Home › Privacy
Privacy
policy.
As of September 2026
Here you can find out which personal data we process when you visit this website, send us an enquiry, stay with us or subscribe to our newsletter: for what purposes, on what legal basis, who is involved and how long we keep the data.
1. Controller
Hotel Robben – Grollander Krug e.K., proprietor Frank Robben, Emslandstraße 30, 28259 Bremen, Germany, phone 0421 51 46 20, e-mail info@hotel-robben.de.
You can also reach us at these contact details with any questions about data protection and if you wish to exercise your rights (sections 13 and 14).
2. The key points at a glance
- This website sets no cookies and uses no tracking, no statistics or advertising services and no embedded maps or videos. Fonts and the map image are delivered with the website itself.
- Our enquiry forms do not send anything to the website. They create a ready-made e-mail that you send to us yourself using your e-mail program.
- So that prices, the weekly menu and dates are always up to date, every page loads content from our content management system (section 5).
- You only receive the newsletter once you have confirmed your subscription. We do not analyse whether you open it or click on links (section 9).
- RevScaling Agency GbR from Bremen supports us technically, working with the service providers Vercel, Supabase and IONOS. Vercel also uses certain access data for its own purposes. Data may also reach the USA or Singapore (sections 3, 4 and 11).
- You have a right to object to processing based on our legitimate interest (section 14).
3. Who supports us in our operations
Our website, content management system and newsletter are operated for us by RevScaling Agency GbR, Waltjenstr. 96, 28237 Bremen, Germany. It is our processor under Art. 28 GDPR: it may process personal data only on our behalf and in accordance with our instructions, not for its own purposes. For this it uses the following sub-processors:
- Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA: makes the website and the content management system available on the internet (hosting). The pages are delivered via a worldwide network of data centres, usually from a location near you. The program functions of the content management system generally run in Frankfurt am Main. For certain usage data, Vercel is additionally a controller in its own right (section 4).
- Supabase Pte. Ltd., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513: database and file storage of the content management system, used among other things for newsletter sign-ups and for photos and documents that we upload ourselves. The database and file storage are located in Frankfurt am Main.
- IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany: e-mail mailbox of RevScaling Agency GbR through which the newsletter e-mails are sent. Under its data processing agreement, IONOS generally processes the data in the EU or the European Economic Area.
Vercel and Supabase in turn work with other service providers, such as Amazon Web Services and Google, and Supabase also with Cloudflare. You can read what this means for transfers outside the EU in section 11.
4. Visiting the website
When you open a page, your browser necessarily sends data to Vercel for technical reasons: your IP address, date and time, the address requested, information about your browser and operating system and, where applicable, the address of the page you came from. All connections are encrypted (HTTPS).
The address requested also includes the details from the room search: it passes the arrival and departure dates, the number of guests and rooms and the ages of accompanying children to the booking page in the address. These details are evaluated only in your browser. Your entries in the search on our website are evaluated by a script directly in your browser; they are not transmitted.
We need this data to deliver the pages to you, to detect faults and to protect the website against misuse and attacks. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is a secure and reliably available website. Vercel automatically deletes the access logs that RevScaling can view for us in the Vercel account after 30 days at the latest. We ourselves do not analyse this data for statistics or advertising.
Vercel as an independent controller: Under its data processing agreement, Vercel additionally uses, under its own responsibility, usage data and metadata generated in the operation of its services. This may include your IP address and information about your browser. According to Vercel, it uses this data to operate, secure and improve its services and for analytics and evaluations. Vercel decides for itself how long it keeps the data: according to Vercel, for as long as it needs the data for these purposes or to meet legal obligations; after that the data is deleted or anonymised. This also applies to the requests described in section 5 and to the newsletter pages (section 9). You can find more information in Vercel’s privacy policy. It cannot be avoided that Vercel receives this data when the website is operated via Vercel. The legal basis for this transfer is Art. 6(1)(f) GDPR; our legitimate interest is the reliable and secure operation of the website with an established hosting provider.
