Privacy Policy
Introduction
Last updated: 24 July 2026
With this privacy notice we inform guests and users of our booking platform about the processing of personal data in connection with
the booking and completion of stays in the studio apartments of Motz19,
visiting and using our website,
visiting and using our social media profiles.
We reserve the right to amend this privacy notice in the event of legal or technical changes. The current version is available at any time on our website. In the event of significant changes, we will inform you in an appropriate manner.
Section I – Scope, Controller and Data Protection Officer
1. Scope and Definitions
This privacy notice applies to the processing of personal data by B&S SmartStay GmbH (“Motz19”) as the controller under data protection law in connection with the booking and completion of stays in hotel rooms and studio apartments, the visit to and use of the website www.motz19.de including all subpages, as well as within our external online presences such as social media profiles (“Online Offering”).
This privacy notice does not apply to websites or offerings of other providers to which we merely refer by way of a link (e.g. third-party online booking platforms (OTAs), payment services, messenger services). These providers are themselves responsible for the processing of personal data when their respective websites are used. We recommend that you observe the privacy notices on the respective websites of these other providers, to which we refer at the relevant points.
The data protection terms used in this notice (e.g. “personal data”, “processing”, “controller”, “processor”) are used as defined in Art. 4 GDPR.
2. Controller
The controller within the meaning of Art. 4 No. 7 GDPR is:
B&S SmartStay GmbH
Lietzenburger Straße 54
10719 Berlin
E-mail: info@motz19.de
Website: www.motz19.de
3. Data Protection Officer
No data protection officer has currently been appointed. If you have any questions or concerns regarding data protection, please contact info@motz19.de.
Section II – Processing Operations in Connection with Booking and Stay
4. Registration and User Account
Guests can optionally create a user account on our booking platform to manage their bookings. Optionally, it is possible to sign in via an existing Google or Apple account.
Categories of data:
For e-mail registration: first and last name, e-mail address, self-chosen password (stored in encrypted form)
When using the social login: first and last name, e-mail address and pseudonymised account ID of the respective provider (Google/Apple).
Purpose: We process your data in order to set up and manage your user account and to enable you to make bookings, manage your bookings and complete the digital check-in via our booking platform.
Legal basis: The processing of your registration data is based on Art. 6(1)(b) GDPR (performance of a contract), as it is necessary for the performance of the user relationship. If you additionally use the social login of Google or Apple, we also base the processing on your consent pursuant to Art. 6(1)(a) GDPR (your consent). You may withdraw your consent at any time with effect for the future (see Section 20).
Storage period: We store your user account data for the duration of the user relationship. Your account data will be deleted if you delete your account or ask us to delete it. To the extent that data is further required to comply with statutory retention obligations or to secure, assert or defend legal claims, it will continue to be stored for the duration of the applicable statutory period (see Section 19).
Recipients: For the technical operation of the booking platform we use the service “Supabase” of the provider Supabase Pte. Ltd., 65 Chulia Street, #38-02/03, OCBC Centre, Singapore 049513, on the basis of a data processing agreement concluded with Supabase. Supabase provides the technical infrastructure for user authentication (login function) and for operating the database of our platform. The database is hosted via Amazon Web Services, Inc. (AWS) in an EU region, i.e. the data is stored in the EU. Even with EU-based hosting, the processing of personal data in third countries without a recognised adequate level of data protection (in particular Singapore) cannot be completely ruled out in the course of Supabase providing its services. Such third-country transfers take place on the basis of the EU standard contractual clauses pursuant to Implementing Decision (EU) 2021/914 of the European Commission to ensure the required level of data protection (Art. 46(2)(c) GDPR). Further information on data protection at Supabase can be found at https://supabase.com/privacy.
If you use the social login (Google / Apple), we transmit the data required for authentication to the responsible company of the respective provider. For users in the European Economic Area (EEA), these are Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Google login) and Apple Distribution International Limited, Hollyhill Industrial Estate, Hollyhill, Cork, Ireland (Apple login); for users outside the EEA, this is the respective Google or Apple company with which you hold your account. In this respect, these providers act as independent controllers. Further information on data protection at Google can be found at https://policies.google.com/privacy and at Apple at https://www.apple.com/privacy/.
Obligation to provide data: Providing a valid e-mail address and a password is a prerequisite for setting up a user account. Setting up a user account is optional. A booking is also possible without a user account as a guest. For bookings made via external booking platforms (OTAs), the information set out below under Section 5.2 applies.
5. Booking and Conclusion of Contract
Bookings can be made directly via our platform (direct booking) or via external online booking platforms (OTAs). All booking and guest data is managed centrally in the property management system Apaleo.
5.1 Direct booking via the Motz19 platform
Categories of data: In the context of a direct booking, we process the guest’s first and last name, e-mail address, telephone number and billing address (including, where applicable, company name and address). In addition, we record the arrival and departure dates, the number of accompanying travellers, the booked services and additional options (e.g. pet, early check-in, late check-out), the booking reference and transaction data for payment processing (see Section 7).
Purpose: We process your data in order to conclude, perform and settle the accommodation contract with you, to handle your stay in our hotels and studio apartments, and to be able to issue you a proper invoice.
Legal basis: The processing is based on Art. 6(1)(b) GDPR, as it is necessary for the conclusion and performance of the accommodation contract, including pre-contractual measures taken at your request.
