Privacy policy for the website, online booking, and hotel operations
Information pursuant to Articles 12, 13, and 14 of the GDPR
Kral GmbH
Luitpoldstraße 77
91052 Erlangen
Version 2.1 | Last updated: July 2026
www.hotel-kral.de
This privacy policy describes the data processing operations intended for the website www.hotel-kral.de and the operation of Hotel Kral. The technical configuration actually in use is always the decisive factor. Services that are only loaded upon consent remain deactivated until you make a selection.
The controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection regulations is:
Kral GmbH
Hotel Kral
Luitpoldstraße 77
91052 Erlangen
Germany
Phone: +49 (0) 9131 81009-0
Fax: +49 (0) 9131 81009-33
Email: info@hotel-kral.de
Represented by the Managing Directors Mario Kral and Helmut Kral.
For questions regarding the processing of your personal data, the exercise of your rights, or this privacy policy, you can contact us at any time using the contact details provided above.
A separate data protection officer is not appointed in this policy. Should a data protection officer be appointed in the future, their contact details will be published here.
This privacy policy applies in particular to:
Personal data is any information relating to an identified or identifiable natural person. Processing refers to any operation in connection with such data, such as collection, storage, use, transmission, or deletion.
We process personal data in accordance with the principles of lawfulness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality.
Employees and service providers are granted access only to the extent necessary for their tasks.
Depending on the processing operation, we base the processing in particular on the following legal grounds:
Depending on how you interact with us and which services you use, the following categories of data may be processed in particular:
Within Kral GmbH, only those departments that require access to personal data to fulfill their tasks receive such access.
External recipients may include, in particular, IT and hosting providers, technical support staff, providers of hotel software and booking systems, payment service providers, banks, tax advisors, auditors, legal advisors, shipping and communication service providers, booking portals, travel agencies, as well as authorities and courts selected and directly commissioned by Kral GmbH. The selection, commissioning, and integration of these entities under data protection law are carried out exclusively by Kral GmbH.
Insofar as service providers process data exclusively on our behalf, they are contractually bound in accordance with Art. 28 GDPR. Insofar as a recipient determines the purposes and means of processing themselves, they process the data under their own responsibility in terms of data protection law.
Some technical service providers are based outside the European Union or the European Economic Area. A transfer to a third country only takes place if the requirements of Art. 44 et seq. GDPR are met.
Suitable bases include, in particular, an adequacy decision by the European Commission, a valid certification under the EU-U.S. Data Privacy Framework, the European Commission's standard contractual clauses, and supplementary protective measures.
Despite such guarantees, it cannot be completely ruled out that authorities in certain third countries may access data and that European data subject rights may only be enforceable to a limited extent. Services involving third countries that require consent are therefore only activated after you have selected them.
We only store personal data for as long as is necessary for the respective purpose. Subsequently, the data will be deleted or anonymized, provided that there are no legal retention obligations, legitimate interests in securing evidence, or other legal grounds to the contrary.
Tax-relevant booking documents and invoices are generally subject to an eight-year retention period. Commercial and business correspondence may generally need to be kept for six years. Data for the defense or enforcement of claims can generally be stored until the end of the standard statutory limitation period of three years, and in justified individual cases, longer.
Specific or deviating retention periods are explained in the respective processing operations.
The provision of personal data is in some cases required for the conclusion of a contract, the execution of your stay, payment processing, or the fulfillment of legal obligations. Without the necessary information, we may be unable to process or fulfill a request, reservation, or service.
Voluntary information is identified as such or is evident from the context. Failure to provide voluntary information has no negative consequences, but may limit individual processing.
We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you. Should such a process be used in the future, we will inform you separately.
When you visit our website, technically necessary data is processed to ensure that content is delivered to your device, stability is maintained, and attacks or errors can be detected.
Processing is carried out for technical provision, load balancing, error analysis, abuse prevention, and IT security. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest lies in the secure, stable, and efficient operation of the website.
Log data is generally only stored for as long as is necessary for operation and security. Insofar as the storage period is within our control, standard server log data is regularly deleted after 30 days at the latest, provided there is no security-related reason to retain it. In the event of specific security incidents, affected data may be stored longer until the incident has been fully investigated and resolved.
