Privacy Policy

Information on data protection

The use of this website may be associated with the processing of personal data. In order for you to be able to understand these processing operations, we would like to provide you with the following information to give you an overview of these processing operations. In order to guarantee fair processing, we would also like to inform you about your rights under the European Data Protection Basic Regulation (DSGVO) and the Federal Data Protection Act (BDSG).
Responsible for data processing is Esfand GmbH (hostel name: Rixhouse), Richardstraße 1, 12043 Berlin (hereinafter referred to as “we” or “us”).

table of contents

 

1. General information
a. Contact
b. General information on data processing
c. Duration of storage
d. Technical service provider
e. Data transmission to the USA

2. Processing of server log files

3. Contact options and inquiries

4. Booking / reservation
a. Data processing for booking/reservation
b. Payment by Paypal

5. Data transmission by booking.com

6. Cookies

7. Analysis about ViK Booking

8. Integrated services and contents of third parties

9. Processing in the exercise of your rights pursuant to Art. 15 to 22 DSGVO

10. Your rights

11. Right of objection

 

1. General information

 

a. Contact

If you have any questions or suggestions regarding this information or if you would like to contact us about asserting your rights, please contact us at
Esfand GmbH
Richardstraße 1, 12043 Berlin
Tel.: * 49 (0)30 68085757
E-Mail: rixhouseberlin@gmail.com

b. General information on data processing

When using this website, personal data may be processed. The data protection term “personal data” refers to all information relating to a specific or identifiable individual. The IP address can also be a personal date. An IP address is assigned to each device connected to the Internet by the Internet provider so that it can send and receive data. When you use the Site, we collect information that you yourself provide. In addition, certain information about your use of the website by us is automatically collected during your visit to the website.
We process personal data in compliance with the relevant data protection regulations, in particular the DSGVO and the BDSG. A data processing by us takes place only on the basis of a legal permission. When using this website, we process personal data to fulfil a contract to which you are a party, or at your request to carry out pre-contractual measures (Art. 6 Para. 1 Letter b) DSGVO), to fulfil a legal obligation (Art. 6 Para. 1 DSGVO), to fulfil a legal obligation (Art. 6 Para. 1 DSGVO) or to fulfil a legal obligation (Art. 6 Para. 1 DSGVO). c) DSGVO) or if the processing is necessary to protect our legitimate interests or the legitimate interests of a third party, unless your interests or fundamental rights and freedoms, which require the protection of personal data, prevail (Art. 6 Para. 1 S letter f) DSGVO).

c. Duration of storage

Unless otherwise stated in the following notices, we shall only store the data for as long as is necessary to achieve the purpose of processing or to fulfil our contractual or statutory obligations.
Such storage periods result in particular from tax and commercial law regulations. From the end of the calendar year in which the data was collected, we will retain such personal data contained in our accounting data for ten years and retain personal data contained in commercial letters and contracts for six years. In addition, we will retain personal data, in particular complaint and claim data, for a maximum of four years from the end of the respective process. We will delete data stored for advertising purposes if you object to the processing for this purpose.

d. Technical Service Provider

Unless otherwise stated in the following notices, the data will be processed on the servers of technical service providers commissioned by us for this purpose. These service providers process the data only according to express instructions and are contractually obliged to guarantee sufficient technical and organisational measures for data protection.

e. Data transfer to the USA

Visiting our website may involve the transfer of certain personal data to the USA. For the transfer of data to the USA as a third country, i.e. a country in which the DSGVO is not applicable law, the European Commission has decided in accordance with Art. 45 DSGVO that an adequate level of data protection is required for companies certified under the EU-US Privacy Shield. The transmission to the USA is then carried out in a permissible manner.

2. Processing of server log files

For the purely informative use of our website, general information is initially stored automatically (i.e. not via registration), which your browser transmits to our server. This includes by default: browser type/version, operating system used, page accessed, previously visited page (referrer URL), IP address, date and time of the server request and HTTP status code.
The processing is carried out to safeguard our legitimate interests and is based on the legal basis of Art. 6 Para. 1 Letter f) DSGVO. This processing serves the technical administration and security of the website. The stored data will be deleted after seven days unless there is a justified suspicion of illegal use on the basis of concrete indications and further examination and processing of the information is necessary for this reason.
We are not in a position to identify you as the person concerned on the basis of the stored information. Art. 15 to 22 DSGVO therefore do not apply pursuant to Art. 11 para. 2 DSGVO, unless you provide additional information to enable identification in order to exercise the rights set out in these articles.

