Data collection on our website
Who is responsible for data collection on this website?
The data processing on this website is carried out by the website operator. You can find their contact details in the legal notice of this website.
How do we collect your data?
There are two ways your information is gathered. The first is when you provide the information to us, such as when inputting details into a contact form.
The second is when our IT systems automatically record information when you visit our website. This includes technical details like your browser, operating system, and when you accessed the page. This data collection is done automatically as soon as you visit our website.
What do we use your data for?
Some of the data is collected to ensure error-free provision of the website. Other data may be used to analyze your user behavior.
What rights do you have regarding your data?
You have the right to receive information about the origin, recipient, and purpose of your personal data stored at any time and free of charge. You also have the right to request the correction, blocking, or deletion of this data. For this purpose, as well as for further questions regarding data protection, you can contact us at any time using the address provided in the legal notice. Furthermore, you have the right to file a complaint with the appropriate supervisory authority.
Analysis tools and third-party tools
When visiting our website, your surfing behaviour can be statistically evaluated. This is done primarily with cookies and so-called analysis programs. The analysis of your surfing behaviour is usually anonymous; the surfing behaviour cannot be traced back to you. You can object to this analysis or prevent it by not using certain tools. You will find detailed information on this in the following data protection declaration.
You can object to this analysis. We will inform you about the objection options in this data protection declaration.
General information and bbligatory notices
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the legal data protection regulations as well as this data protection declaration.
When you use this website, various personal data is collected. Personal data is data that can be used to personally identify you. This data protection declaration explains which data we collect and for what purpose. It also explains how and for what purpose this is done.
We would like to point out that data transmission over the Internet (e.g. when communicating by email) can have security gaps. Complete protection of data from access by third parties is not possible.
Note on the responsible entity
The data controller for this website is:
Saunapark Siebengebirge GmbH & CoKG
Dollendorfer Straße 106-110
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data (e.g. names, e-mail addresses, etc.).
Revocation of your consent to data processing
Many data processing operations are only possible with your explicit consent. You can revoke a previously given consent at any time. To do so, it is sufficient to send an informal notification by email to us. The legality of the data processing carried out until revocation remains unaffected by the revocation.
Right of appeal to the competent supervisory authority
Im Falle datenschutzrechtlicher Verstöße steht dem Betroffenen ein Beschwerderecht bei der zuständigen Aufsichtsbehörde zu. Zuständige Aufsichtsbehörde in datenschutzrechtlichen Fragen ist der Landesdatenschutzbeauftragte des Bundeslandes, in dem unser Unternehmen seinen Sitz hat. Eine Liste der Datenschutzbeauftragten sowie deren Kontaktdaten können folgendem Link entnommen werden:
Right to data portability
You have the right to have data that we process automatically on the basis of your consent or in fulfilment of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done insofar as it is technically feasible.
SSL or TLS encryption
This website uses SSL/TLS encryption as a measure of security and to protect the transmission of confidential content such as orders or inquiries that you send to us as the site operator. You can recognize an encrypted connection by the change in the browser’s address bar from “http://” to “https://” and the lock symbol in your browser bar.
When SSL/TLS encryption is enabled, data that you transmit to us cannot be read by third parties.
Encrypted payment transactions on this website
After purchasing a paid subscription, if there is an obligation to provide us with your payment information (such as bank account number for direct debit), this data is required for payment processing.
Payments using common methods (Visa/Mastercard, Direct Debit) are exclusively conducted through an encrypted SSL or TLS connection. You can recognize an encrypted connection by the browser address bar changing from “http://” to “https://” and the presence of a lock symbol in your browser.
When using encrypted communication, your payment information that you transmit to us cannot be read by third parties.
Information, blocking, deletion
You have the right at any time, within the framework of applicable legal provisions, to obtain free-of-charge information about your personal data stored by us, their origin, recipients and the purpose of data processing, and, if applicable, a right to correct, block or delete this data. For this purpose, as well as for further questions regarding personal data, you can contact us at any time at the address provided in the imprint.
