Privacy policy.
The Haus — Portugal Alegria · Santa Bárbara I · Santa Bárbara II — Lisboa
Versão 2.0 · Em vigor a partir de 3 de agosto de 2026Substitui integralmente a versão anterior.
1. ENQUADRAMENTO
A presente Política descreve o tratamento de dados pessoais realizado pela The Haus em Portugal, ao abrigo do Regulamento (UE) 2016/679 (RGPD) e da Lei n.º 58/2019, de 8 de agosto, que assegura a sua execução na ordem jurídica nacional.
Aplica-se a hóspedes, acompanhantes, visitantes, contactos comerciais e utilizadores do sítio www.the-haus.co, no âmbito das unidades de alojamento situadas em Lisboa.
Esta Política é complementada pelos Termos e Condições de Reserva, pelo Regulamento Interno da Unidade e pela Política de Cookies. Em matéria de proteção de dados prevalece a presente Política.
Nota: as unidades de Nuremberga (The Haus KAI e The Haus HANS) são exploradas por uma entidade distinta, sujeita a legislação alemã, e regem-se por política própria disponível em www.the-haus.co/datenschutz.
2. RESPONSÁVEL PELO TRATAMENTO
Short Conclusion — Mediação e Gestão Imobiliária, Lda. Rua Domingos Sequeira, 27, Lisboa, Portugal NIPC: [inserir] Registo Nacional de Alojamento Local (RNAL): [inserir número por unidade] Correio eletrónico: info@the-haus.co Contacto para proteção de dados: privacidade@the-haus.co
Encarregado de Proteção de Dados (EPD): não foi designado, por não se verificarem os pressupostos do artigo 37.º do RGPD nem do artigo 12.º da Lei n.º 58/2019. Esta avaliação é revista anualmente e, caso se altere, a presente Política será atualizada.
3. CATEGORIAS DE DADOS TRATADOS
| Categoria | Exemplos |
|---|---|
| Identificação | nome completo, data de nascimento, nacionalidade, morada, tipo e número de documento de identificação ou passaporte, país de residência, assinatura |
| Contacto | endereço de correio eletrónico, telefone |
| Reserva | número de reserva, unidade e tipologia, datas de entrada e saída, número e identificação dos acompanhantes, canal de reserva, preferências e pedidos especiais |
| Pagamento e faturação | token de cartão, titular, quatro últimos dígitos, validade, morada de faturação, estado do pagamento, pré-autorizações, débitos, reembolsos, NIF para efeitos de fatura |
| Comunicações | mensagens de correio eletrónico, WhatsApp e chat, pedidos ao serviço de apoio, avaliações |
| Acesso e permanência | emissão e utilização de chaves digitais, cartões e códigos, registos da fechadura eletrónica |
| Incidentes e danos | ver secção 8 |
| Dados técnicos | endereço IP, tipo de navegador, identificadores de dispositivo, data e hora de acesso, URL de origem |
Categorias especiais de dados (artigo 9.º do RGPD) apenas são tratadas quando o próprio titular as comunica — por exemplo, necessidades de acessibilidade ou alergias alimentares — com fundamento no seu consentimento explícito (artigo 9.º, n.º 2, alínea a)), ou quando sejam estritamente necessárias à declaração, exercício ou defesa de um direito em processo (artigo 9.º, n.º 2, alínea f)).
Menores: o contrato é celebrado exclusivamente com maiores de 18 anos. Os dados de menores acompanhantes são tratados na medida estritamente necessária ao cumprimento das obrigações de alojamento e comunicação legal, sob responsabilidade do adulto que efetua a reserva.
4. FINALIDADES E FUNDAMENTOS DE LICITUDE
| Finalidade | Fundamento |
|---|---|
| Celebração e execução do contrato de alojamento: reserva, check-in, atribuição de acesso, prestação do serviço, faturação | Art. 6.º, n.º 1, al. b) RGPD |
| Comunicação de boletins de alojamento de cidadãos estrangeiros através do sistema SIBA | Art. 6.º, n.º 1, al. c) RGPD, em conjugação com os artigos 15.º a 17.º da Lei n.º 23/2007, de 4 de julho, e o Decreto Regulamentar n.º 84/2007 |
| Emissão, comunicação e conservação de faturas e documentos fiscais; comunicação à Autoridade Tributária; liquidação e entrega da taxa municipal turística de dormida | Art. 6.º, n.º 1, al. c) RGPD (CIVA, CIRC, regulamentos municipais) |
| Livro de Reclamações Eletrónico e tratamento de reclamações | Art. 6.º, n.º 1, al. c) RGPD (Decreto-Lei n.º 156/2005) |
| Comunicação de serviço antes, durante e após a estadia | Art. 6.º, n.º 1, al. b) RGPD |
| Comunicações promocionais e newsletter | Art. 6.º, n.º 1, al. a) RGPD (consentimento); para clientes, artigo 13.º-A da Lei n.º 41/2004 |
| Documentação de danos e de incumprimentos do Regulamento Interno; apuramento e cobrança dos valores devidos; débito no cartão | Art. 6.º, n.º 1, al. b) e al. f) RGPD — ver secção 8 |
| Prevenção de fraude, verificação de meios de pagamento, prevenção de incumprimento | Art. 6.º, n.º 1, al. f) RGPD |
| Segurança de pessoas e bens nas unidades | Art. 6.º, n.º 1, al. f) RGPD |
| Melhoria do serviço, estatística e análise do sítio | Art. 6.º, n.º 1, al. a) RGPD quanto a cookies não essenciais; al. f) nos restantes casos |
Os interesses legítimos invocados são: a correta execução da estadia, a segurança das instalações, dos hóspedes, dos vizinhos e dos colaboradores, a proteção do património da empresa e a declaração, exercício e defesa de direitos.
5. COMUNICAÇÃO DE BOLETINS DE ALOJAMENTO (SIBA)
5.1 A The Haus está legalmente obrigada a comunicar às autoridades competentes a entrada e a saída de cidadãos estrangeiros, através do Sistema de Informação de Boletins de Alojamento (SIBA), atualmente sob a alçada da AIMA — Agência para a Integração, Migrações e Asilo, sucessora do SEF.
5.2 A comunicação é efetuada no prazo de três dias úteis a contar da entrada do hóspede e inclui nome, data de nascimento, nacionalidade, tipo e número do documento, país de residência e datas de entrada e saída.
5.3 Esta comunicação não depende de consentimento e não pode ser recusada pelo hóspede. A recusa de apresentação de documento de identificação válido impede a formalização do alojamento.
5.4 A cópia do documento de identificação é recolhida apenas quando necessária à verificação e ao cumprimento desta obrigação e é conservada nos termos da secção 9.
6. DADOS DE PAGAMENTO E AUTORIZAÇÃO DE DÉBITO
6.1 Os dados de cartão são tratados exclusivamente através de prestadores de serviços de pagamento certificados PCI-DSS e conservados sob forma tokenizada. O número completo do cartão e o código de segurança (CVC/CVV) não são acessíveis nem armazenados pela The Haus.
6.2 A The Haus pode exigir, verificar e pré-autorizar um cartão de crédito válido como garantia de pagamento, bem como exigir caução nos termos dos Termos e Condições.
6.3 Ao efetuar a reserva e ao aceitar os Termos e Condições, o hóspede autoriza expressamente o débito do cartão indicado relativamente ao preço do alojamento, serviços adicionais, taxas turísticas, encargos de cancelamento e não comparência, bem como aos montantes previstos na secção 8 e na cláusula correspondente dos Termos e Condições.
6.4 Os débitos posteriores à saída são processados como operações iniciadas pelo comerciante, ao abrigo da autorização prestada no momento da reserva. Cada débito é acompanhado de fatura ou documento equivalente, com indicação do facto que lhe deu origem e do respetivo montante.
7. DESTINATÁRIOS E SUBCONTRATANTES
Os dados são comunicados apenas na medida do necessário, a:
- Sistema de gestão hoteleira (PMS) e motor de reservas
- Prestadores de serviços de pagamento, adquirentes e redes de cartões
- Plataformas de reserva em linha (OTA) e gestor de canais
- Plataformas de comunicação com o hóspede e de check-in
- Fornecedores do sistema de controlo de acessos e fechaduras
- Prestadores de serviços informáticos, alojamento de dados, análise e marketing
- Empresas de limpeza, manutenção e segurança — apenas os dados indispensáveis
- Contabilistas certificados, revisores, advogados, empresas de cobrança e seguradoras
- Autoridades públicas, tribunais, AIMA, PSP/GNR, Autoridade Tributária e municípios, no cumprimento de obrigação legal ou para defesa de direitos
Com todos os subcontratantes foram celebrados contratos nos termos do artigo 28.º do RGPD. A lista atualizada de subcontratantes é disponibilizada mediante pedido para privacidade@the-haus.co.
8. DANOS, INCUMPRIMENTOS DO REGULAMENTO INTERNO E DÉBITO NO CARTÃO
Esta secção descreve o tratamento de dados em caso de danos ou incidentes. O direito da The Haus a exigir o pagamento resulta dos Termos e Condições de Reserva e da lei civil, e não da presente Política.
