arborea Marina Resort Neustadt GmbH Declaration of accessibility
arborea Marina Resort Neustadt GmbH strives to make its website accessible in accordance with the Accessibility Strengthening Act (BFSG) and the Regulation on the Accessibility Strengthening Act (BFSGV). This statement applies to arborea-resorts.com.
Status of compatibility with the requirements
This website is partially compliant with the BFSG and the BFSGV due to the following incompatibilities or exceptions.
Our products and services can be found, accessed and used by people with disabilities in the usual way, without particular difficulty and generally without outside help.
Description of the service
We offer the sale of vouchers and hotel rooms on our website.
Our voucher store is integrated via an accessible iframe from incert and also meets the requirements for digital accessibility.
Descriptions and explanations necessary to understand the execution of the service
Non-accessible content
The following content is not accessible because it is not compatible with the underlying harmonized standard EN 301 549:
There are links without link text on all pages.
On single pages there are 'iframe' elements without labelling. Navigation with screen readers to the iframes is difficult.
On several pages, a parent element lacks the appropriate child elements. This can confuse screen reader users because content is expected but none is there.
On single pages, links are indistinguishable from the surrounding text.
This declaration was created on 27.06.2025. The declaration was prepared using the Eye-Able® technology of Web Inclusion GmbH. Eye-Able Report ® – a product of Web Inclusion GmbH – has gone through all machine-verifiable test steps.
Feedback and contact details
You can report any difficulties accessing the content of the website to us:
arborea Marina Resort Neustadt GmbH
Heimhuder Straße 36
20148 Hamburg
Hamburg
marketing@rimc.de
Market surveillance
The contact details of the market surveillance body responsible for us are:
MLBF (in Errichtung)
c/o Ministerium für Arbeit, Soziales, Gesundheit und Gleichstellung Sachsen-Anhalt
Postfach 39 11 55
39135 Magdeburg
MLBF@ms.sachsen-anhalt.de
Tel.: 0391 567 6970
Disclaimer
The automatic check of the web content took place on: 27.06.2025. The Google Chrome browser version 136.0.7103.92 was used for the web content. We guarantee the accuracy of the information provided for the tested application version under the specified browser and operating system parameters, as stated before. If different versions, browsers or environments are used, a different display is possible, which differ from the results given here. For a complete check, manual tests by the website operator are also recommended.
Privacy in recruitment and in the application process
The controller collects and processes personal data for the purposes of the application procedure. The processing can also be done electronically. This is particularly the case where an applicant submits the corresponding documents to the controller by means of electronic communications, e.g. by e-mail. If the controller concludes a contract of employment with one applicant, the transmitted data are stored for the purpose of executing the employment relationship in compliance with the statutory provisions. If the controller does not conclude a contract of employment with any of the applicants, the application documents will automatically be deleted six months after the notification of letter of rejection, provided that deletion does not conflict with any other legitimate interests of the controller. In this context other legitimate interest means for instance a burden of proof in legal proceedings pursuant to the General Law on Equal Treatment (AGG).
Information on video surveillance in our properties
Video surveillance is a particularly intensive form of processing personal data. Almost everyone feels uncomfortable when they are under video surveillance. This is also referred to as "surveillance pressure". Not being exposed to this pressure is almost one of the basic human needs.
Another human need, however, is the desire for security. Individuals and communities, but also inanimate things such as objects and systems, derive great benefit from an environment that is free of security risks or dangers.
Video surveillance is subject to strict data protection requirements for good reasons. On the other hand, the security interests of the controller must also be fairly assessed. Because often these interests are not limited to the controller alone. Employees, interested parties, suppliers, customers, tenants, guests, visitors, etc. may also have a need for security, which can be satisfied by a moderate and sensible use of video surveillance.
Even if some of the following information is already mentioned elsewhere in this data protection declaration, we would like to list all the information in this section of the text as it can also be found in a detailed information sign for video surveillance (information sheet according to Art. 13 GDPR):
Name and contact details of controller and, if applicable, his representative:
To be found at the bottom of this Data Protection Statement.
Contact details of the data protection officer:
To be found at the bottom of this Data Protection Statement.
Purposes and legal basis of data processing:
Investigation and detection of criminal offences as well as other security-related events.
Art. 6 Para. 1 lit. f EU General Data Protection Regulation.
Legitimate interests pursued:
Safety of employees, suppliers, guests, visitors, etc.