5. Up-to-date content from our content management system
We maintain room rates and event-date rates, the weekly menu with prices and times, and other texts and photos ourselves in a content management system provided by RevScaling Agency GbR. So that you always see the latest information, every page loads a script and the current content from the address revscaling-dashboard.vercel.app when it is opened. In the process, Vercel receives your IP address, date and time, information about your browser and operating system and the address of our website, but not which subpage you are currently viewing. Nothing about you is stored in the database of the content management system; section 4 applies to the access data at Vercel.
Photos that we upload to the content management system are loaded by your browser directly from Supabase’s file storage; the same applies when you open documents stored there, such as a weekly menu as a PDF. The address of these files ends in “supabase.co”. Supabase delivers the files via a worldwide delivery network in which Cloudflare is involved, and in the process receives your IP address, information about your browser and operating system and the address of our website. The access logs in our Supabase project are deleted after one day. Otherwise, this access data is stored only for as long as is necessary to deliver the files and to keep the services secure.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest: prices, the weekly menu and dates should be correct on every page, and we want to be able to change them ourselves without programming skills. RevScaling and Supabase process the data only on our behalf; the same applies to Vercel, with the exception described in section 4.
6. Storage in your browser – no cookies
This website does not set cookies. However, some functions store entries in your browser’s session storage as soon as you use them. These entries remain on your device, are not transferred to us or our service providers, and are deleted automatically as soon as you close the browser tab:
- Room booking (“robben-booking”): as soon as you select or enter something in the booking assistant, it stores the rooms and rates you have chosen, occupancy, extra beds, requests and extras, as well as the details you enter in the form, i.e. name, contact details, company, country, purpose of travel, arrival time and your message. This means nothing is lost when you move between the steps. Your travel dates are not included; they are in the address of the page (section 4).
- Room enquiry (“robben-raum”): as soon as you select or enter something in the form, it stores the date, number of guests, time period, occasion, your contact details including your address and your message, for the same reason.
- Notice window (“robben-highlights-zu”): only a note that you have closed the “Highlights & events” window on the home page, so that it does not appear again during this session.
The legal basis for storing and reading these entries is § 25(2) no. 2 TDDDG (German Telecommunications Digital Services Data Protection Act): the entries are strictly necessary for the functions you use to work as you want them to. No consent is required for this. Your entries in the forms are processed exclusively by your browser; we only receive them when you send us your enquiry (section 7).
Earlier versions of this website stored entries in your browser’s local storage whose names begin with “rs:”: a copy of public content from section 5 and notes that the content management system needed to set up the pages. The website deletes these entries on your next visit. You can also delete them yourself in your browser settings.
7. Enquiries via the forms, by e-mail or by telephone
Using our forms, you can enquire about a room, a table or a function room, or send us a message. The forms do not transfer anything to the website: they compile your details in your browser into a ready-made e-mail to info@hotel-robben.de. Your enquiry only reaches us when you send this e-mail using your own e-mail program. Alternatively, you can copy the text to the clipboard or call us. Your own e-mail provider is involved in sending the e-mail.
Depending on the enquiry, we process: title, name, e-mail address and telephone number, company where applicable, your postal address for function room enquiries, as well as travel dates, number of guests and rooms, ages of accompanying children, room, bed and other requests, country, purpose of travel and arrival time; for table reservations the date, time, number of guests, preferred seating and occasion; for events the date, time period and occasion; and the subject and your message. The same applies if you contact us directly by e-mail or telephone.
We use this information to answer your enquiry, to make you an offer and to prepare and carry out your stay, your reservation or your event. The legal basis is Art. 6(1)(b) GDPR (enquiry prior to entering into a contract and performance of a contract). If you enquire on behalf of a company or write to us without reference to a booking, the legal basis is Art. 6(1)(f) GDPR; our legitimate interest is answering enquiries and maintaining business contacts.
Mandatory fields are marked with an asterisk (*) in the form. We need this information to process your enquiry and to reply to you; without it the form cannot be completed. All other information is voluntary.
