Legal
Privacy Policy
Last updated: August 2026
1. Controller
The controller for the processing of personal data on this website and in the course of hotel operations is:
Hotel am Theater UG (haftungsbeschränkt)Plzener Straße 16
07546 Gera
Germany
Place of business / hotel address:
Promenaden Hotel am Theater
Theaterstraße 4
07545 Gera
Germany
Telephone: +49 170 4790000
E-mail: info@hotel-am-theater.de
Represented by its Managing Director: Michael Olenberg
2. General information on data processing
We process personal data only where this is necessary to provide our website, to deal with enquiries, to handle bookings, to perform the accommodation contract, to comply with legal obligations or to protect legitimate interests.
Personal data means all information by which a natural person can be identified, for example name, address, telephone number, e-mail address, booking data, payment data or stay data.
3. Legal bases for processing
Personal data is processed in particular on the following legal bases:
- Art. 6(1)(b) GDPR for the performance of a contract or pre-contractual measures;
- Art. 6(1)(c) GDPR for compliance with legal obligations;
- Art. 6(1)(f) GDPR for the protection of legitimate interests;
- Art. 6(1)(a) GDPR where consent has been given.
4. Visiting our website and server log files
When you access our website, technical data is processed automatically by the web server. This may include:
- IP address,
- date and time of access,
- page accessed,
- volume of data transferred,
- browser used,
- operating system,
- referrer URL,
- host name of the accessing computer.
This data is processed in order to provide the website technically, to ensure the security of our systems and to detect malfunctions.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and stable operation of our website.
5. Hosting and technical service providers
Our website is hosted by Vercel Inc. (USA). Delivery of the site and execution of our server functions are pinned to the Frankfurt am Main region; the processing therefore takes place within the European Union.
Protection against automated access:The forms on this site (chat, booking information, payment page) run a check as to whether a request originates from a human or from a program, together with a limit on the number of requests per internet connection. In doing so, the IP address and technical characteristics of the browser are processed; for this purpose, technically necessary information may be stored in your browser’s storage. The sole purpose is to prevent abuse. No analysis of your behaviour and no advertising takes place.
The processing is carried out on the basis of Art. 6(1)(f) GDPR (secure operation of the website) and on the basis of a data processing agreement pursuant to Art. 28 GDPR.
6. Contacting us by e-mail or telephone
If you contact us by e-mail or telephone, we process the data you provide in order to deal with your enquiry. This may include:
- name,
- telephone number,
- e-mail address,
- content of the enquiry,
- preferred travel period,
- booking or stay data.
The legal basis is Art. 6(1)(b) GDPR where the enquiry relates to a booking or a stay. In other cases the processing is carried out on the basis of Art. 6(1)(f) GDPR.
7. Contacting us via WhatsApp
If you contact us via WhatsApp, we process the data you transmit in order to deal with your enquiry.
Please note that WhatsApp is an external service. When WhatsApp is used, data may be processed by the provider of that service. We have no full control over the processing of data by WhatsApp.
The use of WhatsApp is voluntary. You may contact us by telephone or e-mail instead at any time.
The legal basis is Art. 6(1)(b) GDPR where the communication serves to prepare or perform a contract. Otherwise the processing is carried out on the basis of Art. 6(1)(f) GDPR.
8. AI chat assistant “Mia”
We offer an AI-supported chat assistant (“Mia”) on our website. It is an artificial intelligence system. The chat window states that you are communicating with an AI assistant.
Mia has two functions:
- general questions about the hotel (for example breakfast, arrival, parking, rooms);
- on request, information about your own booking, following prior verification.
The following data may be processed in the course of use:
- the content of your chat messages,
- for booking information: your surname and your booking number,
- the details displayed for your booking (for example arrival and departure, room category, availability of the room) from our hotel system.
Processing by an AI provider: In order to generate the replies, your messages are transmitted to an external provider of language models whose processing takes place within the European Union (Mistral AI, France). No transfer to the USA takes place. The processing is carried out on the basis of a data processing agreement pursuant to Art. 28 GDPR.
