Privacy Ploicy

Last updated: February 2026

1. Data Controller

The data controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws, as well as other data protection regulations, is:

Carl.22 GmbH & Co. KG

represented by the general partner FCH Management GmbH

Managing Director: Sandro Felber

Karlsplatz 22, 99817 Eisenach

Telephone: +49 (0) 3691 8193300

Email: hello@carl22.de | Website: www.carl22.de

Commercial Register: HRA 505220, Jena Local Court | VAT No.: DE328391321

2. Overview of data processing

We operate a website at carl22.de to showcase and facilitate bookings for our boutique apartments in Eisenach. In addition, we process personal data in the course of our accommodation business, in particular in relation to booking processing, digital check-in, payment processing, security deposit processing, the payment of the tourism promotion levy and the fulfilment of statutory reporting obligations. This privacy policy informs you, in accordance with Articles 13 and 14 of the GDPR, about the nature, scope and purpose of the processing of personal data.

2.1 Types of data processed

In particular, we process the following categories of personal data: Master data (e.g. name, address, nationality), contact details (e.g. email address, telephone number), identification data (e.g. passport number and nationality for foreign guests in accordance with the Federal Registration Act), booking and contract data (e.g. travel dates, choice of apartment, choice of rate, payment information), check-in data (e.g. personal details of all guests, arrival time), access data (e.g. timestamps of access system usage), payment data (e.g. credit card authorisations, PayPal transactions), usage data (e.g. pages visited, access times) and meta and communication data (e.g. IP addresses, device information).

2.2 Legal bases

The processing of personal data is always carried out on a legal basis. Where we obtain consent for processing operations, Article 6(1)(a) of the GDPR serves as the legal basis. For processing carried out to fulfil contractual obligations (e.g. booking processing, check-in, payment processing, collection of security deposits), Article 6(1)(b) of the GDPR applies. Processing carried out to fulfil legal obligations (e.g. registration forms for foreign guests in accordance with the Federal Ministry of the Interior, tax retention obligations, payment of the tourism promotion levy) is based on Article 6(1)(c) of the GDPR. Where processing is necessary to safeguard our legitimate interests, we rely on Article 6(1)(f) of the GDPR.

3. Your rights as a data subject

You have the following rights in relation to your personal data:

Right of access (Art. 15 GDPR): You may request access to your personal data held by us.

Right to rectification (Art. 16 GDPR): You may request the rectification of inaccurate data.

Right to erasure (Art. 17 GDPR): You may request the erasure of your data, provided that there are no statutory retention obligations preventing this.

Right to restriction of processing (Art. 18 GDPR): Under certain conditions, you may request that the processing of your data be restricted.

Right to data portability (Art. 20 GDPR): You may request to receive your data in a structured, commonly used and machine-readable format.

Right to object (Art. 21 GDPR): You may object to the processing of your data at any time, in particular where such processing is based on legitimate interests or is carried out for the purposes of direct marketing.

Right to withdraw consent (Article 7(3) of the GDPR): You may withdraw any consent you have given at any time with effect for the future.

Right to lodge a complaint with a supervisory authority (Article 77 of the GDPR): You have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority responsible for us is:

Thuringian State Commissioner for Data Protection and Freedom of Information (TLfDI), Häßlerstraße 8, 99096 Erfurt | https://www.tlfdi.de

4. SSL or TLS encryption

This website uses SSL or TLS encryption for security reasons and to protect the transmission of personal data.

5. Hosting

Our website is hosted by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. When you visit our website, IONOS automatically collects information in so-called server log files, which your browser transmits automatically. This includes, in particular: IP address, date and time of access, page/file accessed, referrer URL, browser and operating system used, and the host name of the accessing computer.

Processing is carried out on the basis of our legitimate interest in the secure and efficient provision of our website in accordance with Article 6(1)(f) of the GDPR. We have entered into a data processing agreement with IONOS in accordance with Article 28 of the GDPR. The servers are located in Germany.

6. Cookies and Consent Management

6.1 Cookies

Our website uses cookies. Some cookies are technically necessary for the website to function. Other cookies are used for analysis or optimisation and are only set with your consent. You can configure your browser to allow cookies on a case-by-case basis or to block them altogether. Disabling cookies may restrict the functionality of this website.

