Privacy Policy
Data Protection Information and Privacy Policy
1) Introduction and contact details of the data controller
1.1 We are delighted that you are visiting our website and thank you for your interest. Below, we provide information on how we handle your personal data when you use our website. Personal data refers to any data that can be used to identify you personally.
1.2 The data controller for this website within the meaning of the General Data Protection Regulation (GDPR) is Schlossbrauerei Odelzhausen Hans & Maria Eser GmbH & Co. KG, Am Schlossberg 1, 85235 Odelzhausen, Germany, Tel.: +49813499870, Email: post@schlossgut-odelzhausen.de. The controller responsible for the processing of personal data is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.
2) Data collection when visiting our website
2.1 When you use our website purely for information purposes – that is, if you do not register or otherwise provide us with information – we only collect data that your browser transmits to the website server (so-called ‘server log files’). When you visit our website, we collect the following data, which is technically necessary for us to display the website to you:
- The page you visited
- Date and time of access
- Amount of data transmitted in bytes
- Source/referrer from which you accessed the page
- Browser used
- Operating system used
- IP address used (where applicable: in anonymised form)
Processing is carried out in accordance with Article 6(1)(f) of the GDPR on the basis of our legitimate interest in improving the stability and functionality of our website. The data will not be disclosed or used for any other purpose. However, we reserve the right to review the server log files retrospectively should there be concrete indications of unlawful use.
2.2 For security reasons and to protect the transmission of personal data and other confidential content (e.g. orders or enquiries to the data controller), this website uses SSL or TLS encryption. You can recognise an encrypted connection by the string ‘https://’ and the padlock symbol in your browser address bar.
3) Hosting & Content-Delivery-Network
3.1 Laravel Cloud
We use the system provided by the following provider to host our website and display its content: Laravel Holdings Inc., 60 Broad Street, 24th Floor #1559, New York, NY 10004, USA
All data collected on our website is processed on the provider’s servers, unless different data recipients are specified below for specific data processing operations.
We have entered into a data processing agreement with the provider, which ensures the protection of our website visitors’ data and prohibits unauthorised disclosure to third parties.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, on the basis of an adequacy decision by the European Commission, ensures compliance with European data protection standards.
3.2 Cloudflare
We use a content delivery network provided by the following provider: Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA
This service enables us to deliver large media files, such as graphics, page content or scripts, more quickly via a network of regionally distributed servers. Data processing is carried out to safeguard our legitimate interest in improving the stability and functionality of our website in accordance with Article 6(1)(f) of the GDPR. We have entered into a data processing agreement with the provider, which ensures the protection of our website visitors’ data and prohibits unauthorised disclosure to third parties.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, on the basis of an adequacy decision by the European Commission, ensures compliance with European data protection standards.
4) Cookies
To make your visit to our website more enjoyable and to enable the use of certain functions, we use cookies – small text files that are stored on your device. Some of these cookies are automatically deleted when you close your browser (so-called ‘session cookies’), whilst others remain on your device for longer and enable page settings to be saved (so-called ‘persistent cookies’). In the latter case, you can find the storage period in the overview of your web browser’s cookie settings.
Where individual cookies used by us also involve the processing of personal data, such processing is carried out in accordance with Article 6(1)(b) of the GDPR either for the performance of a contract, in accordance with Article 6(1)(a) of the GDPR where consent has been given, or in accordance with Article 6(1)(f) of the GDPR to safeguard our legitimate interests in ensuring the best possible functionality of the website and a user-friendly and effective browsing experience.
You can configure your browser so that you are notified when cookies are set and can decide on a case-by-case basis whether to accept them, or you can block the acceptance of cookies in specific cases or generally.
Please note that if you do not accept cookies, the functionality of our website may be restricted.
5) Contacting us
5.1 When you contact us (e.g. via the contact form or by email), personal data is processed – solely for the purpose of handling and responding to your enquiry and only to the extent necessary for this purpose.
