Privacy Policy
Your data is safe
1. Controller
The controller within the meaning of the GDPR is:
Hotel & Restaurant Ashley's Garden
Karl-Kleppe-Straße 20
40474 Düsseldorf-Golzheim, Germany
Phone: +49 (0) 211 51 61 71-0
Email: ashley@ashleysgarden.de
2. General Information
When using this website, various items of personal data are collected. Personal data is information that can be used to identify you personally. This privacy policy explains which data we collect and what we use it for.
We point out that data transmission via the internet (e.g. communication by email) may have security gaps. Complete protection against access by third parties is not possible.
3. Collection and storage when visiting the website
3.1 Server log files
When you visit our website, our hosting provider automatically records information that your browser transmits to us:
- IP address
- Date and time of the request
- Time-zone difference to Greenwich Mean Time
- Content of the request (specific page)
- Access status / HTTP status code
- Volume of data transferred in each case
- Website from which the request originates
- Browser, operating system and its interface
- Language and version of the browser software
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a technically faultless and secure presentation).
Storage duration: a maximum of 7 days, after which the data is anonymised or deleted.
4. Cookies and consent management
Our website uses cookies. Cookies are small text files that are stored on your end device.
4.1 Strictly necessary cookies
These cookies are required to ensure the functionality of the website (e.g. saving your cookie selection). Legal basis: Art. 6(1)(f) GDPR and § 25(2)(2) TTDSG.
4.2 Optional cookies (analytics / marketing)
These are only set with your consent in accordance with § 25(1) TTDSG and Art. 6(1)(a) GDPR. You may withdraw your consent at any time via the cookie banner ("Cookie settings" link in the footer).
5. Third-party services used
We use the following service providers on and in connection with our website:
5.1 SiteGround (hosting)
Provider: SiteGround Spain S.L., Calle de Prim 19, 28004 Madrid, Spain
Purpose: Provision of the website infrastructure.
Data types: IP address, server logs.
Legal basis: Art. 6(1)(f) GDPR.
Server location: EU.
5.2 Google Analytics
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Purpose: Web analytics for the optimisation of our offering.
Data types: Pseudonymised usage data, truncated IP address, device/browser information.
Legal basis: Art. 6(1)(a) GDPR (consent via cookie banner).
Third-country transfer: USA. Safeguards: Standard Contractual Clauses + EU-U.S. Data Privacy Framework (Google is DPF-certified).
Storage duration: up to 14 months.
Withdrawal: possible at any time via the cookie banner.
5.3 Google Search Console
Provider: Google Ireland Limited
Purpose: Evaluation of the website's visibility in Google search results.
Data types: aggregated search queries, click counts, technical data.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in SEO optimisation).
As a rule, no directly personal data is transmitted to us.
5.4 Reservation systems (hotel & restaurant)
The following reservation systems are linked or embedded on our website. Your booking data is transmitted to them as soon as you make a reservation:
- SiteMinder "Direct Booking Engine" (hotel bookings, accessible via
direct-book.com) – Provider: SiteMinder Limited, Sydney, Australia. When you click on a booking button, you are redirected to the SiteMinder booking flow; the data you enter there is processed directly by SiteMinder and subsequently passed automatically to our internal hotel management system (3RPMS, see section 7). - OpenTable (restaurant reservations) – see section 8.
We do not operate any booking or reservation software on www.ashleysgarden.de itself; the website only redirects to or embeds the external systems mentioned above.
Legal basis: Art. 6(1)(b) GDPR (initiation/performance of a contract).
5.5 AI-supported correspondence (Anthropic / Claude)
For the drafting of reply emails and business documents we use the AI assistant Claude by Anthropic, PBC (San Francisco, USA). In limited cases, pseudonymised correspondence data is processed.
Safeguards: Before any input into the AI assistant, personal data such as names, full addresses and phone numbers is replaced by placeholders (pseudonymisation). The training opt-out is enabled.
Third-country transfer: USA. Safeguards: Standard Contractual Clauses (SCC) under Art. 46 GDPR.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the efficient processing of enquiries).
Anthropic data protection contact: privacy@anthropic.com – Privacy policy: anthropic.com/legal/privacy
5.6 Our own application server (OneDesk / Railway)
Some content on our website is loaded live from our own application server (“OneDesk”) – specifically the events calendar and, on the hotel page, the current room rates and availability. Your browser connects to ashleys-onedesk-production.up.railway.app for this purpose. Your IP address is necessarily transmitted as part of that connection; no cookies are set and no profiles are created.
