PRIVACY POLICY

Privacy Policy for the Website

https://www.theclouth.koeln

Effective as of: 01 August 2026

1. Information on the Collection of Personal Data

(1)

In the following, we inform you about the collection of personal data when using our website. Personal data means any information relating to an identified or identifiable natural person, such as your name, address, email address, or user behaviour.

(2)

Controller pursuant to Article 4 (7) GDPR

Clouth Nr. 1 Hotelbetriebs GmbH

Rathausgasse 17

12529 Schönefeld

Germany


E-mail: hallo@theclouth.cologne

Phone: +49 159 06752554

Managing Director: Andreas Gerhardt

(hereinafter referred to as "THE CLOUTH", "we", "our", or "us")


Contact details of the Data Protection Officer


Mortimer Graf zu Eulenburg

ASCON HORIZON INNOVATION GROUP GmbH

Hamerlingweg 18

14167 Berlin

Germany


Phone: +49 30 28667408

E-mail: ds@ahig-group.com


You may also contact our Data Protection Officer by post using the above address and adding the reference "Data Protection Officer".


(3)

If you contact us by e-mail or via a contact form, we will store the data you provide (your e-mail address and, where applicable, your name and telephone number) in order to respond to your enquiry.


We will delete the data collected in this context once storage is no longer necessary or restrict its processing if statutory retention obligations apply.


(4)

Where we use commissioned service providers for individual functions of our website or wish to use your data for marketing purposes, we will provide detailed information about the respective procedures below.


2. Your Rights


You have the following rights with regard to your personal data processed by us:


Right of Access

You have the right at any time to obtain information about the processing of your personal data by us in accordance with Article 15 GDPR.


Right to Rectification

If the data stored by us is inaccurate, outdated or incomplete, you have the right to request that such data be corrected or completed in accordance with Article 16 GDPR.


Right to Erasure

You may request the deletion of your personal data if it is no longer necessary for the purposes for which it was collected, pursuant to Article 17 GDPR.


If deletion is exceptionally not possible due to statutory retention obligations, the data will be restricted so that it is available only for the respective legal purpose. Where outstanding claims against you exist within the scope of receivables management, any request for deletion will be implemented only after such claims have been settled.


Right to Restriction of Processing

Under certain conditions, you may request that we restrict the processing of your personal data pursuant to Article 18 GDPR.


This includes situations where:

  • the accuracy of the personal data is contested and verification is required;

  • the processing is unlawful but you oppose deletion and instead request restriction of use;

  • we no longer require the data for processing purposes, but you require it for the establishment, exercise or defence of legal claims; or

  • you have objected to processing pursuant to Article 21 (1) GDPR pending verification of whether our legitimate grounds override yours.


Right to Data Portability

Pursuant to Article 20 GDPR, you have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format.


Where technically feasible, you may also request that these data be transmitted directly to another controller.


This right enables you to transfer your personal data easily between different services and platforms.


Right to Object

Under the conditions set out in Article 21 GDPR, you have the right to object to the processing of your personal data.


Upon receipt of a justified objection, we will examine the circumstances and either discontinue or adjust the processing or explain the compelling legitimate grounds that require us to continue processing your personal data.


You may object at any time to the processing of your personal data for direct marketing or data analysis purposes.


Right to Withdraw Consent

Where processing is based on your consent, you have the right to withdraw your consent at any time in accordance with Article 7 (3) GDPR.


Withdrawal of consent shall not affect the lawfulness of processing carried out before the withdrawal.


You may notify us of your withdrawal by e-mail at:

ds@ahig-group.com


To exercise any of the rights described above, you may contact us at ds@ahig-group.com or using the contact details provided above.


Right to Lodge a Complaint

You also have the right to lodge a complaint with a supervisory authority regarding our processing of your personal data.


You may exercise this right in particular before the supervisory authority in the Member State of your habitual residence, place of work or the place of the alleged infringement.


The supervisory authority responsible for us is:

State Commissioner for Data Protection and the Right of Access to Files Brandenburg

Dagmar Hartge

Stahnsdorfer Damm 77

14532 Kleinmachnow

Germany

Phone: +49 (0)33203 356-0

Fax: +49 (0)33203 356-49

E-mail: poststelle@lda.brandenburg.de


3. Collection of Personal Data When Visiting Our Website (Log Files)


(1)

When you use our website for informational purposes only, i.e. if you do not register or otherwise provide us with information, we only collect the personal data that your browser transmits to our server.