Storage period: Your data is generally stored until the contract has been fully settled and all mutual claims have been resolved (as a rule, after expiry of any warranty and limitation periods). In addition, we store the information required under statutory retention obligations, in particular under commercial and tax law, for the duration of the statutorily prescribed periods (as a rule, 6 years for commercial or business letters and tax-relevant documents and information, and 8 years for accounting records). Longer storage may take place in individual cases where this is necessary to assert, exercise or defend legal claims.
Recipients: We process the booking and guest data in our property management system “Apaleo” of the provider apaleo GmbH (see Section 5.4). For payment processing, we transmit the necessary transaction data to Adyen N.V. (see Section 7). For communication, the recipients named under Section 9 apply.
Obligation to provide data: The provision of the aforementioned data is necessary for the conclusion of the accommodation contract. Without this data, we cannot conclude or perform the contract.
5.2 Booking via online booking platforms (OTAs)
Bookings can also be made via external booking platforms (OTAs) such as Booking.com, Expedia, Airbnb or Agoda. The OTAs act as independent controllers; their respective privacy policies apply to the data processing carried out there.
Categories of data: If your booking is made via an OTA, we receive from it the booking data required for the performance of the contract, in particular the guest’s title, first and last name, e-mail address (where applicable, an internal OTA communication address), telephone number and billing address (including, where applicable, company name and address). We also receive the booking reference, arrival and departure dates, the number of accompanying travellers and the booked services and additional options (e.g. pet, early check-in, late check-out).
Purpose: We process the data transmitted by the OTA in order to conclude, perform and settle the accommodation contract with you, to handle your stay in our hotels and studio apartments, and to be able to issue you a proper invoice.
Legal basis: The processing is based on Art. 6(1)(b) GDPR, as it is necessary for the conclusion and performance of the accommodation contract.
Storage period: The storage periods described under Section 5.1 apply.
Recipients: We process the booking and guest data in our property management system “Apaleo” of the provider apaleo GmbH (see Section 5.4). For payment processing, we transmit the necessary transaction data to Adyen N.V. (see Section 7). For communication, the recipients named under Section 9 apply.
Origin of the data: The data is transmitted by the respective OTA on the basis of the booking you made there; we have no influence on the nature and scope of this transmission.
Obligation to provide data: The provision of the aforementioned data is necessary for the conclusion of the accommodation contract. Without this data, we cannot conclude or perform the contract.
5.3 Enquiries via the group and corporate booking form (Group & Corporate Bookings)
On our website we offer an enquiry form for group and corporate bookings. Interested parties can use this form to submit a non-binding enquiry for a group or corporate booking.
Categories of data: In the context of the enquiry form, we collect your name, your e-mail address, your telephone number, the desired number of guests and rooms, the travel dates and any information provided in a free-text field.
Purpose: We process your data in order to handle your group enquiry and to provide you with an individual offer. If a booking is made, we also process the data in order to conclude, perform and settle the accommodation contract with you, to handle the stay in our hotels and studio apartments, and to be able to issue you a proper invoice.
Legal basis: The processing is based on Art. 6(1)(b) GDPR, as it is necessary for preparing the offer (pre-contractual measures taken at your request) and for the conclusion and performance of the accommodation contract. If you yourself are not our contractual partner, but rather your employer or client is, your data is processed on the basis of Art. 6(1)(f) GDPR. Our legitimate interest results from the need to process this data for the purpose of handling your enquiry.
Storage period: Your enquiry data is stored until your enquiry has been conclusively handled. If no contract is concluded, the data will be deleted after the pre-contractual communication has ended and any limitation periods have expired. If a contract is concluded, the storage periods described under Section 5.1 apply.
Recipients: We process the booking and guest data in our property management system “Apaleo” of the provider apaleo GmbH (see Section 5.4). For payment processing, we transmit the necessary transaction data to Adyen N.V. (see Section 7). For communication, the recipients named under Section 9 apply.
Obligation to provide data: Providing the data marked as mandatory fields is necessary for processing your enquiry. Use of the enquiry form is voluntary.
5.4 Management in the property management system (Apaleo)
For the central management of bookings, guest data and operational processes, we use the property management system “Apaleo” of apaleo GmbH.
Categories of data: In Apaleo, your first and last name, your contact details, booking and stay data, the room assignment as well as invoice and, where applicable, company information are processed.
Purpose: We use Apaleo to centrally manage bookings, guest data and operational processes, to properly settle accommodation contracts and to issue invoices.
Legal basis: The processing in Apaleo is based on Art. 6(1)(b) GDPR insofar as it is necessary for the performance of the accommodation contract, and on Art. 6(1)(c) GDPR insofar as the data processing is necessary to comply with legal obligations (in particular under registration, commercial or tax law).
Storage period: The storage periods described under Section 5.1 apply.
Recipients: The recipient of the data is apaleo GmbH, Dachauer Straße 15A, 80335 Munich, which we engage on the basis of a data processing agreement. The processing takes place exclusively on servers within the European Union.
Obligation to provide data: The processing of your booking and guest data in Apaleo is technically necessary for the performance of the accommodation contract and cannot be excluded.
6. Digital Check-in and Identity Verification
Motz19 operates accommodation without a physical reception. Check-in and identity verification are carried out exclusively digitally via the Guestway platform. Completing the full digital check-in is a mandatory prerequisite for access to the booked unit.