The rate enquiry sent to SiteMinder (see section 7.4) takes place server to server only – none of your data is transmitted to SiteMinder in the process.
Operation: Railway Corp. (USA) as the hosting provider of our application server, acting as a processor.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in displaying current information on our website).
6. Contact
If you contact us via the contact form or by email, your details are stored by us for the purpose of processing the enquiry.
Data processed: name, email address, content of the message, phone number where applicable.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measure / contract performance) or Art. 6(1)(f) GDPR (handling of general enquiries).
Storage duration: until your enquiry has been finally processed; for legally relevant matters, until the expiry of the statutory retention periods (max. 6 or 10 years).
7. Online hotel booking
Online bookings do not run directly on our website but via the SiteMinder "Direct Booking Engine" (see section 5.4). When you click on a booking button, you are redirected to direct-book.com/properties/AshleyGardenDirect. The booking data you enter there is processed by SiteMinder and subsequently transferred automatically to our internal hotel management system 3RPMS (Provider: HaDre GmbH, Bauerngasse 32, 90443 Nürnberg, Germany), where it is stored to perform the contract. 3RPMS is not directly connected to our website; it receives bookings exclusively via SiteMinder.
Data processed: name, address, date of birth, contact details, booking details, payment data.
7.1 Online payment processing (Stripe)
Carried out by Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (PCI-DSS-certified). Data Protection Officer: dpo@stripe.com. Credit card data is processed exclusively on Stripe's servers and is not stored by us. Stripe acts in part as a processor (for our payment processing) and in part as an independent controller (for fraud prevention, KYC and statutory compliance obligations).
Third-country transfer: Stripe also processes data in the USA (parent company Stripe, Inc.) and India. Safeguards: EU Standard Contractual Clauses (SCC) and EU-U.S. Data Privacy Framework (Stripe is DPF-certified).
Stripe privacy policy: stripe.com/privacy
7.2 On-site card payments (Nexi)
Carried out by Nexi Germany GmbH (formerly Concardis), Helfmann-Park 7, 65760 Eschborn, Germany (PCI-DSS-certified). Phone: +49 69 7922-0. Data Protection Officer: DPO-DACH@nexigroup.com. Nexi acts as an independent controller within the meaning of Art. 4(7) GDPR. We process exclusively tokenised/masked card data; full card data is not stored by us. Third-country transfers to the USA and other third countries by Nexi are safeguarded by Standard Contractual Clauses under Art. 44 et seq. GDPR. Privacy policy: nexi.de/de/legal-footer/datenschutzerklaerung
Legal basis: Art. 6(1)(b) GDPR (accommodation contract), Art. 6(1)(c) GDPR (registration obligation under the BMG).
7.3 Bookings via third-party platforms (OTAs)
If you book via Booking.com, HRS, Expedia or other third-party platforms, they transmit your booking data to us (name, contact details, stay data and, where applicable, credit card data as a guarantee). We process this data to perform the contract.
For Booking.com (Booking.com B.V., Herengracht 597, 1017 CE Amsterdam, Netherlands), there is joint controllership under Art. 26 GDPR. Booking.com, as platform operator, is responsible for processing your data on the platform (e.g. marketing, recommendations, reviews); we as the hotel are responsible for processing your data for the performance of the accommodation contract. Booking.com privacy policy: booking.com/content/privacy.html
For HRS (HRS – HOTEL RESERVATION SERVICE - HRS GmbH, Breslauer Platz 4, 50668 Köln, Germany), HRS is an independent controller within the meaning of Art. 4(7) GDPR. HRS hosts exclusively on servers in the EU/EEA. HRS data protection officer: datenschutz@hrs.de
For Expedia (Expedia, Inc., part of the Expedia Group, USA), there is also joint controllership. Expedia acts as data controller for platform data; we as the hotel are an independent controller for the processing of your data for the performance of the accommodation contract. Third-country transfer to the USA via Standard Contractual Clauses (SCC) + EU-U.S. Data Privacy Framework + Global Cross Border Privacy Rules System. Privacy policy: expedia.com/lp/b/privacy
7.4 Channel manager & Direct Booking Engine (SiteMinder)
For accepting direct bookings via the "Direct Booking Engine" (see section 5.4) and for synchronising booking data between the booking portals (Booking.com, HRS, Expedia etc.) and our internal hotel management system, we use SiteMinder Limited (Sydney, Australia). SiteMinder acts as a processor under Art. 28 GDPR. Third-country transfer to Australia: Standard Contractual Clauses (SCC) under Art. 44 et seq. GDPR. Data protection contact: privacy.officer@siteminder.com
7.5 Security notice on OTA bookings
We will never ask you outside of the platform – by email or SMS – to make payments via external links. If you receive such a message, please ignore it and report the incident directly to the platform (e.g. report.booking.com) and to us.
