Privacy Policy
Wohntraum Saar Mosel GmbH — Last updated: August 2026
1) Introduction and Contact Details of the Controller
We are pleased that you are visiting our website and thank you for your interest. Below we inform you about how we handle your personal data when you use our website.
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Wohntraum Saar Mosel GmbH
Gartenstr. 79
54450 Freudenburg
Mobile: 0160-98577349
2) Data Collection When Visiting Our Website
When you use our website purely for information purposes, i.e. if you do not register or otherwise provide us with information, we only collect the data that your browser transmits to our server (so-called "server log files"). When you access our website, we collect the following data, which is technically necessary for us to display the website to you:
- Page visited
- Date and time of access
- Amount of data sent in bytes
- Source/referrer from which you accessed the page
- Browser used
- Operating system used
- IP address used (anonymised where applicable)
This processing takes place in accordance with Art. 6 (1) lit. f GDPR on the basis of our legitimate interest in improving the stability and functionality of our website. Server log files are stored for a maximum of 7 days for security reasons and then automatically deleted.
For security reasons and to protect the transmission of personal data and other confidential content, this website uses SSL/TLS encryption. You can recognise an encrypted connection by the "https://" prefix and the lock icon in your browser bar.
3) Hosting
For hosting our website and displaying its content, we use the provider Vercel Inc. (USA), represented for EU customers by Vercel International B.V. (Netherlands). We have concluded a data processing agreement with the provider pursuant to Art. 28 GDPR. As processing outside the EU cannot be ruled out, we base the transfer on the EU Standard Contractual Clauses pursuant to Art. 46 GDPR. More information: https://vercel.com/legal/privacy-policy.
4) Cookies and Consent
Our website uses technically necessary cookies required for the operation of the site (e.g. to store your cookie choice). The legal basis, insofar as it concerns the storage of or access to information on your device, is § 25 (2) no. 2 TDDDG (technical necessity); otherwise Art. 6 (1) lit. f GDPR on the basis of our legitimate interest. We do not use a third-party tool to store your cookie choice; instead we use a self-built solution: your choice is stored exclusively locally in your browser (localStorage entry "wsm-cookie-consent") for up to 12 months.
In addition, we embed the interactive Google Maps directions map. It is only loaded after you have given explicit consent via our cookie consent banner; only then does Google set cookies and transfer data (including your IP address) to Google Ireland Limited, which may be forwarded to Google LLC in the USA, based on the EU-U.S. Data Privacy Framework or, alternatively, the EU Standard Contractual Clauses pursuant to Art. 46 GDPR. The legal basis is your consent pursuant to Art. 6 (1) lit. a GDPR. You can withdraw your consent at any time via the "Cookie settings" link in the footer. More information: https://policies.google.com/privacy.
We do not currently embed any further analytics, marketing or social media services (e.g. Google Analytics, Meta Pixel, Facebook/Instagram plugins).
5) Contacting Us
When you contact us (e.g. by phone or email), personal data is collected. This data is stored and used solely for the purpose of processing your enquiry and the related technical administration. The legal basis is our legitimate interest pursuant to Art. 6 (1) lit. f GDPR, or, where the contact is aimed at concluding a contract, Art. 6 (1) lit. b GDPR. We store this data for as long as is necessary to process your enquiry, generally up to 6 months after it has been concluded; beyond that only insofar as statutory retention obligations apply.
6) Booking Through Our Website
If you book a holiday apartment through our website, we process the data you provide (name, contact details, travel dates, payment data) to carry out the booking and payment process. The legal basis is Art. 6 (1) lit. b GDPR (performance of a contract). For processing, we use the booking platform Smoobu (Smoobu GmbH, Berlin, Germany; https://www.smoobu.com/en/privacy-policy) and the payment provider Stripe (Stripe Payments Europe, Ltd., Ireland, potentially in conjunction with Stripe, Inc., USA; https://stripe.com/privacy); data processing agreements are in place with both providers. Where this involves a transfer of data to the USA, we base this on the EU Standard Contractual Clauses or the EU-U.S. Data Privacy Framework pursuant to Art. 44 et seq. GDPR. Booking and invoicing data is stored for up to 10 years due to commercial and tax law retention obligations (§ 257 HGB, § 147 AO); all other booking-related data is deleted no later than 3 years after the end of the year of stay, unless a longer statutory retention obligation applies.
7) Your Rights
Applicable data protection law grants you extensive rights as a data subject vis-à-vis the controller:
- Right to information pursuant to Art. 15 GDPR
- Right to rectification pursuant to Art. 16 GDPR
- Right to erasure pursuant to Art. 17 GDPR
- Right to restriction of processing pursuant to Art. 18 GDPR
- Right to data portability pursuant to Art. 20 GDPR
- Right to withdraw consent given pursuant to Art. 7 (3) GDPR
- Right to lodge a complaint with a supervisory authority pursuant to Art. 77 GDPR
The supervisory authority responsible for us is: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz, Hintere Bleiche 34, 55116 Mainz, Germany.
8) Right to Object
You have the right, at any time and on grounds relating to your particular situation, to object to the processing of your personal data carried out on the basis of Art. 6 (1) lit. f GDPR. We will then stop processing your data unless we can demonstrate compelling legitimate grounds for the processing.
9) Access System (Electronic Locks)
To ensure controlled and secure access to our holiday apartments, we use an electronic access control (lock) system. Depending on the apartment booked, access is granted via an individually issued PIN code and/or a QR code.
Purpose of processing: The log data generated when using the electronic access system is processed for access control, to ensure the security of the apartments and the building, and to investigate and trace technical faults, operating errors or unauthorised access attempts. We do not use this data for any further purpose, in particular not to create movement or behavioural profiles of guests.
Legal basis: Processing takes place on the basis of Art. 6 (1) lit. f GDPR. Our legitimate interest lies in particular in ensuring controlled access, protecting the apartments and property, and investigating security or fault incidents.
Data stored: Depending on the technical design of the system, this may include the access medium or access code used, the door concerned, and the date and time of access.
Storage period: Access system data is stored only for as long as necessary for the purposes described. Automatic deletion or overwriting takes place after departure, unless longer storage is required to investigate a specific security, fault or misuse incident, or a statutory retention obligation applies.
Persons with access: Access to the access system administration and the associated log data is restricted to authorised persons: the IT service provider responsible for managing the access system, the managing director, and the staff member (office administration) entrusted with managing and supporting the apartments. The IT service provider we commission to set up, maintain and troubleshoot the system may also access the relevant data insofar as necessary for that purpose. Access rights are limited to what is necessary for the respective task. Access log data is generally not passed on to other third parties unless there is a legal obligation to do so, or this is necessary and permissible to investigate a specific security or misuse incident.
