How we handle your data.
Please note: This is a translation. The legally binding version is the German original.
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Schinberg Impex GmbH (Aparthotel Tannenhof)
Managing Director: Daniyar Shintassov
Badstraße 42
79410 Badenweiler, Germany
E-mail: info@relax-tannenhof.de
No data protection officer has been appointed, as there is no legal obligation to do so.
This website is an information site and does not store any form entries. Without your consent, it sets no cookies – only your choice in the cookie banner is stored. Only if you select “Accept all” in the banner do we use Google Analytics 4 and Google Ads conversion tracking (see section 10). Personal data is also processed insofar as this is technically necessary to operate the website, when you contact us, or when you use third-party content or services (e.g. the map, online booking). We explain the individual processing operations below.
We process personal data on the basis of Art. 6(1) GDPR, in particular:
This website is hosted by: ALL-INKL.COM – Neue Medien Münnich, owner René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany.
When you access the website, the web server automatically records information transmitted by your browser in so-called server log files: IP address, date and time of access, page/file accessed, amount of data transferred, referrer URL, browser type and version, and operating system. This data is technically necessary to display the website and to ensure its stability and security (Art. 6(1)(f) GDPR). It is not combined with other data sources. IP addresses are stored in the log files only in shortened form: the last two blocks are removed (e.g. 11.22.33.44 → 11.22.0.0). The log files are automatically deleted after 7 days.
We have concluded a data processing agreement with the host in accordance with Art. 28 GDPR.
For security reasons, this website uses SSL/TLS encryption. You can recognise an encrypted connection by “https://” and the padlock symbol in your browser’s address bar.
For a consistent appearance, we use the fonts “Inter” and “Merriweather” (and additionally “Noto Sans Arabic” and “Noto Naskh Arabic” on the Arabic language version) from Google Fonts. The fonts are stored locally on our web server and are loaded from there when you access a page. No connection to Google’s servers is established; no data is transmitted to Google and no cookies are set.
Retrieving the font files only generates the server log files with our host described in section 4. The legal basis is Art. 6(1)(f) GDPR (consistent, easily readable presentation). The fonts are licensed under the SIL Open Font License.
On our contact page, you can choose to display a map from Google Maps (provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). The map is not loaded automatically (two-click solution): at first you only see a placeholder, and no data is transmitted to Google before you click. Only when you click “Load map” is the map loaded from Google’s servers. Data such as your IP address, date/time and the page accessed is then transmitted to Google; Google may set cookies and may also process the data in the USA. We have no influence over this processing.
We use Google Maps to show you our location and directions clearly. The legal basis is your consent, which you give by clicking “Load map” (Art. 6(1)(a) GDPR and § 25(1) TDDDG); it applies only to the respective page view and is not stored. The “Open in Google Maps” link leads directly to Google Maps, where Google’s privacy policy applies. Google LLC is certified under the EU-US Data Privacy Framework. Details: policies.google.com/privacy.
If you write to us by e-mail, we process the data you provide (e.g. name, e-mail address, travel dates, message) in order to answer your enquiry. The contact form on this website does not transmit any data to our server: when you submit it, your own e-mail program simply opens with a pre-filled message, which you send yourself.
The legal basis is Art. 6(1)(b) GDPR if your enquiry relates to a booking, and otherwise Art. 6(1)(f) GDPR. We use Gmail (Google Ireland Limited) for our e-mail inbox; e-mails are therefore stored on Google’s servers. We delete enquiries as soon as they have been dealt with, provided there are no statutory retention obligations to the contrary.
Our booking buttons lead to the booking page booking.roomraccoon.de. This is operated by RoomRaccoon B.V., Keizerstraat 15, 4811 HL Breda, the Netherlands, which acts for us as a hotel software and booking service provider. When you make a booking, the data processed there includes in particular your name, contact details, address, travel dates, number of guests, payment information and, where applicable, the information required for the registration obligation.
Payment data: Online payments in the RoomRaccoon booking form are handled via RaccoonPay, technically provided by Adyen N.V., Simon Carmiggeltstraat 6-50, 1011 DJ Amsterdam, the Netherlands. You enter your card details directly with this payment service provider, and they remain with this provider. We ourselves do not receive or store any payment card data – we only receive the payout of the booking amount. The respective provider is responsible for processing the payment data; we have no access to complete card data.
