Skip to main content

Privacy policy

Information pursuant to Art. 13 and 14 GDPR

1. Controller

Hotelbetriebsgesellschaft Sonnenhof mbH

Hermann-Aust-Straße 11

86825 Bad Wörishofen

Phone: +49 8247 959 0

Email: info@spahotel-sonnenhof.de

2. Overview of processing

We process personal data only to the extent necessary to provide a functioning website, our content and our services.

Personal data is generally processed only with the user’s consent. An exception applies where processing is permitted by law.

Categories of data processed:

  • Master data (e.g. names, addresses)
  • Contact data (e.g. email, telephone numbers)
  • Content data (e.g. text entered in forms and the AI chat)
  • Usage data (e.g. pages visited, access times)
  • Meta and communication data (e.g. device information, IP addresses)

3. Applicable legal bases

Below we state the legal bases under the GDPR on which we process personal data:

  • Consent (Art. 6(1)(a) GDPR) – the data subject has given consent to the processing (e.g. cookies, newsletter).
  • Performance of a contract (Art. 6(1)(b) GDPR) – processing is necessary for the performance of a contract (e.g. booking enquiries).
  • Legitimate interests (Art. 6(1)(f) GDPR) – processing is necessary to safeguard legitimate interests (e.g. website security).

4. Security measures

In line with statutory requirements and taking account of the state of the art, we implement appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.

This website is transmitted over an encrypted HTTPS/TLS connection. The website is hosted on servers in Germany; this hosting involves no transfer to third countries. Separate cases concerning map content that you actively load are described in sections 11 and 17.

5. Rights of data subjects

As a data subject you have the following rights under the GDPR:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent (Art. 7(3) GDPR)

6. Right to lodge a complaint with a supervisory authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR).

Competent supervisory authority: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany.

7. Hosting

This website is provided on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Technical access data are processed for this purpose, in particular IP address, date and time of access, the URL requested, the volume of data transferred, browser and device information as well as security and error logs.

The website is maintained on our behalf by Neon Arc, proprietor Alexander Hertle, Pfarrer-Walser-Str. 3, 87544 Blaichach, Germany, acting as a processor under Art. 28 GDPR; a corresponding agreement is in place. Hetzner is engaged as a further processor within that arrangement.

This processing serves the secure, fast and stable provision of the website. No transfer to third countries takes place.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the security of the website).

8. Cookies and consent management

This website uses cookies. A cookie is a small text file stored on your device. We distinguish between:

  • Strictly necessary cookies: these are required for security, access protection and storing your cookie settings. They include inspira_consent (your consent choice, SameSite=Lax, for no longer than 365 days) and, while the preview gate is active, inspira_access (website access).
  • Analytics: We only measure how quickly this website loads, on our own server and only after your consent. No third-party analytics service is used.
  • Optional external content: no Google Maps or YouTube cookies are currently set by embedded content. Any future video or social media embeds would only be loaded after your consent.

If you use “Adjust display” in the footer, your browser stores the display options you explicitly select under inspira-accessibility-v1 in local storage. The selection is not sent to our server, contains no identifier and remains on your device until you reset the settings or clear your browser data. This storage is necessary to provide the display you requested (section 25(2)(2) TDDDG).

Your light or dark colour-scheme choice is likewise stored only locally in your browser under inspira-theme and is not transmitted to our server. This is necessary to retain the display you selected across page views (section 25(2)(2) TDDDG).

You can adjust your cookie settings at any time via our .

Legal basis: Art. 6(1)(a) GDPR (consent) for non-essential cookies.

Logging of your consent

Art. 7(1) GDPR obliges us to be able to demonstrate your consent. We therefore record every decision made in the cookie dialogue on our server – the initial consent as well as every later change and every withdrawal. The following is logged:

  • a randomly generated identifier for your consent (consentId), together with the time and type of the decision
  • which categories and services you accepted and which you rejected
  • the version number of the cookie notice your decision relates to
  • your device’s browser identification (user agent)

For new decisions, we store neither your IP address nor a hash of it. Entries logged before 27 August 2026 may still contain the short IP hash recorded at that time until their regular deletion.