Protection of property, exercise of domiciliary rights.
Duration of storage or criteria for determining the duration:
In our properties, image data is usually deleted after 72 hours at the latest, insofar as the purpose of the storage has also ceased to apply at this time.
In doing so, we follow a recommendation of the independent data protection authorities of the federal and state governments (Data Protection Conference - DSK).
With a storage period of 72 hours, according to the DSK's justification, the supervisor can regularly pursue his security interests, while at the same time the interests of the data subjects worthy of protection remain protected.
If necessary, a special monitoring purpose may justify longer storage. However, this must be adequately justified.
Recipients or categories of recipients of the data (if data transfer takes place):
The data controller will not transfer the personal data to a third country or an international organisation.
Information on the rights of the data subject
See also the section "Rights of the data subject" at the top of this Data Protection Statement. For video surveillance in summary:
Without prejudice to any other administrative or judicial remedy, any data subject shall have the right to lodge a complaint with a supervisory authority if the data subject considers that the processing of personal data relating to him or her infringes the GDPR (Art. 77 GDPR). The data subject may exercise this right before a supervisory authority in the Member State of his or her residence, place of work or the place of the alleged infringement. In Hamburg, the competent supervisory authority is:
The Hamburg Commissioner for Data Protection and Freedom of Information
Ludwig-Erhard-Str. 22
20459 Hamburg
Phone: +49 (0)40 42854-4040
Email: mailbox@datenschutz.hamburg.de
Security of personal data
Our company shall take numerous technical and organizational measures in order to protect your personal data against accidental or illegal destruction, alteration, loss, unlawful disclosure or unauthorized access.
Nevertheless, for instance internet-based data transfer can principally bear gaps in the security, and therefore absolute protection cannot be guaranteed. For this reason, any data subject is free to communicate personal data to us in an alternative way, for instance by telephone.
Website Encryption
This site TLS-encryption for security reasons and to protect the transmission of confidential content, such as the requests you send to us as the site operator. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http: //" to "https: //" and by the lock symbol in the browser line.
If encryption is activated, the data that you transmit to us cannot be read by third parties.
Collection of general data and information
Our website collects a number of general data and information each time the website is accessed by data subject or an automated system. This general data and information is stored in the log files of the server. Following data can be collected:
When using this general data and information, our company does not draw any conclusions about the data subject. In fact, this information is needed in order:
This collected data and information is therefore evaluated by our company on the one hand statistically, and on the other hand to increase data protection and data security in our company, and last but not least to ensure the best possible level of protection for the personal data processed by us. The anonymous data of the server log files are stored separately from all personal data provided by the data subject.
This data is not amalgamated with other data sources.
This data is recorded on the basis of Art. 6 Para. 1 lit. f GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of his website - the server log files must be recorded for this.
Request by E-Mail, Phone or Fax
If you contact us by e-mail, phone or fax, your request, including all personal data resulting from it (name, request), will be stored and processed by us for the purpose of processing your request. We will not pass on this data without your consent.
This data is processed on the basis of Art. 6 Para. 1 lit. b GDPR, if your request is related to the fulfilment of a contract or is necessary to carry out pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of inquiries addressed to us (Art. 6 Para. 1 lit. f GDPR) or on your consent (Art. 6 Para. 1 lit. a GDPR) if this was queried.
The data you send to us via contact requests will remain with us until you request deletion, revoke your consent to storage or the purpose for data storage no longer applies (e.g. after your request has been processed). Mandatory statutory provisions - especially legal storage periods - remain unaffected.
Data transmission via web form
Data subject has an option to register on the website of the controller stating his or her personal data. During the registration process the respective entry windows indicate, which personal data are transmitted to the controller. The personal data entries made by the data subject are exclusively intended for internal use of the controller, this data is collected and stored for the purposes of own use. The controller can transmit the data to one or to several processor(s), e.g. to parcel service which also makes only internal use of the personal data and acts under the responsibility of the controller.
By registration on the website of the controller the following data is also stored: data subject’s IP address, which the internet service provider has assigned, the date and the exact time at the moment of the registration. These data are stored against the background of being the only way to prevent misuse of our services. If necessary, these data can enable clearing up offences or copyright infringements committed. Insofar it is necessary to store this data as to protect the controller. In general, these data are not transmitted to a third party, unless there is a legal obligation to a transmission, or the data transmission serves legal pursuit of rights or criminal prosecution.
