Legal
Privacy Policy
Information on the processing of personal data pursuant to the GDPR — as of June 2026
Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws of the member states, as well as other data protection provisions, is:
Kaliorexi UG (haftungsbeschränkt)Birkenstraße 25
76846 Hauenstein
Deutschland
Represented by: Jutta Scheib
Phone: 06392 9129980
Email: info@kaliorexi.online
If you have any questions about data protection, you can contact us at any time using the contact details given above.
Hosting
This website is hosted by an external service provider (host). The personal data collected on this website is stored on the host's servers. This may include, in particular, IP addresses, contact requests, meta and communication data, contract data, contact details, names, website access data, and other data generated through a website.
IONOS SEElgendorfer Str. 57
56410 Montabaur
Deutschland
IONOS Privacy Policy
The host is used for the purpose of fulfilling our contracts with prospective and existing customers (Art. 6(1)(b) GDPR) and in the interest of a secure, fast, and efficient provision of our online offering by a professional provider (Art. 6(1)(f) GDPR). A data processing agreement (DPA) pursuant to Art. 28 GDPR has been concluded with the host.
Collection of General Data and Information (Server Log Files)
Each time our website is accessed, our system automatically collects data and information from the accessing computer system. The following data is collected:
- Browser type and version used
- the operating system used
- the website from which an accessing system reaches our website (referrer)
- the time of access to the website
- a shortened IP address
- internet service provider of the accessing system
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the technically error-free presentation and optimization of our website, as well as ensuring system security).
Retention period: Server log files are stored for a period of 7 days and then automatically deleted, unless further retention is required for evidentiary purposes.
Cookies
Our website uses cookies. Cookies are small text files that are stored on your device and saved by your browser. Cookies do not cause any damage to your device and do not contain viruses. We use cookies, among other things, for the following purposes:
- to ensure the basic functionality of our website (e.g. login status, language setting)
- to analyze user behavior in order to improve our offering
- to store your cookie preferences
Legal basis: Art. 6(1)(c) GDPR in conjunction with Section 25(2) TTDSG (technically necessary cookies) or Art. 6(1)(a) GDPR (consent, for non-essential cookies).
Retention period: The storage period depends on the individual cookie and can range from the duration of the session to several months. Please see Section 13 of this policy for details.
Contacting Us
When you contact us, e.g. via a contact form, email, or telephone, the information you provide (including name, email address, and message text) is stored by us in order to process your inquiry and in case of follow-up questions. The following data is collected:
- Name
- Email address
- Phone number, if applicable
- Content of the message
Legal basis: Art. 6(1)(b) GDPR (pre-contractual/contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in processing inquiries addressed to us).
Retention period: We do not share this data without your consent and delete it once the purpose for which it was stored no longer applies, at the latest once your inquiry has been resolved, unless statutory retention obligations require otherwise.
Registration and User Account
Users can create a user account on our website in order to manage bookings, submit reviews, or save hotels. The following data is collected during registration:
- Name
- Email address
- Password (stored encrypted)
- Time of registration
The data entered during registration is used for the purposes of using our offering. Users may be informed about relevant information, such as booking confirmations, via system messages.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract or carrying out pre-contractual measures).
Payment Processing via Stripe
We use the payment service provider Stripe to process payments:
Stripe Payments Europe, Limited
1 Grand Canal Street Lower, Grand Canal Dock
Dublin, D02 H210, Irland
If you select Stripe as your payment method during the booking process, the data you enter is transmitted to Stripe. This specifically includes:
- Name
- Billing address
- Payment details (e.g. credit card details or bank account information)
- Transaction amount
The transmission of data is carried out for the purpose of payment processing. Stripe is certified according to the PCI DSS standard (Payment Card Industry Data Security Standard).
Legal basis: Art. 6(1)(b) GDPR (contract performance).
Retention period: For further information on data processing by Stripe, please see Stripe's privacy policy: https://stripe.com/de/privacy
Note: For data transfers to the USA, Stripe has agreed to appropriate safeguards in the form of EU standard contractual clauses.