The website was created using the Webflow website and content management system and is provided via Webflow's infrastructure. Kral GmbH is the sole owner of the Webflow account, operator of the website, and contractual partner of Webflow.
Webflow, Inc.
398 11th Street, 2nd Floor
San Francisco, California 94103
USA
When hosting and providing the website, Webflow processes technical access and log data on behalf of Kral GmbH. Insofar as data is transmitted via Webflow forms, Webflow may also process the entered form data for Kral GmbH.
The legal basis for technical provision is Art. 6 (1) (f) GDPR. For form data, the legal bases stated under "Contacting us" also apply.
As the account holder and contractual partner, Kral GmbH enters into the necessary data processing agreement with Webflow. Webflow engages further sub-processors. Data may be processed in the USA. Webflow describes its transfer mechanisms, in particular its certification under the EU-US Data Privacy Framework and standard contractual clauses.
Further information: Webflow Privacy Policy and Webflow DPA
Ongoing technical support, maintenance, and administration of the website are organized exclusively by Kral GmbH and, where commissioned, delegated directly to the following service provider:
1601.com e.K.
Patrick Siegler
Spardorfer Straße 37
91054 Erlangen
1601.com e.K. is commissioned directly by Kral GmbH, insofar as it is used for ongoing support. In the context of support, error analysis, updates, or administration, access to technical data or content transmitted via the website cannot be completely ruled out. Processing is carried out exclusively to the extent necessary and in accordance with the instructions of Kral GmbH on the basis of Article 6(1)(f) GDPR as well as, where a data processing agreement exists, a contract pursuant to Article 28 GDPR. Data protection responsibility remains with Kral GmbH.
Our website uses an encrypted connection. You can usually recognize this by "https://" and the lock icon in your browser. This protects transmitted content from being read by unauthorized third parties.
Furthermore, we employ appropriate technical and organizational measures, including access and authorization concepts, data backups, updates, logging, and organizational confidentiality measures. Nevertheless, a completely risk-free data transfer over the internet cannot be guaranteed.
Our website uses cookies and similar technologies that allow information to be stored on or read from your end device.
Technically essential technologies may be used if they are necessary for the transmission of a message or for a digital service you have expressly requested.
The legal basis for accessing the end device is Section 25(2) TDDDG. To the extent that personal data is subsequently processed, this is based on Article 6(1)(b) or (f) GDPR, depending on the purpose.
Statistics, convenience, map, or other non-essential technologies are only activated after your express consent. The legal bases are Section 25(1) TDDDG and Article 6(1)(a) GDPR.
Your selection is saved so that we can take it into account and provide proof of it. In this context, consent status, time, version of the consent text, and a technical identifier may be processed. Proof data is generally stored for as long as the consent is used and legal requirements for proof or limitation periods exist.
You can change or revoke your selection at any time via the "Cookie Settings" link in the footer of the website. The revocation applies to the future and does not affect the lawfulness of previous processing. The specific list of cookies used, providers, purposes, and durations is displayed in the cookie settings.
When you use a contact or inquiry form, we process the data you enter, in particular your name, contact details, accommodation preferences, message, and other voluntary information. Additionally, the time, technical metadata, and information for abuse detection may be processed.
Processing is carried out to handle your inquiry and, for contract-related matters, is based on Article 6(1)(b) GDPR. For general matters, it is based on Article 6(1)(f) GDPR; our legitimate interest is orderly and efficient communication.
Form data may be technically processed via Webflow, stored in the Kral GmbH Webflow project account, and forwarded to communication systems operated or directly commissioned by Kral GmbH. We regularly delete general inquiries no later than six months after final processing, provided no contract is concluded and no legal or statutory reasons require longer storage.
When you contact us via email, telephone, or fax, we process the information you provide and the content of the communication to handle your request.
The legal basis is Art. 6 (1) (b) GDPR, provided the communication relates to a contract or reservation; otherwise, it is Art. 6 (1) (f) GDPR. Telephone calls are generally not recorded.