Objection to promotional emails
The use of contact data published within the framework of the imprint obligation for the purpose of sending unsolicited advertising and informational materials is hereby prohibited. The operators of the website expressly reserve the right to take legal action in the event of unsolicited advertising information, such as spam emails.
Data Protection Officer
Data Protection Officer required by law
We have appointed a data protection officer for our company.
Saunapark Siebengebirge GmbH & CoKG
Dollendorfer Straße 106-110
Datenerfassung auf unserer Website
Most of the cookies used by the website are session cookies that are automatically deleted after your visit. Other cookies remain on your device until you delete them and allow the website to recognize your browser during your next visit.
Server log files
The provider of the website automatically collects and stores information in so-called server log files that your browser automatically transmits to us. This includes the browser type and version, operating system used, referrer URL, hostname of the accessing computer, server request time, and IP address.
The data will not be merged with other data sources. The processing of data is based on Art. 6 para. 1 lit. f GDPR, which allows the processing of data for the fulfillment of a contract or pre-contractual measures.
Processing data (customer and contract data)
We only collect, process and use personal data to the extent necessary for establishing, developing or altering the legal relationship (inventory data). This is done on the basis of Art. 6 para. 1 lit. b GDPR, which allows the processing of data for the performance of a contract or pre-contractual measures. We only collect, process and use personal data regarding the use of our website (usage data) to the extent necessary to enable the user to use the service or to bill for it.
The collected customer data will be deleted after completion of the order or termination of the business relationship. Legal retention periods remain unaffected.
Data transfer during the conclusion of contracts for online shops, merchants, and shipping of goods
We only transmit personal data to third parties if this is necessary in the context of processing the contract, for example to the companies entrusted with the delivery of the goods or the credit institution commissioned with processing the payment. Further transmission of data does not take place or only if you have expressly consented to the transmission. Your data will not be passed on to third parties without your express consent, for example for advertising purposes.
The basis for data processing is Art. 6 para. 1 lit. b DSGVO, which permits the processing of data for the fulfilment of a contract or pre-contractual measures.
Data transmission during contract conclusion for services and digital content
We only transmit personal data to third parties if it is necessary for the processing of the contract, such as to the credit institution responsible for payment processing.
Further transmission of the data does not occur unless you have expressly consented to the transmission. Your data will not be passed on to third parties without your express consent, for example for advertising purposes.
The legal basis for data processing is Art. 6 para. 1 lit. b GDPR, which allows the processing of data for the fulfillment of a contract or pre-contractual measures.
Facebook plugins (Like & Share-Button)
On our pages, social network Facebook’s plugins, provided by Facebook Inc., 1 Hacker Way, Menlo Park, California 94025, USA, are integrated. You can identify Facebook plugins by the Facebook logo or the “Like” button on our page. An overview of Facebook plugins can be found here: https://developers.facebook.com/docs/plugins/.
If you do not want Facebook to associate your visit to our pages with your Facebook user account, please log out of your Facebook account.
Analysis tools and advertising
This website uses features of the web analysis service Google Analytics. The provider is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Google Analytics uses so-called “cookies”. These are text files that are stored on your computer and allow an analysis of your website usage. The information generated by the cookie about your use of this website is usually transmitted to and stored on a Google server in the United States.
The storage of Google Analytics cookies is based on Art. 6 para. 1 lit. f DSGVO. The website operator has a legitimate interest in analyzing user behavior in order to optimize both his website and his advertising.
We have activated the IP anonymization function on this website. This means that your IP address is truncated by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before it is transmitted to the USA. Only in exceptional cases will the full IP address be transferred to a Google server in the USA and truncated there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity, and to provide other services related to website and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other data from Google.
You can prevent the storage of cookies by adjusting the settings of your browser software; however, please note that in this case you may not be able to use all the features of this website to their full extent. Furthermore, you can prevent the collection of data generated by the cookie about your use of the website (including your IP address) to Google and the processing of this data by Google, by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=en.
Objection to data collection
You can prevent Google Analytics from collecting your data by clicking on the following link. This will set an opt-out cookie which will prevent the collection of your data during future visits to this website: Disable Google Analytics.
