Privacy Policy

This is a translation for your convenience. The German version is legally binding.

This privacy policy applies to the website hotel-muehlheim.de and to Hotel-Pension Weller Mühlheim in Mühlheim am Main.

Introduction

As a host – particularly for room reservations, overnight stays, worker accommodation and breakfast services – as well as an operator of this website, we inevitably come into contact with personal data.

In accordance with Article 12 of the General Data Protection Regulation (GDPR), we inform you here transparently, in an easily accessible manner and in as plain language as possible about the purpose, scope and legal basis on which your data is collected and processed. This statement is not limited to data collection via our website but also covers other channels of communication such as email, phone and personal conversations, for example during enquiries, reservations and check-in.

Data controller

The controller responsible for data processing within the meaning of Art. 4 No. 7 GDPR is:

Sandeep Sandhu, Hotel – Pension Weller
Owner: Sandeep Sandhu
Albertstraße 7
63165 Mühlheim am Main
Deutschland
Phone: 06108 60911
Email: muehlheim@hotelweller.de

General information & terms

External links and third-party providers

Our website may contain links to third-party offers – for example to our sister properties, to excursion destinations in the Rhein-Main region, or to map services. This privacy policy expressly does not apply to the processing of personal data by external providers. We recommend reading the respective provider's privacy notice before interacting with their services.

Provision of data by you

In principle, you are not obliged to provide personal data unless there is a statutory or contractual obligation to do so. In certain cases – such as when using our enquiry form or making a room reservation – providing certain data is nevertheless required. Without this information, we may not be able to process your enquiry or provide the requested service.

Personal data – definition

Personal data is any information relating to an identified or identifiable natural person: name, address, phone number or email address, but also indirectly identifying characteristics such as the IP address of your device.

Storage period & security

We inform you in this statement of the respective storage period. Where no specific period is given, we store data only for as long as necessary for the respective purpose or until you exercise your rights.

Specific retention periods:

  • Room enquiries via the form or by email: up to 3 years after the correspondence has ended
  • Reservation and invoice data: 10 years (statutory retention obligations under commercial and tax law)
  • Registration forms pursuant to § 30 Federal Registration Act: 1 year, then destroyed
  • Server log files: generally 7 days
  • Consent decision in the cookie banner: stored locally in your browser, until you change or delete it

Security measures for your data

Electronic data transmission – particularly via the internet – generally involves security risks; complete protection against unauthorised access cannot be guaranteed. However, we implement appropriate technical and organisational measures pursuant to Art. 32 GDPR. A key component is the SSL/TLS encryption of this website, recognisable by the padlock symbol in the browser and the address beginning with "https://".

Legal bases for processing

Sandeep Sandhu, Hotel – Pension Weller processes personal data in order to handle enquiries and reservations, communicate with you, organise your stay, ensure the security of our offerings, and comply with legal obligations.

Basis 1 – Performance of a contract (Art. 6(1)(b) GDPR)

Processing takes place to fulfil an accommodation contract or to carry out pre-contractual measures at your request – such as room enquiries, reservation confirmations, check-in and billing.

Basis 2 – Legal obligation (Art. 6(1)(c) GDPR)

Processing is necessary to comply with legal obligations, in particular the registration duty under the Federal Registration Act as well as retention obligations under commercial and tax law.

Basis 3 – Legitimate interests (Art. 6(1)(f) GDPR)

Processing serves the legitimate interests of our business, such as IT security, stable operation of the website and efficient guest communication, provided your interests do not override these.

Basis 4 – Consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG)

You have given us your consent, for example to load the external map view or to store non-essential entries in your browser.

Your rights

You have the right to control your personal data stored with us. To exercise any of the following rights, an informal message to muehlheim@hotelweller.de is sufficient.

Please note: A request or objection may be refused if processing remains permissible:

  • to fulfil legal obligations (Art. 6(1)(c) GDPR)
  • to protect vital interests (Art. 6(1)(d) GDPR)
  • to perform a task carried out in the public interest (Art. 6(1)(e) GDPR)
  • or to assert, exercise or defend legal claims

Withdrawal of your consent (Art. 7(3) GDPR)

You may withdraw any consent given at any time without giving reasons, with effect for the future – you can change your cookie selection here: .

Right to access, rectification and erasure (Art. 15–17 GDPR)

You have the right to obtain free information about the data we hold about you, its origin, the purpose for which it is processed and whether it has been transferred to third parties – as well as to have inaccurate data corrected and to have it erased, provided no statutory retention obligations apply.

Right to restriction of processing (Art. 18 GDPR)

In certain cases you may request the restriction of processing, for example if the accuracy of the data is disputed or you have objected to the processing.

Right to data portability (Art. 20 GDPR)

On request, we will provide your data in a structured, commonly used and machine-readable format, provided the processing is based on consent or a contract.