Unencrypted emails may pose security risks. Please only transmit highly confidential information via an appropriately secure communication channel.
We use the DIRS21 booking system from TourOnline AG for online reservations. The booking function only loads once you actively select it or provide the necessary consent.
TourOnline AG
Borsigstraße 26
73249 Wernau
Germany
Email: info@dirs21.de
When loading, a direct connection is established to the servers of TourOnline AG. In doing so, TourOnline processes your IP address, time, browser and device information, referrer, accessed content, as well as technically necessary cookies and log data. Loading occurs based on your consent pursuant to Section 25 (1) TDDDG and Art. 6 (1) (a) GDPR.
During the booking process, we process your name, address, contact details, stay dates, number and, if applicable, ages of guests, room category, additional services, booking number, payment or guarantee details, and any voluntary messages. We process this data to initiate and fulfill the accommodation contract pursuant to Art. 6 (1) (b) GDPR and to comply with legal obligations pursuant to Art. 6 (1) (c) GDPR.
TourOnline AG provides the online booking tool and acts as the controller for data processing within the tool. Kral GmbH processes booking data transmitted to the hotel for reservations and stays under its own responsibility. The privacy policy of TourOnline AG also applies to processing within the DIRS21 system.
Booking and contract data are stored by us in accordance with the periods specified under "Reservations and Accommodation Contracts." TourOnline AG is additionally responsible for storage periods within the DIRS21 system.
Privacy policy for the DIRS21 online booking tool: DIRS21 Privacy Policy
Google Maps may be integrated to display our location. The map service does not load automatically. A connection to Google is only established once you activate the map function or provide your consent.
Google Ireland Limited
Gordon House, Barrow Street
Dublin 4
Ireland
When loading, data such as your IP address, device and browser information, location data—if you share it—usage data, and accessed map content may be processed. Google may also transfer data to Google LLC and other companies in the USA.
The legal bases are Section 25 (1) TDDDG and Art. 6 (1) (a) GDPR. Your consent is voluntary and can be revoked at any time via the cookie settings. Without consent, you can still use our address as text and access it via a map service of your choice.
Further information: Google Privacy Policy
If the "Google Analytics" statistical service can be selected in the cookie settings, we use Google Analytics 4 for the statistical analysis of website usage. The service remains disabled until you provide your consent.
Google Ireland Limited
Gordon House, Barrow Street
Dublin 4
Ireland
Data processed may include, in particular, pseudonymous online identifiers, shortened or otherwise processed IP information, device and browser data, pages visited, origin, approximate region, interactions, session duration, and technical events. We receive aggregated reports on website usage from this.
The legal bases are Section 25 (1) TDDDG and Art. 6 (1) (a) GDPR. The storage duration of user-level and event-level data depends on the retention period selected in the Google Analytics account.
Use for personalized advertising, Google Signals, or linking with other Google advertising services only occurs if this is technically enabled, transparently disclosed, and covered by your consent.
Google may transfer data to the USA. Further information on recipients, storage periods, and protection mechanisms can be found in Google's privacy policy. You can revoke your consent at any time via the cookie settings.
Our website may contain links to external websites and social media profiles, such as Instagram, Facebook, Tripadvisor, or other review and business profiles. As long as you do not click on a link, no data is generally transferred to the respective provider.
Once you click the link, you leave our area of responsibility. The respective provider processes data according to its own privacy policy. We generally have no influence over the scope, purposes, or storage duration of this processing.
When you book directly with us—whether by phone, email, via a form, or in person—we process the data required for quotes, reservations, check-in, your stay, departure, billing, and follow-up.
Processing is carried out for the performance of pre-contractual measures and for the fulfillment of the contract in accordance with Art. 6 (1) (b) GDPR. Tax, commercial, and other legally required processing is carried out in accordance with Art. 6 (1) (c) GDPR. The documentation of processes, quality assurance, and legal defense may be based on Art. 6 (1) (f) GDPR.
Operational reservation and stay data are stored for as long as they are required for the contract, billing, and customer service. Booking receipts, invoices, and tax-relevant documents are generally kept for eight years, and business correspondence for six years. Data regarding outstanding claims or disputes may be stored until final resolution.
