Privacy Policy
Last updated: March 2025
This Privacy Policy explains how Astoria Apartment ("we", "us", "our") collects, uses, and protects your personal data in accordance with the EU General Data Protection Regulation (GDPR) Articles 13 and 14.
1. Controller and Contact
The data controller is Astoria Apartment. For privacy-related inquiries, please contact us via the contact form on our website or at the details provided in our Imprint.
2. Data We Collect
We may collect:
- Contact data: Name, email address, phone number, and message content when you use our contact form
- Technical data: IP address, browser type, device information, and cookies (see our Cookie Policy)
- Usage data: Pages visited, time spent, and interaction with our site (if you consent to analytics cookies)
3. Legal Basis and Purposes
We process your data based on:
- Contract performance (Art. 6(1)(b) GDPR): To respond to inquiries and manage bookings
- Legitimate interests (Art. 6(1)(f) GDPR): To operate and secure our website
- Consent (Art. 6(1)(a) GDPR): For non-essential cookies and marketing communications
4. Data Retention
We retain personal data only as long as necessary for the purposes stated above or as required by law. Contact form submissions are typically kept for up to 24 months unless a longer retention period is required for legal or contractual reasons.
5. Your Rights (GDPR Arts. 15–22)
You have the right to:
- Access your personal data (Art. 15)
- Rectification of inaccurate data (Art. 16)
- Erasure ("right to be forgotten") (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Object to processing (Art. 21)
- Withdraw consent at any time
- Lodge a complaint with a supervisory authority
6. Data Sharing and Transfers
We do not sell your data. We may share data with service providers (e.g. hosting, email) who act as processors under GDPR. Data may be transferred outside the EEA only with appropriate safeguards (e.g. Standard Contractual Clauses).
7. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction.
8. Changes
We may update this Privacy Policy from time to time. The "Last updated" date at the top indicates when changes were last made.