Privacy Policy

PRIVACY POLICY OF YOUPARTMENTS GMBH

Version: July 6, 2026

Note: This English text is a convenience translation. The legally binding version is the German original ("Datenschutzerklaerung"), available at youpartments.com. In case of any discrepancy, the German version prevails.

1. CONTROLLER

youpartments GmbH, Urbanstrasse 8, 48143 Muenster, Germany

Managing Director: Kilian Fenneberg

Phone: +49 159 01603022 | Email: info@youpartments.com

Competent supervisory authority: State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW), Kavalleriestrasse 2-4, 40213 Duesseldorf, www.ldi.nrw.de

2. PRINCIPLES

We process personal data only insofar as this is necessary for providing our website, performing bookings and stays, communicating with you, or on the basis of statutory obligations - or insofar as you have given your consent. The legal bases are Art. 6(1)(a) (consent), (b) (contract), (c) (legal obligation) and (f) (legitimate interest) GDPR.

3. BOOKING AND STAY

Data processed: name, address, email address, telephone number, booking data (period, apartment, price, fellow travellers), correspondence.

Purposes: conclusion and performance of the accommodation contract, guest support, billing.

Legal basis: Art. 6(1)(b) GDPR.

Processors used:

- Hostaway Oy/Inc. (property management system) - processing also in the USA, see Section 11.

- Microsoft Ireland Operations Ltd. / Microsoft Corporation (Microsoft 365, OneDrive, Azure - hosting of our internal booking and management software) - see Section 11.

When booking via Booking.com or Airbnb, we receive your data from the respective platform; for the processing there, the platform itself is responsible (the platform's own privacy policy).

Storage period: We delete booking and guest data at the latest 5 years after the end of the stay (based on the standard limitation period and the care of returning guests), unless longer statutory retention obligations (in particular Sections 147 AO, 257 HGB: 8 or 10 years for invoice data) exist.

4. REGISTRATION FORM AND IDENTITY VERIFICATION

Upon arrival, we are legally obliged to collect a registration form (Sections 29, 30 German Federal Registration Act, BMG). For this purpose, we have a valid identification document presented and record the details prescribed under registration law. Copies of identification documents are not stored.

Legal basis: Art. 6(1)(c) GDPR in conjunction with Sections 29, 30 BMG.

Storage period: Registration forms are retained for one year pursuant to Section 30(4) BMG and then destroyed.

5. PAYMENT PROCESSING (STRIPE)

Payments are processed via Stripe Payments Europe Ltd. (Ireland) or Stripe Inc. (USA). Your credit card data is collected and stored directly by Stripe; we ourselves do not receive or store complete card data.

Legal basis: Art. 6(1)(b) GDPR. Third-country transfer: see Section 11.

Stripe may review payments as part of its own fraud prevention as an independent controller; details in Stripe's privacy policy.

6. TELEPHONE AI VOICE ASSISTANT AND CALL RECORDING

Our telephone availability is supported by an AI-based voice assistant. At the beginning of each call, you are informed that you are speaking with an AI system; on request, you will be transferred to an employee (transparency pursuant to Art. 50 of Regulation (EU) 2024/1689, "AI Act").

Recording: We record telephone calls only if you expressly consent at the beginning of the call (active "yes" answer). Without consent, the call is not recorded; you can still use our service without restriction.

Data processed: telephone number, call content/audio recording, transcript, date/time, documented consent.

Purposes: recording and handling of your request, quality assurance.

Legal bases: Art. 6(1)(a) GDPR (recording); Art. 6(1)(b) GDPR (handling of the request). You can withdraw your consent at any time with effect for the future (contact: Section 14).

Storage period: Recordings and transcripts are deleted after 90 days, unless they are required for the further performance of the contract.

Processors used:

- ElevenLabs Inc. (USA) - speech processing / speech output

- Anthropic PBC (USA) - language model for request recognition

- OpenAI, L.L.C. / OpenAI Ireland Ltd. (USA/Ireland) - language model for request recognition

Data processing agreements are in place with these providers. Use of your data to train the AI models is contractually excluded. Third-country transfer: see Section 11.

7. COMMUNICATION BY EMAIL, SMS AND WHATSAPP

Email: We use Microsoft 365 (Exchange Online). The content and metadata of your messages are processed to handle your request (Art. 6(1)(b) GDPR).

SMS: For contract- and service-related messages (e.g., check-in information), we send SMS via the infrastructure of our booking system Hostaway; the dispatch is carried out via an SMS provider used by Hostaway, potentially with a US connection. Your mobile number and the message content are processed. Legal basis: Art. 6(1)(b) GDPR (performance of the contract). We send promotional SMS only with your express consent. Third-country transfer: see Section 11.