If a reservation is made via a booking portal, tour operator, travel agency, corporate travel department, or other intermediary, we receive the data required for the reservation from this third party. This may include name, contact details, travel period, room and rate information, company affiliation, special requests, and payment or guarantee details.
The legal basis is Art. 6 (1) (b) GDPR, provided you are a party to the contract or the booking is made at your request. For bookings made by employers or other contractual partners, Art. 6 (1) (f) GDPR may also apply; our legitimate interest is the execution and allocation of the booking.
The respective portal or intermediary processes data under its own responsibility. Please refer to their privacy policy. We transmit changes, cancellations, billing, or status data back to the intermediary as required for booking processing.
We may receive personal data, in particular, from the following sources:
The categories and purposes correspond to the reservation, contract, communication, and billing data described in this statement. Processing is carried out in accordance with Art. 6 (1) (b), (c), or (f) GDPR.
Information pursuant to Art. 14 GDPR may be provided by the third party or during the first direct communication with you, provided the legal requirements are met.
For corporate bookings, the hotel also processes business contact details of contact persons, ordering parties, auditors, and travelers. If data of other persons is provided, the booking person is obliged to transmit only necessary data and to inform the affected persons appropriately.
Data of fellow travelers and children is only processed to the extent necessary, for example for room occupancy, price calculation, service provision, and the fulfillment of legal obligations.
Please only provide us with information that is necessary for the requested service. Details regarding accessibility, allergies, health restrictions, religion, or dietary requirements may contain special categories of personal data within the meaning of Art. 9 GDPR.
Where such information is required for an individual service you have requested, we generally only process it with your express consent in accordance with Art. 9(2)(a) GDPR. Consent can be withdrawn at any time with effect for the future. In medical emergencies, processing may be permitted to protect vital interests in accordance with Art. 9(2)(c) GDPR.
The information is only made accessible to employees who require it to provide the service and is deleted as soon as it is no longer needed, provided there are no legal reasons to the contrary.
According to applicable registration regulations, foreign guests are required to sign a special registration form on the day of arrival. The legally required information is collected for this purpose. Statutory simplifications apply to accompanying spouses, life partners, and minor children.
The legal basis is Art. 6(1)(c) GDPR in conjunction with Sections 29 and 30 of the Federal Registration Act (Bundesmeldegesetz). Registration forms are kept for one year from the date of arrival and destroyed in accordance with data protection regulations within three months after this retention period expires. There is no general special registration requirement for German guests; however, their data is processed to the extent necessary for reservations and contracts.
For cashless payments and credit card guarantees, the data required for authorization, billing, refunds, fraud prevention, and verification are processed. This may include the cardholder's name, masked card number, expiration date, and transaction, authorization, and payment status data.
Full card details are generally not stored permanently in publicly accessible hotel systems. Technical processing may be carried out by banks, card organizations, acquirers, terminal providers, and the booking system. These entities may act on their own responsibility or be involved as service providers.
The legal basis is Art. 6(1)(b) GDPR; legally required accounting is based on Art. 6(1)(c) GDPR. Security and fraud prevention measures may be based on Art. 6(1)(f) GDPR.
We process master data, contract data, service data, payment data, and billing data for invoicing, receivables management, cash management, accounting, and tax documentation purposes. Data may be transmitted to tax advisors, auditors, banks, tax authorities, and other legally authorized bodies.
The legal bases are Art. 6(1)(b) and (c) GDPR. Where data is processed for the assertion or defense of legal claims, this is based on Art. 6(1)(f) GDPR.
Wi-Fi access can be provided to hotel guests. Depending on the network system used, technical connection and usage data may be processed, in particular IP and MAC addresses, device identifiers, login or voucher information, the time and duration of the connection, the volume of data transmitted, and security and error logs.
Processing is carried out to provide access in accordance with Art. 6(1)(b) GDPR and to ensure network security, prevent abuse, and resolve technical issues in accordance with Art. 6(1)(f) GDPR. As a general rule, there is no monitoring of the content of communications.
Technical logs are only stored for as long as necessary for operation, security, billing, or the investigation of a specific case of abuse. If an external Wi-Fi provider is used, they may provide further information directly upon login.