When the data subject registers himself or herself on the website and voluntarily supplies personal data, it enables the controller to offer to him or her content and services, which can by the very nature of the issues only be offered to registered users.
This data is processed on the basis of Art. 6 Para. 1 lit. b GDPR, if your request is related to the fulfilment of a contract or is necessary to carry out pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of inquiries addressed to us (Art. 6 Para. 1 lit. f GDPR) or on your consent (Art. 6 Para. 1 lit. a GDPR) if this was queried.
The data you send to us via contact requests will remain with us until you request deletion, revoke your consent to storage or the purpose for data storage no longer applies (e.g. after your request has been processed). Mandatory statutory provisions - especially legal storage periods - remain unaffected.
Links to other websites
Our websites contain links to other websites (so called external links).
Our company is as a supplier responsible for the contents of our own as required by the European and national legislation in force. Our own contents are to be distinguished from links to contents provided by other suppliers. We have no influence over whether or not operators of other websites comply with the European and national data protection regulations in force. Please learn more about the data protection statements on the websites of the respective suppliers.
Cookies
We use cookies in order to further improve our internet presentation for you, make it more user-friendly and to tailor it as well as possible to meet your needs. Cookies are small text data files, which a webserver sends to your internet browser when you visit a website. The cookies are stored locally on your terminal (personal computer, notebook, tablet, smartphone etc.).
Numerous websites and servers use cookies. Many cookies contain so called cookie ID, which is a unique identifier of the cookie. Cookie ID consists of a string of characters through which websites and servers can trace back the actual web browser, on which the cookie is stored. This allows the visited web pages and servers to distinguish the individual browser of the data subject from other web browsers that contain other cookies. A specific web browser can be recognized and identified by the unique cookie ID. The purpose of this information is to automatically recognize you and to facilitate your navigation, when you visit the website again with the same device.
You can also consent or reject cookies - also for web tracking - via the settings of your web browser. You can configure your web browser so that it blocks cookies generally, or you will be warned in advance when a new cookie is about to be stored. In this case, however, the functionality of the website may be impaired (for example when placing orders). Your browser also offers a function to delete cookies (for instance by choosing “Clear browsing data”. This is possible in all common web browsers. Further information can be found in the user manual or in the settings of your browser.
First-Party Cookies
First-party cookies are permanent cookies that are stored on the computer and only lose their validity when the expiry date assigned to them has expired. The word "party" refers to the domain from which the cookie originated. In contrast to third-party cookies, first-party cookies usually come from the website operator itself. They are therefore not accessible to browsers across domains. For example, website A assigns a cookie A, which is not recognized by website B, but can only be recognized by website A. This means that data cannot be passed on to third parties.
Third-Party Cookies
With a third-party cookie, the cookie is set and recorded by a third party. These cookies are mostly used by advertisers who use their cookies on other websites to collect information about website visitors using the cookies. These are data records that are stored in the user's web browser when he visits a page with the advertisement. If he visits a page with advertising from the same provider again, he will be recognized.
Transient cookies
Transient cookies are automatically deleted when you close the browser. These include session cookies in particular. These store a so-called session ID, with which various requests from your browser can be assigned to the joint session. This allows your computer to be recognised when you return to our website. The session cookies are deleted when you log out or close the browser.
Persistent cookies
Persistent cookies are automatically deleted after a specified period, which may vary depending on the cookie. You can delete the cookies at any time in the security settings of your browser.
Cookiebot
A web service from Cybot A/S, Havnegade 39, 1058 Copenhagen, DK (hereinafter referred to as "Cookiebot") is loaded onto our website. Through Cookiebot we can inform you exactly and transparently about the use of cookies on our website. You will receive an up-to-date and data protection-compliant cookie notice and decide for yourself which cookies you want to allow.
For this purpose, Cookiebot shows you a cookie list divided into function groups when you visit it for the first time. Here you can activate the cookies by clicking the appropriate box. Please note that the technical cookies are already saved when the website is accessed and that the relevant box is preset. If you deselect technical cookies, the use of the website or individual functions on the website may be restricted or even impossible.
