Privacy Policy

1. Data protection at a glance

General information

The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data means any data that can identify you personally. Detailed information can be found in the privacy policy below.

Data collection on this website

Who is responsible for data collection on this website?

Data on this website is processed by the website operator. Their contact details are provided in the section entitled 'Information about the controller' in this privacy policy.

How do we collect your data?

Some data is collected when you provide it to us, for example information entered in a contact form or when making a booking.

Other data is collected by our IT systems automatically or with your consent when you visit the website. This is mainly technical data, such as your browser, operating system or the time of access. It is collected automatically when you access this website.

What do we use your data for?

Some data is collected to ensure the website works properly. Other data may be used to analyse how you use the website.

What rights do you have regarding your data?

You may request information free of charge at any time about the origin, recipients and purpose of your stored personal data. You also have the right to request its rectification or erasure. If you have consented to processing, you may withdraw consent at any time with future effect. In certain circumstances, you may request restriction of processing. You also have the right to complain to the competent supervisory authority.

You may contact us at any time about these rights or other data protection questions.

2. Hosting

We host our website content with the following provider:

External hosting

This website is hosted externally. Personal data collected on it is stored on the hosting provider's servers. This may include IP addresses, contact enquiries, metadata and communications data, contractual data, contact details, names, website access records and other data generated through a website.

External hosting serves to fulfil contracts with prospective and existing customers under Article 6(1)(b) GDPR and our legitimate interest in secure, fast and efficient online services provided by a professional host under Article 6(1)(f) GDPR. Where consent is requested, processing takes place exclusively under Article 6(1)(a) GDPR and Section 25(1) TDDDG insofar as consent covers storing cookies or accessing information on your device, such as device fingerprinting, within the meaning of the TDDDG. Consent may be withdrawn at any time.

Our hosting provider(s) will process your data only as necessary to meet their service obligations and will follow our instructions regarding that data.

We use the following hosting provider:

HOSTINGER operations, UAB
Švitrigailos str. 34, Vilnius 03230 Lithuania

Phone: +37064503378
Email: domains@hostinger.com

3. General and mandatory information

Data protection

The operators of this website take the protection of your personal data very seriously. We treat it confidentially and in accordance with applicable data protection law and this privacy policy.

Various personal data is collected when you use this website. Personal data is information that can identify you personally. This policy explains what we collect, how and why we collect it, and what we use it for.

Please note that transmitting data over the internet, for example by email, may involve security vulnerabilities. Complete protection against third-party access is not possible.

Information about the controller

The controller responsible for processing data on this website is:

Seliem Taher [Vietec]
Mittelstraße 54
68169 Mannheim

Phone: 0176 31035878
Email: info@vietec.de

The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data, such as names and email addresses.

Retention period

Unless this policy states a more specific retention period, your personal data remains with us until the processing purpose no longer applies. If you submit a valid erasure request or withdraw consent, we will delete your data unless we have other legally permissible grounds for retaining it, such as tax or commercial retention requirements. In that case, deletion takes place when those grounds no longer apply.

General information about the legal bases for processing on this website

If you consent to processing, we process your personal data under Article 6(1)(a) GDPR or Article 9(2)(a) GDPR where special categories under Article 9(1) are involved. Express consent to transfers to third countries also provides a basis under Article 49(1)(a) GDPR. Consent to storing cookies or accessing information on your device, such as through fingerprinting, additionally provides a basis under Section 25(1) TDDDG. Consent can be withdrawn at any time. Data needed to fulfil a contract or take pre-contractual steps is processed under Article 6(1)(b) GDPR. Processing necessary to meet a legal obligation is based on Article 6(1)(c) GDPR. We may also process data on the basis of legitimate interests under Article 6(1)(f) GDPR. The relevant legal bases are explained in the sections below.

Recipients of personal data

We work with various external organisations in the course of our business, which sometimes requires transferring personal data. We share it only where necessary to fulfil a contract, required by law, such as disclosure to tax authorities, supported by a legitimate interest under Article 6(1)(f) GDPR, or permitted by another legal basis. When using processors, customer data is shared only under a valid data processing agreement. Joint processing is governed by a joint-controller agreement.

