Privacy Policy
Last updated: 22 September 2026
The protection of your personal data is important to us. This Privacy Policy explains how Saxony Stays UG (haftungsbeschränkt) collects, uses, stores and protects personal data when you visit our website, contact us or make a booking.
1. Controller
The controller responsible for the processing of personal data on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Saxony Stays UG (haftungsbeschränkt)
Am Eiswurmlager 18
01189 Dresden
Germany
Email: gerd@saxony-stays.com
Phone: +49 156 79590200
Website: https://www.saxony-stays.com
2. Personal Data We Process
Depending on how you use our website and services, we may process the following categories of personal data:
* Name and contact details, such as your email address and telephone number
* Booking and reservation information, including arrival and departure dates, number of guests and selected accommodation
* Information you provide when contacting us
* Information required to process and manage your booking
* Payment and billing-related information
* Technical information such as IP address, browser type, operating system, device information, date and time of access and referring website
* Cookie and consent information
* Other information you voluntarily provide to us
We only collect personal data that is necessary for the relevant purpose.
3. Purposes and Legal Bases for Processing
We process personal data for the following purposes:
### Website Operation and Security
When you visit our website, technical information may automatically be processed in order to provide the website, maintain its security, identify technical problems and prevent misuse.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure, reliable and efficient operation of our website.
### Booking and Reservation Management
When you make or request a reservation, we process the information required to manage your booking, communicate with you, provide the accommodation and fulfil our contractual obligations.
The legal basis is Article 6(1)(b) GDPR, as the processing is necessary to take steps at your request before entering into a contract and/or to perform a contract with you.
### Contact Requests
If you contact us using our contact form, email, telephone or another communication channel, we process the information you provide in order to respond to your request.
Depending on the nature of your request, the legal basis is Article 6(1)(b) GDPR or Article 6(1)(f) GDPR.
Our legitimate interest is to communicate efficiently with guests, prospective guests and business partners.
### Legal and Accounting Obligations
Certain booking, payment, invoice and business records may need to be retained in order to comply with tax, accounting and other legal requirements.
The legal basis is Article 6(1)(c) GDPR.
### Consent-Based Processing
Where we ask for your consent, for example for certain analytics, marketing or non-essential cookies, the legal basis is Article 6(1)(a) GDPR.
You may withdraw your consent at any time with effect for the future.
4. Booking Platform and Hostaway
We use Hostaway to operate parts of our booking infrastructure, website functionality and reservation management.
In connection with reservations, Hostaway may process information such as:
* Guest names
* Contact details
* Booking dates
* Property and reservation information
* Messages and communications
* Payment-related information
* Technical and usage information
Where Hostaway processes personal data on our behalf, it acts as a service provider or processor in accordance with applicable data protection requirements.
Further information about Hostaway's data processing practices can be found in Hostaway's own Privacy Policy.
5. Payment Processing
If you make a paid reservation through our website, payment information may be transmitted to and processed by the payment service provider made available through our booking platform.
Payment service providers process the information necessary to authorize, execute and document the payment.
Depending on the circumstances, the legal basis for this processing is Article 6(1)(b) GDPR and/or Article 6(1)(c) GDPR.
We do not intentionally store complete payment card details ourselves where the payment is processed directly by the respective payment provider.
6. Cookies and Similar Technologies
Our website uses cookies and similar technologies.
Some cookies are technically necessary for the website, booking functionality, security or storing your privacy preferences.
Other cookies, such as analytics or marketing cookies, are only used where permitted and, where required, after you have given your consent.
You can manage or withdraw your preferences at any time using the Cookie Preferences function available on our website.
Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
7. Server Log Files
When you access our website, technical information may automatically be recorded in server log files.
This may include:
* IP address
* Browser type and version
* Operating system
* Date and time of access
* Requested pages or resources
* Referring website
* Technical error and security information
We process this information to operate and secure our website, diagnose technical problems and prevent misuse.
The legal basis is Article 6(1)(f) GDPR.
8. Recipients of Personal Data
We only share personal data where this is necessary for the purposes described in this Privacy Policy or where we are legally required to do so.
Recipients may include:
* Hosting and IT service providers
* Hostaway and providers involved in our booking infrastructure
* Payment service providers
* Communication service providers
* Accountants, tax advisers and other professional advisers
* Public authorities where required by law
* Other service providers necessary for operating our accommodation and processing reservations
Where service providers process personal data on our behalf, appropriate data processing arrangements are used where required by law.
We do not sell your personal data.
9. International Data Transfers
Some of the service providers involved in providing our website or booking infrastructure may process personal data outside the European Economic Area (EEA), including in the United States.
Where personal data is transferred to a country outside the EEA, we take appropriate measures as required by applicable data protection law. Depending on the recipient, these measures may include an adequacy decision of the European Commission, participation in an applicable recognized data transfer framework or the use of Standard Contractual Clauses approved by the European Commission.
Service providers used by Hostaway may also operate outside the EEA.
10. Storage Period
We retain personal data only for as long as necessary for the purposes for which it was collected or as required by applicable law.
In particular:
* Contact requests are generally retained only for as long as necessary to process and follow up on the request.
* Booking and contractual information may be retained for the duration of the contractual relationship and applicable limitation periods.
* Accounting records and booking documents that constitute accounting records may generally need to be retained for eight years.
* Certain other business records may need to be retained for six or ten years, depending on the applicable legal requirement.
* Cookie and consent information is retained in accordance with the duration and settings of the respective cookie or consent mechanism.
After the relevant retention period has expired, personal data is deleted or anonymised unless further storage is legally permitted or required.
11. Your Rights under the GDPR
Subject to the applicable legal requirements, you have the following rights:
* Right of access under Article 15 GDPR
* Right to rectification under Article 16 GDPR
* Right to erasure under Article 17 GDPR
* Right to restriction of processing under Article 18 GDPR
* Right to data portability under Article 20 GDPR
* Right to object under Article 21 GDPR
* Right to withdraw consent under Article 7(3) GDPR
Where processing is based on our legitimate interests pursuant to Article 6(1)(f) GDPR, you may object to such processing on grounds relating to your particular situation.
Where personal data is processed for direct marketing purposes, you may object to such processing at any time.
To exercise your rights, please contact:
Requests relating to your data protection rights are generally free of charge. In cases of manifestly unfounded or excessive requests, the rules set out in Article 12 GDPR apply.
12. Right to Lodge a Complaint
You also have the right to lodge a complaint with a data protection supervisory authority.
The supervisory authority responsible for Saxony Stays UG is:
Sächsische Datenschutz- und Transparenzbeauftragte
Maternistraße 17
01067 Dresden
Germany
Email: post@sdtb.sachsen.de
Phone: +49 351 85471-101
You may also contact another competent supervisory authority, in particular in the EU Member State of your habitual residence, place of work or the place of the alleged infringement.
13. Children
Our website and booking services are primarily intended for adults who are able to enter into accommodation contracts.
Where children are included as guests in a reservation, we may process limited information about them where this is necessary for the reservation, accommodation, pricing or compliance with legal requirements.
We do not knowingly use children's personal data for advertising or marketing purposes.
14. Data Security
We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or unauthorized access.
However, no transmission or storage method can provide absolute security.
15. Changes to this Privacy Policy
We may update this Privacy Policy if our website, services, service providers or legal requirements change.
The current version of the Privacy Policy is always available on this website.
Last updated: 22 September 2026