Privacy Policy
§1 Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection provisions is:
Winneburger Hof
Owner: Anke Beilstein
Raiffeisenstraße 1
56814 Ernst, Germany
Phone: +49 (0) 2671 7518
E-mail: info@winneburger-hof.de
§2 Data Protection Officer
We are not legally required to appoint a data protection officer and have chosen not to appoint one. For any questions regarding data protection, please contact us using the details provided in Section 1.
§3 Hosting and Server Log Files
Our website is hosted by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. The host processes, on our behalf, the data generated when you visit the website – in particular the log file data described below. A data processing agreement pursuant to Art. 28 GDPR is in place. The legal basis for using a capable host is our legitimate interest in the secure and reliable operation of our website pursuant to Art. 6(1)(f) GDPR.
When you access our website, the browser on your device automatically transmits information to our website’s server and temporarily stores it in a so-called log file. The following is recorded:
- IP address of the requesting device,
- date and time of access,
- name and URL of the retrieved file,
- the website from which access is made (referrer URL),
- the browser used, your operating system, and the name of your access provider.
We process this data to ensure a smooth connection, comfortable use of our website, and to evaluate system security and stability. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest follows from the purposes stated above.
The log files are automatically deleted after no more than eight weeks, unless longer storage is required in an individual case to investigate a specific security incident. Under no circumstances do we use this data to draw conclusions about your identity.
§4 Cookies and Consent
Cookies are small files that your browser stores on your device. We distinguish between technically necessary cookies and services that require consent.
Technically necessary cookies
These are required for the operation of the website – for example for session management, language selection (WPML), and to store your cookie choice. The legal basis for storage is Section 25(2) no. 2 TDDDG (German Telecommunications Digital Services Data Protection Act); the associated data processing is based on Art. 6(1)(f) GDPR (legitimate interest in the technically flawless operation of the website). No consent is required for these cookies.
Services that require consent
Services that are not technically necessary – in particular Google reCAPTCHA (Section 6) and any additional services listed in Section 10 – are only used after you have actively given your consent via our consent banner. The legal basis for storing and reading information on your device is Section 25(1) TDDDG, and for the subsequent data processing Art. 6(1)(a) GDPR. Your consent is voluntary and can be withdrawn at any time with effect for the future, e.g. via the cookie settings on our website.
Consent management (CookieYes)
To obtain and manage your consent, we use the tool “CookieYes” (CookieYes Limited, 3 Warren Yard, Warren Farm Office Village, Wolverton Mill, Milton Keynes, MK12 5NW, United Kingdom). On your first visit, CookieYes displays a consent banner and blocks services requiring consent until you agree. Your choice is stored in a technically necessary cookie (“cookieyes-consent”) so that the request does not reappear on every page load. The legal basis for its use is our legitimate interest in legally compliant consent management (Art. 6(1)(f) GDPR); storage of the consent cookie is based on Section 25(2) no. 2 TDDDG. The United Kingdom is covered by an adequacy decision of the European Commission.
Most browsers accept cookies automatically. You can configure your browser so that no cookies are stored or so that a notice appears before a new cookie is set. Disabling cookies entirely may limit the functionality of the website.
§5 Contact Form
You can contact us via our contact form. In doing so, we collect the following information:
- Mandatory information: first name, last name, e-mail address, and your consent to processing;
- Voluntary information: street, postal code, city, phone number, and the content of your message.
We process this data exclusively to handle and respond to your enquiry. The legal basis is Art. 6(1)(b) GDPR insofar as your enquiry is aimed at concluding or initiating a contract (e.g. a booking enquiry), and otherwise Art. 6(1)(f) GDPR (legitimate interest in responding to your enquiry). When you submit the form, Google reCAPTCHA is additionally used (see Section 6).
Your data is deleted as soon as your enquiry has been conclusively processed and no statutory retention obligations prevent deletion. If the enquiry leads to a contract, the statutory retention periods apply (see Section 11).
§6 Google reCAPTCHA
To protect our contact form against automated input (spam, misuse), we use the “reCAPTCHA” service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. reCAPTCHA analyses user behaviour based on various characteristics (including IP address, time spent on the page, mouse movements). For this purpose, data is transmitted to and processed by Google; a transfer to Google LLC in the USA cannot be ruled out.
reCAPTCHA is only loaded after you have consented via our consent banner. The legal basis is Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG. For the transfer to the USA, we rely on the European Commission’s adequacy decision (EU-US Data Privacy Framework) or on the EU standard contractual clauses. Further information can be found in Google’s privacy policy and terms of service.