Booking Processing
When you book accommodation through our platform, we process the data necessary to carry out the booking and transmit it to the respective hotel operator. In particular, the following data is processed:
- Names of the guests
- Arrival and departure dates
- Room category and number of guests
- Contact details (email address, phone number)
- Special requests (e.g. purpose of travel — business or private)
Legal basis: Art. 6(1)(b) GDPR (contract performance, as the booking mediates a contract between you and the respective hotel operator).
Retention period: Booking data is stored for the duration of the statutory retention periods, in particular under commercial and tax law (generally 6 to 10 years).
Review Feature
Registered users can submit reviews of hotels on our platform. The following data is processed:
- Username or displayed name
- Review text and star rating
- Time of the review
- Reference to the underlying booking
Submitted reviews are publicly displayed on the respective hotel page.
Legal basis: Art. 6(1)(a) GDPR (consent) or Art. 6(1)(f) GDPR (legitimate interest in providing a review system).
Retention period: Reviews are stored for as long as the user account exists, or until the user requests deletion of the review.
Hotel Provider Account (Dashboard)
Hotel operators who wish to offer their accommodations on our platform can create a business account (dashboard). The following data is processed:
- Company name and legal form
- Contact details of the responsible person
- Commercial register details or trade registration
- Bank details for payouts
- Information on the accommodations, rooms, and availability offered
Legal bases:
- Art. 6(1)(b) GDPR (contract performance in connection with the use of the platform)
- Art. 6(1)(c) GDPR (compliance with legal obligations, e.g. tax-related documentation requirements)
Retention period: Data is stored for the duration of the business relationship and in accordance with statutory retention periods.
Login Session
To keep you logged in during a visit, we use a technically necessary session token, which is stored locally in your browser and authenticates you to our system as a logged-in user.
Legal basis: Art. 6(1)(b) GDPR (contract performance) in conjunction with Art. 6(1)(f) GDPR (legitimate interest in a user-friendly and secure login feature).
Retention period: The session token is deleted as soon as you log out, or at the latest after the technically defined validity period expires.
Newsletter
If you have subscribed to our newsletter, we use your email address to regularly send you information about our offerings.
For registration, we use the double opt-in procedure, i.e. we only send an email to the address you provided once you have confirmed your registration by clicking a link contained in that email. The following data is collected:
- Email address
- Time of registration
- IP address at the time of registration (double opt-in verification)
Legal basis: Art. 6(1)(a) GDPR (consent).
Revocation: You can revoke your consent at any time with future effect by clicking the unsubscribe link at the end of each newsletter or by contacting us at info@kaliorexi.online.
Retention period: Your data is stored for the duration of the subscription and deleted after you unsubscribe.
Provider: The newsletter is sent via a technical service provider with whom a data processing agreement pursuant to Art. 28 GDPR has been concluded.
Overview of Cookies Used
Below you will find a detailed overview of the cookie categories we use.
Necessary Cookies
- session_token Stores your login status so you don't need to log in again during your visit.
- cookie_consent Stores your selection in the cookie banner.
- locale Stores your preferred language (German, English, or French).
Legal basis: Art. 6(1)(c) GDPR in conjunction with Section 25(2) No. 2 TTDSG.
Functional Cookies
- recently_viewed Stores recently viewed hotels to improve your navigation experience.
- search_preferences Stores your most recently used search filters (e.g. travel period, number of guests).
Legal basis: Art. 6(1)(a) GDPR (consent).
You can revoke or adjust your consent to functional cookies at any time via our cookie banner.
Google Maps
We use the map service Google Maps on our website. The provider is:
Google LLC1600 Amphitheatre Parkway
Mountain View, CA 94043, USA
When you visit a page that has a Google Maps map embedded, the following data is transmitted to Google:
- IP address
- Location data (if authorized by you)
- Interactions with the map (e.g. zooming and panning)
This transmission occurs regardless of whether Google provides a user account and whether you are logged in. If you are logged into Google, your data is directly linked to your account.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in an appealing presentation of our location-based offerings).
Retention period: The storage period is determined by Google and is outside our control.
Objection: You can prevent data collection by Google Maps by disabling JavaScript in your browser or installing a JavaScript blocker. For more information, see Google opt-out as well as Google's ad settings.