If you allow cookies, the following data will be transmitted to Cybot:
The legal basis for the use of Cookiebot results from our legitimate interest in functional cookie management and is therefore in accordance with Article 6 Para. 1 lit. f GDPR. A further legal basis results from the fulfillment of data protection law requirements in connection with cookies requiring consent (e.g. also through the "cookie judgment" of the European Court of Justice) and is therefore in accordance with Art. 6 Para. 1 lit. c GDPR.
If you consented to the use of cookies when visiting this website, you can revoke your consent by calling up Cookiebot (see below) and deselecting the relevant cookie category. In addition to the revocation option via Cookiebot, you can deactivate cookies directly with a cookie provider or prevent the processing of data by browser plug-ins. You can also use the appropriate settings to control the use of cookies in most browsers.
Further information about "Cookiebot" and the company behind it, Cybot, can be found in the data protection declaration at https://www.cookiebot.com/de/privacy-policy/.
Microsoft Clarity
We partner with Microsoft Clarity and Microsoft Advertising to capture how you use and interact with our website through behavioral metrics, heatmaps, and session replay to improve and market our products/services. Website usage data is captured using first and third-party cookies and other tracking technologies to determine the popularity of products/services and online activity. Additionally, we use this information for site optimization, fraud/security purposes, and advertising. For more information about how Microsoft collects and uses your data, visit the Microsoft Privacy Statement.
Booking system OnePageBooking
We use the OnePageBooking service from HotelNetSolutions GmbH, Genthiner Strasse 8, 10785 Berlin for online room reservations. Clicking the corresponding button opens a browser window that redirects you to the OnePageBooking website.
If you would like to book a room with us, it is necessary for the conclusion of the contract that you provide your personal data, which we need to process your booking. Mandatory information required for the execution of the contracts is marked separately, further information is voluntary. The data is entered in an input mask and transmitted to us and saved.
Data is also passed on to the relevant payment service providers. The data will only be passed on to third parties if the transfer is necessary for the purpose of contract execution or for billing purposes or for collecting the fee or if you have given your express consent. In this regard, we only pass on the data required in each case. The data recipients are: the respective delivery / shipping company (transfer of name and address), collection agencies, insofar as the payment has to be collected (transfer of name, address, order details), payment institutions for the purpose of collecting claims, insofar as you have chosen direct debit as the method of payment and payment service providers - depending on the choice of payment method.
The legal basis is Art. 6 Para. 1 lit. b GDPR. Regarding the voluntary data, the legal basis for the processing of the data is Art. 6 Para. 1 lit. a GDPR. There is a Data Protection Agreement between us and HotelNetSolutions GmbH.
The compulsory information collected is required to fulfill the contract with the user (for the purpose of providing the goods or service and confirming the content of the contract). We therefore use the data to answer your inquiries, to process your booking, if necessary, to check the creditworthiness or recovery of a claim and for the purpose of technical administration of the website. The voluntary information is provided to prevent abuse and, if necessary, to investigate crimes.
The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. Due to commercial and tax regulations, we are obliged to store your address, payment and order data for a period of 10 years after the contract has been carried out. However, after 6 years, we restrict processing, i.e. H. Your data will only be used to comply with legal obligations. If there is a permanent obligation between us and the user, we save the data for the entire term of the contract and for a period of ten years thereafter (see above). With regard to the voluntarily provided data, we will delete the data 6 years after the contract has been executed, provided that no further contract is concluded with the user during this time; In this case, the data will be deleted 6 years after the last contract has been carried out.
If the data is necessary to fulfill a contract or to carry out pre-contractual measures, the data can only be deleted prematurely unless there are contractual or legal obligations to prevent deletion. Otherwise, you are free to have the personal data provided during registration completely deleted from the data base of the person responsible. Regarding the voluntary data, you can revoke your consent to the person responsible at any time. In this case, the voluntary data will be deleted immediately.
Information on data protection at HotelNetSolutions GmbH can be found here: https://hotelnetsolutions.de/Datenschutz/ (in German).
Newsletter dispatch with Smart Host
If you would like to receive the newsletter offered on the website, we require an e-mail address from you as well as information that allows us to verify that you are the owner of the e-mail address provided and that you agree to receive the newsletter. No further data is collected, or only on a voluntary basis. We use this data exclusively for sending the requested information and do not pass it on to third parties.
The data entered in the newsletter registration form is processed exclusively on the basis of your consent in accordance with Art. 6 Para. 1 lit. a GDPR. You can revoke your consent to the storage of the data, the e-mail address and its use for sending the newsletter at any time, for example via the ‘unsubscribe’ link in the newsletter. The legality of the data processing operations that have already taken place remains unaffected by the cancellation.
