Privacy Policy
Last updated: 17 August 20261. Controller
The controller responsible for processing personal data in connection with this website and the security deposit process is:
Schröder & Friends Event Consulting GmbH
Hamburger Straße 3
22083 Hamburg
Germany
Managing Director: Martin Schröder
Telephone: +49 1511 1022202
Email: info@schroeder-friends.de
Website: https://www.schroeder-friends.de
2. Website provision using Google Sites
This website is provided using Google Sites. The provider for users in the European Economic Area is generally:
Google Ireland Limited
Gordon House, Barrow Street
Dublin 4
Ireland
When you visit the website, technically necessary data is transmitted to and processed by Google. This may include in particular:
IP address,
date and time of access,
page or file accessed,
browser type, browser language and browser version,
operating system and device type,
referrer URL,
system activity and technical error data, and
cookie or similar identifiers.
This processing is required to display the website and ensure its security, stability and functionality. To the extent that we determine the purposes and means of this processing, it is based on Article 6(1)(f) GDPR. Our legitimate interest lies in providing a secure and reliable website.
Google Sites also uses Google services to deliver images, fonts and technical website components. In particular, content may be loaded from googleusercontent.com, googleapis.com and gstatic.com. Google also processes the connection data generated in this context.
We have not entered our own Google Analytics measurement ID in Google Sites and do not use Google Analytics ourselves to analyse this website. However, Google states that Google Sites uses cookies to provide services and analyse traffic. Where consent is required for cookies or similar technologies that are not technically necessary, they are used only on the basis of your consent. The legal basis is Section 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR. You may withdraw your consent with effect for the future using the options provided by Google Sites. Section 25(2) no. 2 TDDDG applies to technically necessary storage or access.
Google also processes data on servers outside the European Union and the European Economic Area. Where required, Google states that it relies on applicable adequacy decisions and appropriate safeguards, in particular the European Commission's Standard Contractual Clauses, for such transfers.
Further information:
Google Privacy Policy: https://policies.google.com/privacy?hl=en
Information about cookies on Google Sites: https://support.google.com/sites/answer/9396802?hl=en
Information about data transfers at Google: https://policies.google.com/privacy/frameworks?hl=en
3. Domain and DNS provided by netcup
The domain schroeder-friends.de and the associated DNS settings are managed by:
netcup GmbH
Emmy-Noether-Straße 10
76131 Karlsruhe
Germany
The content of this Google Sites website is not hosted by netcup. However, DNS and connection data may be processed when the domain is technically resolved. This processing is carried out to make the domain available and securely accessible on the basis of Article 6(1)(f) GDPR.
Further information: https://www.netcup.com/de/kontakt/datenschutzerklaerung
4. Contact by email or telephone
No contact form is used on this website.
If you contact us by email or telephone, we process the data you provide. This may include your name, contact details, the content of your enquiry and the time of contact.
Where your enquiry relates to entering into or performing a contract, the legal basis is Article 6(1)(b) GDPR. In all other cases, processing is based on Article 6(1)(f) GDPR. Our legitimate interest lies in properly handling and documenting your enquiry.
We delete enquiries once they have been fully dealt with and there are no contractual, statutory or other legitimate reasons for continued storage. Statutory retention obligations remain unaffected.
5. Security deposit authorisation and payment processing via Stripe
We use Stripe services to authorise and manage security deposits. The contractual partner for payment services in the European Economic Area is generally:
Stripe Payments Europe, Limited
The One Building
1 Grand Canal Street Lower
Dublin 2
Ireland
Depending on the Stripe service used, Stripe Technology Europe, Limited and other companies in the Stripe group may also be involved.
When you open a security deposit link provided by us, the payment page is provided directly by Stripe. The card and contact details you enter there are transmitted directly to Stripe. We do not receive or store your full card number or card verification code.
Stripe may process the following data in particular:
name and contact details,
billing address, where requested,
information about the payment method used,
security deposit amount and the date, time and status of the authorisation,
payment, Checkout and transaction identifiers,
card brand, expiry date and last digits of the card,
IP address, browser, device and system information,
information about acceptance of the security deposit terms, and
data used for fraud, risk and security checks.
Your card is initially authorised only for the stated security deposit amount. The amount is not automatically charged. The authorisation may be released after your stay or, where contractually and legally permitted, captured in full or in part.
Processing required to carry out the agreed security deposit authorisation is based on Article 6(1)(b) GDPR. Processing for the prevention of misuse and fraud, IT and payment security, and the establishment, exercise or defence of legal claims is based on Article 6(1)(f) GDPR. Our legitimate interests lie in secure security deposit processing, preventing payment defaults and misuse, and maintaining legal records.