The legal basis is Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR: the logging fulfils our statutory duty of proof. It does not depend on your consent, because its very purpose is to evidence that consent – including when you decline or withdraw.

9. Contact form and email contact

If you contact us via the contact form, the meeting configurator or by email, the data you provide (name, email address, telephone number where given, your message or details of your event) is transmitted by email to our mailbox and processed there in order to handle your enquiry.

This website operates no database of its own. Your form entries are forwarded to us by email only and are not additionally stored on the web server.

For sending form emails we use our mailbox with the email service mailbox.org, operated by Heinlein Hosting GmbH, Schwedter Straße 8/9A, 10119 Berlin, Germany, as a processor.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures). Enquiries in our mailbox are deleted once the enquiry has been concluded, at the latest after 6 months, unless statutory retention obligations apply.

10. Web analytics, loading-speed measurement and error logs

We do not use a third-party web analytics service. No reach measurement takes place that would combine your behaviour across several page views.

Loading-speed measurement on our own server

In addition we measure how quickly this website actually renders on your device (the Core Web Vitals: LCP, INP, CLS, FCP, TTFB). Transmitted are only those measured values, the type of page visit and the page path visited, without query parameters. The values go to our own server; no third party is involved, no cookies are set for this purpose and no identifier is assigned that would make you recognisable across visits.

Legal basis: Art. 6(1)(a) GDPR (consent). The measurement is listed in the cookie banner as a separate service, “Loading-speed measurement (own server)”, and can be declined there.

Error logs

If a technical error occurs in your browser on this website, it is reported to our own server and logged there. Recorded are the error message, the program file concerned with its line number, the beginning of the technical stack trace and the page path without query parameters. Input from forms is not transmitted.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is being able to notice and fix faults on this website at all; an unnoticed error in a contact form otherwise means your message never reaches us. This report does not depend on consent because an error typically occurs before any banner decision. The logs are deleted together with the other server log files (see the section on storage periods).

11. Maps and route links

On some pages we offer interactive maps based on MapLibre and OpenFreeMap. Map tiles, font glyphs and map styles are loaded from the OpenFreeMap service via tiles.openfreemap.org; the map data comes from OpenStreetMap contributors.

The map does not load on its own. In its place you first see a notice with a “Load map” button. Only when you press that button is the map loaded, and only then, for technical reasons, is your IP address transmitted to OpenFreeMap. If you do not press it, no transmission takes place.

As matters stand, OpenFreeMap sets no cookies and requires no API key. Your decision is held in the browser’s memory for the current session only – no cookie is set for it and nothing is stored permanently on your device. The route overlays shown are loaded as static files from our own website.

We verified where the map tiles come from. OpenFreeMap delivers them via the content delivery network of Cloudflare, Inc.; when we measured on 12 August 2026, an edge location in Paris responded. Cloudflare, Inc. is based in the United States. If you load the map, your IP address may therefore reach a US company. This map transfer occurs only if you press the button.

According to its own statement, Cloudflare is certified under the EU-US Data Privacy Framework and additionally relies on the European Commission’s Standard Contractual Clauses. For certified recipients the Commission found an adequate level of protection by decision of 10 July 2023; the transfer therefore rests on Art. 45 GDPR. Checked on 12 August 2026 against Cloudflare’s own information.

The website may additionally contain links to Google Maps or a Google Maps route planner. Google Maps is not embedded; data is only transmitted to Google once you actively click such an external link and leave our website.

Legal basis for loading the map: Art. 6(1)(a) GDPR (consent, given by pressing the button).

12. Fonts

This website uses self-hosted fonts (Google Fonts: Source Serif 4, DM Sans). The font files are loaded directly from our own server – your browser establishes no connection to Google servers, and our content security policy could not permit one either. For completeness: the font files are downloaded from Google once, when the website is built, and then stored on our server. No visitor data is involved – that step happens long before you open the page.