This website uses the services of Smart Host to send newsletters. The provider is Smart Host GmbH, Am Kupfergraben 6A, 10117 Berlin.
Smart Host is a service that can be used to organise and analyse the sending of newsletters, among other things. When you open an email sent with Smart Host, a file contained in the email (known as a web beacon) connects to the Smart Host servers. This makes it possible to determine whether a newsletter message has been opened and which links, if any, have been clicked on. Technical information is also recorded (e.g. time of access, IP address, browser type and operating system). This information is used exclusively for the statistical analysis of newsletter campaigns. The results of these analyses can be used to better adapt future newsletters to the interests of the recipients.
If you do not wish to be analysed by Smart Host, you must unsubscribe from the newsletter. For this purpose, we provide a corresponding link in every newsletter message.
The data processing takes place on the basis of your consent in accordance with Art. 6 Para. 1 lit. a GDPR. You can revoke this consent at any time by unsubscribing from the newsletter. The legality of the data processing operations that have already taken place remains unaffected by the cancellation.
The data you provide us with for the purpose of subscribing to the newsletter will be stored by us until you unsubscribe from the newsletter and deleted from both our servers and the servers of Smart Host after you unsubscribe from the newsletter. Data stored by us for other purposes remains unaffected by this.
We have concluded a Data Processing Agreement (“DPA”) with Smart Host in accordance with Art. 28 Para. 3 GDPR. In this contract, we oblige this service provider to protect our customers' data and not to pass it on to third parties.
Further information on data protection at Smart Host can be found in their privacy policy at: https://www.smart-host.com/en/privacy-policy
Google Analytics 4
If you have given your consent, this website uses Google Analytics 4, a web analytics service provided by Google LLC. The controller for users in the EU/EEA and Switzerland is Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google").
Nature and purpose of the processing
Google Analytics 4 uses cookies that enable an analysis of your use of our websites. The information collected by means of the cookies about your use of this website is generally transferred to a Google server in the USA and stored there.
In Google Analytics 4, the anonymisation of IP addresses is activated by default. Due to IP anonymisation, your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there. According to Google, the IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
During your visit to the website, your user behaviour is recorded in the form of ‘events’. Events can be:
Also recorded:
Purposes of the data processing
On behalf of the operator Google will use this information to evaluate your use of the website and to compile reports on website activity. The reports provided by Google Analytics 4 serve to analyse the performance of our website and the success of our marketing campaigns.
Recipients
Recipients of the data are/may be:
Third country transfer
For the USA, the European Commission adopted a news adequacy decision on 10 July 2023. Google LLC is certified under the EU-US Privacy Framework. Since Google servers are distributed worldwide and a transfer to third countries (for example to Singapore) cannot be completely ruled out, we have also concluded the EU standard contractual clauses with the provider to establish an appropriate level of data protection in those countries.
Retention period
The data sent by us and linked to cookies are automatically deleted after 14 months. The maximum lifespan of Google Analytics cookies is 2 years. The deletion of data whose retention period has been reached occurs automatically once a month.
Legal basis
The legal basis for this data processing is your consent pursuant to Art.6 Para.1 lit.a GDPR and § 25 Para. 1 TDDDG.
Withdrawal
You can withdraw your consent at any time with effect for the future by accessing the cookie settings at the bottom left of the screen and changing your selection there. The lawfulness of the processing carried out on the basis of the consent until revocation remains unaffected.
You can also prevent the storage of cookies from the outset by setting your browser software accordingly. However, if you configure your browser to reject all cookies, this may result in a restriction of functionalities on this and other websites. You can also prevent the collection of data generated by the cookie and relating to your use of the website (including your IP address) by Google, and the processing of this data by Google, by:
For more information on Google Analytics' terms of use and Google's privacy policy, please visit https://marketingplatform.google.com/about/analytics/terms/us/ and at https://policies.google.com/?hl=en.
Google Ads with enhanced conversions
We use the remarketing and conversion tracking function of Google Ads on our website, a service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA (hereinafter referred to as ‘Google’).
The remarketing function is used to present interest-based adverts to website visitors within the Google advertising network. The conversion tracking function in turn enables us to measure how effective the adverts placed by us and clicked on by website visitors are.