8.1 Situações abrangidas
Sempre que, durante ou em conexão com uma estadia, ocorram:
- danificação, destruição ou desaparecimento de mobiliário, equipamento, elementos do imóvel ou partes comuns;
- sujidade anómala que exceda a limpeza corrente, incluindo situações que exijam limpeza especializada, descontaminação ou substituição de têxteis e colchões;
- fumar em áreas onde tal é proibido, ou manipulação de detetores de fumo e equipamentos de segurança;
- festas ou eventos não autorizados, ocupação superior à declarada, ou cedência de credenciais de acesso a terceiros;
- ruído, perturbação do descanso, queixas de vizinhos, do condomínio ou de autoridades;
- agressões, atos de violência, ou intervenção de forças de segurança, bombeiros ou emergência médica;
- saída para além da hora contratada ou perda de meios de acesso;
a The Haus trata os dados necessários ao apuramento, quantificação e cobrança dos valores devidos.
8.2 Dados tratados
- identificação e contactos do titular da reserva e, quando conhecidos, dos acompanhantes;
- registo fotográfico e videográfico dos danos e das áreas afetadas, realizado após a saída ou após a deteção do incidente;
- autos de ocorrência, relatórios de limpeza, de manutenção e de técnicos externos;
- orçamentos, faturas de reparação, substituição e limpeza, e valor das noites em que a unidade fica indisponível;
- registos de acesso da fechadura eletrónica relativos ao período do incidente;
- reclamações de terceiros, participações e correspondência com autoridades, condomínio e seguradoras;
- dados de pagamento e de débito do cartão associado à reserva.
O registo fotográfico limita-se ao dano e às áreas afetadas. Pessoas apenas são captadas quando inevitável. Os bens pessoais eventualmente deixados na unidade não são revistados nem documentados para além do estritamente necessário ao apuramento do dano.
8.3 Fundamentos de licitude
- Artigo 6.º, n.º 1, alínea b) do RGPD — execução do contrato de alojamento, incluindo os encargos contratualmente previstos e a autorização de débito prestada no momento da reserva.
- Artigo 6.º, n.º 1, alínea f) do RGPD — interesse legítimo na preservação de prova, na quantificação do prejuízo, na proteção do património e na segurança de hóspedes, vizinhos e colaboradores, bem como na declaração, exercício e defesa de direitos, ao abrigo dos artigos 483.º, 798.º, 799.º, 562.º e 566.º do Código Civil.
- Artigo 6.º, n.º 1, alínea c) do RGPD — quando exista dever legal de participação ou de prestação de informação.
- Artigo 9.º, n.º 2, alínea f) do RGPD — quando, excecionalmente, o incidente envolva dados de categoria especial (por exemplo, indícios de lesões corporais num episódio de violência). Tais dados são tratados apenas para efeitos de exercício ou defesa de direitos e de resposta a solicitações de autoridades.
8.4 Procedimento de cobrança
Com fundamento na autorização referida em 6.3, a The Haus procede nos seguintes termos:
- Comunicação prévia por escrito ao hóspede, com descrição do facto, indicação do montante e da respetiva base de cálculo, acompanhada dos elementos de prova disponíveis (fotografias, orçamentos, faturas).
- Concessão de prazo para pronúncia. Quando o valor não seja ainda determinável, o hóspede é informado da existência do dano e a quantificação é comunicada posteriormente.
- Débito no cartão dos montantes devidos, com emissão de fatura.
- Os montantes fixos previstos nos Termos e Condições correspondem a uma estimativa razoável do prejuízo típico e são sempre imputados ao valor do prejuízo efetivo, não se acumulando com este. O hóspede pode demonstrar que o prejuízo não ocorreu ou foi inferior; a The Haus pode demonstrar prejuízo superior e exigir a diferença.
- Havendo pluralidade de hóspedes na mesma reserva, a responsabilidade é solidária (artigos 512.º e 513.º do Código Civil).
- O hóspede pode contestar o débito. Os seus direitos perante o emitente do cartão, o Livro de Reclamações Eletrónico e as vias judiciais mantêm-se integralmente.
8.5 Conservação
Os dados de incidente e dano são conservados pelo período necessário ao apuramento e cobrança e, em regra, até três anos após o encerramento do processo. Existindo litígio, processo criminal, participação a seguradora ou execução pendente, a conservação prolonga-se até ao respetivo trânsito em julgado ou encerramento. As fotografias são eliminadas logo que o processo se encontre concluído.
8.6 Direito de oposição
Quanto aos tratamentos fundados no artigo 6.º, n.º 1, alínea f), o titular pode opor-se nos termos do artigo 21.º do RGPD (secção 11). A The Haus avaliará a existência de razões imperiosas e legítimas que prevaleçam; tal verifica-se, em regra, quando o tratamento se destine à declaração, exercício ou defesa de direitos.
9. PRAZOS DE CONSERVAÇÃO
| Categoria | Prazo |
|---|---|
| Boletins de alojamento e cópias de documento de identificação | período necessário ao cumprimento e comprovação da obrigação legal, até 5 anos |
| Faturas, registos contabilísticos e documentos de suporte | 10 anos civis (artigo 52.º do CIVA) |
| Dados de reserva e perfil de hóspede | até 3 anos após a estadia, salvo obrigação legal mais longa |
| Comunicações com o serviço de apoio | 3 anos após o último contacto |
| Reclamações e Livro de Reclamações Eletrónico | 3 anos |
| Documentação de incidentes e danos | ver secção 8.5 |
| Token de cartão | até à extinção das obrigações da estadia, no máximo 13 meses após a saída |
| Registos da fechadura eletrónica | 90 dias, prorrogáveis em caso de incidente |
| Consentimentos de marketing | até revogação; prova da revogação por 3 anos |
| Registos técnicos do sítio (logs) | 7 dias, salvo relevância para segurança |
Findos os prazos, os dados são eliminados ou anonimizados de forma irreversível.
10. TRANSFERÊNCIAS INTERNACIONAIS
As transferências para fora do Espaço Económico Europeu ocorrem apenas ao abrigo de decisão de adequação da Comissão Europeia (artigo 45.º do RGPD) ou de Cláusulas Contratuais-Tipo aprovadas pela Comissão (artigo 46.º, n.º 2, alínea c)), acompanhadas de medidas complementares. Cópia das garantias é disponibilizada mediante pedido.
11. DIREITOS DOS TITULARES
Assistem ao titular os direitos de acesso (art. 15.º), retificação (art. 16.º), apagamento (art. 17.º), limitação do tratamento (art. 18.º), portabilidade (art. 20.º), oposição (art. 21.º) e de retirada do consentimento a todo o tempo, sem afetar a licitude do tratamento anteriormente efetuado (art. 7.º, n.º 3).
O exercício é gratuito e efetua-se por mensagem para privacidade@the-haus.co. Pode ser solicitada informação adicional para confirmação da identidade. A resposta é prestada no prazo de um mês, prorrogável até dois meses em casos complexos.
Reclamação à autoridade de controlo: Comissão Nacional de Proteção de Dados (CNPD) Av. D. Carlos I, 134, 1.º, 1200-651 Lisboa geral@cnpd.pt · www.cnpd.pt
12. DIREITO DE OPOSIÇÃO
O titular tem o direito de se opor, a todo o tempo e por motivos relacionados com a sua situação particular, ao tratamento de dados que se fundamente no artigo 6.º, n.º 1, alínea f) do RGPD. Nesse caso, o tratamento cessa, salvo se existirem razões imperiosas e legítimas que prevaleçam sobre os interesses, direitos e liberdades do titular, ou se o tratamento se destinar à declaração, exercício ou defesa de um direito.
A oposição ao tratamento para efeitos de marketing direto pode ser exercida a todo o tempo, sem necessidade de fundamentação.
13. SEGURANÇA
São adotadas medidas técnicas e organizativas adequadas nos termos do artigo 32.º do RGPD: cifragem TLS/HTTPS, armazenamento cifrado, controlo de acessos por perfil, autenticação de dois fatores nos acessos de colaboradores, registo de acessos, dever de confidencialidade e formação dos colaboradores, revisão periódica das medidas e utilização exclusiva de prestadores de pagamento certificados PCI-DSS.
Em caso de violação de dados pessoais suscetível de resultar em risco para os direitos e liberdades dos titulares, a CNPD é notificada no prazo de 72 horas (artigo 33.º) e, verificando-se risco elevado, os titulares são informados (artigo 34.º).
14. COOKIES
A utilização de cookies e tecnologias equivalentes rege-se pela Lei n.º 41/2004, de 18 de agosto. Os cookies não estritamente necessários apenas são instalados mediante consentimento prévio, revogável a qualquer momento através das definições de cookies. Ver a Política de Cookies.
15. RECLAMAÇÕES E RESOLUÇÃO DE LITÍGIOS
15.1 Reclamações podem ser apresentadas para info@the-haus.co ou através do Livro de Reclamações Eletrónico em www.livroreclamacoes.pt, nos termos do Decreto-Lei n.º 156/2005.