8. Restaurant reservations via OpenTable
Restaurant reservations can be made by phone, by email or via OpenTable.
Provider: OpenTable GmbH, Warschauer Platz 12, 10245 Berlin, Germany (part of Booking Holdings Inc., USA).
Data Protection Officer Germany: Dr. Felix Wittern, Fieldfisher Tech Rechtsanwaltsgesellschaft mbH, Amerigo-Vespucci-Platz 1, 20457 Hamburg, privacy@opentable.com.
According to its own privacy policy, OpenTable acts as an independent controller within the meaning of the GDPR. If you reserve via OpenTable, the OpenTable data protection terms apply additionally: opentable.com/legal/privacy-policy
Data processed: name, phone number, email, number of guests, date, time, special requests, allergies (if provided).
Legal basis: Art. 6(1)(b) GDPR (initiation of a contract); for allergy data Art. 9(2)(a) GDPR (explicit consent).
Third-country transfer: USA via the corporate group structure (Booking Holdings). Safeguards: Standard Contractual Clauses (SCC) + EU-U.S. Data Privacy Framework (OpenTable is DPF-certified).
9. Video surveillance
We operate video surveillance in the following areas:
- Restaurant cash desk (with video recording)
- Hotel entrance door with intercom (as a rule only a live image to identify visitors ringing the bell)
Purposes: protection against theft, security of cash handling, identification of guests outside reception hours.
Legal basis: Art. 6(1)(f) GDPR – legitimate interest in the protection of property and the right to determine who enters the premises.
Storage duration: recordings are usually overwritten automatically after 72 hours. Longer storage takes place only in the case of specific incidents for the purpose of preserving evidence.
Notice signs with a camera symbol and a data protection notice are displayed in front of every recording area.
10. Job applications
If you apply to us (via the contact form on our website, by email or by phone), we process your application data for the purpose of personnel selection.
Data processed: name, contact details, CV and references where applicable, position, availability.
Legal basis: Art. 6(1)(b) GDPR in conjunction with § 26(1) BDSG (initiation of an employment relationship).
Retention periods: If your application is unsuccessful, we delete your application data within 6 months (in accordance with § 15 AGG). If you are hired, the data is transferred to your personnel file. Longer storage in the applicant pool only takes place with your express consent.
11. Your rights
You have the following rights at any time:
- Access to the data stored about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Objection to processing (Art. 21 GDPR)
- Data portability (Art. 20 GDPR)
- Withdrawal of consent given, with effect for the future (Art. 7(3) GDPR)
- Complaint to a supervisory authority (Art. 77 GDPR)
To exercise your rights, please contact:
Email: ashley@ashleysgarden.de
Post: Hotel & Restaurant Ashley's Garden, Karl-Kleppe-Straße 20, 40474 Düsseldorf, Germany
Competent supervisory authority:
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia
Kavalleriestraße 2–4, 40213 Düsseldorf, Germany
Phone: 0211/38424-0 · Email: poststelle@ldi.nrw.de · Web: www.ldi.nrw.de
12. Data deletion and storage duration
Personal data is deleted as soon as the purpose of processing ceases to apply and there are no statutory retention obligations. In particular:
- Booking and invoice data: 10 years (§ 147 AO)
- Business correspondence: 6 years (§ 257 HGB)
- Registration forms: 1 year from the date of travel (§ 30 BMG)
- Server logs: max. 7 days
- Cookie consent records: 3 years (proof obligation)
13. Data security
We use technical and organisational security measures to protect your data against manipulation, loss, destruction and unauthorised access. Our security measures are continuously improved in line with technological developments.
The transmission of your data takes place via a TLS/SSL-encrypted connection (HTTPS).
14. Currency of this privacy policy
We reserve the right to adapt this privacy policy so that it always complies with the latest legal requirements or reflects changes to our services. The version available at the time of your visit shall apply.
Last updated: May 2026