When Google Ads is used, the following data is collected and transmitted to Google in the USA: Data on the device and browser (host name, browser type, referrer, language), IP address and the respective user interaction on our website as well as on other websites on which our adverts are placed (e.g. which page a user visits or which adverts a user clicks on). In addition, a cookie is used to assign a random, pseudonymous ID to a user, to which the aforementioned information is assigned.
We also use conversion tracking as part of the Google Ads service. When you click on an advert placed by Google, a cookie for conversion tracking is stored on your end device. These cookies lose their validity after 30 (our setting at Google) or a maximum of 90 days (according to Google itself), do not contain any personal data and are therefore not used for personal identification. The information collected with the help of the conversion cookie is used to create conversion statistics.
We have set up Enhanced Conversions for this purpose.
Enhanced Conversions is a feature that can improve the accuracy of conversion tracking while protecting user privacy by supplementing existing conversion tags with the hashed first-party conversion data from the website. Hashing the first-party data before sending it to Google Ads ensures data protection, as personal information such as (here: email address) is converted into a hashed / pseudonymised (SHA256) character string.
The legal basis for the use of Google Ads is your consent in accordance with Art. 6 Para. 1 lit. a GDPR and § 25 Para. 1 TDDDG.
The data collected is stored and processed in the USA, i.e. a third country for which there is no adequacy decision by the European Commission.
However, Google bases the data transfer to the USA on the EU-U.S. Data Privacy Framework of the European Commission.
You can prevent the installation of these cookies by refusing your consent to the storage of these cookies when you enter the website, deleting existing cookies or deactivating the storage of cookies in the settings of your web browser. We would like to point out that in this case you may not be able to use all the functions of our website to their full extent. You can also prevent the storage of cookies by setting your web browser to block cookies from the domain ‘www.googleadservices.com’ (https://www.google.com/settings/ads ). We would like to point out that this setting will be deleted if you delete your cookies. You can also deactivate interest-based adverts via the link http://optout.aboutads.info . Please note that this setting will also be deleted if you delete your cookies.
Information on data protection at Google Ads can be found at: https://ads.google.com/home/ads-experts-support/
The Hotels Network
To improve your user experience on our hotel website, we use a software provided by THE HOTELS NETWORK (https://www.thehotelsnetwork.com , Muntaner 262, 3º, 08021 Barcelona, Spain). Using The Hotels Network, we are able to measure your user behavior in an anonymised way to better understand how visitors use our website and offer a more relevant user experience. To enable this, The Hotels Network uses cookies to store data from website users such as browser information, pages viewed, scrolls etc. As any analysis or processing is always anonymised, it is impossible to identify the user in person from this data.
Should it nevertheless become necessary to process personal data, this will be done exclusively on the basis of your consent in accordance with Art. 6 Para. 1 lit. a GDPR and § 25 Para. 1 TDDDG.
We have entered into a contract Data Processing Agreement (“DPA”) in accordance with Art. 28 Para. 3 GDPR with THE HOTELS NETWORK and implement the strict provisions of the EU General Data Protection Regulation to the fullest when using it.
Further information can be found on the website and in the privacy statement of The Hotels Network:
DialogShift chat application on our website
Our website uses the chat application of DialogShift GmbH, Rheinsberger Str. 76/77, 10115 Berlin. This application processes (and in this sense also: stores) data for the purpose of web analysis, to operate the chat application and to answer enquiries.
For the operation of the chat function, the chat texts are stored and a cookie with a unique ID is set - this is used to recognise you as a customer.
A cookie is a small text file that is stored locally in the cache on your device. Using this cookie, our application recognises the device and can retrieve past chat logs. This cookie is stored for 90 days since last use. You can disable the storage of cookies in your browser settings. However, without the use of cookies, the chat function will not work.
The possible disclosure of e.g. name, e-mail address or a telephone number is voluntary and with the consent to temporarily use and store this data for the purpose of contacting you until the end of the contact. This personal data is deleted after 90 days.
The legal basis for data processing is Article 6 Para. 1 lit. f GDPR on the basis of our legitimate interest in effective customer support, for statistical analysis of user behaviour and for optimisation purposes of our offers.
DialogShift offers further information on the processing (in this sense also collection and use) of data as well as on your rights and options for protecting your privacy at https://www.dialogshift.com/en/data-privacy
CloudFlare
We use the “Cloudflare” service provided by Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA. (hereinafter referred to as “Cloudflare”).