Order data processing
Demografische Merkmale bei Google Analytics
We have signed a contract with Google for order data processing and fully comply with the strict regulations of the German data protection authorities when using Google Analytics.
This website uses Google Analytics’ “demographic features” function to create reports on the age, gender, and interests of site visitors. This data comes from Google’s interest-based advertising and third-party visitor data and cannot be linked to any specific individual. You can disable this feature at any time through the ad settings in your Google account or opt-out of data collection by Google Analytics as demonstrated in the “objection to data collection” section.
We use “Google reCAPTCHA” (hereinafter “reCAPTCHA”) on our websites. The provider is Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”).
The purpose of reCAPTCHA is to check whether data entry on our websites (e.g. in a contact form) is made by a human or by an automated programme. For this purpose, reCAPTCHA analyses the behaviour of the website visitor on the basis of various characteristics. This analysis begins automatically as soon as the website visitor enters the website. For the analysis, reCAPTCHA evaluates various information (e.g. IP address, time spent by the website visitor on the website or mouse movements made by the user). The data collected during the analysis is forwarded to Google.
The reCAPTCHA analyses run entirely in the background. Website visitors are not informed that an analysis is taking place.
The data processing is based on Art. 6 para. 1 lit. f DSGVO. The website operator has a legitimate interest in protecting its web offers from abusive automated spying and from SPAM.
https://www.google.com/intl/de/policies/privacy/ and https://www.google.com/recaptcha/intro/android.htm
If you would like to receive the newsletter offered on the website, we require an e-mail address from you as well as information that allows us to verify that you are the owner of the specified e-mail address and that you agree to receive the newsletter. Further data will not be collected or will only be collected on a voluntary basis. We use this data exclusively for sending the requested information and do not pass it on to third parties.
The processing of the data entered in the newsletter registration form is based exclusively on your consent (Art. 6 para. 1 lit. a DSGVO). You can revoke your consent to the storage of the data, the e-mail address and their use for sending the newsletter at any time, for example via the “unsubscribe” link in the newsletter. The legality of the data processing operations already carried out remains unaffected by the revocation.
The data you provide for the purpose of receiving the newsletter will be stored by us until you unsubscribe from the newsletter and will be deleted after you unsubscribe from the newsletter. Data stored by us for other purposes (e.g. e-mail addresses for the members’ area) remain unaffected by this.
This website uses Sendinblue to send newsletters. The provider is Sendinblue gmbH, Köpenicker Str. 126, 10179 Berlin. Sendinlbue is a service with which the newsletter dispatch can be organised and analysed. The data you enter for the purpose of receiving newsletters (e.g. e-mail address) is stored on Sendinblue’s servers in Germany.
Our newsletters sent with Sendinblue enable us to analyse the behaviour of the newsletter recipients. Among other things, we can analyse how many recipients have opened the newsletter message and how often which link in the newsletter was clicked. With the help of so-called conversion tracking, it can also be analysed whether a predefined action (e.g. purchase of a product on our website) has taken place after clicking on the link in the newsletter.
The data processing is based on your consent (Art. 6 para. 1 lit. a DSGVO). You can revoke this consent at any time by unsubscribing from the newsletter. The legality of the data processing operations already carried out remains unaffected by the revocation.
If you do not want Sendinblue to analyse your data, you must unsubscribe from the newsletter. For this purpose, we provide a corresponding link in every newsletter message. Furthermore, you can also unsubscribe directly on the website.
The data you provide us with for the purpose of receiving the newsletter will be stored by us until you unsubscribe from the newsletter and will be deleted from our servers as well as from the servers of Sendinblue after you unsubscribe from the newsletter. Data stored by us for other purposes (e.g. email addresses for the member area) remain unaffected by this.
Plugins and tools
This site uses the map service Google Maps via an API. The provider is Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
To use the functions of Google Maps, it is necessary to store your IP address. This information is usually transferred to a Google server in the USA and stored there. The provider of this site has no influence on this data transmission.
Google Maps is used in the interest of an appealing presentation of our online offers and to make it easy to find the places we indicate on the website. This constitutes a legitimate interest within the meaning of Art. 6 Para. 1 lit. f DSGVO.
