1. Data protection at a glance
General information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data means any data that can identify you personally. Detailed information can be found in the privacy policy below.
Data collection on this website
Who is responsible for data collection on this website?
Data on this website is processed by the website operator. Their contact details are provided in the section entitled 'Information about the controller' in this privacy policy.
How do we collect your data?
Some data is collected when you provide it to us, for example information entered in a contact form or when making a booking.
Other data is collected by our IT systems automatically or with your consent when you visit the website. This is mainly technical data, such as your browser, operating system or the time of access. It is collected automatically when you access this website.
What do we use your data for?
Some data is collected to ensure the website works properly. Other data may be used to analyse how you use the website.
What rights do you have regarding your data?
You may request information free of charge at any time about the origin, recipients and purpose of your stored personal data. You also have the right to request its rectification or erasure. If you have consented to processing, you may withdraw consent at any time with future effect. In certain circumstances, you may request restriction of processing. You also have the right to complain to the competent supervisory authority.
You may contact us at any time about these rights or other data protection questions.
2. Hosting
We host our website content with the following provider:
External hosting
This website is hosted externally. Personal data collected on it is stored on the hosting provider's servers. This may include IP addresses, contact enquiries, metadata and communications data, contractual data, contact details, names, website access records and other data generated through a website.
External hosting serves to fulfil contracts with prospective and existing customers under Article 6(1)(b) GDPR and our legitimate interest in secure, fast and efficient online services provided by a professional host under Article 6(1)(f) GDPR. Where consent is requested, processing takes place exclusively under Article 6(1)(a) GDPR and Section 25(1) TDDDG insofar as consent covers storing cookies or accessing information on your device, such as device fingerprinting, within the meaning of the TDDDG. Consent may be withdrawn at any time.
Our hosting provider(s) will process your data only as necessary to meet their service obligations and will follow our instructions regarding that data.
We use the following hosting provider:
HOSTINGER operations, UAB
Švitrigailos str. 34, Vilnius 03230 Lithuania
Phone: +37064503378
Email: domains@hostinger.com
3. General and mandatory information
Data protection
The operators of this website take the protection of your personal data very seriously. We treat it confidentially and in accordance with applicable data protection law and this privacy policy.
Various personal data is collected when you use this website. Personal data is information that can identify you personally. This policy explains what we collect, how and why we collect it, and what we use it for.
Please note that transmitting data over the internet, for example by email, may involve security vulnerabilities. Complete protection against third-party access is not possible.
Information about the controller
The controller responsible for processing data on this website is:
Seliem Taher [Vietec]
Mittelstraße 54
68169 Mannheim
Phone: 0176 31035878
Email: info@vietec.de
The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data, such as names and email addresses.
Retention period
Unless this policy states a more specific retention period, your personal data remains with us until the processing purpose no longer applies. If you submit a valid erasure request or withdraw consent, we will delete your data unless we have other legally permissible grounds for retaining it, such as tax or commercial retention requirements. In that case, deletion takes place when those grounds no longer apply.
General information about the legal bases for processing on this website
If you consent to processing, we process your personal data under Article 6(1)(a) GDPR or Article 9(2)(a) GDPR where special categories under Article 9(1) are involved. Express consent to transfers to third countries also provides a basis under Article 49(1)(a) GDPR. Consent to storing cookies or accessing information on your device, such as through fingerprinting, additionally provides a basis under Section 25(1) TDDDG. Consent can be withdrawn at any time. Data needed to fulfil a contract or take pre-contractual steps is processed under Article 6(1)(b) GDPR. Processing necessary to meet a legal obligation is based on Article 6(1)(c) GDPR. We may also process data on the basis of legitimate interests under Article 6(1)(f) GDPR. The relevant legal bases are explained in the sections below.
Recipients of personal data
We work with various external organisations in the course of our business, which sometimes requires transferring personal data. We share it only where necessary to fulfil a contract, required by law, such as disclosure to tax authorities, supported by a legitimate interest under Article 6(1)(f) GDPR, or permitted by another legal basis. When using processors, customer data is shared only under a valid data processing agreement. Joint processing is governed by a joint-controller agreement.
Withdrawal of consent to processing
Many processing activities require your express consent. You may withdraw consent already given at any time. This does not affect the lawfulness of processing carried out before withdrawal.
Right to object in particular circumstances and to direct marketing (Article 21 GDPR)
WHERE PROCESSING IS BASED ON ARTICLE 6(1)(e) OR (f) GDPR, YOU MAY OBJECT AT ANY TIME ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION. THIS ALSO APPLIES TO PROFILING BASED ON THOSE PROVISIONS. THE RELEVANT LEGAL BASIS IS SET OUT IN THIS PRIVACY POLICY. FOLLOWING AN OBJECTION, WE WILL NO LONGER PROCESS THE PERSONAL DATA CONCERNED UNLESS WE DEMONSTRATE COMPELLING LEGITIMATE GROUNDS OVERRIDING YOUR INTERESTS, RIGHTS AND FREEDOMS, OR PROCESSING IS NECESSARY TO ESTABLISH, EXERCISE OR DEFEND LEGAL CLAIMS (ARTICLE 21(1) GDPR).
IF PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING, YOU MAY OBJECT AT ANY TIME TO PROCESSING FOR THAT PURPOSE, INCLUDING RELATED PROFILING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE USED FOR DIRECT MARKETING (ARTICLE 21(2) GDPR).