15.2 Nos termos do artigo 18.º da Lei n.º 144/2015, de 8 de setembro, informa-se que, em caso de litígio de consumo, o consumidor pode recorrer à entidade de resolução alternativa de litígios territorialmente competente — o Centro de Arbitragem de Conflitos de Consumo de Lisboa (CACCL), www.centroarbitragemlisboa.pt — ou ao Centro Nacional de Informação e Arbitragem de Conflitos de Consumo (CNIACC), www.cniacc.pt. A The Haus não aderiu previamente a qualquer entidade de resolução alternativa de litígios, salvo nos casos em que a lei imponha a arbitragem necessária.
16. SÍTIOS DE TERCEIROS
A The Haus não responde pelos conteúdos nem pelas práticas de privacidade de sítios de terceiros, designadamente das plataformas de reserva em linha. Nas reservas efetuadas através de OTA, a plataforma é responsável autónoma pelos dados que recolhe diretamente.
17. ALTERAÇÕES
A presente Política é atualizada sempre que se alterem os tratamentos ou o enquadramento legal. Prevalece a versão publicada em www.the-haus.co. As alterações substanciais são comunicadas por escrito aos hóspedes com reserva ativa.
18. CONTACTOS
Proteção de dados: privacidade@the-haus.co Geral: info@the-haus.co Morada: Short Conclusion — Mediação e Gestão Imobiliária, Lda., Rua Domingos Sequeira, 27, Lisboa, Portugal
Esta Política está disponível em português e em inglês. Em caso de divergência, prevalece a versão portuguesa.
The Haus — Portugal Alegria · Santa Bárbara I · Santa Bárbara II — Lisbon
Version 2.0 · Effective 3 August 2026This version supersedes the previous version in its entirety.
1. SCOPE
This Policy describes the processing of personal data carried out by The Haus in Portugal, under Regulation (EU) 2016/679 (GDPR) and Lei n.º 58/2019, de 8 de agosto (Portuguese Data Protection Implementation Act), which ensures its execution within the national legal order.
It applies to guests, accompanying persons, visitors, business contacts and users of the website www.the-haus.co, in connection with the accommodation units located in Lisbon.
This Policy is supplemented by the Booking Terms and Conditions, the House Rules of the Unit and the Cookie Policy. In data protection matters, this Policy prevails.
Note: the Nuremberg units (The Haus KAI and The Haus HANS) are operated by a separate entity, subject to German law, and are governed by their own policy available at www.the-haus.co/datenschutz.
2. DATA CONTROLLER
Short Conclusion — Mediação e Gestão Imobiliária, Lda. Rua Domingos Sequeira, 27, Lisbon, Portugal NIPC (corporate tax number): [to be inserted] Registo Nacional de Alojamento Local (RNAL) (National Register of Local Accommodation): [to be inserted, per unit] Email: info@the-haus.co Data protection contact: privacidade@the-haus.co
Data Protection Officer (DPO): none has been appointed, as the conditions set out in Article 37 GDPR and in artigo 12.º da Lei n.º 58/2019 are not met. This assessment is reviewed annually and, should it change, this Policy will be updated.
3. CATEGORIES OF DATA PROCESSED
| Category | Examples |
|---|---|
| Identification | full name, date of birth, nationality, address, type and number of identification document or passport, country of residence, signature |
| Contact | email address, telephone number |
| Booking | booking number, unit and unit type, arrival and departure dates, number and identification of accompanying persons, booking channel, preferences and special requests |
| Payment and invoicing | card token, cardholder, last four digits, expiry date, billing address, payment status, pre-authorisations, charges, refunds, NIF (Portuguese tax number) for invoicing purposes |
| Communications | email, WhatsApp and chat messages, support requests, reviews |
| Access and stay | issuance and use of digital keys, cards and codes, electronic lock records |
| Incidents and damage | see section 8 |
| Technical data | IP address, browser type, device identifiers, date and time of access, referring URL |
Special categories of data (Article 9 GDPR) are processed only where the data subject discloses them — for example, accessibility needs or food allergies — on the basis of their explicit consent (Article 9(2)(a)), or where they are strictly necessary for the establishment, exercise or defence of legal claims (Article 9(2)(f)).
Minors: the contract is concluded exclusively with persons aged 18 or over. Data of accompanying minors is processed only to the extent strictly necessary to comply with accommodation and statutory reporting obligations, under the responsibility of the adult making the booking.
4. PURPOSES AND LEGAL BASES
| Purpose | Legal basis |
|---|---|
| Conclusion and performance of the accommodation contract: booking, check-in, granting of access, provision of the service, invoicing | Article 6(1)(b) GDPR |
| Reporting of accommodation bulletins for foreign nationals through the SIBA system | Article 6(1)(c) GDPR, in conjunction with artigos 15.º a 17.º da Lei n.º 23/2007, de 4 de julho (Portuguese Foreigners Act), and Decreto Regulamentar n.º 84/2007 (implementing regulation) |
| Issuance, reporting and retention of invoices and tax documents; reporting to the Autoridade Tributária (Portuguese Tax Authority); assessment and remittance of the municipal tourist overnight-stay tax | Article 6(1)(c) GDPR (CIVA (Portuguese VAT Code), CIRC (Portuguese Corporate Income Tax Code), municipal regulations) |
| Livro de Reclamações Eletrónico (Electronic Complaints Book) and handling of complaints | Article 6(1)(c) GDPR (Decreto-Lei n.º 156/2005 (Complaints Book)) |
| Service communications before, during and after the stay | Article 6(1)(b) GDPR |
| Promotional communications and newsletter | Article 6(1)(a) GDPR (consent); for existing customers, artigo 13.º-A da Lei n.º 41/2004 (Portuguese Electronic Communications Privacy Act) |
| Documentation of damage and of breaches of the House Rules; assessment and collection of the amounts due; charging of the card | Article 6(1)(b) and (f) GDPR — see section 8 |
| Fraud prevention, verification of means of payment, prevention of default | Article 6(1)(f) GDPR |
| Safety of persons and property at the units | Article 6(1)(f) GDPR |
| Service improvement, statistics and website analytics | Article 6(1)(a) GDPR as regards non-essential cookies; (f) in all other cases |
The legitimate interests relied upon are: the proper performance of the stay, the safety of the premises, guests, neighbours and staff, the protection of the company's assets, and the establishment, exercise and defence of legal claims.
5. REPORTING OF ACCOMMODATION BULLETINS (SIBA)
5.1 The Haus is under a legal obligation to report to the competent authorities the arrival and departure of foreign nationals, through the Sistema de Informação de Boletins de Alojamento (SIBA) (Accommodation Bulletin Information System), currently under the remit of AIMA — Agência para a Integração, Migrações e Asilo, successor to SEF.
5.2 The report is made within three working days of the guest's arrival and includes name, date of birth, nationality, document type and number, country of residence, and arrival and departure dates.
5.3 This reporting does not depend on consent and cannot be refused by the guest. Refusal to present a valid identification document prevents the accommodation from being formalised.
5.4 A copy of the identification document is collected only where necessary for the verification and fulfilment of this obligation and is retained in accordance with section 9.
6. PAYMENT DATA AND DIRECT DEBIT AUTHORISATION
6.1 Card data is processed exclusively through PCI-DSS certified payment service providers and stored in tokenised form. The full card number and the security code (CVC/CVV) are neither accessible to nor stored by The Haus.
6.2 The Haus may require, verify and pre-authorise a valid credit card as a payment guarantee, and may require a security deposit under the Terms and Conditions.
6.3 By making the booking and accepting the Terms and Conditions, the guest expressly authorises the charging of the card provided in respect of the accommodation price, additional services, tourist taxes, cancellation and no-show charges, as well as the amounts set out in section 8 and in the corresponding clause of the Terms and Conditions.
6.4 Charges made after departure are processed as merchant-initiated transactions, under the authorisation granted at the time of booking. Each charge is accompanied by an invoice or equivalent document, stating the event giving rise to it and the corresponding amount.
7. RECIPIENTS AND PROCESSORS
Data is disclosed only to the extent necessary, to:
- Property management system (PMS) and booking engine
- Payment service providers, acquirers and card networks
- Online travel agencies (OTAs) and channel manager
- Guest communication and check-in platforms
- Suppliers of the access control and lock systems
- IT service providers, data hosting, analytics and marketing providers
- Cleaning, maintenance and security companies — only the indispensable data
- Certified accountants, auditors, lawyers, debt collection companies and insurers
- Public authorities, courts, AIMA, PSP/GNR, the Autoridade Tributária and municipalities, in compliance with a legal obligation or for the defence of legal claims
Contracts pursuant to Article 28 GDPR have been concluded with all processors. An up-to-date list of processors is made available upon request to privacidade@the-haus.co.
8. DAMAGE, BREACHES OF THE HOUSE RULES AND CARD CHARGES
This section describes the processing of data in the event of damage or incidents. The Haus's right to demand payment derives from the Booking Terms and Conditions and from civil law, and not from this Policy.
8.1 Situations covered
Whenever, during or in connection with a stay, there occurs:
- damage to, destruction of or disappearance of furniture, equipment, elements of the property or common areas;
- abnormal soiling exceeding ordinary cleaning, including situations requiring specialised cleaning, decontamination or replacement of textiles and mattresses;
- smoking in areas where it is prohibited, or tampering with smoke detectors and safety equipment;
- unauthorised parties or events, occupancy exceeding that declared, or transfer of access credentials to third parties;
- noise, disturbance of rest, complaints from neighbours, the condominium or the authorities;
- assaults, acts of violence, or intervention by law enforcement, the fire brigade or emergency medical services;
- departure beyond the contracted time or loss of means of access;
The Haus processes the data necessary for the assessment, quantification and collection of the amounts due.