6.1 Online check-in
Once your booking has been confirmed by Motz19, you will receive a personalised check-in link from Guestway through which you can complete the digital check-in. During check-in, you enter your personal details, verify your identity as the main guest (see Section 6.2) and confirm our house rules.
Categories of data: In the context of the digital check-in, we collect and process your first name, last name, e-mail address, mobile phone number, date of birth, nationality and address (street, city, postal code). In addition, the names of your accompanying travellers are recorded. The main guest’s confirmation of our general terms and conditions and house rules is also documented.
Purpose: We process your data in order to enable you to complete the digital check-in, to verify your identity as the main guest, to document the confirmation of our house rules, to comply with our contractual and legal obligations in the context of performing the accommodation contract (in particular the registration obligations under the BMG (German Federal Registration Act), see Section 6.2) and to grant you access to the booked unit after successful check-in.
Legal basis: The processing of your personal data is based on Art. 6(1)(b) GDPR, as the digital check-in is necessary for the performance of the accommodation contract. Insofar as we are legally obliged to collect registration form data for foreign guests, we additionally base the processing on Art. 6(1)(c) GDPR in conjunction with sections 29, 30 BMG.
Storage period: The storage periods described under Section 5.1 apply. For registration form data, the one-year period under section 30(4) BMG also applies (see Section 6.2).
Recipients: To carry out the digital check-in, we use the platform “Guestway” of the provider Guestway BV, Soenenspark 1, 9051 Ghent, Belgium, on the basis of a data processing agreement concluded with Guestway. The production data is hosted via Amazon Web Services, Inc. (AWS) within the European Economic Area (EEA). Insofar as processing takes place in a country outside the EEA that does not offer an adequate level of data protection comparable to that of the EU, the transfer is generally safeguarded by the EU standard contractual clauses pursuant to Implementing Decision (EU) 2021/914 of the European Commission to ensure the required level of data protection (Art. 46(2)(c) GDPR).
Obligation to provide data: The complete provision of the check-in data is a mandatory prerequisite for access to the booked unit. Without a successfully completed online check-in, access is not possible. In this case, Motz19 is entitled to refuse access.
6.2 Identity / ID document verification
As part of the digital check-in, the main guest is obliged to verify their identity. Identity verification is carried out by default by uploading a valid photo ID (front and back) via the Guestway platform. As an alternative for guests who do not wish to upload their ID, it is possible to present the identity document live in a video call; in this case, the identity check is carried out manually by Motz19 staff.
Categories of data:
For ID verification by upload, an image of the main guest’s identity document (front and back) and the data automatically extracted from it (in particular name, date of birth, nationality, document number and validity) are processed by the service provider Didit (see under “Recipients” below). After the check has been completed, only the result of the verification (identity confirmed / not confirmed) is transmitted to Motz19.
For the alternative identity check in a video call, the presented identity document and the information it contains are viewed and compared by our staff. After the check has been completed, only the result (match successful – yes/no) is documented.
Purpose: We process your ID data in order to verify your identity as the main guest and to verify guest information, to prevent fraudulent bookings and to ensure the protection of our property. For foreign guests, the ID verification additionally serves to fulfil the statutory registration obligations under the German Federal Registration Act (BMG).
Legal basis: The legal basis for the processing of the verification and ID data is Art. 6(1)(b) GDPR (performance of a contract) and, in addition, Art. 6(1)(f) GDPR (legitimate interest). Our legitimate interest lies in maintaining the digital operation of our accommodation, protecting our property and preventing fraudulent bookings. You may object to the processing of your data based on Art. 6(1)(f) GDPR under the conditions of Art. 21 GDPR (on the right to object, see Section 20). For foreign guests, we additionally base the comparison and processing of the ID and registration data on Art. 6(1)(c) GDPR in conjunction with sections 29(2), (3), 30 BMG.
Storage period: ID images and the data automatically extracted from them are processed exclusively transiently during the check-in process and are deleted immediately after completion of the digital check-in. The storage periods described under Section 5.1 apply to the result of the ID verification (identity confirmed / not confirmed). Identity documents and copies thereof are not stored permanently. For the registration form data collected from foreign guests, a statutory retention period of one year from the day of departure applies; the data is destroyed within three months after expiry of this period (section 30(4) BMG; total period max. 15 months from departure).
Recipients: To carry out the digital check-in, we use the platform “Guestway” of the provider Guestway BV, Soenenspark 1, 9051 Ghent, Belgium, on the basis of a data processing agreement concluded with Guestway. The production data is hosted via Amazon Web Services, Inc. (AWS) within the European Economic Area (EEA). The automated ID verification by upload is additionally carried out by the third-party provider Didit Identity Spain, S.L., CIF B22929327, Calle Nápoles 227, P. 1, 08013 Barcelona, Spain. Insofar as the identity check takes place in a video call, the video conferencing service used may need to be named as a further recipient. Upon official request, the registration form data of foreign guests is transmitted to the competent registration authority (section 29(4) BMG).
Obligation to provide data: Identity verification of the main guest is contractually mandatory; for foreign guests, identity verification is also legally required pursuant to section 29(3) BMG. The main guest can choose between uploading the identity document via the Guestway platform and presenting the identity document in a video call. Refusal of the identity check entitles Motz19 to refuse access to the booked unit.
