Privacy notice

This privacy notice applies to the “Gastgeber Amrum” portal on the Stayful platform. The portal name identifies the service; the responsible legal entity is the Bitbox company identified below.

Last updated: 2 October 2026

Contents

1. At a glance

We process data when you open the portal, use an account, submit an enquiry or review, or manage content and contracts as a provider. The data concerned depends on the functions you use.

We do not use advertising pixels, social media plugins or Google Analytics. Necessary storage, external maps and any payment or analytics services in use are explained below. Using the portal does not constitute blanket consent to data processing.

2. Controller

The controller responsible for processing personal data on the platform is:

For privacy enquiries and to exercise your rights, contact:

Address
bitbox – Agentur für digitale Medien GmbH & Co. KG
Stresemannstraße 6
21335 Lüneburg
Represented by
Komplementär-bitbox GmbH, diese vertreten durch den Geschäftsführer Frank Dalock
Commercial register
HRA 1866
Amtsgericht Lüneburg
VAT ID
DE205681801

3. Privacy contact

4. Hosting and technical delivery

The platform is hosted in Germany by the service provider named below. In particular, server requests, IP addresses, technical metadata and the content, account and communication data stored in the platform are processed there.

The service is used to provide a secure, stable and efficient platform pursuant to Art. 6(1)(b) and (f) GDPR. A data processing agreement is in place with the provider.

Address
terralink networks GmbH
Wendenstraße 375
20537 Hamburg

5. Server logs

Each request involves technically necessary information. This may include the IP address, time, requested URL, amount of data transferred, referrer, browser, operating system and user agent. We use this information for delivery, troubleshooting, abuse prevention and system security.

Processing is based on Art. 6(1)(f) GDPR. Logs are deleted or anonymised when no longer needed for these purposes, unless a security incident or legal obligation requires longer retention.

6. Essential cookies and sessions

The portal uses essential cookies and comparable browser storage for language, login, security and, where enabled, protected previews. Your cookie preferences are saved for six months in stayful_consent_v1 without a personal identifier. External maps load only with your consent. You can change your preferences and withdraw consent at any time using “Cookie settings” in the footer.

This storage is necessary for functions explicitly requested by you. It is based on section 25(2) TDDDG and, depending on the function, Art. 6(1)(b) or (f) GDPR. We do not use advertising or profiling cookies.

7. Accounts, login and provider workspace

For registration and login, we process names, email address, account assignments, roles, permissions and security-related session data. Passwords are not stored in the portal; login is handled through the self-hosted Stayful account service.

The provider workspace additionally processes business, team, billing, contract and content data. Security-relevant actions may be recorded with time, account, IP address and user agent in an audit log. Processing is required for contract performance, access control and security under Art. 6(1)(b) and (f) GDPR.

Provider profiles, contact persons, contact details, listings and images published by providers are publicly accessible and may be indexed by search engines. Processing is based on Article 6(1)(b) GDPR for requested publication and Article 6(1)(f) GDPR for regional discoverability. Publish personal information about others only with appropriate authority.

Required fields identify the information needed for each function. Without necessary account, enquiry or billing data we cannot provide that function or contract. Optional information may be omitted. The portal does not perform automated decision-making, including profiling, with legal or similarly significant effects under Article 22 GDPR.

8. Contact and booking enquiries

When you send an enquiry from a listing, we process your name, email address, optional telephone number and travel dates, message, listing assignment and IP address. The IP address is used to limit automated or abusive submissions.

The enquiry is made available to the provider identified in the listing and may be announced by email. Processing is based on Art. 6(1)(b) GDPR where the enquiry concerns steps prior to a contract, and otherwise on Art. 6(1)(f) GDPR. Data is retained for as long as necessary to handle the enquiry, prevent abuse or meet legal obligations.

Enquiries are forwarded to your selected provider, who independently controls processing for advice and contract fulfilment. Its privacy notice also applies. Stayful is the platform brand; the name alone does not identify an additional data recipient.

9. Reviews and reactions

For reviews, we process the supplied name, email address, star rating, text, optional images and technical verification attributes. The email address is not displayed publicly. Votes on whether a review is helpful are protected against duplicate voting using the IP address.

Processing supports publication of authentic reviews, moderation and prevention of manipulation pursuant to Art. 6(1)(b) and (f) GDPR. Published content remains available until deleted or until the purpose of publication ends; verification and blocking data may be required for longer to prevent abuse.

10. Reach and performance statistics

For public listings, the platform counts page views per day and only in aggregated form. The user agent is checked immediately to identify automated requests but is not stored with the view counter. No visitor profile is created.

Providers receive aggregate view and enquiry counts. Processing is based on our legitimate interest in privacy-conscious functional statistics under Art. 6(1)(f) GDPR.