3. Security plugin ithemes-SecurityPro

We use the security plugin ithemes-SecruityPro. This tool compares the IP addresses used with black lists in order to avoid hack attacks. This processing serves our legitimate interest in the technical protection of our website and is based on the legal basis of Art. 6 para. 1 letter f) DSGVO.

4. Contact options and enquiries

Our website contains a contact form via which you can send us messages. The transfer of your data is encrypted (recognizable by the “https” in the address bar of the browser). All data fields marked as mandatory fields are required to process your request. Failure to do so will result in us being unable to process your request. The provision of further data is voluntary. Alternatively, you can also send us a message via the contact e-mail.
We process the data for the purpose of answering your inquiry. If your request is aimed at the conclusion or execution of a contract with us, Art. 6 Para. 1 Letter b) DSGVO is the legal basis for data processing. Otherwise, we process the data due to our legitimate interest in contacting inquiring persons. The legal basis for data processing is then Art. 6 Para. 1 Letter f) DSGVO.

5. Booking/Reservation

 

a. Data processing for booking/reservation

If you make a booking or reservation via our website, we process personal data exclusively for the purpose of contract processing or to enable us to execute your booking or reservation. Within the framework of the booking or reservation process, we only process the data that you have entered yourself in the input mask and, if applicable, payment information if you pay in advance by bank transfer. The legal basis for the processing is Art. 6 Para. 1 Letter b) DSGVO. All data fields marked as mandatory fields are required for processing your booking or order. Failure to do so will result in us being unable to process your booking or order. The provision of further data is voluntary.

b. Payment by Paypal

Furthermore you have the possibility to pay by Paypal. Please note that the relevant payment information is collected and processed by PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg. Paypal will send us your address data stored with Paypal, which we process exclusively for contract processing. Legal basis is Art. 6 Para. 1 Letter b) DSGVO.
Further information on data protection at Paypal can be found at: https://www.paypal.com/en/webapps/mpp/ua/privacy-full?locale.x=en_GB#r5
 
6. DATA TRANSMISSION BY BOOKING.COM
If you have made a booking with us via the booking.com service, booking.com will transmit the following data to us: first name, surname, country, address, duty: telephone number, email address, amount of the booking, booking ID of Booking.com and confirmation ID of Booking.com and the information as to whether at booking.com a registered user or guest user is.
We process this data to process your booking. The legal basis for the processing is Art. 6 Para. 1 Letter b) DSGVO.
Further information on data protection at booking.com can be found at https://www.booking.com/content/privacy.de.html?label=gen173nr-1FCAEoggI46AdIM1gEaDuIAQGYAQe4ARfIAQ_YAQHoAQH4AQuIAgGoAgO4Aunp4-MF;sid=d7594ee1ec917a6c3559c924a7a37957.

7. Cookies

We use cookies on our website. Cookies are small text files that are stored by your browser when you visit a website. This identifies the browser used and can be recognised by our web server. If this use of cookies results in the processing of personal data, this is based on the legal basis of Art. 6 Para. 1 Letter f) DSGVO. This processing serves our legitimate interest in making our website more user-friendly, effective and secure.
We used so-called “session cookies”, which are deleted when the browser session is closed. Other cookies (“persistent cookies”) are automatically deleted after a specified period of time, which may vary depending on the cookie.
You can delete the cookies at any time in the security settings of your browser. You can object to the use of cookies through your browser settings in principle or in certain cases. The Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) can provide you with further information on this at https://www.bsi-fuer-buerger.de/BSIFB/DE/Empfehlungen/EinrichtungSoftware/EinrichtungBrowser/Sicherheitsmassnahmen/Cookies/cookies_node.html.