7. Payment Processing (Adyen)
Payments are processed exclusively via the payment service “Adyen”. The payment form of the payment service provider Adyen N.V. is embedded directly into our checkout page; your payment data is transmitted directly to Adyen via this embedded payment form. Credit/debit cards and digital payment options (e.g. Apple Pay, Google Pay) are accepted. Adyen N.V. is itself the controller within the meaning of Art. 4 No. 7 GDPR for the processing of your payment data in the context of payment processing. For information on data protection in connection with payment processing by Adyen N.V., please refer to Adyen’s privacy notice: https://www.adyen.com/privacy-policy
Categories of data: Adyen collects and processes your payment data for payment processing. After you select the payment method, we automatically transmit to Adyen – depending on the selected payment method – the data required for the payment method you have chosen: title, first and last name, billing and delivery address, telephone number, e-mail address, description of the service, payment amount and currency. Your credit card data is encrypted by Adyen upon collection, so that we have no access to this data at any time. After completion of the payment process, Adyen informs us whether the payment was processed properly. In the context of the payment process, Motz19 processes only the following data: payment amount, time of payment, payment method, transaction status and reference, and the booking reference. Full credit card numbers or other complete payment data are not stored by Motz19.
Purpose: We process your payment data in order to securely process the payment for booked accommodation services and additional services (e.g. early check-in, late check-out, pet).
Legal basis: The processing is based on Art. 6(1)(b) GDPR, as it is necessary for the performance of the accommodation contract.
Storage period: We store transaction data for the duration of the statutory retention periods under commercial and tax law (as a rule, 8 years for accounting records pursuant to section 257(4) HGB (German Commercial Code) and section 147(3) AO (German Fiscal Code)). Adyen’s privacy notice applies to the storage period of the data held by Adyen.
Recipients: The recipient of the data is the payment service provider Adyen N.V., Simon Carmiggeltstraat 5-60, 1011 DJ Amsterdam, Netherlands, as controller within the meaning of Art. 4 No. 7 GDPR. For information on data processing by Adyen, please refer to Adyen’s privacy notice at https://www.adyen.com/privacy-policy.
Obligation to provide data: Under our general terms and conditions, payment must be made in advance and is therefore necessary for the use of our accommodation services. Without payment, a booking is not possible.
8. Digital Access System and Access Logs
Access to the booked unit and to communal areas is provided exclusively via digital access codes, which are managed via the electronic access system “Salto KS”.
Categories of data: In connection with the digital access system, we process your name, your period of stay, the room assignment and the access code, as well as access logs (which code opened which door at what time).
Purpose: We process your data in order to give you access to the booked unit and to the communal areas via the digital access code. The logging of access events serves the security of the property and of our guests, the traceability and investigation of security-related incidents, and the assertion of and defence against claims of the guest or other third parties in connection with the booking and the stay (in particular card chargebacks and payment disputes). At Motz19, only persons at management level have access to the access logs.
Legal basis: The processing for assigning and managing the access code is based on Art. 6(1)(b) GDPR, as it is necessary to enable access to the booked unit and thus for the performance of the accommodation contract. The legal basis for the logging of access events is Art. 6(1)(f) GDPR (legitimate interests). Our legitimate interests lie in the security of the property and of our guests, the traceability and investigation of security-related incidents, and the assertion of and defence against legal claims, in particular in the case of card chargebacks and payment disputes. As Motz19 operates its accommodation without a physical reception, access logs serve in individual cases as evidence in the case of damage discovered late, payment disputes or other mutual legal claims. You may object to the processing of your data based on Art. 6(1)(f) GDPR under the conditions of Art. 21 GDPR (on the right to object, see Section 20).
Storage period: Digital access codes are automatically deactivated and deleted at the end of the stay. Access logs are deleted 90 days after departure, unless a security-related incident or another legitimate reason (e.g. open payment disputes) requires longer retention.
Recipients: To operate the digital access system, we use the cloud-based access control solution “SALTO KS” of the provider Salto Systems, S.L. (C/ Arkotz 9 Pol. Lanbarren 20180 Oiartzun (Gipuzkoa), Spain) on the basis of a data processing agreement concluded with Salto Systems, S.L. Within the framework provided by law, data may be transmitted to law enforcement authorities. Insofar as processing takes place in a country outside the EEA that does not offer an adequate level of data protection comparable to that of the EU, the transfer is generally safeguarded by the EU standard contractual clauses pursuant to Implementing Decision (EU) 2021/914 of the European Commission to ensure the required level of data protection (Art. 46(2)(c) GDPR).
Obligation to provide data: The use of the digital access system is inseparably linked to the accommodation contract; a physical alternative is not provided. The issuing of an access code requires the successful completion of the digital check-in.
9. Guest Communication
Communication with guests takes place by e-mail, via WhatsApp Business and via automated messages before, during and after the stay.
9.1 Email communication / communication via the OTA platform
Categories of data: In the context of e-mail communication or – in the case of a booking via an external booking platform (OTA), see Section 5.2 – we process your name, your e-mail address (alternatively, in the case of an OTA booking: the OTA e-mail address, where applicable) and the content of the messages exchanged.
Purpose: We process your data in order to communicate with you in the context of the performance and settlement of the accommodation contract (in particular booking confirmation, check-in information, invoicing) and to respond to your enquiries and concerns.
Legal basis: Insofar as the e-mail communication serves the performance or settlement of the accommodation contract or pre-contractual measures (e.g. enquiries about accommodation), we base it on Art. 6(1)(b) GDPR. We base the answering of general enquiries and concerns on our legitimate interest pursuant to Art. 6(1)(f) GDPR. We have a legitimate interest in enabling you to contact us quickly and easily and in processing your enquiries. You may object to the processing of your data based on Art. 6(1)(f) GDPR under the conditions of Art. 21 GDPR (on the right to object, see Section 20).