To protect guests, employees, visitors, buildings, and assets, certain publicly accessible areas of the hotel may be under video surveillance. Monitored areas are indicated by signs before entry.
The legal basis is Article 6 (1) (f) of the GDPR. Our legitimate interest lies in the aforementioned protection and security purposes. The cameras are limited to necessary areas. Hotel rooms, sanitary facilities, and other areas requiring special privacy are not monitored.
Access is restricted to authorized personnel only. Data is only disclosed in the event of a specific incident to the police, public prosecutor's offices, courts, insurance companies, legal advisors, or other authorized bodies.
Recordings are generally deleted automatically after 72 hours at the latest, provided no security-relevant incident has been identified within that period. In the event of a specific incident, relevant sequences may be secured until the matter is fully resolved and legal action is concluded.
Where necessary for parking space allocation, access authorization, parking management, or the billing of charging services, we may process names, room numbers, license plate numbers, parking space details, usage periods, charging processes, energy consumption, and billing data.
The legal basis is Article 6 (1) (b) of the GDPR. Security and fraud prevention may be based on Article 6 (1) (f) of the GDPR. Billing documents are stored in accordance with statutory retention periods.
When processing lost and found items, we process contact details, information about the item, and location and shipping data. This processing is carried out for the purpose of returning items, documentation, and, if applicable, shipping, based on Article 6 (1) (b) or (f) of the GDPR, as well as legal provisions regarding lost property.
Data and unclaimed items are only stored for as long as is required by law or for the purpose of returning them.
When you apply for a position with us, we process the application and contact data you provide to decide on the establishment of an employment relationship. The legal basis for this is Section 26 (1) of the German Federal Data Protection Act (BDSG) in conjunction with Article 6 (1) (b) of the GDPR.
If application documents contain special categories of personal data, processing is only carried out under the conditions of Article 9 GDPR and Section 26(3) BDSG. If you are not hired, your application documents will generally be deleted no later than six months after the conclusion of the process, unless you have consented to longer storage or there is a legal reason to the contrary.
Personal data may be processed where necessary for the investigation of security incidents, handling of complaints, enforcement of outstanding claims, defense against unjustified claims, or defense in legal proceedings. The legal basis is Article 6(1)(f) GDPR.
Data is only transferred to authorities, courts, or other bodies if there is a legal obligation, an official order, or if it is necessary and permitted for the purpose of legal prosecution.
Subject to the statutory requirements, you have the right:
Where processing is based on your consent or a contract and is carried out by automated means, you have the right to receive the data you have provided in a structured, commonly used, and machine-readable format or, where technically feasible, to request the direct transmission of the data to another controller (Article 20 GDPR).
Where personal data is processed on the basis of Article 6(1)(e) or (f) of the GDPR, you have the right to object at any time for reasons relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, or if the processing is for the establishment, exercise, or defense of legal claims.
You may object to processing for direct marketing purposes at any time without providing a reason. We will subsequently no longer process your data for this purpose.
You may withdraw your consent at any time with future effect. For website-related consent, please use the cookie settings. Alternatively, you can contact us using the contact details provided in section 1.
The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, place of work, or place of the alleged infringement.
For non-public companies based in Bavaria, the responsible authority is:
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach
Germany
Email: poststelle@lda.bayern.de
Online complaint and current contact details: www.lda.bayern.de
To exercise your rights, please use the contact details provided in Section 1. Processing is generally free of charge.
If there are reasonable doubts regarding your identity, we may request additional information necessary to confirm it. This is to prevent personal data from being disclosed to unauthorized persons.
We update this privacy policy whenever there are changes to the legal situation, the services used, technical configurations, or our processing operations. The version published on the website applies.
In the event of significant changes requiring renewed consent, we will deactivate the affected services until a new decision is made or obtain fresh consent.
Version: 2.1
Date: July 2026
Website: www.hotel-kral.de
Approved by the management of Kral GmbH.
Whether for a short business trip, a long-term project, or temporary housing.
Hotel Kral offers the perfect solution for your stay in Erlangen.