Diese Seite gibt es auch auf Deutsch. Zur deutschen Fassung
Legal

Privacy policy

As of: August 2026 · under the GDPR, BDSG, § 25 TDDDG (formerly TTDSG)

1. Controller

The joint controllers for the processing of data within the meaning of the GDPR are:
Thomas Bernhardt & Sabine Herdzin
Am Donnerberg 3
01773 Altenberg, Rehefeld-Zaunhaus district, Germany
E-mail: info@fewo-am-skihang.de
Phone: +49 35057 580001

2. General information on data processing

As a rule, we process our users' personal data only to the extent necessary to provide a functioning website together with our content and services. Personal data is regularly processed only with the user's consent or where another legal basis under Art. 6 GDPR applies.

3. Server logs and hosting

When our website is accessed, the web server automatically records the following information and stores it in server log files:

  • IP address of the requesting device (the last octet is removed/anonymised after 7 days)
  • date and time of access
  • URL requested and HTTP status code
  • browser type and operating system

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the security and stability of the website). The IP address is anonymised after 7 days (last octet removed). The anonymised log entries are deleted automatically after 30 days.

4. External resources

4.1 Bootstrap & Lucide Icons (self-hosted)

This website loads design resources (CSS, JavaScript, icons) exclusively from our own server. No data is transferred to external CDN providers (no jsDelivr, no Cloudflare CDN).

4.2 OpenStreetMap (map and cross-country trail network display)

On the pages Arrival, Trail status and Winter holidays we embed interactive maps whose map tiles are loaded from OpenStreetMap. The operator is the OpenStreetMap Foundation (OSMF), St John's Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom. When a map loads, your browser connects to OSMF servers (among others tile.openstreetmap.org); in doing so your IP address is transmitted.

The trail network shown on the trail maps (route, names, difficulty) also comes from OpenStreetMap, but is retrieved and cached on the server side by our own server (Overpass API). In this process no data from your device is transmitted to third parties.

OpenStreetMap processes data in accordance with the GDPR (UK adequacy decision). No transfer to the USA takes place. No tracking cookies are set. Further information: OpenStreetMap privacy policy.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in showing the route and the trail network). The maps are embedded directly – no additional consent is required, because no data is transferred to third countries without an adequacy decision.

4.3 QR codes in the digital guest folder

The QR codes in the digital guest folder – for the Wi-Fi access data or the guest card, for example – have been generated on our own serversince August 2026. No external service is called and nothing is transmitted.

Previously the service goQR.me (api.qrserver.com) was used for this, with the content of the code – in the case of the Wi-Fi code, therefore also the Wi-Fi password – transmitted to the provider as part of the address. That has been discontinued without replacement.

4.4 Trail status and snow report widget (SnowOnline / TouriSpo)

On the page Trail status and in the section Winter holidays we embed the free snow and trail report widget from SnowOnline (operator: TouriSpo GmbH & Co. KG). The widget is loaded as an embedded frame (iframe) from snow-online.de . When the page is opened, your browser establishes a direct connection to the provider's servers; your IP address is transmitted in the process, and the provider may set cookies.

Purpose: display of current snow depths, fresh snow forecasts and piste conditions for the Altenberg and Holzhau trail areas.
Data transmitted: IP address of the requesting device, technical browser/device information and, where applicable, cookie data.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing our guests with current winter sports information).
Provider's registered office: Germany.
Further information: SnowOnline privacy policy · Legal notice.

4.5 Rehefeld webcam

On the home page (section Webcam) we show the image from the webcam of Winterwelt Rehefeld. The current live image is loaded into your browser directly from winterwelt-rehefeld.de ; your IP address is transmitted to the operator of that server in the process. Older archive images , by contrast, are delivered via our own server (server-side proxy) – in that case no direct connection is made between your device and the webcam server.

Purpose: showing the current snow and weather conditions on site.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in showing the current weather and snow conditions).
Image source/operator: Winterwelt Rehefeld.

