PRIVACY

Privacy Policy

Last updated: August 2026

1. Controller

The controller responsible for processing personal data on this website and in connection with our hotel operations is:

Munich Rooms Hotel e.K.
Proprietor: Selcuk Gürler
Herzogstr. 51
80803 Munich
Germany

Email: hello@mucrooms.de
Website: www.mucrooms.de

2. Data Protection Officer

Our company is currently not legally required to appoint a data protection officer.

If you have any questions about data protection, you may contact the controller named above at any time.

3. General Information on Data Processing

We process personal data exclusively in accordance with applicable data protection laws, in particular the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

Personal data means any information relating to an identified or identifiable natural person.

We process personal data in particular to provide our website, respond to inquiries, carry out and manage hotel reservations, process payments, provide our hotel services, and comply with legal obligations.

4. Website and Hosting

When you visit our website, the hosting provider commissioned by us processes data that is technically necessary.

This may include in particular:

  • IP address,

  • date and time of access,

  • pages and files accessed,

  • amount of data transferred,

  • browser type and browser version,

  • operating system,

  • referrer URL,

  • information about successful access.

The data is processed to provide our website technically, ensure its security and stability, and detect and prevent misuse.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in providing our website securely and reliably.

5. Cookies and Cookie Consent Management

Our website uses cookies and comparable technologies.

Technically necessary cookies are used insofar as they are required to operate the website or provide functions expressly requested by you.

For non-essential cookies and comparable technologies, particularly those used for analytics and marketing purposes, we obtain your consent before using them where required by law.

We use a cookie consent management system to manage and document your consent choices.

Our consent management system allows you to decide which categories of cookies and comparable technologies you consent to.

You may change or withdraw your consent at any time with effect for the future via the cookie settings on our website.

6. Google Analytics

We use Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics uses cookies and comparable technologies to analyze the use of our website and generate statistical evaluations.

This may involve processing information about your use of our website, your IP address, technical information about your device, and information about pages accessed and interactions.

Google Analytics is activated on our website only if you have first given the corresponding consent.

The legal basis for processing is Article 6(1)(a) GDPR.

You may withdraw your consent at any time with effect for the future via our cookie settings.

Google may also process personal data outside the European Union or the European Economic Area. The safeguards required by law in each case are used for transfers to third countries.

Further information about Google’s processing of personal data can be found in Google’s privacy policy.

7. Google Maps

We use Google Maps, a map service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, on our website.

Google Maps enables us to provide you with the locations of our hotels, map views, and, where applicable, route planning.

When a page with an embedded Google Maps map is accessed, personal data, particularly your IP address and technical information about your device, may be transferred to Google.

As a rule, Google Maps is loaded on our website only after you have given the corresponding consent, where required by law.

The legal basis is Article 6(1)(a) GDPR.

You may withdraw your consent at any time with effect for the future via our cookie settings.

Further information about Google’s processing of personal data can be found in Google’s privacy policy.

8. Contact and Contact Form

If you contact us by email, telephone, or through a contact form, we process the personal data you provide to the extent necessary to handle your inquiry.

This may include in particular your name, email address, telephone number, and the information you provide as part of your inquiry.

If your inquiry relates to steps taken prior to entering into a contract or to the performance of a contract, the processing is based on Article 6(1)(b) GDPR.

In all other cases, processing is based on our legitimate interest pursuant to Article 6(1)(f) GDPR.

The data provided will be deleted once the inquiry has been conclusively resolved and there are no statutory retention obligations or other legitimate grounds for continued storage.

9. Hotel Reservations and PMS

We use a hotel property management or reservation management system (PMS) to manage and process hotel reservations and guest data.

The following data in particular may be processed in connection with a reservation:

  • name and contact details,

  • address,

  • period of stay,

  • booking and reservation data,

  • payment and billing data,

  • details of fellow travelers, where required,

  • other information you provide to us in connection with your stay.

The data is processed to take steps prior to entering into, perform, and administer the accommodation contract pursuant to Article 6(1)(b) GDPR and to comply with legal obligations pursuant to Article 6(1)(c) GDPR.

Where external service providers process personal data on our behalf in this context, processing is carried out on the basis of the data protection agreements required for this purpose pursuant to Article 28 GDPR.

10. Online Bookings

If you make a hotel reservation through our website, we process the data you enter to handle and fulfill the reservation.

The processing is necessary to perform the accommodation contract or take steps prior to entering into a contract and is based on Article 6(1)(b) GDPR.

The data required for the booking may be transferred to the technical service providers and booking systems we use.

11. Payment Processing – Stripe

We may use the payment service provider Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin 2, Ireland, to process online payments.

In connection with payment processing, names, payment information, billing data, and booking- and payment-related information in particular may be processed.

The processing is carried out to perform the contract pursuant to Article 6(1)(b) GDPR and to comply with legal obligations pursuant to Article 6(1)(c) GDPR.

