Privacy Policy
Last updated: 18 October 2025
Learn more about our
1. Controller
KR Hotelbetriebs GmbH
Hauptstraße 374
52629 Königswinter, Germany
Email: stay@eldalio.com
2. Hosting & Infrastructure
- Web hosting: Our website is hosted by Hostinger in a data center located in Frankfurt, Germany (EU).
- Automation (n8n): We operate an n8n instance on Hostinger in Frankfurt to orchestrate operational processes (e.g., booking flows, payment events, document generation, email notifications). We do not store sensitive categories of data in n8n and we do not save execution logs.
3. Categories of Personal Data We Process
- Identification & contact data: name, email address, postal address, phone number (if provided).
- Booking & contract data: stay details, unit, dates, pricing, terms, signatures, contract metadata.
- Billing & payment references: invoice details, tax info, Stripe customer/subscription IDs, payment method metadata (e.g., brand/last 4 where available). We do not store full card numbers or CVCs.
- Technical data: IP address, timestamps, pages visited, user agent, referrer, consent status (for cookies).
- Analytics data (only with consent): usage metrics and events from Google Analytics.
4. Purposes & Legal Bases
- Website delivery & security – Art. 6(1)(f) GDPR (legitimate interests).
- Inquiries & communication – Art. 6(1)(b) (pre-contract) or Art. 6(1)(f).
- Booking, payment & invoicing – Art. 6(1)(b) (contract) and Art. 6(1)(c) (legal obligations).
- Contract creation & e-signature (DocuSign) – Art. 6(1)(b) (contract).
- Fraud prevention & service integrity – Art. 6(1)(f) (legitimate interests).
- Analytics/measurement – Art. 6(1)(a) (consent; cookies only after opt-in).
- Compliance & retention – Art. 6(1)(c) (legal obligations).
5. Payments via Stripe
We use Stripe to process payments, including recurring charges. Stripe stores your payment method for recurring invoices. We receive and store payment references (e.g., customer ID, subscription ID) and invoice metadata needed for accounting. We do not store full card data on our systems. Processing may involve transfers outside the EU/EEA with appropriate safeguards (e.g., Standard Contractual Clauses).
6. Contract Generation via DocuSign
We use DocuSign to generate and route contracts tailored to tenants. Data processed can include your name, email, address, booking details, contract terms and signature data. Executed contracts are stored in DocuSign and in our records where necessary for contract performance and legal retention. Processing may involve transfers outside the EU/EEA with appropriate safeguards (e.g., Standard Contractual Clauses).
7. Automation via n8n (Frankfurt)
Operational steps (e.g., receiving Stripe webhooks, generating invoices, sending confirmations, initiating DocuSign envelopes) are automated in n8n on our Frankfurt server. We minimize data processing, avoid special-category data, and do not save execution logs. Only data necessary for each workflow step is processed and passed to the required service.
8. Analytics (Google Analytics)
We use Google Analytics (GA4) only if you consent via our cookie banner. GA uses cookies or similar technologies to collect usage metrics; IP anonymization is enabled. If you decline analytics cookies, Google Analytics will not load. Analytics data is retained no longer than 14 months.
9. Cookies & Consent
- Essential cookies: required for basic functionality (Art. 6(1)(f) GDPR; §25(2) TTDSG).
- Analytics cookies: used only after consent (Art. 6(1)(a) GDPR; §25(1) TTDSG). Your consent status is stored so we can honor your choice. You can change your choice at any time via the cookie settings on our site.
10. Data Recipients & Processors
- Hosting & infrastructure: Hostinger (Frankfurt, DE).
- Automation: n8n (self-managed on Hostinger, Frankfurt).
- Payments: Stripe.
- Contracts & e-signature: DocuSign.
- Analytics: Google Analytics.
Where processors or their sub-processors operate outside the EU/EEA, we ensure an adequate level of protection (e.g., Standard Contractual Clauses and other safeguards as applicable).
11. Retention
- Contracts, invoices, and booking/accounting records: retained in line with statutory obligations (generally up to 10 years for tax documents; certain business correspondence up to 6 years under German law).
- Operational communications: retained as needed for contract performance and evidence, then deleted.
- Analytics data: up to 14 months (if consented).
- n8n executions: no execution logs are saved.
12. Security
We apply appropriate technical and organizational measures, including HTTPS/TLS, access controls, data minimization, encryption in transit (and at rest where supported by providers), and processor due diligence.
13. No Automated Decision-Making
We do not perform automated decision-making or profiling producing legal or similarly significant effects. Contract generation via DocuSign is templated document automation, not automated decision-making.
14. Changes to This Policy
We may update this policy to reflect legal, technical, or business developments. The “Last updated” date will be adjusted accordingly.
15. Contact
For questions about this policy or how we process personal data, contact:
KR Hotelbetriebs GmbH
Hauptstraße 374, 53639 Königswinter, Germany
Email: stay@eldalio.com
Ready to Book Your Stay?
Explore our furnished coliving apartments in Königswinter or get in touch with our team.