Cloudflare offers a content delivery network with DNS that is available worldwide. As a result, the information transfer that occurs between your browser and our website is technically routed via Cloudflare’s network. This enables Cloudflare to analyze data transactions between your browser and our website and to work as a filter between our servers and potentially malicious data traffic from the Internet.
In this context, Cloudflare may also use cookies or other technologies deployed to recognize Internet users, which shall, however, only be used for the herein described purpose.
The storage and processing of the collected data takes place in the USA, i.e. a third country for which there is no adequacy decision by the European Commission.
However, Cloudflare bases the data transfer to the USA on the EU-U.S. Data Privacy Framework of the European Commission.
The use of Cloudflare is based on our legitimate interest in a provision of our website offerings that is as error free and secure as possible (Art. 6 Para. 1 lit. f GDPR).
We have concluded a Data Processing Agreement (“DPA”) for the use of the above-mentioned service. This is a contract mandated by data privacy laws that guarantees that they process personal data of our website visitors only based on our instructions and in compliance with the GDPR.
For more information on Cloudflare’s security precautions and data privacy policies, please follow this link: https://www.cloudflare.com/privacypolicy/.
Akamai (CDN)
For the purpose of accelerating our website, we use the Content Delivery Network (CDN) of Akamai Technologies Inc., 150 Broadway, Cambridge, MA 02142, USA, German branch Akamai Technologies GmbH, Parkring 20-22, 85748 Garching (Akamai).
CDN is a service that enables content to be delivered faster with the help of regionally distributed servers connected via the Internet. Your data is processed solely for the aforementioned purposes and to maintain the security and functionality of the CDN.
Akamai transfers personal data from the log files (e.g. IP addresses) to the USA each time data is processed, as certain servers for processing the log files are only located in the USA. The data is stored for up to 24 hours so that content can be provided more quickly during a visit.
The storage and processing of the collected data takes place in the USA, i.e. a third country for which there is no adequacy decision by the European Commission.
However, Akamai bases the data transfer to the USA on the EU-U.S. Data Privacy Framework of the European Commission.
Data processing at Akamai is carried out solely to speed up delivery. The legal basis for processing is Art. 6 Para. 1 lit. f GDPR (legitimate interest). Our legitimate interest lies in the provision of a high-performance website.
You can find more information on the data protection of Akamai Technologies Inc. at the following link: https://www.akamai.com/legal/compliance/privacy-trust-center.
BootstrapCDN
In order to deliver our website to you quickly and securely on all devices, we use the Content Delivery Network (CDN) BootstrapCDN of the Polish software company ProspectOne, Królewska 65A/1, 30-081, Kraków, Poland (hereinafter referred to as "BootstrapCDN").
A Content Delivery Network (CDN) is a network of regionally distributed servers that are connected to each other via the Internet. Through this network, content, especially very large files, can be delivered quickly even during large load peaks.
BootstrapCDN works in such a way that so-called JavaScript libraries are delivered to your browser. If your browser downloads a file from BootstrapCDN, your IP address is transmitted during the connection to the Bootstrap CDN server. This means that personal data can also be sent and stored. BootstrapCDN can thus collect and store user data such as IP address, browser type, browser version, which web page is loaded or time and date of the page visit. BootstrapCDN's privacy policy explicitly states that the company does not use cookies or other tracking technologies.
BootstrapCDN has servers located in various countries and your data may be stored outside the European Economic Area. BootstrapCDN will retain personal data for as long as is necessary to provide the services offered or to comply with legal obligations.
If you wish to prevent this data transfer, you can install a JavaScript blocker (e.g. "NoScript") or deactivate the execution of JavaScript codes in your browser. Please note that this will mean that the website can no longer offer the usual service (e.g. fast loading speed).
On our part, there is a legitimate interest in using BootstrapCDN to optimise our online service and make it more secure. The corresponding legal basis for this is Art. 6 Para. 1 lit. f GDPR (legitimate interests).
More information on data protection at BootstrapCDN can be found at https://www.jsdelivr.com/terms/privacy-policy-jsdelivr-net.
Our social media presences
Data processing through social networks
We maintain publicly accessible profiles on social networks. The social networks used by us in detail can be found below.