11. OpenStreetMap maps

When an interactive map is displayed, your browser loads map tiles from servers operated by the OpenStreetMap Foundation. In particular, your IP address, browser information, referrer and requested map area are transmitted. Servers may also be located in the United Kingdom or other countries.

Maps provide geographical context for regional offers and load only after your voluntary consent. The subsequent data transfer is based on Art. 6(1)(a) GDPR. You can withdraw consent for future transfers using “Cookie settings” in the footer. Geocoding of an address entered by a provider is performed server-side; the visitor’s location is not collected for this purpose.

12. Weather information

Where the portal enables its weather module, our server retrieves information from MET Norway for a fixed configured location. The device location of a visitor is not requested and the visitor’s IP address is not transmitted to the weather service.

The retrieval supplies regional information and is based on Art. 6(1)(f) GDPR.

13. Payments through Stripe

When a provider subscribes to a paid plan, payment is handled by Stripe. Contract, billing, contact and payment data is transmitted for this purpose. Full card details are processed directly by Stripe and are not stored on our servers.

Processing is based on Art. 6(1)(b) GDPR. Stripe may also process data under its own responsibility to meet legal obligations and prevent fraud. According to Stripe, appropriate safeguards are used for transfers outside the European Economic Area.

For EEA users, Stripe identifies, among others, Stripe Payments Europe, Limited and Stripe Technology Europe, Limited, Ireland. The responsible Stripe entity and its role depend on the product and Stripe privacy information. We receive payment status, transaction and customer identifiers and billing data. Legally required accounting records are processed under Article 6(1)(c) GDPR.

14. Email communication

System messages, confirmations, enquiries and replies may be sent through our hosting provider’s mail servers. Sender and recipient address, subject, content and technical delivery data are processed. Depending on the reason for the message, processing is generally based on Art. 6(1)(b) or (f) GDPR.

16. Optional error diagnostics

If error diagnostics are enabled in the operating environment, our server sends error details and context data to Sentry (Functional Software, Inc.) when technical failures occur. This may include the URL, request method, request, portal and user identifiers, and performance data. Authorisation and cookie headers are removed before transmission.

Processing serves to identify and resolve faults and to secure the platform on the basis of Art. 6(1)(f) GDPR. Sentry may process data in the United States and identifies the EU-US Data Privacy Framework and Standard Contractual Clauses as safeguards.

17. Legal bases, recipients and retention

Depending on the operation, we process data for contract performance or pre-contractual communication (Art. 6(1)(b) GDPR), compliance with legal obligations (Art. 6(1)(c) GDPR), on the basis of consent (Art. 6(1)(a) GDPR), or for legitimate interests (Art. 6(1)(f) GDPR).

Recipients receive data only where required for their task. They may include the selected provider, hosting and mail providers, payment providers and legally authorised bodies. Processors are bound by contract.

Data is deleted when the purpose ends and no statutory retention, evidence or security requirement applies. Contract and billing records may in particular be subject to commercial and tax retention periods.

Transfers outside the EEA require compliance with Articles 44 et seq. GDPR, including an applicable adequacy decision or appropriate safeguards such as EU standard contractual clauses and supplementary measures where necessary. Information and copies of the safeguards used for a particular service are available from the privacy contact.

Retention depends on the purpose: account data for the lifetime of the account, enquiries until processing and necessary evidence are complete, published content until removal or expiry of its purpose. Legally required records are retained for the applicable period with processing for other purposes restricted. Backups are overwritten during the backup cycle.

18. Your rights

Subject to the statutory conditions, you may request access, rectification, erasure, restriction of processing and data portability. You may withdraw consent at any time with effect for the future.

Where processing is based on Art. 6(1)(f) GDPR, you may object on grounds relating to your particular situation. Contacting the address above is sufficient to exercise your rights. We may request proof of identity before disclosing personal data.

You may object to direct marketing at any time without giving reasons. Withdrawal of consent does not affect the lawfulness of earlier processing. Your rights are set out in Articles 15–21 GDPR. You may also complain to the supervisory authority where you live or work.

19. Right to lodge a complaint

You may lodge a complaint with a data protection authority. The State Commissioner for Data Protection of Lower Saxony is in particular responsible for the controller’s registered office.

20. Security and changes

Transmission between your browser and the portal is protected by TLS. We use technical and organisational measures to protect data against loss, alteration and unauthorised access.

We update this notice when functions, service providers or legal requirements change. The version published on this page applies.

21. Withdrawal declarations

For withdrawals, we process the portal, service, name, email and any contract references or details you provide. We store the declaration with its receipt date and time, forward it to our accounting team at buchhaltung@marktplatz-agentur.de and acknowledge receipt by email. Processing is for contract handling and proof of receipt under Article 6(1)(b) and (c) GDPR and, where necessary, (f) for legal claims. Records are retained for the necessary processing, evidentiary and statutory periods, then deleted.