Right to complain to the competent supervisory authority
In the event of a GDPR infringement, data subjects may complain to a supervisory authority, particularly in the Member State of their habitual residence, workplace or the alleged infringement. This right is without prejudice to other administrative or judicial remedies.
Right to data portability
You may receive, or have a third party receive, data we process automatically on the basis of consent or a contract in a commonly used, machine-readable format. Direct transfer to another controller will take place only where technically feasible.
Access, rectification and erasure
Within applicable law, you may obtain free information at any time about your stored personal data, its origin and recipients and the purpose of processing, and may have a right to rectification or erasure. Contact us at any time about this or other personal data questions.
Right to restriction of processing
You may request restriction of processing by contacting us at any time. This right applies in the following circumstances:
- If you contest the accuracy of stored personal data, we generally need time to verify it. You may request restriction during that verification period.
- If processing was or is unlawful, you may request restriction instead of erasure.
- If we no longer need your data but you need it to establish, exercise or defend legal claims, you may request restriction instead of erasure.
- If you object under Article 21(1) GDPR, your interests must be weighed against ours. You may request restriction while it remains unclear whose interests prevail.
Restricted data may, apart from storage, be processed only with your consent, to establish, exercise or defend legal claims, to protect another natural or legal person's rights, or for important public interests of the European Union or a Member State.
SSL or TLS encryption
For security and to protect confidential content such as orders or enquiries sent to us, this website uses SSL or TLS encryption. An encrypted connection is indicated by the address changing from 'http://' to 'https://' and by the lock symbol in your browser.
When SSL or TLS encryption is active, third parties cannot read the data you transmit to us.
Use of the Salonized booking widget
For online appointments we use the booking system Salonized, a service of Salonized B.V., Vijzelstraat 79, 1017 HG Amsterdam, Netherlands. Salonized lets you select and book appointments online. It processes the necessary information, particularly your name, contact details, chosen service, appointment time and other information provided during booking.
Processing serves pre-contractual steps or contract performance under Article 6(1)(b) GDPR. We also have a legitimate interest in efficient, clear and reliable appointment management under Article 6(1)(f) GDPR.
More information about Salonized's processing is available in its privacy policy: https://www.salonized.com/de/privacy-statement.
5. Plugins and tools
Google Maps
This website uses Google Maps, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. This service enables us to display maps on our website.
Google Maps requires your IP address to be stored. This information is usually transferred to a Google server in the USA and stored there. We have no control over that transfer. When Maps is activated, Google may use Google Fonts for consistent typography. Your browser downloads the necessary web fonts to its cache to display text correctly.
Google Maps serves our legitimate interest in presenting our online services attractively and making our locations easy to find under Article 6(1)(f) GDPR. Where consent is requested, processing is based exclusively on Article 6(1)(a) GDPR and Section 25(1) TDDDG insofar as consent covers cookies or access to device information, such as fingerprinting, within the meaning of the TDDDG. Consent may be withdrawn at any time.
Transfers to the USA are based on the European Commission's standard contractual clauses. Details are available at: https://privacy.google.com/businesses/gdprcontrollerterms/ and https://privacy.google.com/businesses/gdprcontrollerterms/sccs/.
More information about Google's handling of user data is available in its privacy policy: https://policies.google.com/privacy?hl=de.
The company is certified under the EU–US Data Privacy Framework (DPF), an agreement intended to ensure European data protection standards for processing in the USA. Every certified company undertakes to comply with those standards. The provider offers more information at: https://www.dataprivacyframework.gov/participant/5780.
6. Online bookings
Use of the Salonized online booking system
For online appointments, our website uses or links to the booking system Salonized provided by Salonized B.V., Vijzelstraat 79, 1017 HG Amsterdam, Netherlands. When you book online, the personal data needed to arrange the appointment is transferred to and processed by Salonized.
This may include your name, phone number, email, chosen service, appointment time and voluntary booking-form details. Processing is used exclusively for appointment management and communication relating to your booking.
The legal basis is Article 6(1)(b) GDPR where booking serves pre-contractual steps or contract performance. Use is also based on our legitimate interest in efficient appointment organisation under Article 6(1)(f) GDPR.
More information about Salonized's processing is available at: https://www.salonized.com/de/privacy-statement.
You can also book appointments by phone or email.
Payment processing through Stripe
For online payments, particularly gift voucher purchases, we use the payment service provider Stripe. The provider is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland.
When paying through Stripe, the necessary payment-processing data is transferred to Stripe. This may include your name, email, billing details, amount, payment information, IP address, device information and transaction data.
Processing serves payment completion and thus contract performance or pre-contractual steps under Article 6(1)(b) GDPR. It may also be based on our legitimate interest in secure, reliable and efficient payments under Article 6(1)(f) GDPR.
The provider generally does not receive complete credit card or bank account details. Stripe processes payment data directly. Depending on the payment method, other payment providers or banks may be involved.
More information about Stripe's processing is available in its privacy policy: https://stripe.com/de/privacy.
Privacy information for WhatsApp use
You may contact us through WhatsApp to make a booking at our hotel. Please note that using WhatsApp transfers personal data, such as your name and phone number, to WhatsApp Inc. (WhatsApp Ireland Limited), where it is processed under their privacy policies.
We use the data you provide exclusively to handle your enquiry and booking. More information about WhatsApp's processing is available in the WhatsApp Privacy Policy.
Last updated: 3 June 2026