8.2 Data processed
- identification and contact details of the booking holder and, where known, of the accompanying persons;
- photographic and video records of the damage and of the affected areas, taken after departure or after detection of the incident;
- incident reports, cleaning and maintenance reports and reports by external technicians;
- estimates, invoices for repair, replacement and cleaning, and the value of the nights during which the unit is unavailable;
- electronic lock access records relating to the period of the incident;
- third-party complaints, official reports and correspondence with authorities, the condominium and insurers;
- payment and card charge data associated with the booking.
Photographic records are limited to the damage and the affected areas. Persons are captured only where unavoidable. Personal belongings possibly left in the unit are neither searched nor documented beyond what is strictly necessary to assess the damage.
8.3 Legal bases
- Article 6(1)(b) GDPR — performance of the accommodation contract, including the contractually stipulated charges and the direct debit authorisation granted at the time of booking.
- Article 6(1)(f) GDPR — legitimate interest in preserving evidence, quantifying the loss, protecting assets and ensuring the safety of guests, neighbours and staff, as well as in the establishment, exercise and defence of legal claims, under Articles 483, 798, 799, 562 and 566 of the Portuguese Civil Code.
- Article 6(1)(c) GDPR — where a legal duty to report or to provide information exists.
- Article 9(2)(f) GDPR — where, exceptionally, the incident involves special category data (for example, indications of bodily injury in an episode of violence). Such data is processed solely for the purposes of the exercise or defence of legal claims and of responding to requests from the authorities.
8.4 Collection procedure
On the basis of the authorisation referred to in 6.3, The Haus proceeds as follows:
- Prior written notice to the guest, describing the event, stating the amount and the corresponding basis of calculation, accompanied by the available evidence (photographs, estimates, invoices).
- Granting of a period to respond. Where the amount is not yet determinable, the guest is informed of the existence of the damage and the quantification is communicated subsequently.
- Charging of the card for the amounts due, with the issuance of an invoice.
- The fixed amounts set out in the Terms and Conditions correspond to a reasonable estimate of the typical loss and are always set off against the amount of the actual loss, and do not accumulate with it. The guest may demonstrate that the loss did not occur or was lower; The Haus may demonstrate a higher loss and claim the difference.
- Where there are several guests under the same booking, liability is joint and several (Articles 512 and 513 of the Portuguese Civil Code).
- The guest may contest the charge. Their rights vis-à-vis the card issuer, the Livro de Reclamações Eletrónico and the judicial remedies remain fully unaffected.
8.5 Retention
Incident and damage data is retained for the period necessary for assessment and collection and, as a rule, for up to three years after the closure of the matter. Where there is litigation, criminal proceedings, an insurance claim or pending enforcement, retention is extended until the respective final and unappealable decision or closure. Photographs are deleted as soon as the matter is concluded.
8.6 Right to object
As regards processing based on Article 6(1)(f), the data subject may object under Article 21 GDPR (section 11). The Haus will assess whether compelling legitimate grounds override the objection; this is generally the case where the processing serves the establishment, exercise or defence of legal claims.
9. RETENTION PERIODS
| Category | Period |
|---|---|
| Accommodation bulletins and copies of identification documents | the period necessary to comply with and evidence the legal obligation, up to 5 years |
| Invoices, accounting records and supporting documents | 10 calendar years (artigo 52.º do CIVA (Portuguese VAT Code)) |
| Booking data and guest profile | up to 3 years after the stay, unless a longer legal obligation applies |
| Communications with the support service | 3 years after the last contact |
| Complaints and Livro de Reclamações Eletrónico | 3 years |
| Incident and damage documentation | see section 8.5 |
| Card token | until the obligations arising from the stay are discharged, at most 13 months after departure |
| Electronic lock records | 90 days, extendable in the event of an incident |
| Marketing consents | until withdrawal; evidence of withdrawal for 3 years |
| Website technical records (logs) | 7 days, unless relevant for security purposes |
Once the periods have elapsed, data is deleted or irreversibly anonymised.
10. INTERNATIONAL TRANSFERS
Transfers outside the European Economic Area take place only on the basis of an adequacy decision of the European Commission (Article 45 GDPR) or of Standard Contractual Clauses approved by the Commission (Article 46(2)(c)), accompanied by supplementary measures. A copy of the safeguards is made available upon request.
11. DATA SUBJECT RIGHTS
Data subjects have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), portability (Art. 20), objection (Art. 21) and to withdraw consent at any time, without affecting the lawfulness of processing carried out previously (Art. 7(3)).
Exercise of these rights is free of charge and is effected by message to privacidade@the-haus.co. Additional information may be requested in order to confirm identity. A response is provided within one month, extendable to up to two months in complex cases.
Complaint to the supervisory authority: Comissão Nacional de Proteção de Dados (CNPD) Av. D. Carlos I, 134, 1.º, 1200-651 Lisboa geral@cnpd.pt · www.cnpd.pt
12. RIGHT TO OBJECT
The data subject has the right to object at any time, on grounds relating to their particular situation, to processing of data based on Article 6(1)(f) GDPR. In that case, the processing shall cease, unless there are compelling legitimate grounds which override the interests, rights and freedoms of the data subject, or the processing serves the establishment, exercise or defence of legal claims.
Objection to processing for direct marketing purposes may be exercised at any time, without any need to state reasons.
13. SECURITY
Appropriate technical and organisational measures are adopted pursuant to Article 32 GDPR: TLS/HTTPS encryption, encrypted storage, role-based access control, two-factor authentication for staff access, access logging, confidentiality obligations and staff training, periodic review of the measures, and exclusive use of PCI-DSS certified payment providers.
In the event of a personal data breach likely to result in a risk to the rights and freedoms of data subjects, the CNPD is notified within 72 hours (Article 33) and, where there is a high risk, the data subjects are informed (Article 34).
14. COOKIES
The use of cookies and equivalent technologies is governed by Lei n.º 41/2004, de 18 de agosto (Portuguese Electronic Communications Privacy Act). Cookies that are not strictly necessary are placed only with prior consent, which may be withdrawn at any time through the cookie settings. See the Cookie Policy.
15. COMPLAINTS AND DISPUTE RESOLUTION
15.1 Complaints may be submitted to info@the-haus.co or through the Livro de Reclamações Eletrónico at www.livroreclamacoes.pt, pursuant to Decreto-Lei n.º 156/2005.
15.2 Pursuant to artigo 18.º da Lei n.º 144/2015, de 8 de setembro (alternative consumer dispute resolution), it is hereby stated that, in the event of a consumer dispute, the consumer may refer the matter to the territorially competent alternative dispute resolution body — the Centro de Arbitragem de Conflitos de Consumo de Lisboa (CACCL), www.centroarbitragemlisboa.pt — or to the Centro Nacional de Informação e Arbitragem de Conflitos de Consumo (CNIACC), www.cniacc.pt. The Haus has not previously adhered to any alternative dispute resolution body, save in cases where the law imposes mandatory arbitration.
16. THIRD-PARTY WEBSITES
The Haus is not responsible for the content or privacy practices of third-party websites, in particular those of online travel agencies. For bookings made through an OTA, the platform is an independent controller in respect of the data it collects directly.
17. AMENDMENTS
This Policy is updated whenever the processing activities or the legal framework change. The version published at www.the-haus.co prevails. Substantial amendments are communicated in writing to guests with an active booking.
18. CONTACTS
Data protection: privacidade@the-haus.co General: info@the-haus.co Address: Short Conclusion — Mediação e Gestão Imobiliária, Lda., Rua Domingos Sequeira, 27, Lisbon, Portugal
This English version is a translation. In the event of any discrepancy, the Portuguese version prevails.
The Haus — Deutschland The Haus KAI, Kaiserstraße 27, 90403 Nürnberg · The Haus HANS, Heugäßchen 5, 90402 Nürnberg
Fassung 2.0 · Gültig ab 3. August 2026Ersetzt vollständig die bisherige Fassung.
1. ALLGEMEINES
Diese Datenschutzerklärung informiert Sie gemäß Art. 13 und 14 DSGVO über die Verarbeitung personenbezogener Daten durch The Haus in Deutschland. Ergänzend gilt das Bundesdatenschutzgesetz (BDSG) sowie das Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz (TDDDG).
Sie gilt für Gäste, Mitreisende, Besucher, Geschäftskontakte und Nutzer der Website www.the-haus.co, soweit die Objekte in Nürnberg betroffen sind.
Ergänzend gelten unsere Allgemeinen Geschäftsbedingungen (AGB), die Hausordnung und die Cookie-Richtlinie. In datenschutzrechtlichen Fragen ist ausschließlich diese Erklärung maßgeblich.
Hinweis: Die Objekte in Lissabon (Alegria, Santa Bárbara I, Santa Bárbara II) werden von einer anderen Gesellschaft nach portugiesischem Recht betrieben und unterliegen einer eigenen Datenschutzerklärung, abrufbar unter www.the-haus.co/privacy-policy.