4.6 Interactive trail, hiking and cycling map (tile overlays, GPS, elevation profile)

On the pages Trail map and Hiking & cycling map (and in the digital guest folder) we show an interactive map. The map background comes from OpenStreetMap (see section 4.2); the coloured piste/trail overlay is loaded as tiles from OpenSnowMap (tiles.opensnowmap.org). When the map is opened, your browser establishes a direct connection to these tile servers; your IP address is transmitted in the process. No tracking cookies are set. The map and library files (Leaflet and others) are held on our own server.

Summer map: On the hiking & cycling map you can additionally display a relief map from OpenTopoMap (tile.opentopomap.org) and the route network overlays from Waymarked Trails (tile.waymarkedtrails.org). Here too, your browser establishes a direct connection to these servers when loading the tiles and transmits its IP address. The route and POI data itself (hiking, cycling and MTB routes, places of interest, refreshment stops, car parks) is fetched by our server from the OpenStreetMap interface overpass-api.de and cached – in this process no data from your device is transmitted.

Location (“Where am I?”): If you tap the location button, your browser asks for your permission and determines your position via the device. The position is used locally in the browser only to display the map and is not transmitted to us or to third parties.

Elevation profile/GPX: Elevation data for trails, hiking and cycling routes is retrieved and cached where required on the server side by our server via the service opentopodata.org – in this process no data from your device is transmitted to third parties.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in showing the trail, hiking and cycling network). Map, piste and route data: OpenStreetMap (ODbL), OpenSnowMap (CC‑BY‑SA), OpenTopoMap (CC‑BY‑SA) and Waymarked Trails. Further information: opensnowmap.org, opentopomap.org, waymarkedtrails.org.

4.7 Weather data (Open-Meteo)

The weather tile in the digital guest folder uses the service Open-Meteo (Open-Meteo, Zurich, Switzerland). The request is made by our server, not by your device – only the coordinates of the property are transmitted. Your IP address never reaches the service.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a usable weather display). Switzerland is covered by an adequacy decision of the EU Commission.

5. Booking form and contact requests

When you use our booking form we collect the following personal data:

  • first and last name
  • e-mail address
  • telephone number (optional)
  • desired booking period and number of persons
  • payment information (transmitted directly to our payment service provider Stripe only after our confirmation)
  • your voluntary statement of how you came to hear about us, together with the technically detected origin of your booking request – details and the legal basis for this in section 8a

Legal basis: Art. 6(1)(b) GDPR (initiation and performance of a contract). Your data is used exclusively to process your booking request and to carry out the tenancy. Retention period: 10 years from the end of the booking year, in line with tax retention obligations (§§ 147 AO, 257 HGB), after which the data is anonymised.

6. Payment processing – Stripe and PayPal

6.1 Stripe

For card payment processing we use Stripe (Stripe Inc., 354 Oyster Point Blvd, South San Francisco, CA 94080, USA). Stripe is a processor within the meaning of Art. 28 GDPR – a corresponding data processing agreement has been concluded. When a payment is completed, payment data is transmitted to Stripe. Stripe is certified to PCI-DSS Level 1 – we do not store any card data ourselves. The transfer to the USA takes place on the basis of the EU Commission's standard contractual clauses (SCC).

Purpose: card payment processing, fraud prevention (3-D Secure).
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
Data transfer: USA, on the basis of the standard contractual clauses (SCC) under Art. 46(2)(c) GDPR.
Process: Payment is made only after we have confirmed your booking request. You then receive a personal, secure payment link to our payment page by e-mail. Stripe's JavaScript (stripe.js) is loaded exclusively on that payment page – not already when the booking request is sent. Until then, nothing is transmitted to Stripe. Only when it loads does it serve fraud prevention and the preparation of the secure payment form; your IP address is then transmitted to Stripe.
Stripe privacy policy: stripe.com/privacy.