Your e-mail and our reply are kept in our mailbox info@hotel-robben.de, which an e-mail provider operates on our behalf.
Information on allergies, intolerances or accessibility: If you tell us, for example, that you have an allergy or that you use a wheelchair, this is health data, which enjoys special protection. Such information is voluntary. We use it solely to tailor your stay, your table or your event to it, and only with your explicit consent (Art. 9(2)(a) GDPR). In our forms you give this consent by ticking the box “I expressly consent …”; its wording is then included in the e-mail you send us. If you give us such information by telephone or in an e-mail without this declaration, we will ask you whether we may take it into account. You can withdraw your consent at any time with effect for the future; we will then no longer take the information into account and will delete it unless a retention obligation prevents this.
Storage period: We delete enquiries and messages that do not lead to a booking or an event no later than six months after our last message on the matter. We delete table reservations no later than three months after the reserved day. If an accommodation or event contract is concluded, the retention periods set out in section 8 apply.
8. Overnight stays, registration forms and retention obligations
If you stay with us, we process your data in order to carry out and invoice your stay (Art. 6(1)(b) GDPR) and to comply with legal obligations (Art. 6(1)(c) GDPR).
Registration form: Guests who do not hold German citizenship must sign a registration form on the day of arrival (§ 29 German Federal Registration Act). It contains only the information required by law: date of arrival and expected date of departure, surname and first names, date of birth, nationalities, address, number and nationality of foreign travel companions, and the serial number of the passport or passport substitute you show us for this purpose (§ 30(2) Federal Registration Act). You are legally obliged to provide this information. We keep registration forms for one year from the day of departure and destroy them within three months thereafter. We must present them to the competent authorities on request (§ 30(4) Federal Registration Act).
Retention: We keep invoices and booking records for eight years and business correspondence about your booking or event for six years (§ 147 German Fiscal Code, § 257 German Commercial Code). These periods begin at the end of the calendar year in which the document was created. After that we delete the data.
Who else receives your data: Where this is necessary for reservations, invoicing and accounting, your data is also received by IT service providers working on our behalf and by our tax advisers, who are bound by professional secrecy. If you pay by card, the payment service providers and banks involved process the payment data. Where we are legally obliged to do so, we pass data on to authorities, for example tax or registration authorities.
9. Newsletter
You can subscribe to our newsletter on our website, for example in the page footer and on the “What’s On” page: news and offers from Hotel Robben, for example about the asparagus and chanterelle season, kale parties, new menus and events, a few times a year. For this we only need your e-mail address. You may give your name voluntarily; we use it only to address you personally. Subscribing is voluntary and is not a condition for a booking.
Confirmation (double opt-in): After you sign up, we send you an e-mail containing a link. Only when you open the page behind this link and confirm your subscription there by clicking the button do we add you to the mailing list and send you a short welcome message. Without confirmation you will not receive the newsletter. The pages for confirming and unsubscribing are located at revscaling-dashboard.vercel.app and do not set any cookies.
What we store: your e-mail address, your name if given, the time and IP address of the sign-up, the page on which you signed up, the wording and version of your consent, the time of confirmation and, where applicable, of unsubscribing. If you sign up again later, the records of the earlier sign-up are kept. For each newsletter mailing we record whether the e-mail could be sent to your address, with the time and, where applicable, the error message from the mail server. The data is held in the database of the content management system at Supabase in Frankfurt am Main.
Sending: The e-mails bear the sender name “Hotel Robben – Grollander Krug”. They are sent by RevScaling via the e-mail mailbox of RevScaling Agency GbR at IONOS (section 3); the sender address therefore belongs to this agency.
Legal basis: For the newsletter, the legal basis is your consent (Art. 6(1)(a) GDPR), which is also required for advertising by e-mail under § 7(2) no. 2 of the German Act Against Unfair Competition (UWG). We need the confirmation e-mail and the proof data to prevent sign-ups with other people’s addresses and to be able to prove your consent (Art. 6(1)(c) in conjunction with Art. 5(2) and Art. 7(1) GDPR, and Art. 6(1)(f) GDPR; our legitimate interest is being able to defend ourselves against allegations of unlawful advertising).