Storage of the conversation history: With your consent, the conversation history is stored and automatically erased after 30 days. The purpose is to deal with your enquiry and to ensure quality. Without your consent, no storage and no booking information takes place.
Booking information: The booking is matched by surname and booking number. Only details of your own booking are displayed. Payment data and data relating to other guests are not disclosed through the chat.
The legal basis is your consent pursuant to Art. 6(1)(a) GDPR, which you give expressly before the chat begins. You may withdraw your consent at any time with effect for the future; the stored conversation history will then be erased.
Limits of the chat: Through the chat, Mia can neither make nor cancel bookings, cannot initiate payments and cannot issue door codes. The information about your booking is limited to the fields listed above, and the verification of surname and booking number is carried out on our server, not by the language model.
Protection against abuse: The chat and the booking information are protected by a check for automated access and by a limit on the number of requests per internet connection (see section 5).
The chat does not involve any automated decision producing legal effects within the meaning of Art. 22 GDPR.
9. Bookings and accommodation contract
If you book a room, we process the data required for the booking and for carrying out the stay. This may include:
- name,
- address,
- telephone number,
- e-mail address,
- arrival and departure date,
- room category,
- number of guests,
- payment data,
- invoicing data,
- special requests,
- communication data,
- booking number,
- stay history.
The processing is carried out in order to perform the accommodation contract on the basis of Art. 6(1)(b) GDPR.
10. Booking through our booking system and through booking portals
For bookings on this website we use the booking system Mews. The booking window only opens once you click “Reserve” or “Check availability & prices”. No connection to Mews is established beforehand. When you click, your booking details (among other things travel period, name, contact data and payment data) are transmitted to Mews and processed there on our behalf.
A separate cookie consent notice appears in the booking window. It comes from the booking system and relates only to that window (see section 15).
Our website may also link to booking portals.
If you book through an external booking system or a booking portal, your data will also be processed by the respective provider. As a rule, the respective provider is responsible for that processing insofar as it processes the data under its own responsibility.
We receive from booking portals and booking systems the data required to carry out your booking and your stay.
The legal basis is Art. 6(1)(b) GDPR.
Please also refer to the privacy information of the respective booking portal or booking service provider.
11. Payment processing
In the case of payments, we process payment data to the extent necessary to settle the payment.
Card payment via the payment page of this website: If you receive a payment link from us, you enter your card details in input fields provided directly by the payment service provider Datatrans AG (Switzerland). The card number and the verification code therefore do not reach our servers; we receive only a payment identifier. Switzerland is recognised by the European Commission as a country with an adequate level of data protection. We take the amount from your booking in our hotel system, not from the details you enter in the browser.
Depending on the method of payment, data may also be transmitted to banks, credit card companies, other payment service providers or the booking system.
The legal basis is Art. 6(1)(b) GDPR. Insofar as retention obligations under tax or commercial law exist, the processing is additionally carried out on the basis of Art. 6(1)(c) GDPR.
12. Registration data under the German Federal Registration Act
Where required by law, in particular in the case of foreign guests, we process registration data in accordance with the provisions of the Bundesmeldegesetz (German Federal Registration Act). This may include:
- date of arrival,
- expected date of departure,
- surname,
- first name,
- date of birth,
- nationality,
- address,
- identity document data, where required by law,
- number of accompanying persons, where required by law.
The legal basis is Art. 6(1)(c) GDPR in conjunction with the statutory registration duties for accommodation establishments.
13. Invoices, accounting and statutory retention
We process invoicing, payment and accounting data for the purposes of proper bookkeeping and to comply with obligations under tax and commercial law.
The legal basis is Art. 6(1)(c) GDPR.
Data is retained in accordance with the statutory retention periods.
14. Enforcement of house rules, damages and security
We may process personal data where this is necessary to enforce our house rules, to document damage, to deal with complaints, to defend against unjustified claims or to assert our own claims. This may include:
- name of the guest,
- booking data,
- stay data,
- documentation of damage,
- communication data,
- payment data,
- photographs of damage or soiling, where necessary.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in safeguarding our rights, in the security of hotel operations and in the enforcement of justified claims.