6.2 PayPal (via Stripe)

PayPal is available to you as a payment method within the Stripe checkout . If you choose PayPal, the payment is technically handled by our payment service provider Stripe; the data required for the payment is transmitted to Stripe and to PayPal (PayPal (Europe) S.à.r.l. et Cie, S.C.A., Luxembourg). No separate PayPal SDK is loaded on our website.

Purpose: payment processing (performance of a contract).
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
Data transfer to third countries: PayPal may transfer data to PayPal Inc. (San Jose, CA, USA). The transfer takes place on the basis of standard contractual clauses (SCC) under Art. 46(2)(c) GDPR.

PayPal privacy policy: paypal.com/privacy.

7. E-mail notifications

As part of processing a booking we send transactional e-mails (booking confirmation, payment confirmation, cancellation confirmation) to the e-mail address you provide. Legal basis: Art. 6(1)(b) GDPR. Delivery status logs are kept for 2 years and then deleted.

8. Cookies

This website uses only the following cookies:

  • Stripe cookies / fingerprinting: Stripe sets technical identifiers for fraud prevention – only once you actively proceed to card payment in the booking process (lazy load), not already when the booking page is opened. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
  • PayPal (via Stripe): PayPal is offered as a payment method within the Stripe checkout; no separate PayPal SDK is loaded on our website. Legal basis: Art. 6(1)(b) GDPR.
  • Session cookie for the origin of your visit (fewo_h): It is set only if you came to us via a link, an advertisement or a QR code. If you open our pages directly or simply read them, no cookie is created. It has no lifetime beyond your browser session, does not recognise you on a later visit and serves solely the booking process you initiated. Details in section 8a.
  • Cookie for the language you chose (fewo_lang): Set only if you select a language yourself in the menu. It contains nothing but the language code (e. g. “en”), expires after one year and serves solely to save you from switching again on every page. Legal basis: § 25(2) no. 2 TDDDG – the storage is necessary for the service you expressly requested.
  • Cookie for the language notice (fewo_lang_hinweis_zu): Set only if you dismiss the notice “This page is also available in English”. It contains nothing but the value 1, expires after one year and keeps the notice from reappearing. Legal basis: § 25(2) no. 2 TDDDG.

No cookies from tracking services, analytics or marketing providers are used; no profiling takes place and nothing is passed on to third parties.

8a. Origin of your booking request

We want to know which of our own channels work – that is, whether a booking request came about through a search engine, an AI assistant, a directory, a flyer with a QR code or a recommendation. For this we store, only in connection with a booking request:

  • the channel detected (e. g. “search engine”) and, if present, the campaign code of a flyer or QR code,
  • the host name of the referring page – not the full address, since search terms could appear there,
  • the path of the page you entered on (without parameters), the number of pages in your visit and a rough device class (mobile or desktop),
  • your voluntary statement in the booking form (“How did you hear about us?”).

Not stored: your IP address (not even shortened or as a checksum), your browser identifier (user agent), device characteristics for recognition (“fingerprint”), the full referring address and any identifier spanning visits. Anyone who visits our pages and does not send a booking request leaves no record with us – we do not keep visitor or reach statistics.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in knowing how effective our own advertising channels are). For the session cookie: § 25(2) no. 2 TDDDG, since the storage serves solely the booking process you expressly requested and ends with your browser session.
Retention period: The information is technically attached to the booking concerned and is deleted together with it (see section 5).
Objection: You may object to this processing at any time without any formality (contact details in section 1); we then delete the origin information for your booking without delay. Your booking is unaffected.

9. Calendar synchronisation (iCal)

To avoid double bookings we synchronise occupancy data with external booking platforms (e.g. Airbnb, Booking.com) via the iCal format. Only occupancy periods (dates) are transferred, no personal guest data. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in availability management). External occupancy data is deleted automatically after 60 days.

