Controller Responsible for Data Processing

The Retreat HC GmbH & Co. KG
Mauerstraße 78
10117 Berlin

Telephone: +49 30 290 36 290
Email: info@retreatgermany.com
Data Protection Contact: privacy@retreatgermany.com


1. General Website Use

When you visit our website, the following data are collected: date and time, IP address (anonymised), browser type and operating system, and pages visited.

Purpose: To ensure the functionality and security of the website.
Legal basis: Article 6(1)(f) GDPR (legitimate interests).


2. Cookies / Consent Management

We use technically necessary cookies. Analytics and marketing cookies are set only with your consent (Section 25 TDDDG). We use Complianz to manage your cookie consent preferences.


3. Contacting Us

If you contact us by email, telephone, WhatsApp or contact form, we process the information you provide solely for the purpose of handling your enquiry (Article 6(1)(b) or Article 6(1)(f) GDPR).


4. Online Appointment Booking

Data We Process When You Make a Booking

When you book an appointment online, we process: your first and last name, mobile phone number, email address, date of birth, your selected treatment or concern, the chosen appointment, an optional note, technical data for misuse prevention (IP address and browser identifier, stored by us only as checksums), and — only with your consent — advertising click identifiers (see “Advertising Measurement with Meta”).

In our own database, we do not store your mobile phone number, date of birth, name or email address in plain text, but exclusively as cryptographic checksums (SHA-256 with a secret additional value). The appointment itself is created in our practice management system (see the section “Recipients and Processors”).

Purposes and Legal Bases

  • Appointment booking and management (including confirmation by one-time SMS code and appointment reminders): Article 6(1)(b) GDPR (contract or pre-contractual measures taken at your request). We require your date of birth for unambiguous identification in our practice management system and to avoid duplicate patient records.
  • Health-related information (your treatment / concern selection): processing for the purpose of initiating and providing healthcare, pursuant to Article 9(2)(h) GDPR in conjunction with Section 22(1) no. 1(b) BDSG, under the responsibility of medical confidentiality. This information remains with us or in our practice management system and is never transmitted to advertising platforms.
  • Waiting list (if you choose to join it): Article 6(1)(b) GDPR.
  • Misuse prevention (limiting SMS requests and protection against automated access): Article 6(1)(f) GDPR; our legitimate interest is the security of the booking system. For this purpose, we use Google reCAPTCHA during the booking step only (not across the entire website), where this is strictly necessary to prevent abusive SMS requests (Section 25(2) no. 2 TDDDG).
  • Internal funnel analysis (identifying at which stage bookings are abandoned): pseudonymised, exclusively server-side and without disclosure to third parties; Article 6(1)(f) GDPR.
  • Advertising measurement (only with consent): Article 6(1)(a) and Article 9(2)(a) GDPR, as well as Section 25(1) TDDDG. Further details are provided in the section “Advertising Measurement with Meta”.

Advertising Measurement with Meta (Only with Your Consent)

If you expressly consent on the booking page, we transmit the following to Meta Platforms Ireland Limited (Merrion Road, Dublin 4, D04 X2K5, Ireland): your email address and mobile phone number as SHA-256 checksums, advertising click identifiers (fbc, fbp) and a general booking event — for the purpose of measuring and improving our advertising (Meta Pixel and Conversions API). Your treatment selection, concern, notes or date of birth are not transmitted. However, the transmission does indicate that you booked an appointment with a provider of aesthetic medicine services; your express consent also covers this information.

We and Meta are joint controllers (Article 26 GDPR) for the collection of these data on the booking page and their transmission to Meta; any subsequent processing by Meta takes place under Meta’s own responsibility. The essence of the arrangement: Joint Controllership with Meta. Data may be transferred to Meta Platforms, Inc. (USA) on the basis of the EU-U.S. Data Privacy Framework, or alternatively the EU Standard Contractual Clauses together with additional safeguards. The Meta Pixel is loaded and the cookies _fbc/_fbp are set or read only after you have given your consent (Section 25(1) TDDDG); when the Pixel is loaded, your IP address and browser information are also transmitted to Meta for technical reasons. The server-side measurement event does not contain an IP address or browser identifier. No advertising measurement takes place without consent; the booking function remains fully available.

You may withdraw your consent at any time with effect for the future by contacting: privacy@retreatgermany.com.


5. Recipients and Processors

  • Clinicminds (registered office: Amsterdam, the Netherlands): our practice management and booking system; it creates the appointment and sends the one-time SMS code as well as appointment confirmations and reminders (SMS delivery is provided by an SMS service provider acting as a sub-processor of Clinicminds). Processor pursuant to Article 28 GDPR.
  • Vercel (hosting of the booking application) and Supabase (database, EU region): processors pursuant to Article 28 GDPR.
  • Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland): reCAPTCHA for misuse prevention during the booking step. Data (e.g. IP address and device information) may be transferred to Google LLC (USA) on the basis of the EU-U.S. Data Privacy Framework, or alternatively the EU Standard Contractual Clauses.
  • Sentry (Functional Software, Inc., USA): technical error monitoring for the booking application. Personal content is removed before transmission; transfers to the USA take place on the basis of the EU-U.S. Data Privacy Framework, or alternatively the EU Standard Contractual Clauses. Processor pursuant to Article 28 GDPR.
  • Meta Platforms Ireland Limited: only where consent has been given, under joint controllership (see the section “Advertising Measurement with Meta”).