Stripe may disclose transaction data to banks, card networks, payment service providers, identity and fraud prevention services and other financial partners where necessary for authorisation, processing, security checks or the handling of disputes. Stripe also processes certain data under its own responsibility as a controller.
Stripe and service providers used by Stripe may process data outside the European Union and the European Economic Area. Stripe states that such transfers are based, among other things, on adequacy decisions and the European Commission's Standard Contractual Clauses.
Further information:
Stripe Privacy Policy: https://stripe.com/privacy
Stripe Data Processing Agreement: https://stripe.com/legal/dpa
6. Local security deposit management tool
We use a management tool that runs locally on a company Mac to create and manage security deposit links. The tool is not publicly accessible via the internet and does not receive card details.
Only administrative data required to assign and process the security deposit is stored locally. This may include:
Stripe Checkout or payment transaction identifier,
security deposit amount,
assigned accommodation,
an internal booking reference, where applicable,
date and time of creation, and
the generated Stripe security deposit link.
Full card numbers and card verification codes are not stored in this tool. Locally stored records are automatically deleted no later than six months after they are created, unless a specific legal dispute or statutory obligation requires longer retention.
The legal bases are Article 6(1)(b) GDPR for carrying out the security deposit agreement and Article 6(1)(f) GDPR for secure administration, record keeping and the defence of legal claims.
7. Recipients of personal data
We disclose personal data only where this is permitted and necessary for the performance of a contract, security deposit processing, compliance with a legal obligation or on the basis of a legitimate interest.
Possible recipients include in particular:
Google as the provider of Google Sites,
netcup as the domain and DNS provider,
Stripe and the banks, card networks, payment service providers and security service providers involved by Stripe,
IT service providers used by us,
tax advisers, lawyers and other professional advisers, and
courts and public authorities where required by law or necessary to establish or defend legal claims.
We do not sell personal data or disclose it to third parties for our own advertising purposes.
8. Retention periods
We store personal data only for as long as is necessary for the relevant purpose. The data is then deleted or anonymised unless statutory retention obligations, ongoing contractual relationships, specific disputes or other legitimate reasons require continued storage.
The respective privacy and retention policies of Google, Stripe and other independently responsible recipients also apply to data retained by them.
If a security deposit authorisation results in an actual payment, refund, claim for damages or accounting-related business transaction, the relevant documents may be retained for the applicable statutory commercial and tax retention periods.
9. Cookies and similar technologies
We do not use advertising or marketing cookies ourselves and do not use our own analytics tool.
Google Sites may use technically necessary cookies and, depending on your selection in the cookie notice, other Google cookies or similar technologies. Further information is provided in section 2 of this Privacy Policy and in the Google information linked there.
Stripe may use technically necessary cookies and similar technologies on the payment page provided by Stripe, in particular for payment processing, authentication, fraud prevention and security. Stripe's privacy and cookie information additionally applies to the Stripe payment page.
10. Your rights
Subject to the applicable legal requirements, you have the following rights in particular:
right of access under Article 15 GDPR,
right to rectification under Article 16 GDPR,
right to erasure under Article 17 GDPR,
right to restriction of processing under Article 18 GDPR,
right to data portability under Article 20 GDPR,
right to object under Article 21 GDPR, and
right to withdraw consent under Article 7(3) GDPR with effect for the future.
Where processing is based on Article 6(1)(f) GDPR, you may object to that processing at any time on grounds relating to your particular situation.
To exercise your rights, please contact: info@schroeder-friends.de
11. Right to lodge a complaint
Under Article 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for our registered office is:
The Hamburg Commissioner for Data Protection and Freedom of Information
Ludwig-Erhard-Straße 22, 7th floor
20459 Hamburg
Germany
Telephone: +49 40 42854-4040
Website: https://datenschutz-hamburg.de
12. Automated decision-making
We do not make decisions based solely on automated processing within the meaning of Article 22 GDPR that produce legal effects concerning you or similarly significantly affect you.
Stripe may use automated checks for payment processing and fraud prevention. Further information is available in Stripe's Privacy Policy.
13. Updates to this Privacy Policy
We update this Privacy Policy if our website, the services we use or the legal requirements change. The version published on this website at the relevant time applies.
Schröder & Friends Event Consulting GmbH
Hamburger Straße 3, 22083 Hamburg
info@schroeder-friends.de