The legal basis for the processing of this data is our legitimate interest in responding to your enquiry in accordance with Article 6(1)(f) of the GDPR. If your enquiry is aimed at entering into a contract, the additional legal basis for the processing is Article 6(1)(b) of the GDPR. Your data will be deleted once it is clear from the circumstances that the matter in question has been conclusively resolved, provided that there are no statutory retention obligations to the contrary.
5.2 - Microsoft
We use the following provider to send transactional emails, i.e. event-driven messages triggered by a specific user interaction (such as entering into a contract, registering or resetting a password): Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA
On the basis of our legitimate interest in effective and user-friendly email communication, we transfer the data you provide when carrying out such a user action to this provider in accordance with Article 6(1)(f) of the GDPR, so that the provider can handle the sending of emails on our behalf.
We have entered into a data processing agreement with the provider, which protects the data of our website visitors and prohibits disclosure to third parties.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, on the basis of an adequacy decision by the European Commission, ensures compliance with European data protection standards.
6) Data processing for the purposes of contract fulfilment
In accordance with statutory provisions, prior to the start of your stay, we collect the following information from foreign nationals and – where tourism or spa taxes are levied on your stay – from UK nationals as well: in addition to details of your arrival and departure, your first name and surname, your date of birth, your address, your nationality, the serial number of your identity document, and the first names and surnames of any travelling companions electronically, in order to create digital registration forms.
These registration forms must be presented at the request of the relevant registration authority. They must be retained for up to 12 months after the date of departure and destroyed within 3 months of the end of this retention period.
If tourism or spa taxes are levied for your stay in accordance with local regulations, your data from the registration form will be transferred to the relevant local authority to ensure the proper payment of these taxes. The local authority will retain this data for the duration of the statutory retention period under tax law.
The legal basis for the processing is Article 6(1)(c) of the GDPR, in conjunction with the applicable registration regulations and, where relevant, local authority regulations. As the data controller, we are under a legal obligation to record the specified personal data in accordance with registration regulations and, where applicable, to pass it on to the local authority for the purpose of paying taxes.
7) Website features
7.1 - Cloudflare Turnstile
On this website, we use the CAPTCHA service provided by the following provider: Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA
The service checks whether an input is made by a human or, abusively, through machine-based and automated processing, and blocks spam, DDoS attacks and similar automated malicious access attempts. To ensure that an action is carried out by a human and not by an automated bot, Cloudflare Turnstile collects the IP address of the device used, identification data relating to the browser and operating system type used, as well as the date and duration of the visit, and transmits this information to the provider’s servers for analysis.
The legal basis for this is our legitimate interest in establishing individual responsibility on the internet and in preventing misuse and spam, in accordance with Article 6(1)(f) of the GDPR.
We have entered into a data processing agreement with the provider, which ensures the protection of our website visitors’ data and prohibits unauthorised disclosure to third parties.
For data transfers to the USA, the provider has adhered to the EU-US Data Privacy Framework, which, on the basis of an adequacy decision by the European Commission, ensures compliance with European data protection standards.
7.2 Applications for job vacancies via email
On our website, we publish a separate section listing current vacancies, for which interested candidates can apply by email to the contact address provided.
Applicants must provide all personal data necessary for a thorough assessment, including general information such as name, address and contact details, as well as evidence of qualifications and, where applicable, health-related information. Further details regarding the application can be found in the job advertisement.
Upon receipt of the application by email, the data will be stored and processed solely for the purpose of processing the application. Should we have any queries, we will contact the applicant via either their email address or telephone number. The processing is carried out on the basis of Article 6(1)(b) of the GDPR (or Section 26(1) of the BDSG), under which the application process is regarded as the initiation of an employment contract.
Where, as part of the application process, special categories of personal data within the meaning of Article 9(1) of the GDPR (e.g. health data such as information regarding severely disabled status), processing is carried out in accordance with Article 9(2)(b) of the GDPR so that we may exercise the rights arising from labour law and the law on social security and social protection and fulfil our obligations in this regard.