WhatsApp Business: If you contact us via WhatsApp or wish to use this channel, we process your mobile number and message content via the WhatsApp Business Platform of Meta Platforms Ireland Ltd. In doing so, Meta receives metadata of the communication. Use is voluntary; you can always reach us by email or telephone instead. Legal basis: Art. 6(1)(b) GDPR; with respect to the channel, your implied consent (Art. 6(1)(a) GDPR). Third-country transfer: see Section 11.

8. VIDEO SURVEILLANCE AND NOISE SENSORS

Video surveillance: In common and outdoor areas of our properties (not in the apartments), we use video cameras.

Purposes: protection of property, safety of guests, investigation of criminal offences.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest); the areas are signposted.

Storage: The recordings are stored locally on the recording device (SD card) and automatically overwritten, at the latest after 72 hours, unless they are needed to investigate a specific incident. Remote access is only carried out by authorized employees to clarify an incident.

Noise sensors: Decibel sensors may be installed in apartments. These measure only the sound level and do not record voices or conversations.

9. WEBSITE: HOSTING, COOKIES, ANALYTICS

Hosting: Our website is operated under our domain at Strato AG (Berlin); the booking and website system is provided by Hostaway. When the site is accessed, server log data (IP address, time, page accessed) is processed to provide and secure the website (Art. 6(1)(f) GDPR) and deleted after 7 days.

Consent management (consent banner): To obtain and document your consents, we use CookieYes (CookieYes Limited, Ireland/United Kingdom). In doing so, your IP address (shortened), date/time and your consent status are processed (Art. 6(1)(c) in conjunction with Art. 7(1) GDPR).

Cookies and analytics services: We use technically non-essential cookies and analytics services (currently: Google Analytics) only on the basis of your consent (Section 25(1) TDDDG, Art. 6(1)(a) GDPR). Without your consent, these services do not set cookies and do not create usage profiles (Google Consent Mode); evaluation only takes place after you have given your consent. You can withdraw your consent at any time via the cookie settings.

Google Maps / external content: We embed map services only after consent (Art. 6(1)(a) GDPR).

10. INTERNAL ADMINISTRATION AND CLEANING SCHEDULING

To organize the stays, our administrative staff process guest data in our internal CRM (hosted on Microsoft Azure/OneDrive). Cleaning staff see, in a scheduling app, only the information required for the assignment (guest name, arrival/departure, apartment).

Legal basis: Art. 6(1)(b) and (f) GDPR.

11. TRANSFER OF DATA TO THIRD COUNTRIES (IN PARTICULAR THE USA)

Some of our service providers process data in the USA. We base the transfer on:

- the adequacy decision on the EU-US Data Privacy Framework (DPF) (Implementing Decision (EU) 2023/1795 of July 10, 2023), insofar as the respective provider is actively certified (verification at www.dataprivacyframework.gov), and/or

- the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) with supplementary protective measures.

You can request a copy of the respective safeguards via the contact details in Section 1.

12. FURTHER RECIPIENTS

Where necessary, we transfer data to: tax advisors and accounting (statutory obligations), authorities (e.g., registration authorities, tax administration), lawyers and courts (legal enforcement), insurers (claims). Legal bases: Art. 6(1)(c) and (f) GDPR.

13. STORAGE PERIOD AND DELETION

We delete personal data as soon as the purpose of its processing no longer applies and no statutory retention obligations remain. Overview:

- Booking / guest data (CRM, PMS): 5 years after departure

- Invoice / accounting data: 8-10 years (Section 147 AO, Section 257 HGB)

- Registration forms: 1 year (Section 30(4) BMG)

- Telephone recordings / transcripts: 90 days

- Video recordings: 72 hours, in case of incidents until clarified

- Server logs: 7 days

- WhatsApp / email correspondence: 5 years after departure or last contact

14. YOUR RIGHTS

You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) as well as to object to processing based on Art. 6(1)(f) GDPR (Art. 21). You can withdraw consent given at any time with effect for the future (Art. 7(3) GDPR).

To exercise your rights, an informal message is sufficient - e.g., by email to info@youpartments.com or by telephone.

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular with the LDI NRW (contact: Section 1).

We do not make any decisions based solely on automated processing within the meaning of Art. 22 GDPR.

15. DATA SECURITY

We use technical and organizational measures pursuant to Art. 32 GDPR, including encryption of data transmission (TLS), access restrictions based on the need-to-know principle, two-factor authentication for administrative access, and regular review of our service providers.

16. CHANGES TO THIS PRIVACY POLICY

We adapt this privacy policy when our processing activities or the legal situation change. The version published on our website at the time applies.