The service provider Heidelpay processes all payments in the Saunapark Siebengebirge GmbH & CoKG online shop.
However, we do not store your payment data with us. You can find out more about heidelpay at:
The processing can be done via the following payment options:
On our website we offer, among other things, payment via PayPal. The provider of this payment service is PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter “PayPal”).
If you select payment via PayPal, the payment data you enter will be transmitted to PayPal.
The transmission of your data to PayPal is based on Art. 6 para. 1 lit. a DSGVO (consent) and Art. 6 para. 1 lit. b DSGVO (processing for the performance of a contract). You have the option to revoke your consent to data processing at any time. A revocation does not affect the validity of past data processing operations.
Instant bank transfer
On our website we offer, among other things, payment by “Sofortüberweisung”. The provider of this payment service is Sofort GmbH, Theresienhöhe 12, 80339 Munich (hereinafter “Sofort GmbH”).
With the help of the “Sofortüberweisung” procedure, we receive a payment confirmation from Sofort GmbH in real time and can immediately begin to fulfil our obligations.
If you have chosen the payment method “Sofortüberweisung”, you transmit the PIN and a valid TAN to Sofort GmbH, which can then log into your online banking account. After logging in, Sofort GmbH automatically checks your account balance and carries out the transfer to us using the TAN you have transmitted. It then immediately sends us a transaction confirmation. After logging in, it also automatically checks your turnover, the credit line of the overdraft facility and the existence of other accounts and their balances.
In addition to the PIN and the TAN, the payment data you have entered as well as your personal data are transmitted to Sofort GmbH. Your personal data includes your first and last name, address, telephone number(s), email address, IP address and, if applicable, other data required for payment processing. The transmission of this data is necessary to establish your identity beyond doubt and to prevent attempts at fraud.
The transmission of your data to Sofort GmbH is based on Art. 6 para. 1 lit. a DSGVO (consent) and Art. 6 para. 1 lit. b DSGVO (processing for the performance of a contract). You have the option to revoke your consent to data processing at any time. A revocation does not affect the validity of past data processing operations.
For details on payment with Sofortüberweisung, please refer to the following links:
https://www.sofort.de/datenschutz.html and https://www.klarna.com/sofort/
When selecting the direct debit payment method via Heidelpay, you will be asked to provide your personal data (first and last name, street, house number, postcode, town, date of birth, e-mail address and telephone number) during the ordering process. This data will be forwarded by us to Heidelberger Payment GmbH, Vangerowstr. 18, 69115 Heidelberg (hereinafter “Heidelpay”) for the purpose of a credit check. Heidelpay checks on the basis of the personal data provided by you as well as further data (such as shopping basket, invoice amount, payment experience) whether the payment option selected by you can be granted with regard to payment and/or bad debt risks. For the purpose of deciding on the establishment or implementation of a contractual relationship, identity or creditworthiness information from the following credit agencies may also be included:
- SCHUFA Holding AG, Kormoranweg 5, 65201 Wiesbaden, Germany.
- CRIF Bürgel GmbH, Gasstraße 18, 22761 Hamburg, Germany
- Arvato Infoscore GmbH, Rheinstraße 99, 76532 Baden-Baden, Germany
- Deltavista GmbH, Kaiserstrasse 217, 76133 Karlsruhe, Germany
- UNIVERSUM Business GmbH, Hugo-Junkers-Strasse 3, 60386 Frankfurt am Main, Germany
- Bisnode International Group, Robert-Bosch-Straße 11, 64293 Darmstadt, Germany
- Regis24 GmbH, Wallstrasse 58, 10179 Berlin
- Creditreform AG, Hellersbergstraße 12, 41460 Neuss, Germany
The credit report may contain probability values (so-called score values). Insofar as score values are included in the result of the credit report, they are based on a scientifically recognised mathematical-statistical procedure; address data, among other things, are included in the calculation of the score values.
When selecting the payment method of invoice purchase, you will be prompted to enter your personal information (first and last name, street, house number, postal code, city, email address, and telephone number) during the ordering process. This information will only be used for order processing and will not be forwarded to Heidelpay.