§7 Booking and Online Check-in (easybooking)
For enquiries, bookings, and online check-in, we use the hotel software “easybooking” provided by zadego GmbH, Anton-Melzer-Straße 10, 6020 Innsbruck, Austria. For this purpose, modules (“widgets”) such as the enquiry form, booking form, and availability calendar are embedded on our website. If you enter data into these widgets, it is transmitted to zadego GmbH to process your enquiry or booking.
zadego GmbH acts as our processor pursuant to Art. 28 GDPR. This is based on a data processing agreement that ensures processing takes place exclusively in accordance with our instructions and under appropriate technical and organisational measures. The server location is within the EU/EEA.
The legal basis is Art. 6(1)(b) GDPR (contract performance or pre-contractual measures); for the registration data collected during online check-in, Art. 6(1)(c) GDPR in conjunction with the provisions of the German Federal Registration Act (Bundesmeldegesetz). Further details can be found in the supplementary easybooking privacy policy.
§8 Disclosure of Data
Your personal data is only transferred to third parties if:
- you have expressly consented pursuant to Art. 6(1)(a) GDPR,
- disclosure pursuant to Art. 6(1)(f) GDPR is necessary to assert, exercise, or defend legal claims and there is no overriding interest of yours worthy of protection,
- there is a legal obligation for disclosure pursuant to Art. 6(1)(c) GDPR, or
- this is necessary pursuant to Art. 6(1)(b) GDPR for the performance of contractual relationships with you.
Processing by processors engaged by us (see Section 7) that act exclusively on our instructions and on the basis of a data processing agreement pursuant to Art. 28 GDPR does not constitute disclosure to third parties within the meaning of this section.
§9 Social Media (Facebook)
On our website, we link to our Facebook profile. This is a simple link – only when you actively click it are you redirected to Facebook and data is transferred to the provider (Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland). We have no influence over the processing that takes place there; Meta’s privacy policy applies.
§10 Retention Period
- DATA
- Server log files
- Contact enquiries without contractual relevance
- Booking and stay data
- Invoices and booking records
- Registration data (check-in)
- RETENTION PERIOD
- max. 8 weeks (IONOS), then automatic deletion
- deleted after final processing
- for contract performance; beyond that, per statutory periods
- statutory retention under Section 147 AO / Section 257 HGB (usually up to 10 years)
- as required by the German Federal Registration Act
§11 Your Rights
You have the right:
- pursuant to Art. 15 GDPR, to request information about your personal data processed by us;
- pursuant to Art. 16 GDPR, to request the correction of inaccurate data or the completion of your data;
- pursuant to Art. 17 GDPR, to request the deletion of your data, provided no legal obligations or overriding interests preclude this;
- pursuant to Art. 18 GDPR, to request the restriction of processing;
- pursuant to Art. 20 GDPR, to receive your data in a structured, commonly used, and machine-readable format, or to request its transfer to another controller;
- pursuant to Art. 7(3) GDPR, to withdraw consent you have given at any time;
- pursuant to Art. 21 GDPR, to object to processing insofar as it is based on Art. 6(1)(f) GDPR or relates to direct marketing;
- pursuant to Art. 77 GDPR, to lodge a complaint with a supervisory authority (Section 13).
§12 Right to Lodge a Complaint
If you believe that the processing of your data violates the GDPR, you can lodge a complaint with a supervisory authority. The authority responsible for us is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz
(State Commissioner for Data Protection and Freedom of Information, Rhineland-Palatinate)
Postfach 30 40, 55020 Mainz, Germany
Phone: +49 (0) 6131 8920-0
E-mail: poststelle@datenschutz.rlp.de
Web: www.datenschutz.rlp.de
§13 Data Security
The content of our website is transmitted in encrypted form using the TLS/SSL protocol in line with the current state of the art. To protect your data, we and the service providers engaged by us – with whom corresponding contractual agreements are in place – use appropriate technical and organisational measures in line with the current state of the art, in particular to restrict access to the data and to protect it against alteration, loss, and unauthorised disclosure.
§14 Updates to This Privacy Policy
This privacy policy is dated 20.07.2026. We reserve the right to amend it in order to improve data protection and/or to adapt it to changed legal or technical circumstances.