Right to object (Art. 21 GDPR)

You may object at any time, with effect for the future, to processing that is based on legitimate interests.

Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)

If you believe that we are not processing your data in compliance with data protection law, you may lodge a complaint with the competent supervisory authority at any time.

Competent supervisory authority:

Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Gustav-Stresemann-Ring 1, 65189 Wiesbaden

Data transfer to third parties

To provide our services, it may be necessary to pass on personal data to service providers acting on our behalf – for example our hosting provider, email delivery service, or tax and accounting advisors. Disclosure takes place only to the extent necessary and not for third-party advertising purposes. Your data is not passed on to booking portals in the case of a direct enquiry via this website.

Data transfer to third countries

For some online services, we rely on providers that may also process data outside the European Union. In these countries, a lower level of data protection may apply than within the EU. In such cases, transfers are based on EU standard contractual clauses or the EU-US Data Privacy Framework.

Hosting, website & email

To provide this website and to communicate with guests and prospective guests, we operate our online offering, based on Art. 6(1)(b) and (f) GDPR, via an external hosting provider: Lovable (Hosting- und Auslieferungsdienstleister der Website). A data processing agreement pursuant to Art. 28 GDPR is in place with the provider.

Enquiry form and email communication

Via the enquiry form ("Check availability") or by email, you can enquire about rooms without obligation. In doing so, we process your name, email address, optionally your phone number, desired travel period, room preference, number of guests and your message. Processing takes place pursuant to Art. 6(1)(b) GDPR to handle your enquiry, or Art. 6(1)(f) GDPR for efficient guest communication. Your enquiry is sent to muehlheim@hotelweller.de as well as, in copy, to our central reservations team.

For the technical delivery of these emails we use the service provider Resend (Resend, Inc., USA) as a processor pursuant to Art. 28 GDPR. Transfer to the USA is based on EU standard contractual clauses or the EU-US Data Privacy Framework.

Server log files

The provider of these pages automatically collects and stores information in server log files, which your browser transmits:

  • Browser type and version
  • Operating system used
  • Referrer URL
  • Hostname of the accessing computer
  • Time of the server request
  • IP address

This data is not merged with other data sources. The legal basis is Art. 6(1)(f) GDPR.

Cookies & similar technologies

The first time you visit this website, you decide for yourself via a cookie banner whether, beyond the technically necessary entries, external content may be loaded. We do not use any analytics, advertising or social media cookies. You can change your decision at any time: .

Cookie settings in the browser

You can restrict cookies and local storage entries in your browser at any time:

  • Safari: Settings » Privacy » Block cookies
  • Google Chrome: Settings » Privacy and security » Cookies and other site data
  • Firefox: Settings » Privacy & Security » Cookies and Site Data

Please note that individual functions of the website may only be available to a limited extent after disabling them.

Categories of entries used

Category 1 – Necessary (always active)

These entries are required for the operation of the website, for example to store your consent decision. They cannot be disabled.

NameTypePurposeRetention period
hotel-consentlocalStoragestores your consent decisionuntil you change or delete it

Category 2 – External media (only with your consent)

The map view on the "Getting here & surroundings" page is loaded from OpenStreetMap. Only after you consent does your browser establish a connection to OpenStreetMap, transmitting your IP address in the process. Nothing is loaded without your consent.

Category 3 – Analytics and marketing (not used)

We do not use any analytics tools, conversion tracking or advertising networks. No automated decision-making, including profiling under Art. 22 GDPR, takes place.

OpenStreetMap map service

For the directions map we use OpenStreetMap (OpenStreetMap Foundation, St John's Innovation Centre, Cowley Road, Cambridge CB4 0WS, United Kingdom). The map is only loaded after you click. The legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG), which you may withdraw at any time.

Fonts

For a consistent appearance, fonts are loaded from Google Fonts (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland); in doing so, your IP address is transmitted to Google. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a consistent, fast-loading presentation).

Reservation, stay and registration obligation

If a reservation is made, we process the data necessary to perform the contract: name, address, contact details, length of stay, room category, booked services and payment data (Art. 6(1)(b) GDPR). In addition, we are required pursuant to §§ 29 f. Federal Registration Act to record a registration form upon arrival and to retain it for one year (Art. 6(1)(c) GDPR). Registration forms are subsequently destroyed in a data-protection-compliant manner.

Data collection by phone & in person

You may contact us by phone or in person – for example at reception or during check-in. In this context, based on Art. 6(1)(b) and (f) GDPR, we process the contact details you provide as well as information communicated during the conversation, in order to process your enquiry and to prepare or provide contractual services. Phone calls are not recorded.

Questions about data protection?

If you have questions about this privacy policy or would like to know how we handle your data, you can reach us at:

Email: muehlheim@hotelweller.de
Phone: 06108 60911

We generally respond to data protection enquiries within five business days.

Last updated: 2026.