Storage period: For e-mail communication in connection with bookings and an accommodation contract concluded with you, the storage periods described under Section 5.1 apply insofar as the data must be retained under commercial or tax law. Communication data that does not have to be retained contractually or by law is deleted immediately after your departure.
Recipients: For the operation of our e-mail infrastructure, we use a service of Microsoft Ireland Operations Ltd. (Outlook/Microsoft 365) on the basis of a data processing agreement. The processing takes place within the EU. Otherwise, only internally responsible employees have access to the e-mail communication. Insofar as communication takes place via an OTA platform, the respective platform provider is also a recipient of the communication data.
Obligation to provide data: An e-mail address is necessary for the performance of the accommodation contract and for contract-related communication. For bookings via OTAs, communication can alternatively take place via the internal communication address of the respective platform.
9.2 Communication via WhatsApp Business
For operational guest communication, we use WhatsApp Business as our preferred communication channel. If you object to the use of WhatsApp, communication will take place by e-mail or via the respective external booking platform, as described in Section 9.1.
Categories of data: In the context of WhatsApp communication, we process your mobile phone number, your name and the content of the messages exchanged (in particular booking confirmations, check-in information, access details, enquiries and service communication).
Purpose: We use WhatsApp Business as a communication channel for operational guest communication before, during and after the stay.
Legal basis: The use of WhatsApp Business is based on Art. 6(1)(f) GDPR (legitimate interests). Our legitimate interest lies in ensuring fast, reliable and, for our guests, convenient communication in the context of the stay. As an accommodation provider without a physical reception, we depend on an efficient digital communication channel in order to be able to transmit operational information (e.g. booking confirmations, check-in details, access information and service requests) promptly and directly. WhatsApp Business enables direct, low-threshold communication that meets our guests’ expectations of a modern, digital hotel operation. You may object to the use of WhatsApp at any time with effect for the future, without this affecting your booking process or your stay. In that case, we will communicate with you by e-mail instead (see Section 9.1). Further information on your right to object can be found under Section 20.
Storage period: For WhatsApp communication in connection with bookings and an accommodation contract concluded with you, the storage periods described under Section 5.1 apply insofar as the data must be retained under commercial or tax law. Communication data that does not have to be retained contractually or by law is deleted immediately after your departure.
Recipients: The provider of WhatsApp Business is WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. WhatsApp Ireland Limited processes the communication data on the basis of a data processing agreement concluded with WhatsApp Ireland Limited in accordance with the WhatsApp Business data processing terms: https://www.whatsapp.com/legal/business-data-processing-terms/. In addition, your personal data (phone number, message content, metadata) may also be transmitted by WhatsApp Ireland Limited to WhatsApp LLC and Meta Platforms Inc. as sub-processors in the USA. Pursuant to the addendum for WhatsApp Business data transfers, this transfer is primarily based on the EU-US Data Privacy Framework (adequacy decision of the EU Commission pursuant to Art. 45 GDPR). In addition, EU standard contractual clauses pursuant to Implementing Decision (EU) 2021/914 of the European Commission to ensure the required level of data protection (Art. 46(2)(c) GDPR) or other transfer mechanisms recognised under Art. 44 et seq. GDPR are used.
Obligation to provide data: The use of WhatsApp is not mandatory for the performance of the contract. You may object to communication via WhatsApp at any time, without this affecting the booking process or the stay. In that case, communication with you will take place exclusively by e-mail.
9.3 Automated guest messages (pre-stay, during-stay, post-stay)
Via Guestway, we send automated messages before (pre-stay), during (during-stay) and after the stay (post-stay).
Categories of data: For the automated sending of messages, we process your name, your contact details (e-mail address or WhatsApp number) and your booking and stay data.
Purpose: We send automated messages in order to inform you before your stay about the check-in process and access information (pre-stay), to provide you with relevant information during your stay (during-stay), to complete the settlement after your stay (post-stay) and to look after you during your stay.
Legal basis: Messages that are necessary for the performance and settlement of the accommodation contract concluded with you (e.g. check-in link, access details, information about the stay and check-out) are processed on the basis of Art. 6(1)(b) GDPR. Service messages going beyond this are based on Art. 6(1)(f) GDPR (legitimate interest). We have a legitimate interest in comprehensive guest care. You may object to the processing of your data based on Art. 6(1)(f) GDPR under the conditions of Art. 21 GDPR (on the right to object, see Section 20).
Storage period: The messages are deleted after the end of your stay and of the accommodation contract.
Recipients: The automated sending of messages takes place via the platform “Guestway” of the provider Guestway BV, Soenenspark 1, 9051 Ghent, Belgium, on the basis of a data processing agreement concluded with Guestway (see Section 6.1). E-mails sent from the group and corporate enquiry form are delivered via the e-mail service “Resend” of the provider Plus Five Five, Inc. (Resend), 2261 Market Street #5039, San Francisco, CA 94114, USA, on the basis of a data processing agreement. Sending is configured for the EU region Ireland (eu-west-1). The platform itself and the sub-processors it uses – including Amazon Web Services, Inc. as hosting and sending provider – nevertheless process data in the USA. The transfer to the USA takes place on the basis of the EU standard contractual clauses pursuant to Art. 46(2)(c) GDPR. Manual correspondence with guests takes place via Microsoft Outlook (see Section 9.1) and WhatsApp Business (see Section 9.2).