2. VERANTWORTLICHER
SC The Haus Germany GmbH Virchowstraße 17a, 90409 Nürnberg, Deutschland Amtsgericht Nürnberg, HRB 45612 Geschäftsführer: Leonardo Schneider, Lorena Schneider (jeweils einzelvertretungsberechtigt) USt-IdNr.: DE460439078 E-Mail: info@the-haus.co Datenschutzanfragen: datenschutz@the-haus.co
Datenschutzbeauftragter: Ein Datenschutzbeauftragter ist derzeit nicht bestellt, da die Voraussetzungen des § 38 BDSG und des Art. 37 DSGVO nicht erfüllt sind. Diese Bewertung wird jährlich überprüft; bei Änderung wird diese Erklärung angepasst.
3. KATEGORIEN VERARBEITETER DATEN
| Kategorie | Beispiele |
|---|---|
| Identitätsdaten | Name, Geburtsdatum, Staatsangehörigkeit, Anschrift, Art und Nummer des Ausweis- oder Reisedokuments, Unterschrift |
| Kontaktdaten | E-Mail-Adresse, Telefonnummer |
| Buchungsdaten | Reservierungsnummer, Objekt und Kategorie, An- und Abreise, Zahl und Namen der Mitreisenden, Buchungskanal, Präferenzen und Sonderwünsche |
| Zahlungs- und Abrechnungsdaten | Kreditkarten-Token, Karteninhaber, letzte vier Ziffern, Ablaufdatum, Rechnungsanschrift, Zahlungsstatus, Vorautorisierungen, Belastungen, Erstattungen |
| Kommunikationsdaten | E-Mails, WhatsApp- und Chat-Nachrichten, Anfragen an den Gästeservice, Bewertungen |
| Zutritts- und Aufenthaltsdaten | Ausgabe und Nutzung digitaler Schlüssel, Schlüsselkarten und PIN-Codes, Protokolle der Schließanlage |
| Vorfalls- und Schadensdaten | siehe Ziffer 8 |
| Technische Daten | IP-Adresse, Browsertyp, Gerätekennungen, Zugriffszeitpunkt, Referrer-URL |
Besondere Kategorien personenbezogener Daten (Art. 9 DSGVO) verarbeiten wir nur, wenn Sie sie uns von sich aus mitteilen — etwa Barrierefreiheitsbedarf oder Allergien — auf Grundlage Ihrer ausdrücklichen Einwilligung (Art. 9 Abs. 2 lit. a DSGVO), oder soweit dies zur Geltendmachung, Ausübung oder Verteidigung von Rechtsansprüchen erforderlich ist (Art. 9 Abs. 2 lit. f DSGVO).
Minderjährige: Der Beherbergungsvertrag wird ausschließlich mit volljährigen Personen geschlossen. Daten mitreisender Minderjähriger verarbeiten wir nur im gesetzlich erforderlichen Umfang; verantwortlich ist die buchende erwachsene Person.
4. ZWECKE UND RECHTSGRUNDLAGEN
| Zweck | Rechtsgrundlage |
|---|---|
| Abschluss und Durchführung des Beherbergungsvertrags: Reservierung, Check-in und Check-out, Zutrittsberechtigung, Leistungserbringung, Abrechnung | Art. 6 Abs. 1 lit. b DSGVO |
| Meldepflicht: Ausfüllen, Unterzeichnen und Aufbewahren des Meldescheins; besondere Meldepflichten für ausländische Gäste einschließlich Passdatenerfassung | Art. 6 Abs. 1 lit. c DSGVO i. V. m. §§ 29, 30 BMG und § 29 Abs. 4 BMG |
| Erstellung, Übermittlung und Aufbewahrung von Rechnungen und Buchungsbelegen; steuerliche Pflichten | Art. 6 Abs. 1 lit. c DSGVO i. V. m. § 147 AO, § 257 HGB, § 14b UStG |
| Gästekommunikation vor, während und nach dem Aufenthalt | Art. 6 Abs. 1 lit. b DSGVO |
| Werbliche Kommunikation und Newsletter | Art. 6 Abs. 1 lit. a DSGVO (Einwilligung); bei Bestandsgästen ergänzend § 7 Abs. 3 UWG |
| Dokumentation von Schäden und Verstößen gegen die Hausordnung, Bezifferung und Durchsetzung von Ersatzansprüchen, Belastung der hinterlegten Kreditkarte | Art. 6 Abs. 1 lit. b und lit. f DSGVO — siehe Ziffer 8 |
| Betrugsprävention, Prüfung der Zahlungsmittel, Verhinderung von Zahlungsausfällen | Art. 6 Abs. 1 lit. f DSGVO |
| Sicherheit von Gebäude, Gästen, Nachbarn und Personal | Art. 6 Abs. 1 lit. f DSGVO |
| Verbesserung unserer Leistungen, Statistik, Websiteanalyse | Art. 6 Abs. 1 lit. a DSGVO für nicht notwendige Cookies; im Übrigen lit. f |
Unsere berechtigten Interessen sind: die ordnungsgemäße Abwicklung des Aufenthalts, die Sicherheit des Betriebs, der Schutz unseres Eigentums sowie die Geltendmachung, Ausübung und Verteidigung von Rechtsansprüchen.
5. MELDEPFLICHT NACH DEM BUNDESMELDEGESETZ
5.1 Nach §§ 29, 30 BMG sind wir verpflichtet, für jeden Aufenthalt einen Meldeschein zu führen, den der Gast am Anreisetag zu unterschreiben hat.
5.2 Bei ausländischen Gästen sind wir verpflichtet, die Identität anhand eines gültigen Passes oder Passersatzpapiers zu überprüfen und die entsprechenden Angaben auf dem Meldeschein zu erfassen (§ 29 Abs. 4 BMG).
5.3 Die Meldescheine sind ein Jahr aufzubewahren und anschließend innerhalb von drei Monaten zu vernichten (§ 30 Abs. 4 BMG). Sie sind auf Verlangen den in § 30 Abs. 5 BMG genannten Behörden zugänglich zu machen.
5.4 Diese Verarbeitung beruht auf einer gesetzlichen Pflicht und steht nicht zur Disposition des Gastes. Ohne ordnungsgemäße Anmeldung kann der Zutritt verweigert werden.
6. ZAHLUNGSDATEN UND BELASTUNGSERMÄCHTIGUNG
6.1 Kreditkartendaten werden ausschließlich über PCI-DSS-zertifizierte Zahlungsdienstleister verarbeitet und tokenisiert gespeichert. Die vollständige Kartennummer und die Prüfziffer (CVC/CVV) sind für uns nicht einsehbar und werden von uns nicht gespeichert.
6.2 The Haus ist berechtigt, eine gültige Kreditkarte als Zahlungsgarantie zu verlangen, zu verifizieren und vorzuautorisieren sowie in den in den AGB genannten Fällen eine Kaution zu erheben.
6.3 Mit der Buchung und der Anerkennung der AGB erteilen Sie uns eine Belastungsermächtigung für den Übernachtungspreis, Zusatzleistungen, Stornogebühren, No-Show-Beträge sowie für die Beträge nach Ziffer 10 der AGB und Ziffer 8 dieser Erklärung.
6.4 Belastungen nach dem Check-out erfolgen als händlerinitiierte Transaktionen (MIT) auf Grundlage der bei Buchung erteilten Ermächtigung. Über jede Belastung erhalten Sie eine Rechnung bzw. Belastungsanzeige in Textform mit Angabe des zugrunde liegenden Sachverhalts und des Betrags.
7. EMPFÄNGER UND AUFTRAGSVERARBEITER
Eine Weitergabe erfolgt nur, soweit sie zur Vertragserfüllung, aufgrund einer Rechtspflicht oder aufgrund überwiegender berechtigter Interessen erforderlich ist. Empfängerkategorien:
- Property-Management-System und Buchungsmaschine
- Zahlungsdienstleister, Acquirer und Kreditkartennetzwerke
- Online-Reiseportale (OTA) und Channel Manager
- Gästekommunikations- und Check-in-Plattformen
- Anbieter der Zutrittskontroll- und Schließsysteme
- IT-, Hosting-, Analyse- und Marketingdienstleister
- Reinigungs-, Wartungs- und Sicherheitsdienstleister — nur die für den Einsatz erforderlichen Daten
- Steuerberater, Wirtschaftsprüfer, Rechtsanwälte, Inkassodienstleister und Versicherer
- Behörden, Gerichte, Polizei und Finanzverwaltung, bei gesetzlicher Verpflichtung oder zur Verfolgung von Rechtsansprüchen
Mit Dienstleistern, die weisungsgebunden für uns tätig werden, bestehen Verträge zur Auftragsverarbeitung nach Art. 28 DSGVO. Eine aktuelle Übersicht erhalten Sie auf Anfrage an datenschutz@the-haus.co.
8. SCHÄDEN, VERSTÖSSE GEGEN DIE HAUSORDNUNG UND BELASTUNG DER KREDITKARTE
Diese Ziffer beschreibt die Datenverarbeitung bei Schäden und Vorfällen. Der Anspruch auf Zahlung selbst folgt aus den AGB und dem Gesetz, nicht aus dieser Erklärung.