6. Retention Periods

  • Booking session data and SMS code logs: no more than 90 days; advertising click identifiers are deleted immediately after the measurement event has been sent (and no later than after 7 days).
  • Internal funnel analysis: no more than 180 days.
  • Waiting list entries: no more than 12 months (30 days after notification).
  • Transmission logs for measurement events (without personal data in plain text): no more than 24 months.
  • Consent records: until the end of the third calendar year following withdrawal or last use (evidentiary obligations, Sections 195 and 199 BGB).
  • Patient data in the practice management system: subject to medical retention obligations (generally 10 years, Section 630f BGB).
  • Data from general website use and contact enquiries: only for as long as necessary for the relevant purpose.

7. Your Rights

You have the right of access (Article 15 GDPR), rectification (Article 16 GDPR), erasure (Article 17 GDPR), restriction of processing (Article 18 GDPR), data portability (Article 20 GDPR), and the right to object to processing based on legitimate interests (Article 21 GDPR). You may withdraw any consent you have given at any time with effect for the future (Article 7(3) GDPR). Contact: privacy@retreatgermany.com.


8. Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority, for example the Berlin Commissioner for Data Protection and Freedom of Information, Alt-Moabit 59–61, 10555 Berlin — or with any other competent supervisory authority.


9. No Automated Decision-Making

No automated decision-making, including profiling, within the meaning of Article 22 GDPR takes place.


10. Requirement to Provide Certain Data

Providing your name, mobile phone number, email address and date of birth is necessary for online appointment booking; without this information, the appointment cannot be created online. Consent to advertising measurement is voluntary.


11. Data Security

We protect your data through appropriate technical and organisational measures, including TLS/SSL encryption.


12. Changes to This Privacy Policy

We reserve the right to amend this Privacy Policy in response to legal or technical changes.

Contact: privacy@retreatgermany.com (data protection) · info@retreatgermany.com (general enquiries) · Telephone +49 30 290 36 290

Joint controllership with Meta — the essence of our arrangement

If you have consented to advertising measurement, The Retreat HC GmbH & Co. KG, Mauerstr. 78, 10117 Berlin ("The Retreat") and Meta Platforms Ireland Limited (Merrion Road, Dublin 4, D04 X2K5, Ireland; "Meta") are joint controllers under Art. 26 GDPR for the collection of certain data on our booking page and its transmission to Meta, on the basis of Meta's standard "Controller Addendum". Meta's subsequent processing of the data is not part of the joint controllership; for it, Meta is an independent controller. In essence:

What is jointly processed: pseudonymised contact identifiers (email address and mobile number as SHA-256 checksums), advertising click identifiers (fbc, fbp), and a generic booking event — to measure and improve The Retreat's advertising. Your treatment selection, your concern, and any other health information are not transmitted to Meta.
Scope of the joint controllership: it covers the collection of the data named above on our booking page and its transmission to Meta. Meta's subsequent processing is not carried out under joint controllership but under Meta's own responsibility as an independent controller.
What The Retreat is responsible for: the lawful collection and transmission of this data (including obtaining your consent), informing you about it (this page, the privacy policy), and answering your data-subject rights insofar as they concern collection and transmission.
What Meta is responsible for: the security of the joint processing and your data-subject rights with respect to the data Meta stores after transmission. Meta's subsequent processing for its own purposes is Meta's sole responsibility. Details: Meta's Privacy Policy and Meta's own explanation of the addendum.
Your rights (access, rectification, erasure, restriction, objection, portability) can be exercised against either The Retreat or Meta. First point of contact: privacy@retreatgermany.com. You may withdraw your consent at any time with effect for the future.
US transfer: data may be transferred to Meta Platforms, Inc. (USA) — on the basis of the EU-US Data Privacy Framework, alternatively the EU Standard Contractual Clauses plus supplementary measures.
Right to lodge a complaint with a supervisory authority, e.g. the Berlin Commissioner for Data Protection and Freedom of Information.

hotel chateau royal

Das Château Royal liegt zwischen Brandenburger Tor und Museumsinsel und verkörpert den Geist des modernen Berlins – kosmopolitisch, kreativ und charakterstark.

Mit 93 Zimmern und Suiten, einer Bar und einem Restaurant, geschmückt mit Werken zeitgenössischer Künstler:innen, verbindet es handwerkliche Präzision mit moderner, junger Energie.

In enger Zusammenarbeit mit lokalen Partnern – darunter auch The Retreat – bietet das Boutique-Hotel ein Erlebnis, das authentisch berlinisch und zugleich wohltuend persönlich ist. Mehr Erfahren

WordPress Cookie Plugin by Real Cookie Banner