Privacy Policy — hotelsinberlins.de
17.07.2026
Preliminary, important (not part of the published statement):
- I am not a lawyer. This text is a structured, standard GDPR privacy policy — it should be reviewed by a lawyer or a specialized firm before publication, especially regarding point 2.
- The responsible party question must be clarified first. LAC Hotel Advisory Co., Ltd. is formally a Vietnamese company. If this company operates the website, Article 3, paragraph 2 of the GDPR applies (offering to individuals in the EU) and possibly Article 27 GDPR — obligation to designate an EU representative. If, on the other hand, you operate the site as a sole entrepreneur based in Berlin, this obligation is eliminated. This decision determines Section 1 and must be made before going live. The explanation below contains both variants.
- Slots: Hosting provider, newsletter service, analytics tool, and consent solution are marked as
[SLOT]— enter what is actually in use, and delete any section of services you do not use. A privacy policy that names services that are not running is just as faulty as one that omits ongoing services.
1. Responsible Party
Variant A — Berlin Sole Proprietorship (use when you run the page personally/as a German company):
Responsible for data processing on this website is: Loan Anh
2. General Information on Data Processing
We generally process personal data of our visitors only to the extent necessary to provide a functional website as well as our content and services. Legal bases are, depending on the type of processing, Art. 6 para. 1 lit. a (consent), lit. b (contract or pre-contractual measures), and lit. f (legitimate interest) of the GDPR. The applicable legal basis for each processing activity is specified below.
3. Hosting and Server Log Files
This website is hosted by: WordPress. There is a contract with the provider for data processing in accordance with Art. 28 GDPR.
When the website is accessed, the server automatically collects information in so-called server log files: IP address, date and time of access, accessed page, referrer URL, browser used, and operating system. This data is not merged with other data sources. The processing is based on Art. 6 para. 1 lit. f GDPR; our legitimate interest lies in the technical provision and security of the website. The log files are deleted after [e.g. 7 / 14 / 30] days.
4. Contact Information
When contacting us via email or contact form, the data you provide (name, email address, content of the message, and any voluntary information) will be stored for processing your request and for follow-up questions. The legal basis is Article 6(1)(b) of the GDPR, if the request is aimed at concluding a contract; otherwise, it is Article 6(1)(f) of the GDPR (legitimate interest in responding to inquiries). The data will be deleted as soon as it is no longer necessary for processing and no statutory retention obligations prevent this. No disclosure to third parties will occur.
5. Newsletter („The Brief”)
We use the double opt-in procedure for subscribing to our newsletter: After your registration, you will receive an email in which you confirm your subscription. Your email address, the time of registration and confirmation, as well as the IP address at the time of registration (to verify consent) will be processed. The legal basis is your consent, Art. 6 Para. 1 lit. a GDPR.
You can unsubscribe from the newsletter at any time using the unsubscribe link in any email or by sending us a message; the legality of the processing carried out until the revocation remains unaffected. After unsubscribing, your email address will be removed from the distribution list unless retention is necessary to prove the original consent.
6. Cookies and Consent Management
This website uses only technically necessary cookies that are required for the operation of the site. The legal basis is § 25 Abs. 2 TDDDG in conjunction with Art. 6 Abs. 1 lit. f GDPR. Therefore, a consent banner is not required.
7. Web Analytics
We use Google Analytics for the statistical evaluation of the use of this website.
8. Embedded Third-Party Content (YouTube)
We embed videos from YouTube (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) on individual pages. The embedding takes place in enhanced privacy mode; a connection to YouTube’s servers is only established when you actively play a video. In doing so, personal data (e.g., IP address) may be transmitted to Google, also to the USA. The legal basis is your consent by starting the video, Article 6(1)(a) of the GDPR. Further information: https://policies.google.com/privacy
9. Links to Social Networks
Diese Website enthält Links zu unseren Profilen bei LinkedIn, Facebook und Pinterest. Es handelt sich um reine Verlinkungen ohne eingebettete Plugins; beim Besuch unserer Website werden keine Daten an diese Netzwerke übertragen. Erst mit dem Klick auf einen Link verlassen Sie unsere Website; es gelten dann die Datenschutzbestimmungen des jeweiligen Anbieters.
10. Storage Duration
As long as no specific storage duration is mentioned in this declaration, personal data will remain with us until the purpose of processing no longer applies. Legal retention obligations (especially commercial and tax law deadlines of 6 or 10 years for business correspondence and invoices) remain unaffected; the data in question will be blocked for the duration of these deadlines and subsequently deleted.
11. Your Rights
You have the following rights regarding your personal data: the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), as well as the right to withdraw your consent at any time with effect for the future (Art. 7 para. 3 GDPR).
Right to Object (Art. 21 GDPR): As far as we process data on the basis of Art. 6 para. 1 lit. f GDPR, you have the right to object at any time to the processing on grounds relating to your particular situation.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). Responsible for Berlin: Berlin Commissioner for Data Protection and Freedom of Information, Alt-Moabit 59–61, 10555 Berlin.
12. Data Security
This website uses SSL/TLS encryption. Data that you transmit to us cannot be intercepted by third parties. Furthermore, we take technical and organizational measures in accordance with Article 32 of the GDPR to protect your data against loss, destruction, and unauthorized access.
13. Changes to this Privacy Policy
We will adapt this privacy policy as soon as changes to data processing or legal circumstances make it necessary. The version published on this page applies at all times.