10. External links and services

10.1 Google Maps (as a hyperlink only)

The “Getting here” page contains a link to Google Maps (google.com/maps). This link opens Google Maps only when you actively click it. Until then no data is transferred to Google. When you click, the Google privacy policy.

10.2 Other external links

Our website contains links to external third-party websites (e.g. VVO Verkehrsverbund Oberelbe, Winterwelt Rehefeld, BLOCKLINE, Erlebnisberg Altenberg). These links are activated by clicking – only then is a connection established to the respective servers. The operators of those external sites are responsible for data protection there. We have no influence on their content or their data protection practices.

11. Digital guest folder (GuestApp)

Once payment has been received we provide our guests with a digital guest folder (“GuestApp”) containing information about their stay and – depending on the property – digital access. Access is via a personal, non-public link. Whoever has this link has access; please pass it on only to your fellow travellers.

Data processed: name, e-mail address, the booking and apartment assigned, arrival and departure dates and a check value of the access token (the token itself is not stored by us in plain text).

Purpose: provision of information relevant to the stay and – where activated – keyless access.
Legal basis: Art. 6(1)(b) GDPR (performance of the tenancy).

Two periods: The door functions can be used only from the day of arrival until two days after departure. The content of the guest folder remains available from receipt of payment until 14 days after departure – so that you can look through it again at home, recommend something or write a review. After that the personal access is deactivated.

11.1 Logging of security-relevant events

Events concerning access to the apartment – door openings, switching open-house mode on and off, failed access attempts – are logged with time, result, IP address and device identifier (user agent).

Purpose: traceability in the event of damage, loss or misuse, and troubleshooting.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the security of the property and its guests).
Retention period: 12 months, after which the entries are deleted.

11.2 Reporting your arrival time

You may voluntarily tell us your expected arrival time, your vehicle registration number and any wishes or notes, and confirm your arrival. All of this is voluntary; your stay works just as well without it.

Purpose: preparing for your arrival and assigning vehicles on the property.
Legal basis: Art. 6(1)(b) GDPR.
Retention period: until 14 days after departure, then deletion.

11.3 Messages to us

Using the “Contact us” tile you can send us a message with a category and free text. It is stored together with your booking and deleted once it has been dealt with and any warranty periods have expired. Legal basis: Art. 6(1)(b) GDPR.

11.4 Push notifications

In the guest folder you can enable push notifications – for instance as a reminder that open-house mode is still running and the apartment door is unlocked. This happens only at your request: your browser asks you beforehand, and nothing is set up without your consent.

Data processed: the push address (endpoint) assigned by your browser, two cryptographic keys for encrypting the message, and the device identifier (user agent) so that you can tell several devices apart.

Worth knowing: A push message technically always travels via the push service of the maker of your browser or operating system – with Chrome and Android that is Google (Firebase Cloud Messaging), with Safari, iPhone and iPad it is Apple, with Firefox it is Mozilla. Your push address and the encrypted message content are transmitted to that service; only your device can read it. With Google and Apple a transfer to the USA is possible, based on the EU Commission's adequacy decision on the EU-US Data Privacy Framework. We ourselves do not embed any software from these providers in the guest folder.

Legal basis: Art. 6(1)(a) GDPR (consent).
Withdrawal: at any time – switch them off in the guest folder or revoke notifications for this site in your browser settings. The stored push address is then deleted, and in any event by the time your access ends.

11.5 Recommending us and your own pictures

The “Recommend us” tile prepares a text, a photo and a link that you can pass on to an app of your choice via your device's share menu. This process takes place entirely on your device. We do not learn whether, when, what or to whom you send anything, and no social network components are embedded.

There you can also select your own pictures . They stay on your device – unless you expressly grant release via the switch provided for this, which is off by default. Only then are the selected pictures uploaded to us.

Data processed once release is granted: the picture itself, its assignment to your booking, the time of release and the wording of the text you agreed to. On upload we automatically remove the capture data contained in the picture – in particular GPS position, time of capture and device identifier.

