7(3) GDPR):

You can revoke any consent you have given at any time with effect for the future. Processing carried out up to that point remains lawful.

Right to lodge a complaint with a supervisory authority (Art. 77 GDPR):

You have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, your place of work or the place of the alleged infringement.

An informal message to us is sufficient to exercise your rights. Our contact details can be found in the site notice and at the beginning of this privacy policy.

16. Right to object

If we process your personal data on the basis of legitimate interests in accordance with Art. 6(1)(f) GDPR, you have the right to object to the processing at any time on grounds relating to your particular situation. This also applies to profiling based on this provision.

If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

If your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing. This also applies to profiling insofar as it is related to such direct marketing.

After your objection, your personal data will no longer be processed for direct marketing purposes.

The objection can be made informally and should preferably be sent to the contact details given above.

17. Data security and technical safeguards

We take appropriate technical and organisational security measures to protect your personal data against loss, misuse, unauthorised access, disclosure, alteration or destruction.

These include, among other things:

  • encrypted transmission of data via our website using TLS/SSL encryption (recognisable by “https://” in the address bar of your browser),
  • access restrictions and controls at server and database level,
  • regular security updates and system checks,
  • raising awareness and training employees on data protection and IT security,
  • concluding data processing agreements with external service providers.

Please note that data transmission over the internet (e.g. when communicating by email) may have security gaps. Complete protection of data against access by third parties is not possible. We therefore recommend that you transmit particularly confidential information by secure means (e.g. by post or encrypted data transfer).

18. Changes to this privacy policy

Due to further developments of our website, the technologies used, changes in legal requirements or official requirements, it may become necessary to amend this privacy policy. The current version of the privacy policy is available at any time at www.h24hotels.com/en/privacy-policy.

We recommend that you regularly inform yourself about the current status of our privacy policy.
Last updated: October 2026