6.2 Real Cookie Banner (Consent Management)

We use Real Cookie Banner as a Consent Management Platform (CMP) to obtain and manage your consent to the storage of cookies and to data processing by third-party providers. Your consent decision is stored in a cookie on your device. The legal basis is Article 6(1)(c) of the GDPR and Article 6(1)(f) of the GDPR.

7. Booking system (Smartpms)

We use the booking system provided by Smartness Srl, Via Parteli 19, 38068 Rovereto, Trento, Italy, to book our apartments. You can check availability and make bookings via a booking widget embedded on our website.

When you make a booking, the following data in particular is processed: name, email address, telephone number, postal address, travel dates, number of guests, payment details and, where applicable, any special requests.

Data processing is carried out on the basis of Article 6(1)(b) of the GDPR. As Smartness is based in Italy, data is transferred to a third country. This transfer is covered by the EU Commission’s adequacy decision for Italy.

Bookings received via external platforms such as Booking.com, Airbnb and Expedia/Vrbo are also processed via Smartpms. The privacy policies of these platforms also apply to bookings made via them.

Further information: https://www.iubenda.com/app/privacy-policy/50108679/legal

8. Digital check-in and registration requirements

8.1 Digital check-in

Digital check-in via our online system is mandatory prior to arrival. The following data, in particular, is collected: full name, address, email address, telephone number, the number of travelling companions and their personal details, and time of arrival.

Data processing is carried out on the basis of Article 6(1)(b) of the GDPR (performance of a contract). The data will be stored for the duration of your stay and subsequently in accordance with statutory retention obligations.

8.2 Registration form for foreign guests

Guests who are not German nationals are obliged, in accordance with Sections 29 and 30 of the Federal Registration Act (BMG), to complete a registration form on the day of arrival and to sign it by hand. In doing so, their nationality and the details of their identity document (passport or passport substitute) are also collected.

Processing is carried out on the basis of Article 6(1)(c) of the GDPR (legal obligation). The registration forms are retained for 12 months and destroyed or deleted no later than a further 3 months thereafter. The registration forms may be accessed by police authorities, public prosecutors’ offices, courts, prison authorities, the customs investigation service, main customs offices and tax authorities engaged in criminal prosecution.

8.3 Tourism Promotion Levy

The City of Eisenach levies a tourism promotion levy on all guests aged 18 and over. In order to pay this levy, we forward the necessary data (name, period of stay, number of people) to the relevant department of the City of Eisenach.

Processing is carried out on the basis of Article 6(1)(c) of the GDPR (legal obligation to collect and pay municipal levies).

9. Access system

We use an electronic access system to grant guests access to the apartment following successful check-in. In doing so, technical data such as timestamps of access usage may be processed.

Processing is carried out on the basis of Article 6(1)(b) of the GDPR (performance of a contract) and Article 6(1)(f) of the GDPR (legitimate interest in building security). The data will be deleted after the guest’s departure, provided that no legitimate interests (e.g. investigation of damage) preclude earlier deletion.

10. Payment processing

We offer the following payment methods: credit card, PayPal and, in certain cases, prepayment/bank transfer.

When paying by credit card, your payment details are processed via the Smartpms system. We do not store any full credit card details ourselves.

When paying via PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg, you will be redirected to the PayPal website. PayPal processes your payment details in accordance with its own privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full

The processing of payment data is carried out on the basis of Article 6(1)(b) of the GDPR (performance of a contract).

10.1 Credit card pre-authorisation (security deposit)

Where a security deposit is charged in accordance with our Terms and Conditions, this is done via credit card pre-authorisation. This involves reserving an amount on the guest’s credit card as security, without the card actually being charged. The pre-authorisation will be released immediately following the proper handover of the apartment.

Processing is carried out on the basis of Article 6(1)(b) of the GDPR (performance of a contract and security agreement).

11. Contacting us

If you contact us by email, telephone or WhatsApp, we will store your details, including the contact details you have provided, in order to process your enquiry.

This processing is carried out on the basis of Article 6(1)(b) of the GDPR (pre-contractual measures or performance of a contract) or Article 6(1)(f) of the GDPR (legitimate interest in responding to enquiries). Your data will be deleted as soon as your enquiry has been fully processed and there are no statutory retention obligations preventing this.

11.1 WhatsApp

We offer the option of contacting us via WhatsApp (Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland). Please note that WhatsApp gains access to the address book on the device used and processes communication metadata. This may involve the transfer of data to the USA. This is based on the EU-US Data Privacy Framework. Use is based on your consent in accordance with Article 6(1)(a) of the GDPR.