Obligation to provide data: Receiving automated messages in connection with the accommodation contract (e.g. check-in link, access details) is necessary for the performance of the contract and cannot be excluded. You may object at any time to service messages going beyond this (on the right to object, see Section 20). Communication takes place by e-mail or via WhatsApp Business, depending on the chosen channel (see Sections 9.1 and 9.2).
10. Video Surveillance of Communal Areas
For the security of the accommodation, our guests and our operations, and to protect our property, we monitor entrances and communal areas by means of video surveillance. Private guest rooms and other private areas are expressly not monitored. Recordings are only reviewed when there is a specific reason to do so. The video surveillance is indicated by clearly visible signs at the entrance and in the areas concerned.
Categories of data: In the context of the video surveillance, image recordings are processed of persons present in the monitored communal areas, i.e. in the entrance area, in the corridors, in the stairwell, in the courtyard and on other general outdoor areas.
Purpose: We operate the video surveillance in order to ensure the security of the property, our guests and our operations, and to prevent criminal offences (e.g. theft, burglary) and security-related incidents and to investigate them if they occur (preservation of evidence).
Legal basis: The video surveillance is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the protection of property, the safety of our guests and the proper conduct of our operations, as well as in the prevention and investigation of criminal offences and cases of damage. You may object to the processing of your data based on Art. 6(1)(f) GDPR under the conditions of Art. 21 GDPR (on the right to object, see Section 20).
Storage period: The video recordings are retained for 72 hours and then automatically overwritten. In the event of a security-related incident, individual recordings may be stored for longer until the matter has been clarified.
Recipients: Only persons at management level of Motz19 have access to the recordings. Within the framework provided by law, recordings may be transmitted to law enforcement authorities.
Obligation to provide data: There is no obligation to provide data. The video surveillance concerns communal areas only and serves the general interest in security. Private guest areas are not recorded.
11. Review Requests After the Stay
After the stay, we automatically send a review request to the main guest via the Guestway platform. The request contains a link for submitting a review on Google.
Categories of data: For sending the review request, we process your name and your contact details (e-mail address or mobile phone number).
Purpose: We ask you for a review after your stay in order to assure and continuously improve the quality of our services, and to publicly present and promote our company and our services (e.g. through publicly visible reviews on Google).
Legal basis: The legal basis for the processing is Art. 6(1)(f) GDPR. Our legitimate interest lies in quality assurance and in obtaining customer feedback. You may object to the processing of your data based on Art. 6(1)(f) GDPR under the conditions of Art. 21 GDPR (on the right to object, see Section 20).
Storage period: We do not separately store your review. The review is published directly on the Google platform; Google’s privacy notice applies to its storage there.
Recipients: The automated sending of the review request takes place via the platform “Guestway” of the provider Guestway BV, Soenenspark 1, 9051 Ghent, Belgium, on the basis of a data processing agreement concluded with Guestway (see Section 6.1). If you submit a review on Google as a result of the request, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, which is responsible for users in the European Economic Area, is the independent controller for the processing there. Further information on data protection at Google can be found at https://policies.google.com/privacy.
Obligation to provide data: Participation in review requests is voluntary. There is no obligation to submit a review.
Section III – Operation of the Website and Booking Platform
12. Hosting and Server Log Files
When you visit our website and booking platform, the browser used on your device automatically sends information to the server of our website. This is necessary to ensure a smooth connection setup, a user-friendly provision and convenient use of our online offering, and to ensure system security and stability. The information collected is temporarily stored in so-called log files in our systems.
Categories of data: The following information is collected: IP address of the requesting device, browser type and browser version, page accessed (URL), timestamp of the server request, amount of data transferred and, where applicable, the referring website (referrer URL).
Purpose: The processing serves the provision and secure operation of our website and booking platform, ensuring system security and stability, and the analysis and improvement of our online offering (e.g. threat prevention and support in the event of connection problems).
Legal basis: The hosting and the associated processing of server log files are based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the provision and secure operation of our website and booking platform. Under the conditions of Art. 21 GDPR, you have a right to object to this processing of your data (see Section 20).
Storage period: The server log files are stored for security reasons for a maximum of 30 days. They are then deleted.
Recipients: For the hosting of our website and booking platform, we use the services of the service provider Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA, on the basis of a data processing agreement. The hosting takes place on servers in Frankfurt, Germany (EU region). The processing of the server log files takes place in the EU. As Vercel is based in the USA, access to personal data from the USA in the course of support and maintenance services cannot be ruled out. This access is safeguarded on the basis of the EU standard contractual clauses pursuant to Implementing Decision (EU) 2021/914 of the European Commission to ensure the required level of data protection (Art. 46(2)(c) GDPR). Further information on data protection at Vercel can be found at https://vercel.com/legal/privacy-policy.
Obligation to provide data: The provision of the aforementioned information is neither legally nor contractually required. However, without this information, the functionality of our website is not or not fully guaranteed.
14. Google Analytics
We use the web analytics service Google Analytics 4 (“Google Analytics”) on our website and booking platform. Google Analytics is provided to us by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). Google Analytics is only activated after you have given your express consent to the use of statistics cookies via our consent management tool (cookie banner, see Section 13). Without your consent, no data is transmitted to Google.