8. Analysis of ViK Booking

We use the WordPress Vik Booking plugin to manage the bookings we receive. With this tool we can statistically evaluate the bookings. We do not process your name, but only information about the period of your bookings and certain geoinformation. Here we cannot draw any conclusions about a specific address. The IP address used is not processed.
The purpose of this processing is to statistically evaluate our bookings with regard to the booking periods and the location of the person making the booking. This serves to safeguard our legitimate interest in receiving statistical information about our business operations. The processing is therefore based on the legal basis of Art. 6 Para. 1 Letter f) DSGVO.

9. integrated services and contents of third parties

We use services, services and contents provided on our website by third parties (hereinafter collectively referred to as “contents”). For such an integration a processing of your IP address is technically necessary, so that the contents can be sent to your browser. Your IP address will therefore be transmitted to the respective third party providers. These data processing operations are carried out to safeguard our legitimate interests in the optimisation and economic operation of our website and are based on the legal basis of Art. 6 Para. 1 Letter f) DSGVO. You can object to this data processing at any time via the settings of the browser used or certain browser extensions. One such extension is the uMatrix matrix-based firewall for the Firefox and Google Chrome browsers. Please note that this may result in functional limitations on the website.

We have incorporated into our website content from the following third-party services:

– Google Ireland Limited (Ireland/EU) services:

“Google Maps” for map display;
“Google Web Fonts” for font display.

When using Google services, we cannot exclude the possibility that the processed data may be transmitted by us to Google LLC, which is based in the USA. The Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) is certified under the EU-US Privacy Shield (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active).

– The Gravatar service of Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA; “Automattic”) to display profile pictures in our blog. Automattic is certified under the EU-US Privacy Shield (https://www.privacyshield.gov/participant?id=a2zt0000000CbqcAAC&status=Active).

– The Font Awesome service from Fonticons, Inc. (6 Porter Road, Apartment 3R, Cambridge, MA 02140) for the display of icons and fonts.

10. Processing in the exercise of your rights under Art. 15 to 22 DSGVO

If you exercise your rights under Art. 12 to 22 DSGVO, we process the personal data transmitted for the purpose of the implementation of these rights by us and to provide evidence thereof.
We will only process data stored for the purpose of providing information and preparing the same for this purpose as well as for the purposes of data protection control and otherwise restrict processing in accordance with Art. 18 DSGVO.
These processes are based on the legal basis of Art. 6 Para. 1 Letter. c) DSGVO in connection with Art. 15 to 22 DSGVO and § 34 para. 2 BDSG.

11. your rights

As a person concerned you have the right to assert your rights against us. You have the following rights under the DSGVO:

  • You have the right under Art. 15 DSGVO and § 34 BDSG to request information as to whether and to what extent we process personal data about you. You can exercise this right directly on our website.
  • You have the right, according to Art. 16 DSGVO, to demand that we correct your data.
  • You have the right, according to Art. 17 DSGVO and § 35 BDSG, to demand that we delete your personal data.
  • You have the right, according to Art. 18 DSGVO, to restrict the processing of your personal data.
  • You have the right, in accordance with Art. 20 DSGVO, to receive the personal data concerning you that you have provided to us in a structured, common and machine-readable format and to forward this data to another responsible person.
  • Insofar as YOU have given us a separate consent to data processing, you can revoke this consent at any time in accordance with Art. 7 para. 3 DSGVO. Such a revocation does not affect the lawfulness of the processing, which has taken place until the revocation on the basis of the consent.

If you are of the opinion that the processing of your personal data violates the provisions of the DSGVO, you have to inform us in accordance with Art. 7 para. 3 of the DSGVO. 77 DSGVO you have the right to lodge a complaint with a supervisory authority.

12. Pursuant

To Art. 21 para. 1 DSGVO you have the right to object to processing based on the legal basis of Art. 6 para. 1 letter e) or f) DSGVO for reasons arising from your particular situation. If personal data about you is processed by us for the purpose of direct marketing, you may object to such processing pursuant to Art. 21 Para. 2 and Para. 3 DSGVO.

Stand: March 2019

Rixhouse Hostel
Richardstraße 1
12043 Berlin
Email: info@rixhouse.de
Phone: +49 (0) 30 68 08 57 57