13. AI-supported image material

Some room visuals on this website were created or enhanced with artificial intelligence. This does not process visitor data. Where such visuals appear, they are disclosed contextually on that page. The rooms concerned and possible differences in furnishings, lighting and set-up are also explained in the image credits in the legal notice.

14. Newsletter

We currently offer no newsletter via this website; no email addresses are collected for newsletter purposes.

Should a newsletter be offered in future, registration would use a double opt-in procedure on the basis of your consent (Art. 6(1)(a) GDPR), which you could withdraw at any time. We would update this privacy policy accordingly beforehand.

15. AI concierge (chat and FAQ)

Our website offers an AI-supported assistant in the chat and FAQ (“INSPIRA Concierge”) that answers your questions about our house. The assistant is activated only after your explicit consent in the chat window or FAQ; without that consent no data is transmitted.

To answer your questions, the messages you enter in the chat or FAQ and the relevant conversation history are transmitted to our service provider Mistral AI (Mistral AI SAS, 15 rue des Halles, 75001 Paris, France). Inference – processing your input and generating the response – takes place through Mistral’s EU regional endpoint on systems in the EU or EFTA. This regional commitment does not cover all account, usage, security and operational data of the service. Mistral may use contractually bound subprocessors. Please do not enter any special categories of personal data (Art. 9 GDPR) in the chat or FAQ.

Legal basis: Art. 6(1)(a) GDPR (consent). You can withdraw your consent at any time in the chat window or FAQ; withdrawal applies to both areas. Our website keeps the chat and FAQ history only in the current browser tab and does not store it permanently on the server. The use of your inputs for training AI models is switched off in our Mistral account. In addition, zero data retention is activated there: Mistral does not store your inputs or the generated responses beyond what is needed to answer the respective request, and the abuse monitoring that Mistral otherwise carries out as an independent controller does not take place.

16. Retention and erasure

  • Server log files: limited by volume (at most three files of 10 MB per service); older files are overwritten. There is no fixed day-based period
  • Contact and enquiry data in the email mailbox: 6 months after the enquiry has been concluded
  • Cookie consent: your choice is stored in the inspira_consent cookie in your browser (lifetime 365 days). The server-side consent log (see section 8) is kept in a separate log file, apart from the other server log files, and is retained for as long as your consent remains valid – at least 365 days, plus a buffer for the limitation period of potential claims. Only then is it deleted. This retention is the very purpose of the log: without it we could no longer demonstrate your consent even while it is still in force
  • Display options and colour scheme: locally in your browser until you reset them or clear your browser data; no server-side transmission
  • AI chat and FAQ: on our website only for the duration of the open browser tab. Because zero data retention is activated, Mistral does not store your inputs or the responses beyond processing the respective request (see section 15)
  • Booking data: in accordance with commercial and tax retention periods (6–10 years)

No storage beyond this takes place in a database of this website.

17. Transfers to third countries

The website is hosted in Germany and e-mail is sent via a provider in Germany. The AI assistant’s inference runs through Mistral’s EU regional endpoint. Account, usage, security and operational data, as well as processing by subprocessors, may nevertheless be processed outside the European Economic Area. For such transfers, Mistral’s data processing agreement provides for adequacy decisions or appropriate safeguards, in particular the EU Standard Contractual Clauses under Art. 46 GDPR.

A content security policy restricts the website’s technical connection targets to the services required for its functions. The fonts are stored on our own server; nothing is fetched from a font provider when you visit the website.

A further case triggered by you: if you load the map (section 11), your IP address may pass through the content delivery network of Cloudflare, Inc., which is based in the United States. The same applies if you click an external link and leave our website. From that point on, the privacy policy of the respective provider applies.

18. Currency and amendment of this privacy policy

This privacy policy is currently valid and dated October 2026.

As our website develops, or due to changed legal or regulatory requirements, it may become necessary to amend this privacy policy.

Authoritative version

This English text is provided for your convenience. In the event of any discrepancy, the German version shall prevail.

Last updated: October 2026