Purpose: use of the pictures on our website and in our listings on booking portals.
Legal basis: Art. 6(1)(a) GDPR (consent); where people are depicted, also § 22 of the German Act on Copyright in Works of Fine Art and Photography (KunstUrhG).
Withdrawal: at any time – switch the toggle in the guest folder off again and the pictures are deleted. Once your access has expired, a short message to us is enough; we then delete the pictures as well. Copies already published on booking portals are removed as soon as we can arrange that there.
Retention period: until withdrawal. Pictures that are not used are deleted after 24 months at the latest.

Please note: Please release only pictures in which no other people can be identified – you cannot decide about their rights. Every released picture is viewed by us before publication; nothing is published automatically.

About the recommendation link: The link you pass on contains a short code. It is identical for all guests and tells us only that a visit came about via this tile – not who made the recommendation. A personal recommendation link would connect the receiving person with you; we deliberately do not do that (see section 8a).

11.6 Guest card

Where a guest card is issued (e. g. for the Altenberg holiday region), we process the information required to produce it and to provide it to you electronically (PDF). Legal basis: Art. 6(1)(b) and (c) GDPR (visitor's tax).

11.7 Storage on your device

The guest folder can be placed on your home screen as an app and then stores content locally on your device so that it remains usable without an internet connection – including your door code and your progress through the checklists. This data is held with you alone and is not transmitted to us. It disappears when you clear the site data in your browser or remove the app.

11.8 Retention period

Personal access ends 14 days after departure and is then deactivated or deleted. Booking-related data is subject to the periods in section 5, security-relevant logs to the period in section 11.1.

12. Reviews

After your departure we invite you by e-mail to review your stay. The invitation link is personal and applies only to your booking. Leaving a review is voluntary.

Data processed: name, e-mail address, ratings in several categories, your texts and – if you upload any – pictures. Only your name is published (in the form you provide), together with the rating, texts and pictures; your e-mail address stays internal and never appears publicly. We additionally store the wording of the consent you gave when submitting.

Purpose: publication on our website and improvement of what we offer.
Legal basis: Art. 6(1)(a) GDPR (consent).
Withdrawal: at any time, without any formality, by e-mail; we then take the review off the website.
Retention period: until withdrawal.

Reviews on Google: Afterwards we offer you the option of additionally leaving a review on Google. That is a link to an external site – a connection to Google is created only when you click it, and Google's privacy policy then applies. It is entirely your decision. On our website we also show publicly visible Google reviews of our listing; we retrieve these on the server side and cache them, so that your device does not establish any connection to Google.

We do not grant anything in return for reviews – no discount, prize draw or similar – and we do not select who is invited.

13. Your rights as a data subject

You have the following rights against us regarding personal data concerning you:

  • Right of access (Art. 15 GDPR): you may request information about the data we hold about you.
  • Right to rectification (Art. 16 GDPR): you may have incorrect data corrected.
  • Right to erasure (Art. 17 GDPR): you may request the erasure of your data, provided no statutory retention obligation stands in the way.
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR): against processing based on legitimate interests.
  • Withdrawal of consent (Art. 7(3) GDPR): with effect for the future.

To exercise your rights, please contact: info@fewo-am-skihang.de

14. Right to lodge a complaint with the supervisory authority

You have the right to lodge a complaint with the competent data protection supervisory authority. For Saxony this is the Saxon Data Protection Commissioner:
Sächsischer Datenschutzbeauftragter, Devrientstraße 5, 01067 Dresden, Germany
www.saechsdsb.de

15. Data security

This website is delivered over HTTPS (TLS 1.2+). Card data is processed exclusively by Stripe and is not stored on our servers (PCI-DSS compliance by delegation). Database access is exclusively through prepared statements (PDO prepared statements).

16. Changes to this privacy policy

We reserve the right to adapt this privacy policy so that it always meets current legal requirements. The current version is always available at this URL. As of: August 2026.