In Google Analytics, IP address anonymisation is activated by default. Due to IP anonymisation, your IP address is truncated by Google within the EU or EEA. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and truncated there. According to Google, the IP address transmitted by your browser in the context of Google Analytics is not merged with other Google data.
Categories of data: Google Analytics uses cookies that enable an analysis of your use of our website (statistics cookies, see Section 13). The information collected by means of the cookies is generally transmitted to a Google server in the USA and stored there. During your visit to the website, the following information in particular may be transmitted to Google: pages accessed (URL), your “click path” and interaction with the website (e.g. time spent, scrolls, clicks), your approximate location (region), date and time of the visit, your IP address (in truncated form), technical information (browser type, internet provider, device, screen resolution, language setting) and the referrer URL (the website or advertising medium through which you came to this website), as well as a randomly generated user ID. No personal data such as name, address or contact details are transmitted to Google Analytics.
Purpose: Google uses this information on our behalf to analyse your pseudonymous use of the website and to compile reports on website activity. The reports provided by Google serve to analyse the performance of our website and booking platform and to optimise our online offering and tailor it to demand.
Legal basis: The use of Google Analytics and the associated processing of your data takes place exclusively on the basis of your consent pursuant to Art. 6(1)(a) GDPR and section 25(1) sentence 1 TDDDG. Google Analytics is only activated after you have given your consent via the cookie banner (Cookiebot). You may withdraw your consent at any time with effect for the future by adjusting your cookie settings via the cookie banner (see Section 13). You can access the cookie banner at any time via the “Privacy Button” at the bottom left of the website. The lawfulness of the processing carried out on the basis of the consent until its withdrawal remains unaffected.
Storage period: The user-related data sent by us and linked to cookies is automatically deleted after 2 months. The maximum lifetime/storage period of the Google Analytics cookies is 2 years. Data whose retention period has been reached is automatically deleted once a month.
Recipients: The recipient of the data is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google processes the website usage data on our behalf and has committed itself, through a data processing agreement pursuant to Art. 28 GDPR, to measures to ensure the security and confidentiality of the data processed.
In addition, data may be transmitted to Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, and Alphabet Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
This transfer is primarily based on the EU-US Data Privacy Framework (adequacy decision of the EU Commission pursuant to Art. 45 GDPR). Google LLC is certified under the EU-US Data Privacy Framework. As Google servers are distributed worldwide and a transfer to third countries cannot be completely ruled out, we have additionally concluded EU standard contractual clauses with the provider pursuant to Implementing Decision (EU) 2021/914 of the European Commission to ensure the required level of data protection (Art. 46(2)(c) GDPR). Further information on data protection at Google can be found at https://policies.google.com/privacy and on the Google Analytics terms of use at https://marketingplatform.google.com/about/analytics/terms/de/.
Withdrawal and deactivation options: You may withdraw your consent at any time with effect for the future by adjusting your cookie settings via the cookie banner (Cookiebot). You can access the cookie banner at any time via the “Privacy Button” at the bottom left of the website. You can also prevent the storage of cookies from the outset by configuring your browser software accordingly. However, if you configure your browser to reject all cookies, this may result in restrictions of functionalities on this and other websites.
You can also prevent the collection of the data generated by the cookie and relating to your use of the website (incl. your IP address) by Google, and the processing of this data by Google, by downloading and installing the browser add-on for deactivating Google Analytics available at https://tools.google.com/dlpage/gaoptout?hl=de.
Obligation to provide data: The provision of the aforementioned data is neither legally nor contractually required.
15. Google Maps and Google Places API
On our website we use the map service “Google Maps” and the “Google Places API” (for retrieving reviews) of the provider Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”).
Google Maps and the Google Places API are only activated after you have given your consent to the use of marketing cookies via our cookie banner (Cookiebot, see Section 13). Without this consent, only a preview image is displayed. If you actively click on it, Google Maps opens automatically in a new browser window. Please note that this may trigger data processing operations by Google that are outside our sphere of influence. In this respect, Google is solely responsible under data protection law. Further information on the purpose and scope of the data processing by Google can be found in Google’s privacy notice: https://www.google.com/policies/privacy/partners/?hl=de
Categories of data: When Google Maps and the Google Places API are used, personal data is transmitted to Google, in particular your IP address, usage data (e.g. map sections viewed and search terms, reviews accessed, interaction with the map), technical information about your browser and device and, where applicable, location data (if you have activated location sharing in your browser).
Purpose: We use Google Maps to show you our location on an interactive map and to provide you with convenient directions to our studio apartments. We use the Google Places API to display publicly available Google reviews of our accommodation on our website.
Legal basis: The use of Google Maps and the Google Places API and the associated data processing is based on your consent pursuant to Art. 6(1)(a) GDPR and section 25(1) sentence 1 TDDDG. You may withdraw your consent at any time with effect for the future by adjusting your cookie settings via the cookie banner (see Section 13). You can access the cookie banner at any time via the “Privacy Button” at the bottom left of the website. The lawfulness of the processing carried out on the basis of the consent until its withdrawal remains unaffected.
Storage period: We ourselves do not store any personal data in connection with the use of Google Maps or the Google Places API. The storage period of the data and cookies collected by Google is governed by Google’s privacy notice.