Cumulatively or alternatively, the processing of special categories of data may also be based on Article 9(2)(h) of the GDPR if it is carried out for the purposes of preventive healthcare or occupational medicine, for the assessment of the applicant’s fitness for work, for medical diagnosis, care or treatment in the health or social care sector, or for the administration of systems and services in the health or social care sector.
If the applicant is not selected or withdraws their application early, the data they have provided, as well as all electronic correspondence, including the application email, will be deleted no later than six months after notification has been given. This period is determined by our legitimate interest in answering any follow-up questions regarding the application and, where necessary, in being able to fulfil our obligations to provide evidence under the regulations on the equal treatment of applicants.
In the event of a successful application, the data provided will be processed on the basis of Article 6(1)(b) of the GDPR (in the case of processing in Germany, in conjunction with Section 26(1) of the Federal Data Protection Act (BDSG)) for the purpose of entering into the employment relationship.
8) Rights of the data subject
8.1 Under current data protection law, you have the following rights as a data subject (rights of access and intervention) vis-à-vis the controller with regard to the processing of your personal data; please refer to the legal basis cited for the respective conditions for exercising these rights:
- Right of access pursuant to Article 15 of the GDPR;
- Right to rectification pursuant to Article 16 of the GDPR;
- Right to erasure pursuant to Article 17 of the GDPR;
- Right to restriction of processing pursuant to Article 18 of the GDPR;
- Right to be informed pursuant to Article 19 of the GDPR;
- Right to data portability pursuant to Article 20 of the GDPR;
- Right to withdraw consent pursuant to Article 7(3) of the GDPR;
- Right to lodge a complaint pursuant to Article 77 of the GDPR.
8.2 RIGHT TO OBJECT
IF, AS PART OF A BALANCING OF INTERESTS, WE PROCESS YOUR PERSONAL DATA ON THE BASIS OF OUR OVERRIDING LEGITIMATE INTEREST, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO SUCH PROCESSING WITH EFFECT FOR THE FUTURE ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE DATA IN QUESTION. WE RESERVE THE RIGHT TO CONTINUE PROCESSING, HOWEVER, IF WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, FUNDAMENTAL RIGHTS AND FREEDOMS, OR IF THE PROCESSING IS NECESSARY FOR THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS.
IF WE PROCESS YOUR PERSONAL DATA FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA FOR THE PURPOSE OF SUCH MARKETING. YOU MAY EXERCISE THIS RIGHT AS DESCRIBED ABOVE.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE RELEVANT DATA FOR DIRECT MARKETING PURPOSES.
9) Retention period for personal data
The retention period for personal data is determined by the relevant legal basis, the purpose of processing and – where applicable – the relevant statutory retention period (e.g. retention periods under commercial and tax law).
Where personal data is processed on the basis of explicit consent in accordance with Article 6(1)(a) of the GDPR, the data in question will be retained until you withdraw your consent.
Where statutory retention periods apply to data processed in the context of contractual or quasi-contractual obligations on the basis of Article 6(1)(b) of the GDPR, such data will be routinely deleted upon expiry of the retention periods, provided that it is no longer required for the performance of a contract or for entering into a contract and/or we no longer have a legitimate interest in continuing to store it.
Where personal data is processed on the basis of Article 6(1)(f) of the GDPR, this data will be stored until you exercise your right to object under Article 21(1) of the GDPR, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
When personal data is processed for the purposes of direct marketing on the basis of Article 6(1)(f) of the GDPR, this data will be stored until you exercise your right to object under Article 21(2) of the GDPR.
Unless otherwise specified in the other information contained in this policy regarding specific processing situations, stored personal data will otherwise be erased when it is no longer necessary for the purposes for which it was collected or otherwise processed.
Copyright notice: This privacy policy has been drawn up by the specialist solicitors at IT-Recht Kanzlei and is protected by copyright.(https://www.it-recht-kanzlei.de)
Status: 2 October 2026, 12:11:22