Withdrawal of consent to processing

Many processing activities require your express consent. You may withdraw consent already given at any time. This does not affect the lawfulness of processing carried out before withdrawal.

Right to object in particular circumstances and to direct marketing (Article 21 GDPR)

WHERE PROCESSING IS BASED ON ARTICLE 6(1)(e) OR (f) GDPR, YOU MAY OBJECT AT ANY TIME ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION. THIS ALSO APPLIES TO PROFILING BASED ON THOSE PROVISIONS. THE RELEVANT LEGAL BASIS IS SET OUT IN THIS PRIVACY POLICY. FOLLOWING AN OBJECTION, WE WILL NO LONGER PROCESS THE PERSONAL DATA CONCERNED UNLESS WE DEMONSTRATE COMPELLING LEGITIMATE GROUNDS OVERRIDING YOUR INTERESTS, RIGHTS AND FREEDOMS, OR PROCESSING IS NECESSARY TO ESTABLISH, EXERCISE OR DEFEND LEGAL CLAIMS (ARTICLE 21(1) GDPR).

IF PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING, YOU MAY OBJECT AT ANY TIME TO PROCESSING FOR THAT PURPOSE, INCLUDING RELATED PROFILING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE USED FOR DIRECT MARKETING (ARTICLE 21(2) GDPR).

Right to complain to the competent supervisory authority

In the event of a GDPR infringement, data subjects may complain to a supervisory authority, particularly in the Member State of their habitual residence, workplace or the alleged infringement. This right is without prejudice to other administrative or judicial remedies.

Right to data portability

You may receive, or have a third party receive, data we process automatically on the basis of consent or a contract in a commonly used, machine-readable format. Direct transfer to another controller will take place only where technically feasible.

Access, rectification and erasure

Within applicable law, you may obtain free information at any time about your stored personal data, its origin and recipients and the purpose of processing, and may have a right to rectification or erasure. Contact us at any time about this or other personal data questions.

Right to restriction of processing

You may request restriction of processing by contacting us at any time. This right applies in the following circumstances:

Restricted data may, apart from storage, be processed only with your consent, to establish, exercise or defend legal claims, to protect another natural or legal person's rights, or for important public interests of the European Union or a Member State.

SSL or TLS encryption

For security and to protect confidential content such as orders or enquiries sent to us, this website uses SSL or TLS encryption. An encrypted connection is indicated by the address changing from 'http://' to 'https://' and by the lock symbol in your browser.

When SSL or TLS encryption is active, third parties cannot read the data you transmit to us.

4. Data collection on this website

Cookies

Our website uses cookies, small data packages that do not damage your device. They are stored temporarily for a session or permanently. Session cookies are deleted automatically after your visit. Permanent cookies remain until you delete them or your browser deletes them automatically.

Cookies may come from us (first-party cookies) or third-party companies. Third-party cookies enable integration of services such as payment processing.

Cookies have various functions. Many are technically necessary because certain website functions would otherwise not work, such as shopping baskets or video display. Others may analyse user behaviour or serve advertising purposes.

Necessary cookies used for electronic communications, functions you request, such as shopping baskets, or website optimisation, such as audience measurement, are stored under Article 6(1)(f) GDPR unless another basis is stated. The operator has a legitimate interest in necessary cookies for technically reliable, optimised services. Where consent for cookies and similar recognition technologies is requested, processing is based exclusively on that consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG. Consent may be withdrawn at any time.

You can configure your browser to notify you of cookies, allow them individually, reject them in particular cases or entirely, and delete them automatically when closing the browser. Disabling cookies may limit this website's functionality.

The cookies and services used on this website are described in this privacy policy.

This cookie table was created and is maintained by Cookie Consent Tool – CookieFirst.

Server log files

The website provider automatically collects and stores information in server log files that your browser sends to us. This includes:

This data is not combined with other data sources.

Collection is based on Article 6(1)(f) GDPR. The operator has a legitimate interest in technically reliable display and optimisation of the website, for which server logs are necessary.

Enquiries by email, phone or fax

If you contact us by email, phone or fax, we store and process your enquiry, including all resulting personal data such as your name and enquiry, to handle your request. We do not share this data without your consent.