For more information on how Google handles user data, see Google's privacy policy: https://policies.google.com/privacy
Note: Google also processes data in the USA; Google has certified its compliance with the EU-U.S. Data Privacy Framework.
Recipients of Data
In the course of our business activities, we share your personal data with the following categories of recipients, insofar as this is necessary to provide our services:
- Hotel operators: the accommodation you book receives the data necessary to process your reservation.
- Payment service providers: for processing payments (Stripe Payments Europe, Limited).
- Hosting provider: for the technical operation of our website (IONOS SE).
- Authorities: insofar as we are legally obliged to provide information, reports, or data.
Data is only shared with other third parties if you have given your effective prior consent or if there is a legal obligation to do so.
Data Transfers to Third Countries
In some cases, data is also transmitted to service providers outside the European Union or the European Economic Area (so-called third countries). This concerns, in particular, the following providers:
- Google LLC (USA): in connection with the use of Google Maps.
- Stripe, Inc. (USA): in connection with payment processing, handled via the European subsidiary Stripe Payments Europe, Limited.
In these cases, we ensure an adequate level of data protection through appropriate safeguards, in particular EU standard contractual clauses pursuant to Art. 46 GDPR. Further information is available on request at info@kaliorexi.online.
Retention Periods at a Glance
| Data category | Retention period |
|---|---|
| Server log files | 7 days |
| User account data | Until the account is deleted |
| Booking data | 6–10 years (statutory retention periods) |
| Payment data | In accordance with the payment provider's retention periods |
| Newsletter data | Until unsubscribed |
| Review data | Until deleted by the user or account deletion |
| Contact inquiries | Until the inquiry is resolved, max. 3 years |
Your Rights as a Data Subject
You have the following rights with regard to the processing of your personal data:
- Right of access: You have the right to request information about the personal data we process (Art. 15 GDPR).
- Right to rectification: You can request the correction of inaccurate data or the completion of incomplete data (Art. 16 GDPR).
- Right to erasure: You can request the deletion of your data, provided no statutory retention obligations apply (Art. 17 GDPR).
- Right to restriction of processing: Under certain conditions, you can request that the processing of your data be restricted (Art. 18 GDPR).
- Right to data portability: You have the right to receive the data you provided in a structured, commonly used, and machine-readable format (Art. 20 GDPR).
- Right to object: You can object at any time to the processing of your data carried out on the basis of legitimate interests (Art. 21 GDPR).
- Right to withdraw consent: You can withdraw any consent given at any time with future effect (Art. 7(3) GDPR).
To exercise these rights, please contact: info@kaliorexi.online
Right to Lodge a Complaint with a Supervisory Authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, place of work, or the place of the alleged infringement, if you believe that the processing of personal data relating to you infringes the GDPR. The supervisory authority responsible for us is:
Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-PfalzHintere Bleiche 34
55116 Mainz
E-Mail: poststelle@datenschutz.rlp.de
www.datenschutz.rlp.de
Obligation to Provide Data
The provision of your personal data is in part required by law or may also result from contractual arrangements. For example, in order to complete a booking, it is necessary for you to provide us with the personal data required to carry out the contract. Without this data, we will not be able to conclude the respective contract with you.
Automated Decision-Making
As a general rule, we do not use automated decision-making or profiling to produce legal effects concerning you. However, to improve our offering, we do use automated processes to a limited extent, including for:
- sorting and prioritizing search results based on location, availability, and rating
- detecting fraudulent or abusive booking attempts
These processes do not result in any legal or similarly significant effect on you within the meaning of Art. 22 GDPR.
Data Security
We take appropriate technical and organizational measures to protect your data against accidental or intentional manipulation, loss, destruction, or access by unauthorized persons. These measures include, in particular:
- encryption of data transmission using TLS/SSL
- encryption of stored passwords
- regular security updates and access controls
- restricting data access to authorized employees
Our security measures are continuously improved in line with technological developments.
Changes to This Privacy Policy
We reserve the right to amend this privacy policy so that it always complies with current legal requirements, or to implement changes to our services in the privacy policy, e.g. when introducing new features. The new privacy policy will then apply to your next visit.