Recipients: The recipient of the data is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. In addition, data may be transmitted to Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. This transfer is primarily based on the EU-US Data Privacy Framework (adequacy decision of the EU Commission pursuant to Art. 45 GDPR). Google LLC is certified under the EU-US Data Privacy Framework. As Google servers are distributed worldwide and a transfer to further third countries cannot be completely ruled out, we have additionally concluded EU standard contractual clauses with the provider pursuant to Implementing Decision (EU) 2021/914 of the European Commission to ensure the required level of data protection (Art. 46(2)(c) GDPR). Further information on data protection at Google can be found at https://policies.google.com/privacy.
Obligation to provide data: The provision of the aforementioned data is neither legally nor contractually required.
Section V – General Information on Recipient Categories and Storage Periods
18. Further Categories of Recipients
In addition to the recipients specifically named in Sections II and III, personal data may be transferred in the following cases:
tax advisors, auditors, lawyers and legal advisors, insofar as necessary to fulfil tax and commercial law obligations or to pursue legitimate interests;
courts, law enforcement authorities, supervisory and financial authorities and other public bodies, insofar as legally required or necessary to pursue legitimate interests;
IT and web service providers (maintenance, support, IT infrastructure), which generally act for us on the basis of a data processing agreement pursuant to Art. 28 GDPR;
third parties involved in the handling of business, such as credit institutions, postal or telecommunications service providers;
Insofar as external service providers process personal data on our behalf, we ensure through legal, technical and organisational measures that they comply with data protection regulations and process data only on our behalf and in accordance with our instructions.
19. General Information on Storage Periods
Unless an explicit storage period is specified in this privacy notice, personal data is stored for as long as is necessary for the purpose for which it was collected; the data is then deleted or anonymised. Storage beyond this only takes place
if this is necessary to fulfil legal obligations. Insofar as we are legally obliged to retain data, we store your data for the legally prescribed period. Legal requirements regarding storage may arise in particular from the retention periods of the German Commercial Code (HGB) or the German Fiscal Code (AO), in particular from section 147 AO and sections 238, 257 HGB. The retention period under these provisions is generally between 6 years (in particular for commercial and business letters and other documents relevant for taxation) and 8 years (in particular for accounting records) from the end of the year in which the commercial or business letter was received or sent, the accounting record was created or the relevant transaction was completed, e.g. we have conclusively processed your enquiry.
if the data is needed for longer for criminal prosecution or for the assertion, exercise or defence of legal claims, including for documentation and evidence purposes. In that case, the data is stored until the matter in question and any mutual claims have been fully resolved, taking into account the statutory limitation period.
For processing operations that we carry out on the basis of your consent, the data is deleted when you withdraw your consent or at an earlier point in time when the data is no longer necessary for the purpose for which we collected it.
Section VI – Data Subject Rights
20. Your Rights as a Data Subject
If you wish to exercise the rights described below, please contact us using the contact details provided under Section 2.
Right of access: Under the conditions of Art. 15 GDPR, you may at any time request information about the personal data relating to you that we process, in particular about the purposes of processing, the categories of data, the recipients, the storage period, the origin of the data, the existence of automated decision-making including profiling, and your data subject rights. You may also request a copy of your personal data. We generally provide copies of data in electronic form, unless you have specified otherwise. The right of access is subject to certain restrictions (see Art. 15(4) GDPR, section 34 BDSG).
Right to rectification: Under the conditions of Art. 16 GDPR, you may request the immediate rectification of inaccurate personal data or the completion of incomplete personal data.
Right to erasure: Under the conditions of Art. 17 GDPR, you may in principle request the erasure of your personal data stored by us. The right to erasure is subject to certain restrictions (see Art. 17(3) GDPR, section 35 BDSG).
Right to restriction of processing: Under the conditions of Art. 18 GDPR, you may also request the restriction of the processing of your personal data. In this case, we must restrict the data for the duration of the examination of your request.
Right to data portability: Under the conditions of Art. 20 GDPR, you have the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format or, where technically feasible, to request its transmission to another controller, insofar as the processing is based on consent or a contract and is carried out by automated means. The right to data portability is subject to certain restrictions (see Art. 20(3) and (4) GDPR, section 28 BDSG).
Right to withdraw consent: Insofar as we process data on the basis of your consent, you may withdraw your consent at any time with effect for the future in accordance with Art. 7(3) GDPR. The withdrawal does not affect the lawfulness of the processing carried out up to that point. Please address the withdrawal to the contact address provided under Section 2.
RIGHT TO OBJECT (ART. 21 GDPR)
YOU HAVE THE RIGHT TO OBJECT AT ANY TIME, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU WHICH IS BASED ON ART. 6(1)(F) GDPR (LEGITIMATE INTERESTS). IN THE EVENT OF A JUSTIFIED OBJECTION, WE WILL CEASE THE PROCESSING CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES THE ASSERTION, EXERCISE OR DEFENCE OF LEGAL CLAIMS.
WHERE YOUR PERSONAL DATA IS PROCESSED BY US FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME, WITHOUT RESTRICTION, TO THE PROCESSING OF YOUR DATA FOR SUCH MARKETING PURPOSES. IN THIS CASE, IT IS NOT NECESSARY TO STATE A PARTICULAR SITUATION. THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, THE PROCESSING FOR DIRECT MARKETING PURPOSES WILL BE CEASED IMMEDIATELY.
THE OBJECTION MAY BE MADE WITHOUT ANY PARTICULAR FORM (E.G. BY E-MAIL) TO THE CONTACT DETAILS PROVIDED UNDER SECTION 2.