Processing is based on Article 6(1)(b) GDPR if your enquiry relates to a contract or pre-contractual steps. Otherwise, it is based on our legitimate interest in efficiently handling enquiries under Article 6(1)(f) GDPR, or consent under Article 6(1)(a) GDPR where requested. Consent may be withdrawn at any time.

Data sent in contact enquiries remains with us until you request deletion, withdraw consent to storage or the storage purpose no longer applies, for example once the enquiry is resolved. Mandatory law, particularly statutory retention periods, remains unaffected.

Use of the Salonized booking widget

For online appointments we use the booking system Salonized, a service of Salonized B.V., Vijzelstraat 79, 1017 HG Amsterdam, Netherlands. Salonized lets you select and book appointments online. It processes the necessary information, particularly your name, contact details, chosen service, appointment time and other information provided during booking.

Processing serves pre-contractual steps or contract performance under Article 6(1)(b) GDPR. We also have a legitimate interest in efficient, clear and reliable appointment management under Article 6(1)(f) GDPR.

More information about Salonized's processing is available in its privacy policy: https://www.salonized.com/de/privacy-statement.

5. Plugins and tools

Google Maps

This website uses Google Maps, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. This service enables us to display maps on our website.

Google Maps requires your IP address to be stored. This information is usually transferred to a Google server in the USA and stored there. We have no control over that transfer. When Maps is activated, Google may use Google Fonts for consistent typography. Your browser downloads the necessary web fonts to its cache to display text correctly.

Google Maps serves our legitimate interest in presenting our online services attractively and making our locations easy to find under Article 6(1)(f) GDPR. Where consent is requested, processing is based exclusively on Article 6(1)(a) GDPR and Section 25(1) TDDDG insofar as consent covers cookies or access to device information, such as fingerprinting, within the meaning of the TDDDG. Consent may be withdrawn at any time.

Transfers to the USA are based on the European Commission's standard contractual clauses. Details are available at: https://privacy.google.com/businesses/gdprcontrollerterms/ and https://privacy.google.com/businesses/gdprcontrollerterms/sccs/.

More information about Google's handling of user data is available in its privacy policy: https://policies.google.com/privacy?hl=de.

The company is certified under the EU–US Data Privacy Framework (DPF), an agreement intended to ensure European data protection standards for processing in the USA. Every certified company undertakes to comply with those standards. The provider offers more information at: https://www.dataprivacyframework.gov/participant/5780.

6. Online bookings

Use of the Salonized online booking system

For online appointments, our website uses or links to the booking system Salonized provided by Salonized B.V., Vijzelstraat 79, 1017 HG Amsterdam, Netherlands. When you book online, the personal data needed to arrange the appointment is transferred to and processed by Salonized.

This may include your name, phone number, email, chosen service, appointment time and voluntary booking-form details. Processing is used exclusively for appointment management and communication relating to your booking.

The legal basis is Article 6(1)(b) GDPR where booking serves pre-contractual steps or contract performance. Use is also based on our legitimate interest in efficient appointment organisation under Article 6(1)(f) GDPR.

More information about Salonized's processing is available at: https://www.salonized.com/de/privacy-statement.

You can also book appointments by phone or email.

Payment processing through Stripe

For online payments, particularly gift voucher purchases, we use the payment service provider Stripe. The provider is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland.

When paying through Stripe, the necessary payment-processing data is transferred to Stripe. This may include your name, email, billing details, amount, payment information, IP address, device information and transaction data.

Processing serves payment completion and thus contract performance or pre-contractual steps under Article 6(1)(b) GDPR. It may also be based on our legitimate interest in secure, reliable and efficient payments under Article 6(1)(f) GDPR.

The provider generally does not receive complete credit card or bank account details. Stripe processes payment data directly. Depending on the payment method, other payment providers or banks may be involved.

More information about Stripe's processing is available in its privacy policy: https://stripe.com/de/privacy.

Privacy information for WhatsApp use

You may contact us through WhatsApp to make a booking at our hotel. Please note that using WhatsApp transfers personal data, such as your name and phone number, to WhatsApp Inc. (WhatsApp Ireland Limited), where it is processed under their privacy policies.

We use the data you provide exclusively to handle your enquiry and booking. More information about WhatsApp's processing is available in the WhatsApp Privacy Policy.


Last updated: 3 June 2026