8.1 Anlässe
Kommt es während oder im Zusammenhang mit einem Aufenthalt zu
- Beschädigung, Zerstörung oder Verlust von Inventar, Ausstattung, Gebäudeteilen oder Gemeinschaftsflächen,
- außergewöhnlicher Verschmutzung über die übliche Endreinigung hinaus, einschließlich Fällen, die eine Spezial-, Desinfektions- oder Fachreinigung oder den Austausch von Textilien und Matratzen erfordern,
- Rauchen in Nichtraucherbereichen oder Manipulation von Rauchmeldern und Sicherheitseinrichtungen,
- nicht genehmigten Veranstaltungen, Mehrbelegung oder Weitergabe von Zugangsdaten an Dritte,
- Lärm, Störung der Nachtruhe, Beschwerden von Nachbarn, der Hausverwaltung oder von Behörden,
- Auseinandersetzungen, Gewaltvorfällen oder Einsätzen von Polizei, Feuerwehr oder Rettungsdienst,
- verspätetem Check-out oder Verlust von Zugangsmedien,
verarbeiten wir die zur Aufklärung, Bezifferung und Durchsetzung erforderlichen Daten.
8.2 Verarbeitete Daten
- Name, Kontakt- und Reservierungsdaten des Buchenden und, soweit bekannt, der Mitreisenden;
- Lichtbild- und Videoaufnahmen des Schadens und der betroffenen Bereiche, erstellt nach dem Check-out bzw. nach Feststellung des Vorfalls;
- Schadensprotokolle, Berichte des Housekeepings, der Wartung und externer Fachbetriebe;
- Kostenvoranschläge, Reparatur-, Ersatzbeschaffungs- und Reinigungsrechnungen sowie der Wert der Nächte, in denen die Unterkunft nicht vermietbar ist;
- Zutrittsprotokolle der Schließanlage für den Zeitraum des Vorfalls;
- Beschwerden Dritter, Aktenzeichen und Korrespondenz mit Polizei, Behörden, Hausverwaltung und Versicherungen;
- Zahlungs- und Belastungsdaten der hinterlegten Kreditkarte.
Aufnahmen beschränken sich auf den Sachschaden und die betroffenen Räumlichkeiten. Personen werden nur abgebildet, soweit unvermeidbar. Zurückgelassene persönliche Gegenstände werden nicht durchsucht und nicht über das zur Schadensfeststellung erforderliche Maß hinaus dokumentiert.
8.3 Rechtsgrundlagen
- Art. 6 Abs. 1 lit. b DSGVO — Durchführung und Abwicklung des Beherbergungsvertrags einschließlich der vertraglich vereinbarten Kostenpauschalen und der erteilten Belastungsermächtigung (Ziffer 3.4 und Ziffer 10 der AGB).
- Art. 6 Abs. 1 lit. f DSGVO — berechtigtes Interesse an Beweissicherung, Schadensbezifferung, Schutz des Eigentums und Sicherheit von Gästen, Nachbarn und Personal sowie an der Geltendmachung, Ausübung und Verteidigung von Rechtsansprüchen nach §§ 280, 823, 249 ff. BGB.
- Art. 6 Abs. 1 lit. c DSGVO — soweit eine gesetzliche Auskunfts- oder Anzeigepflicht besteht.
- Art. 9 Abs. 2 lit. f DSGVO — soweit ausnahmsweise Daten besonderer Kategorien anfallen, etwa Hinweise auf Verletzungen bei einem Gewaltvorfall. Diese Daten werden ausschließlich zur Geltendmachung oder Verteidigung von Rechtsansprüchen und zur Erfüllung behördlicher Anforderungen verarbeitet.
8.4 Verfahren bei der Belastung
Auf Grundlage der Ermächtigung nach Ziffer 6.3 gilt:
- Vorherige Information in Textform unter Angabe des Sachverhalts, des Betrags und der Berechnungsgrundlage, unter Beifügung der vorliegenden Nachweise (Lichtbilder, Kostenvoranschläge, Rechnungen).
- Gelegenheit zur Stellungnahme. Ist die Höhe noch nicht bezifferbar, informieren wir zunächst dem Grunde nach und rechnen anschließend ab.
- Belastung der Karte und Übersendung einer Rechnung.
- Die in den AGB ausgewiesenen Beträge sind pauschalierter Schadensersatz im Sinne des § 309 Nr. 5 BGB, keine Vertragsstrafen. Sie werden auf einen höheren, tatsächlich nachgewiesenen Schaden angerechnet. Dem Gast bleibt ausdrücklich der Nachweis vorbehalten, dass ein Schaden überhaupt nicht oder wesentlich niedriger entstanden ist; The Haus bleibt der Nachweis eines höheren Schadens vorbehalten.
- Mehrere Gäste einer Reservierung haften als Gesamtschuldner (§ 421 BGB).
- Der Gast kann der Belastung widersprechen und die Forderung bestreiten. Seine Rechte gegenüber dem Kartenherausgeber sowie der Rechtsweg bleiben unberührt.
8.5 Aufbewahrung
Vorfalls- und Schadensdaten werden bis zum Ablauf der gesetzlichen Verjährungsfrist aufbewahrt, regelmäßig drei Jahre ab Schluss des Jahres, in dem der Anspruch entstanden ist und wir Kenntnis erlangt haben (§§ 195, 199 BGB). Bei laufenden Streitigkeiten, Versicherungs-, Straf- oder Vollstreckungsverfahren verlängert sich die Aufbewahrung bis zu deren rechtskräftigem Abschluss. Lichtbilder werden gelöscht, sobald der Vorgang abgeschlossen ist und keine Ansprüche mehr zu erwarten sind.
8.6 Widerspruchsrecht
Gegen Verarbeitungen auf Grundlage von Art. 6 Abs. 1 lit. f DSGVO können Sie nach Art. 21 DSGVO Widerspruch einlegen (Ziffer 11). Wir prüfen dann, ob zwingende schutzwürdige Gründe überwiegen; bei der Geltendmachung oder Verteidigung von Rechtsansprüchen ist dies regelmäßig der Fall.
9. SPEICHERDAUER
| Kategorie | Dauer |
|---|---|
| Meldescheine (§§ 29, 30 BMG) | 1 Jahr ab Aufenthaltsende, danach Vernichtung binnen drei Monaten |
| Rechnungen, Buchungsbelege, Steuerunterlagen | 10 Jahre (§ 147 AO, § 257 HGB, § 14b UStG) |
| Reservierungs- und Gästeprofildaten | bis zu 3 Jahre nach Aufenthaltsende, soweit keine längere Pflicht besteht |
| Kommunikation mit dem Gästeservice | 3 Jahre nach letztem Kontakt |
| Vorfalls- und Schadensdokumentation | siehe Ziffer 8.5 |
| Kreditkarten-Token | bis zur Erledigung aller Ansprüche aus dem Aufenthalt, längstens 13 Monate nach Abreise |
| Zutrittsprotokolle der Schließanlage | 90 Tage, im Vorfallsfall länger nach Ziffer 8.5 |
| Marketing-Einwilligungen | bis zum Widerruf; Nachweis des Widerrufs 3 Jahre |
| Server-Logfiles | 7 Tage, sofern nicht sicherheitsrelevant |
Nach Ablauf werden die Daten gelöscht oder unumkehrbar anonymisiert.
10. INTERNATIONALE DATENÜBERMITTLUNG
Eine Übermittlung in Drittländer außerhalb des EWR erfolgt nur bei Vorliegen eines Angemessenheitsbeschlusses der Europäischen Kommission (Art. 45 DSGVO) oder auf Grundlage geeigneter Garantien, insbesondere der EU-Standardvertragsklauseln (Art. 46 Abs. 2 lit. c DSGVO) nebst ergänzenden Schutzmaßnahmen. Eine Kopie der Garantien erhalten Sie auf Anfrage.
11. IHRE RECHTE
Ihnen stehen zu: Auskunft (Art. 15), Berichtigung (Art. 16), Löschung (Art. 17), Einschränkung der Verarbeitung (Art. 18), Datenübertragbarkeit (Art. 20), Widerspruch (Art. 21) sowie der Widerruf erteilter Einwilligungen mit Wirkung für die Zukunft (Art. 7 Abs. 3 DSGVO).
Die Ausübung ist unentgeltlich; eine Nachricht an datenschutz@the-haus.co genügt. Zur Identitätsprüfung können wir zusätzliche Angaben verlangen. Wir antworten innerhalb eines Monats; in komplexen Fällen kann die Frist um zwei Monate verlängert werden.
Beschwerderecht (Art. 77 DSGVO): Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) Promenade 18, 91522 Ansbach, Deutschland www.lda.bayern.de
Sie können sich auch an die Aufsichtsbehörde Ihres gewöhnlichen Aufenthaltsorts oder Arbeitsplatzes wenden.
12. WIDERSPRUCHSRECHT NACH ART. 21 DSGVO
Sie haben das Recht, aus Gründen, die sich aus Ihrer besonderen Situation ergeben, jederzeit gegen die Verarbeitung Sie betreffender personenbezogener Daten, die aufgrund von Art. 6 Abs. 1 lit. f DSGVO erfolgt, Widerspruch einzulegen. Wir verarbeiten die Daten dann nicht mehr, es sei denn, wir können zwingende schutzwürdige Gründe nachweisen, die Ihre Interessen, Rechte und Freiheiten überwiegen, oder die Verarbeitung dient der Geltendmachung, Ausübung oder Verteidigung von Rechtsansprüchen.