15. Cookies and storage in the browser
This website does not set any cookies. We use neither cookies for audience measurement nor cookies for advertising, and we do not integrate any analytics or tracking services. The fonts, too, are loaded from our own server and not from third parties.
The protection against automated access may store technically necessary information in your browser’s storage (see section 5). It serves solely the security of the forms and not recognition for advertising purposes.
Booking window: If you open the booking window with a click, the booking system sets its own cookies and displays its own consent notice for them. You can change your selection there within the same window. As long as you do not open the booking window, these cookies are not set.
An additional consent banner when our site is accessed is therefore not required (§ 25(2) TDDDG, German Telecommunications Digital Services Data Protection Act).
16. Map, external links and route planning
The map on our site is an image served from our own server. No map service is embedded, in particular not Google Maps. Only when you click on the map does OpenStreetMap open in a new window; from that point onwards the terms of that provider apply.
Our website may also contain links to external services, for example to booking portals or social networks.
When you click an external link, you leave our website. From that point onwards the privacy provisions of the respective provider apply.
We have no influence over the data processing carried out by external providers.
17. Social media links
Our website may contain links to social networks. If you click on these links, you will be redirected to the pages of the respective providers.
Data may be transmitted to the respective provider in the process. The respective provider is responsible for the processing carried out on the pages of the social networks.
18. Recipients of personal data
Personal data is disclosed only where this is necessary or permitted by law. Recipients may in particular be:
- our booking system (Mews),
- booking portals,
- payment service providers (Datatrans AG, Switzerland),
- banks,
- IT and hosting service providers (Vercel Inc., processing within the EU),
- the provider of the language model behind the chat assistant (Mistral AI, France),
- tax advisers,
- accounting service providers,
- cleaning and maintenance service providers, where necessary,
- public authorities, where required by law,
- lawyers or debt collection agencies, where necessary to enforce claims.
No data is disclosed for advertising purposes.
19. Transfer of data to third countries
Personal data is transferred to countries outside the European Union or the European Economic Area only where there is a legal basis for doing so, where appropriate safeguards are in place or where you have given your consent.
For the services used on this website, the following applies in detail:
- Website and server functions:The provider is Vercel Inc. (USA); the processing is pinned to the Frankfurt am Main region. The basis is a data processing agreement and the European Commission’s standard contractual clauses.
- Chat assistant Mia: Processing of the language model in France (Mistral AI). No transfer to the USA takes place.
- Card payment: Datatrans AG in Switzerland. An adequacy decision of the European Commission is in place for Switzerland.
When external services such as WhatsApp or international booking portals are used, processing outside the European Union cannot be ruled out.
20. Storage period
We store personal data only for as long as this is necessary for the respective purposes.
Where statutory retention obligations exist, the data is stored for the duration of those obligations.
Once the respective purpose ceases to apply and the statutory retention periods have expired, the data is erased or blocked.
21. Your rights
You have the following rights under the GDPR:
- the right of access,
- the right to rectification,
- the right to erasure,
- the right to restriction of processing,
- the right to data portability,
- the right to object to processing,
- the right to withdraw consent that has been given.
To exercise your rights, you may contact us at any time:
Hotel am Theater UG (haftungsbeschränkt)E-mail: info@hotel-am-theater.de
22. Withdrawal of consent
Where processing is based on your consent, you may withdraw that consent at any time with effect for the future.
The lawfulness of the processing carried out until withdrawal remains unaffected.
23. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority.
The competent authority for Thuringia is:
Thüringer Landesbeauftragter für den Datenschutz und die Informationsfreiheit (Thuringian Commissioner for Data Protection and Freedom of Information)Häßlerstraße 8
99096 Erfurt
Telephone: 0361 57-31129 00
E-mail: poststelle@datenschutz.thueringen.de
24. SSL / TLS encryption
For security reasons, this website uses SSL / TLS encryption.
You can recognise an encrypted connection by the fact that the address bar of the browser begins with “https” and a padlock symbol is displayed.
25. No automated decision-making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.
26. Currency and amendment of this privacy policy
We reserve the right to adapt this privacy policy if technical, legal or organisational changes arise.