WhatsApp’s privacy policy: https://www.whatsapp.com/legal/privacy-policy-eea

12. Web analytics

12.1 Google Analytics 4

We use Google Analytics 4, a web analytics service provided by Google Ireland Limited. Google Analytics uses cookies and similar technologies. By default, Google Analytics 4 no longer uses full IP addresses. IP anonymisation takes place at the collection stage. Data may be transferred to the USA; this is based on the EU-US Data Privacy Framework.

Use of this service is subject exclusively to your consent in accordance with Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TTDSG.

Further information: https://policies.google.com/privacy | Opt-out: https://tools.google.com/dlpage/gaoptout

12.2 Jetpack Stats (WordPress.com Stats)

Our website uses Jetpack Stats from Automattic Inc., San Francisco, USA. Jetpack Stats uses a tracking pixel and, where applicable, cookies. This is based on your consent in accordance with Article 6(1)(a) of the GDPR. Data transfers to the USA are carried out on the basis of the EU-US Data Privacy Framework.

Automattic’s privacy policy: https://automattic.com/privacy/

13. Other Google Services

13.1 Google Maps

We integrate the Google Maps mapping service, provided by Google Ireland Limited, into our website. When you access the relevant pages, a connection is established with Google’s servers. This integration is based on your consent in accordance with Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TTDSG.

13.2 Google Fonts

Our website uses Google Fonts to ensure consistent font display. The fonts are stored locally on our server. No connection is established with Google’s servers in this process.

13.3 Google Reviews Widget

We integrate a widget to display Google reviews. This integration is based on your consent in accordance with Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TTDSG.

14. Other integrated third-party services

14.1 Gravatar

We use the Gravatar service provided by Automattic Inc. to display user avatars. This is based on your consent in accordance with Article 6(1)(a) of the GDPR.

14.2 WordPress.org CDN

Our website uses the Content Delivery Network (CDN) provided by WordPress.org. This is based on our legitimate interest in accordance with Article 6(1)(f) of the GDPR.

14.3 Jetpack Notifications

We use Jetpack Notifications from Automattic Inc. for internal notifications. This is based on our legitimate interest in accordance with Article 6(1)(f) of the GDPR.

15. Social media presence

We maintain an online presence on Facebook and Instagram (Meta Platforms Ireland Limited). When you visit our social media profiles, data is processed by the platform operator. We process the data of users who communicate with us via social media on the basis of Article 6(1)(f) of the GDPR.

With regard to the data processing carried out by Meta on our Facebook and Instagram pages, we are jointly responsible with Meta Platforms Ireland Limited in accordance with Article 26 of the GDPR.

Meta’s privacy policy: https://www.facebook.com/privacy/policy/

16. Retention period and erasure

We store personal data only for as long as is necessary for the respective processing purposes or as required by statutory retention obligations. Once the purpose no longer applies or the retention period has expired, the data is routinely erased or blocked.

The following retention periods apply in particular to booking and contract data: 10 years for booking receipts, invoices and tax-related documents in accordance with Sections 147(1) of the German Fiscal Code (AO) and 257(1) nos. 1 and 4 of the German Commercial Code (HGB); 6 years for business letters and commercial correspondence in accordance with Section 257(1)(2) and (3) of the German Commercial Code (HGB). Registration forms for foreign guests are retained for 12 months and destroyed no later than a further 3 months thereafter.

17. Transfers to third countries

Some of the services we use are based outside the EU/EEA. For transfers to the USA, we rely on the EU-US Data Privacy Framework, provided that the recipients are certified under it. For transfers to the United Kingdom, an adequacy decision has been issued by the European Commission. In all other cases, transfers to third countries are carried out on the basis of standard contractual clauses in accordance with Article 46(2)(c) of the GDPR.

18. Security measures

In accordance with Article 32 of the GDPR, we implement appropriate technical and organisational measures to ensure a level of protection appropriate to the risk. These include, in particular, the encryption of data transmission (SSL/TLS), protection against unauthorised access, and measures to ensure the confidentiality, integrity and availability of the data.

19. Changes to this Privacy Policy

We reserve the right to amend this Privacy Policy as necessary to bring it into line with changes in the legal landscape, regulatory requirements or changes to our services and data processing procedures. The current version published at https://carl22.de/datenschutz/ shall apply.