Gegen die Verarbeitung zum Zwecke der Direktwerbung können Sie jederzeit ohne Angabe von Gründen widersprechen.
13. SICHERHEIT DER VERARBEITUNG
Wir treffen technische und organisatorische Maßnahmen nach Art. 32 DSGVO: TLS-/HTTPS-Verschlüsselung, verschlüsselte Datenspeicherung, rollenbasierte Zugriffskontrollen, Zwei-Faktor-Authentifizierung für Mitarbeiterzugänge, Protokollierung von Zugriffen, Verpflichtung der Mitarbeitenden auf Vertraulichkeit und regelmäßige Schulung, periodische Überprüfung der Maßnahmen sowie ausschließliche Nutzung PCI-DSS-zertifizierter Zahlungsdienstleister.
Bei einer Verletzung des Schutzes personenbezogener Daten, die voraussichtlich zu einem Risiko für Rechte und Freiheiten führt, informieren wir die Aufsichtsbehörde binnen 72 Stunden (Art. 33 DSGVO) und bei hohem Risiko auch die betroffenen Personen (Art. 34 DSGVO).
14. COOKIES UND WEBSITE-NUTZUNG
Der Einsatz von Cookies und vergleichbaren Technologien richtet sich nach § 25 TDDDG. Nicht unbedingt erforderliche Cookies — insbesondere Analyse- und Marketing-Cookies — setzen wir nur mit Ihrer vorherigen Einwilligung (§ 25 Abs. 1 TDDDG, Art. 6 Abs. 1 lit. a DSGVO). Die Einwilligung ist jederzeit über die Cookie-Einstellungen widerrufbar. Einzelheiten in unserer Cookie-Richtlinie.
15. BESCHWERDEN UND STREITBEILEGUNG
15.1 Beschwerden richten Sie bitte an info@the-haus.co. Mängel sind unverzüglich vor Ort anzuzeigen; nachträgliche Reklamationen binnen 20 Werktagen nach Abreise in Textform.
15.2 Verbraucherstreitbeilegung: The Haus ist zur Teilnahme an einem Streitbeilegungsverfahren vor einer Verbraucherschlichtungsstelle weder verpflichtet noch bereit (§ 36 VSBG).
16. WEBSITES DRITTER
Für Inhalte und Datenschutzpraktiken verlinkter Websites Dritter, insbesondere von Online-Reiseportalen, sind ausschließlich deren Betreiber verantwortlich. Bei Buchungen über ein OTA ist der Portalbetreiber für die dort unmittelbar erhobenen Daten eigenständig verantwortlich.
17. ÄNDERUNGEN
Wir passen diese Erklärung an, wenn sich unsere Verarbeitungen oder die Rechtslage ändern. Maßgeblich ist die unter www.the-haus.co/datenschutz veröffentlichte Fassung. Bei wesentlichen Änderungen informieren wir Gäste mit bestehender Reservierung zusätzlich in Textform.
18. KONTAKT
Datenschutz: datenschutz@the-haus.co Allgemein: info@the-haus.co Anschrift: SC The Haus Germany GmbH, Virchowstraße 17a, 90409 Nürnberg, Deutschland
Diese Datenschutzerklärung liegt in deutscher und englischer Sprache vor. Bei Abweichungen ist die deutsche Fassung maßgeblich.
The Haus — Germany The Haus KAI, Kaiserstraße 27, 90403 Nürnberg · The Haus HANS, Heugäßchen 5, 90402 Nürnberg
Version 2.0 · Effective 3 August 2026Supersedes the previous version in its entirety.
1. GENERAL
This Privacy Policy informs you in accordance with Articles 13 and 14 GDPR about the processing of personal data by The Haus in Germany. The Bundesdatenschutzgesetz (BDSG) (German Federal Data Protection Act) and the Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz (TDDDG) (German Telecommunications and Digital Services Data Protection Act) apply in addition.
It applies to guests, accompanying travellers, visitors, business contacts and users of the website www.the-haus.co, insofar as the properties in Nürnberg are concerned.
Our General Terms and Conditions (AGB), the House Rules and the Cookie Policy apply in addition. In matters of data protection law, this Policy alone is authoritative.
Note: The properties in Lisbon (Alegria, Santa Bárbara I, Santa Bárbara II) are operated by a different company under Portuguese law and are subject to a separate privacy policy, available at www.the-haus.co/privacy-policy.
2. CONTROLLER
SC The Haus Germany GmbH Virchowstraße 17a, 90409 Nürnberg, Germany Amtsgericht Nürnberg (Nuremberg Local Court), HRB 45612 Managing Directors: Leonardo Schneider, Lorena Schneider (each with sole power of representation) VAT ID No.: DE460439078 E-mail: info@the-haus.co Data protection enquiries: datenschutz@the-haus.co
Data Protection Officer: A data protection officer has not been appointed at present, as the requirements of § 38 BDSG (German Federal Data Protection Act) and Article 37 GDPR are not met. This assessment is reviewed annually; should it change, this Policy will be amended accordingly.
3. CATEGORIES OF DATA PROCESSED
| Category | Examples |
|---|---|
| Identity data | Name, date of birth, nationality, address, type and number of identity or travel document, signature |
| Contact data | E-mail address, telephone number |
| Booking data | Reservation number, property and category, arrival and departure, number and names of accompanying travellers, booking channel, preferences and special requests |
| Payment and billing data | Credit card token, cardholder, last four digits, expiry date, billing address, payment status, pre-authorisations, charges, refunds |
| Communication data | E-mails, WhatsApp and chat messages, enquiries to guest services, reviews |
| Access and stay data | Issuance and use of digital keys, key cards and PIN codes, locking system logs |
| Incident and damage data | see Section 8 |
| Technical data | IP address, browser type, device identifiers, time of access, referrer URL |
We process special categories of personal data (Article 9 GDPR) only where you disclose them to us on your own initiative — for example accessibility requirements or allergies — on the basis of your explicit consent (Article 9(2)(a) GDPR), or insofar as this is necessary for the establishment, exercise or defence of legal claims (Article 9(2)(f) GDPR).
Minors: The accommodation contract is concluded exclusively with persons of full legal age. We process data of accompanying minors only to the extent legally required; the booking adult is responsible.
4. PURPOSES AND LEGAL BASES
| Purpose | Legal basis |
|---|---|
| Conclusion and performance of the accommodation contract: reservation, check-in and check-out, access authorisation, provision of services, billing | Article 6(1)(b) GDPR |
| Registration duty: completion, signature and retention of the Meldeschein (registration form); special registration duties for foreign guests, including recording of passport data | Article 6(1)(c) GDPR in conjunction with §§ 29, 30 BMG (German Federal Registration Act) and § 29(4) BMG |
| Issuance, transmission and retention of invoices and booking records; tax obligations | Article 6(1)(c) GDPR in conjunction with § 147 AO (German Fiscal Code), § 257 HGB (German Commercial Code), § 14b UStG (German VAT Act) |
| Guest communication before, during and after the stay | Article 6(1)(b) GDPR |
| Promotional communication and newsletters | Article 6(1)(a) GDPR (consent); for existing guests additionally § 7(3) UWG (German Unfair Competition Act) |
| Documentation of damage and breaches of the House Rules, quantification and enforcement of compensation claims, charging of the credit card on file | Article 6(1)(b) and (f) GDPR — see Section 8 |
| Fraud prevention, verification of means of payment, prevention of payment defaults | Article 6(1)(f) GDPR |
| Security of the building, guests, neighbours and staff | Article 6(1)(f) GDPR |
| Improvement of our services, statistics, website analytics | Article 6(1)(a) GDPR for non-essential cookies; otherwise (f) |
Our legitimate interests are: the proper handling of the stay, the security of operations, the protection of our property, and the establishment, exercise and defence of legal claims.
5. REGISTRATION DUTY UNDER THE FEDERAL REGISTRATION ACT
5.1 Under §§ 29, 30 BMG we are obliged to maintain a Meldeschein (registration form) for every stay, which the guest must sign on the day of arrival.
5.2 In the case of foreign guests, we are obliged to verify identity by means of a valid passport or substitute passport document and to record the corresponding particulars on the Meldeschein (§ 29(4) BMG).
5.3 The Meldescheine must be retained for one year and thereafter destroyed within three months (§ 30(4) BMG). They must be made accessible on request to the authorities named in § 30(5) BMG.
5.4 This processing is based on a statutory obligation and is not at the guest's disposal. Without proper registration, access may be refused.
6. PAYMENT DATA AND CHARGING AUTHORISATION
6.1 Credit card data are processed exclusively via PCI-DSS-certified payment service providers and stored in tokenised form. The full card number and the security code (CVC/CVV) are not visible to us and are not stored by us.
6.2 The Haus is entitled to require, verify and pre-authorise a valid credit card as a payment guarantee, and to levy a deposit in the cases set out in the AGB.