No analysis: We do not measure whether or when you open the newsletter or which links you click. The e-mails contain no tracking pixels and no redirected links. If your e-mail program displays images, it loads the logo and the other images from Vercel or Supabase servers. Your IP address is transmitted in the process, but it is not linked to your subscription.
Unsubscribing: You can cancel the newsletter at any time, using the unsubscribe link in every newsletter e-mail or by sending an informal message to info@hotel-robben.de. This withdraws your consent with effect for the future.
Storage period: As long as you are subscribed, we store your data in order to send you the newsletter. If you do not confirm a sign-up, we delete the information relating to that sign-up after 30 days. If you unsubscribe, we no longer use your address for sending and delete your name. We then keep your e-mail address, the proof data and the sending records for a further three years from the end of the year in which you unsubscribed, because for that long we must be able to prove that we only wrote to you with your consent (Art. 6(1)(c) and (f) GDPR). After that we delete them.
10. Links to other providers and map image
The map in the footer of the pages is an image delivered with the website (map data © OpenStreetMap contributors). No map service is contacted when it is displayed.
Some links lead to other providers, for example to route planning on Google Maps, to the “Links der Weser” nature park or to the market surveillance authority for accessibility (MLBF). Only when you click such a link does the page open in a new tab. Your browser then transmits, among other things, your IP address and the address of our website to the provider. The respective provider alone is responsible for the processing there.
11. Transfers to countries outside the EU
Vercel Inc. is based in the USA. Supabase Pte. Ltd. is based in Singapore and uses, among others, the US company Supabase, Inc. Data may therefore be transferred to the USA or Singapore or accessed from there, for example for operation, maintenance and support. Other service providers of these companies also process data partly outside the EU. This applies even though the database and file storage are located in Frankfurt am Main.
- Vercel is certified under the EU-US Data Privacy Framework. Transfers to Vercel in the USA are therefore covered by the European Commission’s adequacy decision of 10 July 2023 (Implementing Decision (EU) 2023/1795), including where Vercel processes data under its own responsibility (section 4). You can check the certification in the official Data Privacy Framework List.
- Supabase is not certified under the Data Privacy Framework, and there is no adequacy decision for Singapore. Here the basis is the European Commission’s standard contractual clauses (Implementing Decision (EU) 2021/914), which form part of Supabase’s data processing agreement. You can find the text of the clauses on EUR-Lex.
You can obtain a copy of these safeguards from us on request (section 1).
12. Automated decision-making
We do not make any decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR).
13. Your rights
With respect to us, you have the right to
- information about the data we store about you (Art. 15 GDPR),
- rectification of inaccurate data (Art. 16 GDPR),
- erasure (Art. 17 GDPR), unless a statutory retention obligation prevents this; where such an obligation exists, we restrict the processing instead,
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR) for data that you have provided to us and that we process by automated means on the basis of your consent or a contract,
- withdraw consent at any time with effect for the future (Art. 7(3) GDPR); anything done up to that point remains lawful,
- object under Art. 21 GDPR (section 14),
- lodge a complaint with a supervisory authority (section 15).
An informal message to info@hotel-robben.de or a letter to our postal address is sufficient. So that we do not disclose data to unauthorised persons, we may ask you to prove your identity if in doubt.
14. Your right to object
15. Right to lodge a complaint
You can lodge a complaint with any data protection supervisory authority (Art. 77 GDPR), for example with the authority where you live. The authority responsible for us is:
The State Commissioner for Data Protection and Freedom of Information of the Free Hanseatic City of Bremen
Georgstraße 122-124, 27570 Bremerhaven, Germany
Phone +49 471 596 2010 or +49 421 361 2010
E-mail office@datenschutz.bremen.de