Insofar as RoomRaccoon processes booking data on our behalf, this is done on the basis of a data processing agreement (Art. 28 GDPR). RoomRaccoon is itself responsible for the technical operation of the booking page; RoomRaccoon’s privacy policy, which is available on the booking page, applies in addition. Legal bases: Art. 6(1)(b) GDPR (booking) and Art. 6(1)(c) GDPR (registration obligation, tax retention).
On your first visit, we ask you in a banner whether you allow analytics and advertising cookies (“Accept all”) or only want to use the technically necessary functions (“Necessary only”). We store your choice in your browser’s local storage (entry fewo_consent: choice and time) so that the banner does not appear on every page view; after 12 months we ask again. This storage is technically necessary (§ 25(2) no. 2 TDDDG; Art. 6(1)(c) in conjunction with Art. 7(1) GDPR). You can change your choice at any time via the “Cookie settings” link in the footer of every page.
The Google tag (gtag.js) is only loaded after you have selected “Accept all”. Before that, no connection to Google Analytics or Google Ads is established and no data is transmitted to these services. We use Google’s Consent Mode v2 to pass your consent decision (analytics_storage, ad_storage, ad_user_data, ad_personalization) on to Google.
With your consent, we use Google Analytics 4 on this website and on the booking page. This allows us to analyse how our pages are used (e.g. pages viewed, time spent, clicks on “Book now”, completed bookings, approximate location, device/browser). Google Analytics 4 does not store IP addresses. So that a visit that starts here and ends on booking.roomraccoon.de is recognised as a single visit, we use cross-domain measurement: links to the booking page then receive an additional parameter (_gl). Cookies: _ga and _ga_<ID> (duration up to 2 years).
We advertise with Google Ads (tag ID AW-971800995). With your consent, we measure whether visitors who arrive via one of our ads go on to book: after a completed booking, a conversion is transmitted to Google on the confirmation page (booking value, currency, booking number). This enables us to measure the success of our ads. Cookie: _gcl_au (duration 90 days); Google may also use its own cookies on Google domains.
The provider of both services is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; data may be transferred to Google LLC in the USA. Google LLC is certified under the EU-US Data Privacy Framework (adequacy decision of the European Commission, Art. 45 GDPR). Processing takes place exclusively with your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). You can withdraw your consent at any time with effect for the future – via the “Cookie settings” link in the footer of every page (select “Necessary only”); the Google cookies of this website are then deleted. On the booking page, its own cookie settings apply in addition. Further information: How Google uses data from partner sites, Google privacy policy, Google ad settings.
If you book via portals such as Booking.com or Airbnb, the respective portal operator is itself responsible for data processing on its platform. We receive from the portal the data required to carry out your stay (Art. 6(1)(b) and (c) GDPR).
Payment is handled by the respective portal (e.g. Booking.com, Airbnb, Agoda): you enter your card details directly there, and they remain with the portal or its payment service provider. We do not receive or store any payment card data; the portal simply transfers the payment amount to us, usually after your departure. The respective provider is responsible for processing the payment data; we have no access to complete card data.
We only store personal data for as long as is necessary for the respective purpose. We retain booking and invoice data in accordance with the statutory retention periods (in particular § 147 AO (German Fiscal Code), § 257 HGB (German Commercial Code)). Registration data is retained for one year from the day of departure in accordance with § 30(4) of the Federal Registration Act and destroyed within three months thereafter. We delete enquiries that do not result in a booking as soon as they have been dealt with.
Your data is only passed on to third parties insofar as this is necessary to perform the contract (e.g. to our cleaning team, booking and payment service providers), we are legally obliged to do so (e.g. to authorities), or this is expressly provided for in our terms and conditions (e.g. § 4.4 and § 8.4 of the terms and conditions).
You have the right at any time to:
An informal message to info@relax-tannenhof.de is sufficient.
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW)
Lautenschlagerstraße 20, 70173 Stuttgart
www.baden-wuerttemberg.datenschutz.de
No automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place.
We update this privacy policy when the website or the legal requirements change. The version published here at any given time applies. You will also find information on cookies in our cookie policy.
Last updated: October 2026