1. DATA PROTECTION AT A GLANCE
GENERAL NOTES
The following notes provide a simple overview of what happens to your personal data when you visit our website. Personal data is any data that can be used to identify you personally. Detailed information on the subject of data protection can be found in our data protection declaration listed below this text.
DATA COLLECTION ON OUR WEBSITE
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find the operator’s contact details in the legal notice of this website.
How do we collect your data?
On the one hand, your data is collected when you provide it to us. This may, for example, be data that you enter in a contact form.
Other data is collected automatically by our IT systems when you visit the website. This is primarily technical data (e.g. internet browser, operating system or time of page view). This data is collected automatically as soon as you enter our website.
What do we use your data for?
Some of the data is collected to ensure that the website is provided without errors. Other data can be used to analyze your user behavior.
What rights do you have with regard to your data?
You have the right to receive information about the origin, recipient and purpose of your stored personal data free of charge at any time. You also have the right to request the correction, blocking or deletion of this data. You can contact us at any time at the address given in the legal notice if you have any further questions on the subject of data protection. You also have the right to lodge a complaint with the competent supervisory authority.
ANALYSIS TOOLS AND THIRD-PARTY TOOLS
When you visit our website, your surfing behavior may be statistically evaluated. This is mainly done using cookies and so-called analysis programs. The analysis of your surfing behavior is usually anonymous; the surfing behavior cannot be traced back to you. You can object to this analysis or prevent it by not using certain tools. You can find detailed information on this in the following privacy policy. You can object to this analysis.
We will inform you about the possibilities of objection in this privacy policy.
2. GENERAL NOTICE AND OBLIGATORY INFORMATION PRIVACY POLICY
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
When you use this website, various personal data is collected. Personal data is data that can be used to identify you personally. This privacy policy explains what data we collect and what we use it for.
It also explains how and for what purpose this is done. We would like to point out that data transmission over the Internet (e.g. when communicating by e-mail) may be subject to security vulnerabilities. Complete protection of data against access by third parties is not possible.
NOTE ON THE RESPONSIBLE BODY
The responsible body for data processing on this website is:
KOOS Hotel GmbH
Sonnenstraße 18b
80331 Munich
Telefon: +49 (0)89 / 89 80 98 49
E-Mail: henri.reich@koos.team
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data (e.g. names, e-mail addresses, etc.).
WITHDRAWAL OF YOUR CONSENT TO DATA PROCESSING
Many data processing operations are only possible with your express consent. You can withdraw your consent at any time. All you need to do is send us an informal e-mail. The legality of the data processing carried out until the revocation remains unaffected by the revocation.
RIGHT OF COMPLAINT TO THE COMPETENT SUPERVISORY AUTHORITY
In the event of breaches of data protection law, the data subject has the right to lodge a complaint with the competent supervisory authority. The competent supervisory authority for data protection issues is the state data protection officer of the federal state in which our company is based. A list of data protection officers and their contact details can be found at the following link: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html.
RIGHT TO DATA TRANSMISSIBILITY
You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a commonly used, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done insofar as it is technically feasible.
SSL or TLS ENCRYPTION
This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the site operator. You can recognize an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser line.
If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
ENCRYPTED PAYMENT PROCESSING ON THIS WEBSITE
If you are obliged to provide us with your payment details (e.g. account number for direct debit authorization) after concluding a fee-based contract, this data is required for payment processing.
Payment transactions via the usual means of payment (Visa/MasterCard, direct debit) are made exclusively via an encrypted SSL or TLS connection. You can recognize an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser line.
With encrypted communication, the payment data you transmit to us cannot be read by third parties.
INFORMATION, BLOCKING, DELETION
You have the right to free information about your stored personal data, its origin and recipients and the purpose of the data processing and, if necessary, a right to correction, blocking or deletion of this data at any time within the framework of the applicable legal provisions. You can contact us at any time at the address given in the legal notice if you have further questions on the subject of personal data.
OBJECTION AGAINST ADVERTISING MAIL
We hereby object to the use of contact data published as part of our obligation to provide a legal notice for the purpose of sending unsolicited advertising and information material. The operators of this website expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, such as spam e-mails.
DATA PROTECTION OFFICER STATUTORILY MANDATED DATA PROTECTION OFFICER
We have appointed a data protection officer for our company:
heyData GmbH
Schützenstr. 5
10117 Berlin
E-Mail: info@heydata.eu
Alveni AI Phone Assistant (Call Forwarding)
What data is processed?
The hotel’s phone system uses the phone assistant from Alveni AG, R2 Tower, Richtistrasse 2, 8304 Wallisellen, Switzerland (https://alveni.ai/). Under certain conditions, this service allows incoming calls to be forwarded to an AI-powered automated response system. When the telephone assistant is active, we process only the data that you voluntarily provide during the call or that is technically necessary for handling the call, e.g.:
– Information you provide voluntarily (e.g., name, inquiry, email address, request for a callback)
– Your phone number (if it is being transferred)
– Transcripts of the conversations
– Date and time of the call, as well as technical connection metadata
This information is processed in encrypted form and used solely to forward your inquiry to the appropriate hotel team, to facilitate callbacks, or to answer questions. It is not used for any other purpose—such as for advertising, profiling, or training AI models.
Data Processing Necessary for Technical Purposes
The following information is processed for the technical operation of the telephone assistant:
– Technical connection data (e.g., phone number, duration, date/time) for call routing and connection stability.
– Temporary real-time processing of audio to generate transcripts.
– Transcripts are pseudonymized during processing, processed in encrypted form, and deleted in accordance with the time limits specified below.
– Logs/error logs for detecting abuse (e.g., spam) and ensuring proper functionality.
– All data transmissions are encrypted (TLS/SRTP) to ensure the security of communications.
Processing and Storage
All processing takes place on servers located within the EU; the AI models used are operated locally. Personal data is transferred to third countries only on the basis of EU Standard Contractual Clauses or other appropriate safeguards in accordance with Article 46 of the GDPR.
– By default, transcripts and metadata stored with Alveni AI are automatically deleted after 30 days. Upon request, they can be deleted earlier.
– The email summary received by the hotel is subject to the hotel’s applicable retention periods.
– Es findet keine Erkennung von Stimmen statt, es werden keine Stimmenprofile erstellt und keine Audio-Signaturen für Identifikationszwecke verwendet.
– No AI model training is conducted using personal data, and the data processed is not used for profiling purposes.
Alveni AG uses technical subcontractors for certain functions (e.g., hosting, telecommunications infrastructure). These subcontractors are contractually bound in accordance with Article 28 of the GDPR and receive only the data necessary for technical implementation.
Tracking and Cookies
– No cookies or tracking tools are used for the phone feature.
– No fully automated decision with legal effect is made.
– Callers are clearly informed at the start of the call that they are speaking with an AI-powered assistant. If desired, they can be transferred to a human agent at any time.
Legal Basis
Data processing is carried out on the basis of Article 6(1)(f) of the GDPR (legitimate interest), in particular to ensure reliable telephone availability and to efficiently process incoming inquiries. To the extent that processing is necessary for the initiation or performance of a contract (e.g., reservation requests), it is also carried out on the basis of Article 6(1)(b) of the GDPR.
Voluntary Participation and the Right to Object
Providing personal data during a phone call is voluntary. You decide for yourself what information you wish to share. You have the right to object to the processing of your personal data at any time, effective for the future. Please send your request or objection to: privacy@alveni.ai.
More Information
For detailed information on data protection, please see Alveni AG’s Privacy Policy: https://alveni.ai/datenschutz/