6.3 By making a booking and accepting the AGB, you grant us a charging authorisation for the accommodation price, ancillary services, cancellation fees, no-show amounts, and for the amounts under Section 10 of the AGB and Section 8 of this Policy.
6.4 Charges made after check-out are effected as merchant-initiated transactions (MIT) on the basis of the authorisation granted at the time of booking. For every charge you receive an invoice or debit advice in text form (Textform) stating the underlying circumstances and the amount.
7. RECIPIENTS AND PROCESSORS
Disclosure takes place only insofar as it is necessary for the performance of the contract, on the basis of a legal obligation, or on the basis of overriding legitimate interests. Categories of recipients:
- Property management system and booking engine
- Payment service providers, acquirers and credit card networks
- Online travel agencies (OTA) and channel managers
- Guest communication and check-in platforms
- Providers of access control and locking systems
- IT, hosting, analytics and marketing service providers
- Cleaning, maintenance and security service providers — only the data necessary for the assignment
- Tax advisors, auditors, lawyers, debt collection service providers and insurers
- Public authorities, courts, police and tax administration, where legally required or for the pursuit of legal claims
With service providers acting for us on our instructions, data processing agreements pursuant to Article 28 GDPR are in place. A current overview is available on request to datenschutz@the-haus.co.
8. DAMAGE, BREACHES OF THE HOUSE RULES AND CHARGING OF THE CREDIT CARD
This Section describes the processing of data in cases of damage and incidents. The claim for payment itself arises from the AGB and from statute, not from this Policy.
8.1 Triggering events
Where, during or in connection with a stay, there occurs
- damage to, destruction or loss of inventory, fixtures and fittings, parts of the building or common areas,
- exceptional soiling beyond the usual final cleaning, including cases requiring specialist, disinfection or professional cleaning or the replacement of textiles and mattresses,
- smoking in non-smoking areas or tampering with smoke detectors and safety installations,
- unauthorised events, over-occupancy or passing on of access credentials to third parties,
- noise, disturbance of night-time quiet, complaints from neighbours, the building management or public authorities,
- altercations, incidents of violence or deployments of police, fire brigade or emergency services,
- late check-out or loss of access media,
we process the data necessary for investigation, quantification and enforcement.
8.2 Data processed
- Name, contact and reservation data of the booking party and, insofar as known, of the accompanying travellers;
- Photographic and video recordings of the damage and the affected areas, taken after check-out or after the incident has been established;
- Damage reports, reports from housekeeping, maintenance and external specialist firms;
- Cost estimates, repair, replacement and cleaning invoices, as well as the value of the nights during which the accommodation cannot be let;
- Access logs of the locking system for the period of the incident;
- Third-party complaints, file reference numbers and correspondence with police, public authorities, building management and insurers;
- Payment and charging data of the credit card on file.
Recordings are limited to the property damage and the affected premises. Persons are depicted only insofar as unavoidable. Personal belongings left behind are not searched and not documented beyond the extent necessary to establish the damage.
8.3 Legal bases
- Article 6(1)(b) GDPR — performance and settlement of the accommodation contract, including the contractually agreed flat-rate cost amounts and the charging authorisation granted (Section 3.4 and Section 10 of the AGB).
- Article 6(1)(f) GDPR — legitimate interest in the preservation of evidence, quantification of damage, protection of property and safety of guests, neighbours and staff, as well as in the establishment, exercise and defence of legal claims under §§ 280, 823, 249 et seq. BGB (German Civil Code).
- Article 6(1)(c) GDPR — insofar as a statutory duty to provide information or to report exists.
- Article 9(2)(f) GDPR — insofar as, exceptionally, data of special categories arise, for example indications of injuries in an incident of violence. Such data are processed exclusively for the establishment or defence of legal claims and to meet official requirements.
8.4 Procedure for charging
On the basis of the authorisation under Section 6.3, the following applies:
- Prior information in text form (Textform) stating the circumstances, the amount and the basis of calculation, enclosing the available evidence (photographs, cost estimates, invoices).
- Opportunity to comment. If the amount cannot yet be quantified, we first inform you as to the merits and settle the account thereafter.
- Charging of the card and transmission of an invoice.
- The amounts set out in the AGB are liquidated damages (pauschalierter Schadensersatz) within the meaning of § 309 No. 5 BGB, not contractual penalties (Vertragsstrafen). They are set off against any higher damage actually proven. The guest expressly retains the right to prove that no damage at all or substantially lower damage has been incurred; The Haus retains the right to prove higher damage.
- Several guests of one reservation are liable as joint and several debtors (§ 421 BGB).
- The guest may object to the charge and dispute the claim. The guest's rights vis-à-vis the card issuer and recourse to the courts remain unaffected.
8.5 Retention
Incident and damage data are retained until expiry of the statutory limitation period, as a rule three years from the end of the year in which the claim arose and we obtained knowledge thereof (§§ 195, 199 BGB). In the event of ongoing disputes or insurance, criminal or enforcement proceedings, retention is extended until their final and binding conclusion. Photographs are deleted as soon as the matter is closed and no further claims are to be expected.
8.6 Right to object
Against processing based on Article 6(1)(f) GDPR you may lodge an objection pursuant to Article 21 GDPR (Section 11). We will then examine whether compelling legitimate grounds override; in the case of the establishment or defence of legal claims, this is regularly the case.
9. RETENTION PERIODS
| Category | Period |
|---|---|
| Meldescheine (§§ 29, 30 BMG) | 1 year from the end of the stay, followed by destruction within three months |
| Invoices, booking records, tax documents | 10 years (§ 147 AO, § 257 HGB, § 14b UStG) |
| Reservation and guest profile data | up to 3 years after the end of the stay, unless a longer obligation applies |
| Communication with guest services | 3 years after last contact |
| Incident and damage documentation | see Section 8.5 |
| Credit card token | until settlement of all claims arising from the stay, at the latest 13 months after departure |
| Access logs of the locking system | 90 days, longer in the event of an incident pursuant to Section 8.5 |
| Marketing consents | until withdrawal; evidence of withdrawal 3 years |
| Server log files | 7 days, unless security-relevant |
Upon expiry, the data are deleted or irreversibly anonymised.
10. INTERNATIONAL DATA TRANSFERS
Transfers to third countries outside the EEA take place only where an adequacy decision of the European Commission exists (Article 45 GDPR) or on the basis of appropriate safeguards, in particular the EU Standard Contractual Clauses (Article 46(2)(c) GDPR) together with supplementary protective measures. A copy of the safeguards is available on request.
11. YOUR RIGHTS
You are entitled to: access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20), objection (Article 21) and the withdrawal of consent given with effect for the future (Article 7(3) GDPR).
Exercising these rights is free of charge; a message to datenschutz@the-haus.co suffices. We may request additional information to verify your identity. We respond within one month; in complex cases the period may be extended by two months.
Right to lodge a complaint (Article 77 GDPR): Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) (Bavarian Data Protection Authority) Promenade 18, 91522 Ansbach, Germany www.lda.bayern.de
You may also contact the supervisory authority of your habitual residence or place of work.
12. RIGHT TO OBJECT UNDER ARTICLE 21 GDPR
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Article 6(1)(f) GDPR. We will then no longer process the data, unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
You may object at any time and without giving reasons to processing for the purposes of direct marketing.
13. SECURITY OF PROCESSING
We take technical and organisational measures pursuant to Article 32 GDPR: TLS/HTTPS encryption, encrypted data storage, role-based access controls, two-factor authentication for staff accounts, logging of access, obligation of staff to maintain confidentiality and regular training, periodic review of the measures, and exclusive use of PCI-DSS-certified payment service providers.
In the event of a personal data breach likely to result in a risk to rights and freedoms, we notify the supervisory authority within 72 hours (Article 33 GDPR) and, where the risk is high, also the data subjects concerned (Article 34 GDPR).
14. COOKIES AND WEBSITE USE
The use of cookies and comparable technologies is governed by § 25 TDDDG. Cookies that are not strictly necessary — in particular analytics and marketing cookies — are set only with your prior consent (§ 25(1) TDDDG, Article 6(1)(a) GDPR). Consent may be withdrawn at any time via the cookie settings. Details are set out in our Cookie Policy.
15. COMPLAINTS AND DISPUTE RESOLUTION
15.1 Please address complaints to info@the-haus.co. Defects must be notified on site without undue delay; subsequent complaints must be made in text form (Textform) within 20 business days after departure.
15.2 Consumer dispute resolution: The Haus is neither obliged nor willing to participate in dispute resolution proceedings before a consumer arbitration board (§ 36 VSBG) (German Consumer Dispute Resolution Act).
16. THIRD-PARTY WEBSITES
The operators of linked third-party websites, in particular online travel agencies, are solely responsible for their content and data protection practices. In the case of bookings via an OTA, the portal operator is independently responsible for the data collected directly there.
17. AMENDMENTS
We amend this Policy where our processing operations or the legal situation change. The version published at www.the-haus.co/datenschutz is authoritative. In the event of material changes, we additionally inform guests with an existing reservation in text form (Textform).
18. CONTACT
Data protection: datenschutz@the-haus.co General: info@the-haus.co Address: SC The Haus Germany GmbH, Virchowstraße 17a, 90409 Nürnberg, Germany
This English version is a translation. In the event of any discrepancy, the German version prevails.