Social networks such as Facebook, ‘X’, etc. can generally analyze your user behavior extensively when you visit their website or a website with integrated social media content (e.g. like buttons or advertising banners). By visiting our social media presences, numerous data protection-relevant processing operations are triggered. In detail:
If you are logged into your social media account and visit our social media presence, the operator of the social media portal can assign this visit to your user account. However, your personal data may also be collected under certain circumstances if you are not logged in or do not have an account with the respective social media portal. In this case, this data collection takes place, for example, via cookies that are stored on your end device or by recording your IP address.
With the help of the data collected in this way, the operators of the social media portals can create user profiles in which your preferences and interests are stored. In this way, you can be shown interest-based advertising inside and outside the respective social media presence. Provided you have an account with the respective social network, the interest-based advertising may be displayed on all devices on which you are or were logged in.
Please also note that we cannot track all processing on the social media portals. Depending on the provider, further processing operations may therefore be carried out by the operators of the social media portals. For details, please refer to the terms of use and data protection provisions of the respective social media portals.
Legal basis
Our social media presences are intended to ensure the most comprehensive presence possible on the Internet. This is a legitimate interest within the meaning of Art. 6 Para 1 lit. f GDPR. The analysis processes initiated by the social networks may be based on different legal bases, which are to be specified by the operators of the social networks (e.g. consent within the meaning of Art. 6 Para. 1 lit. a GDPR).
Controller and assertion of rights
If you visit one of our social media sites (e.g. Facebook), we are jointly responsible with the operator of the social media platform for the data processing operations triggered during this visit. In principle, you can assert your rights (information, correction, deletion, restriction of processing, data portability and complaint) both vis-à-vis us and vis-à-vis the operator of the respective social media portal (e.g. vis-à-vis Facebook).
Please note that despite the joint responsibility with the social media portal operators, we do not have full influence on the data processing operations of the social media portals. Our options are largely determined by the corporate policy of the respective provider.
Storage period
The data collected directly by us via the social media presence will be deleted from our systems as soon as the purpose for storing it no longer applies, you request us to delete it, revoke your consent to store it, or the purpose for storing the data no longer applies. Stored cookies remain on your terminal device until you delete them. Mandatory legal provisions - in particular retention periods - remain unaffected.
We have no influence on the storage period of your data, which is stored by the operators of social networks for their own purposes. For details, please contact the operators of the social networks directly (e.g. in their privacy policy, see below).
We have a profile on Facebook. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland (hereinafter referred to as "Facebook"). According to Facebook, the collected data is also transferred to the USA and other third countries.
We have concluded a joint processing agreement (Controller Addendum) with Facebook.
This agreement specifies which data processing operations we or Facebook are responsible for when you visit our Facebook page. You can view this agreement at the following link: https://www.facebook.com/legal/terms/page_controller_addendum
You can adjust your advertising settings independently in your user account. To do so, click on the following link and log in: https://www.facebook.com/settings?tab=ads
For details, please refer to Facebook's privacy policy: https://www.facebook.com/privacy/center/
We have a profile on Instagram. The provider is Instagram Inc, 1601 Willow Road, Menlo Park, CA, 94025, USA. For details on how they handle your personal data, please refer to Instagram's privacy policy: https://privacycenter.instagram.com/
We have a profile on LinkedIn. The provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. LinkedIn uses advertising cookies. If you wish to disable LinkedIn advertising cookies, please use the following link: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out
Name and address of the controller:
Party responsible for the processing of personal data for the purposes of the European Union General Data Protection Regulation (GDPR), or of other applicable data protection laws in the Member States of the European Union, and of other provisions relating to protection of personal data, is
arborea Marina Resort Neustadt GmbH
Heimhuder Straße 36
20148 Hamburg
Phone: +49 (0)4561 719 90
Email: neustadt@arborea-resorts.com
Managing Director: Marek N. Riegger
Name and address of the data protection officer:
SHIELD GmbH
Martin Vogel
Ohlrattweg 5
25497 Prisdorf
Phone: +49 (0)4101 80 50 600
Email: info@shield-datenschutz.de
Hamburg, January 2025
Amendments in Data Protection Statement
We reserve the right to amend our data protection practices and this data protection statement in order to adjust the aforesaid to reflect possible changes in relevant laws or regulations, or to meet your needs better. Possible amendments in our data protection practices will correspondingly be published here. Please inform yourself about the current date of our data protection policy.