Under certain circumstances, Stripe may also transfer personal data to affiliated companies or service providers outside the European Economic Area. The safeguards required by law in each case are used for such transfers.

Further information about Stripe’s processing of personal data can be found in Stripe’s privacy policy.

12. Payment Processing – SumUp

We may use payment terminals and services from SumUp for card payments on site at our hotels.

Payment, transaction, and technical data in particular may be processed in connection with payment processing.

The processing is carried out to execute the payment transaction pursuant to Article 6(1)(b) GDPR and to comply with statutory retention and documentation obligations pursuant to Article 6(1)(c) GDPR.

We do not use SumUp as an online payment page on our website.

13. Wi-Fi

We provide our guests with Wi-Fi internet access at our hotels.

Technical connection data, device information, IP addresses, and the date and time of use in particular may be processed to provide and technically secure Wi-Fi access.

The data is processed to provide Wi-Fi access, ensure technical security, and prevent misuse of the network.

The legal basis is Article 6(1)(b) GDPR insofar as the processing is necessary to provide the agreed service, and Article 6(1)(f) GDPR insofar as it is necessary to safeguard our legitimate interests in secure and uninterrupted network operation.

Data is stored only for as long as necessary for the purposes stated or for as long as statutory retention obligations apply.

14. Video Surveillance

We use video surveillance in certain areas of our hotel premises to exercise our domiciliary rights and protect guests, employees, visitors, and our property.

Video surveillance is used in particular to:

  • exercise and enforce our domiciliary rights,

  • prevent and investigate criminal offenses,

  • secure our buildings and facilities,

  • ensure the safety of guests, employees, and visitors.

Personal data is processed through video surveillance on the basis of Article 6(1)(f) GDPR. Our legitimate interest lies in particular in protecting our property and ensuring safety within and in the immediate vicinity of our business premises.

Surveillance is conducted exclusively in the areas where it is necessary for these purposes. Areas where a particular degree of privacy is expected are not monitored.

Recordings are generally stored for 7 days and then deleted automatically, unless longer storage is required due to a specific incident in order to preserve evidence or establish, exercise, or defend legal claims.

Video surveillance is indicated by appropriate signs in the respective monitored areas.

15. Disclosure of Personal Data and Processing on Behalf of the Controller

Personal data is disclosed to third parties only where this is necessary to fulfill our contractual or legal obligations, where you have given your consent, or where another legal basis applies.

Recipients may include in particular:

  • payment service providers,

  • booking and reservation systems,

  • IT and hosting service providers,

  • technical service providers,

  • tax advisers,

  • public authorities,

  • other service providers that support us in carrying out our business activities.

Where service providers process personal data on our behalf, we enter into data processing agreements pursuant to Article 28 GDPR where required by law.

16. Retention Period

We store personal data only for as long as necessary for the respective processing purpose.

In addition, statutory retention obligations apply, particularly under commercial and tax law.

After the applicable retention periods have expired, the data is deleted unless there is another legal basis for its continued storage.

17. Applicant Data

If you apply for an advertised position with us or submit an unsolicited application, we process the personal data you provide as part of your application.

This may include in particular:

  • name and contact details,

  • CV and employment history,

  • certificates and proof of qualifications,

  • information about education and professional experience,

  • other information you voluntarily provide to us as part of the application process.

The data is processed for the purpose of conducting the application process and deciding whether to establish an employment relationship.

The legal basis is, in particular, Section 26(1) BDSG.

After the application process has concluded, application documents are generally deleted no later than six months thereafter, unless another legal basis for continued storage exists or you have expressly consented to continued storage.

If an application results in employment, the data collected during the application process may be further processed to the extent necessary for administering the employment relationship.

18. Data Security

We take appropriate technical and organizational measures to protect personal data against loss, destruction, manipulation, unauthorized access, and other unlawful processing.

Our security measures are regularly reviewed and adapted in line with technological developments and organizational possibilities.

19. Your Rights

Subject to the applicable statutory requirements, you have the following rights in particular:

  • right of access pursuant to Article 15 GDPR,

  • right to rectification pursuant to Article 16 GDPR,

  • right to erasure pursuant to Article 17 GDPR,

  • right to restriction of processing pursuant to Article 18 GDPR,

  • right to data portability pursuant to Article 20 GDPR,

  • right to object pursuant to Article 21 GDPR,

  • right to withdraw consent with effect for the future.

To exercise your rights, you may contact the controller named above at any time.

20. Right to Lodge a Complaint with a Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority concerning the processing of your personal data.

The supervisory authority responsible for our company is:

Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 27
91522 Ansbach
Germany

21. Updates to This Privacy Policy

We reserve the right to amend this Privacy Policy where necessary due to technological developments, changes to our services, or legal or regulatory requirements.

The current version published on our website applies in each case.