When you visit our website, we collect the following data, which is technically necessary to display the website correctly and to ensure its stability and security. The legal basis for this processing is Article 6 (1) (f) GDPR (legitimate interests).


The data is deleted by our web hosting provider after seven (7) days.


The following information is collected:

  • IP address

  • Date and time of the request

  • Time zone difference to Greenwich Mean Time (GMT)

  • Requested content (specific page)

  • Access status / HTTP status code

  • Amount of data transferred

  • Website from which the request originated (referrer)

  • Browser type

  • Operating system and its interface

  • Language and version of the browser software


(2)

In addition to the data listed above, cookies are stored on your device when you use our website.


4. Data Transfer to Framer


We use the services of Framer B.V., Rozengracht 207B, 1016 LZ Amsterdam, The Netherlands ("Framer"), to create, host and operate our website. Our website is hosted on Framer's servers. Framer processes personal data on our behalf pursuant to a Data Processing Agreement in accordance with Article 28 GDPR. Under this agreement, Framer is obliged to process personal data solely in accordance with our documented instructions. Our use of Framer and the related transfer of data is based on our legitimate interest in ensuring the reliable, secure and consistent operation of our website. As a rule, all data collected through our website is transferred to and stored on Framer servers located in the United States.

Any transfer of personal data to the United States is carried out on the basis of the EU Standard Contractual Clauses (SCCs) concluded by Framer and is additionally safeguarded under the EU–U.S. Data Privacy Framework, where applicable.


For further information on how Framer processes personal data, please refer to Framer's Privacy Policy:

https://www.framer.com/legal/privacy-statement/


5. Data Processing in Connection with UP Agency


Description and Scope of Data Processing

When you visit our website, you have the option to make an online booking directly. The booking software is provided by UP Hotel Agency (https://uphotel.agency/). For this purpose, personal data such as your first name, last name, address, telephone number and e-mail address is collected through our website in order to process your booking request or support enquiry.


No personal data is transferred to third parties in this context, including UP Hotel Agency itself.

Your data is processed exclusively for handling your booking request or enquiry.


Legal Basis for Processing

The legal basis for processing your personal data is:

  • Article 6 (1) (b) GDPR (performance of a contract or pre-contractual measures), and

  • Article 6 (1) (f) GDPR (legitimate interests).


Purpose of Processing

The personal data collected through the booking system is processed solely for the purpose of handling your booking request.


Storage Period

Your personal data will be stored for the purpose of processing your enquiry and for any follow-up correspondence. Your data will not be disclosed to third parties without your consent. The retention period depends on your customer relationship with us. If you cancel your booking and have not stayed at our hotel, all personal data relating to the booking will be deleted. Otherwise, statutory retention periods shall apply.


Right to Object

You may object to the processing of your personal data at any time. In this case, it may no longer be possible to continue processing your enquiry or booking. All personal data stored during the course of your enquiry will then be deleted.


6. Cooperation with Other Service Providers


(1)

In addition, personal data may be disclosed to consultants, auditors, attorneys, and public authorities where necessary. As independent controllers pursuant to Article 24 GDPR, these parties are themselves responsible for ensuring compliance with applicable data protection laws. Such disclosures are made either on the basis of our legitimate interests or to comply with legal obligations.


Where we are required or permitted by law or by a court or official order to do so—for example, for the prevention of fraud or money laundering, the enforcement of legal claims, or criminal investigations—we may disclose your personal data to competent authorities, such as residents' registration offices, or to other third parties to the extent necessary.


(2)

In some cases, we engage external service providers to process your personal data on our behalf. These companies are carefully selected by us. Where such providers act as independent controllers under the GDPR (for example, HRS, Booking.com, banks, or public authorities) and are used at your request or upon your instruction, we kindly ask you to exercise your data protection rights directly with those respective organisations.


7. Obligation to Provide Personal Data


In principle, you are not legally obliged to provide us with your personal data. However, if you choose not to provide the personal data required for the purposes described above, we may not be able to make our website available to you, either in full or in part, or to respond to your enquiries. Personal data that is required for the respective processing purposes is identified accordingly where applicable.


8. Automated Decision-Making and Profiling


We do not use automated decision-making or profiling (i.e. the automated analysis of your personal circumstances) within the meaning of the GDPR.


9. Changes to this Privacy Policy


We reserve the right to amend this Privacy Policy at any time. Any changes will be published on this website by making the updated version of the Privacy Policy available. Unless otherwise stated, such amendments shall become effective immediately upon publication. We therefore recommend that you review this Privacy Policy regularly to stay informed about the current version.