Privacy Policy
Last updated: June 2026
The protection of your personal data is important to us. We process your data exclusively on the basis of the applicable legal provisions (GDPR, BDSG, TDDDG). In this policy we inform you about the most important aspects of data processing in connection with our website and our SaaS platform.
§ 1 Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Guestelos GmbH, Musterstraße 1, 12345 Musterstadt, Germany (placeholder)
Email: hello@guestelos.de
§ 2 Collection and purpose of data
We process personal data that you actively provide to us (e.g. when registering, booking a trial or contacting us) as well as technical data that is generated automatically during use (e.g. IP address, browser type, time of access). The purposes of processing are the provision and protection of our services, contract management, support and the improvement of our offering.
§ 3 Legal bases
Depending on the context, processing takes place on the basis of Art. 6(1)(b) GDPR (performance of a contract and pre-contractual measures), Art. 6(1)(a) GDPR (consent, e.g. for optional cookies), Art. 6(1)(c) GDPR (legal obligations, such as retention under tax and commercial law) and Art. 6(1)(f) GDPR (legitimate interest in secure and functional operation).
§ 4 Retention period
We store personal data only for as long as it is necessary for the stated purposes or as required by statutory retention periods (e.g. up to 10 years under commercial and tax law). Once the purpose no longer applies and any periods have expired, the data is deleted or anonymised.
§ 5 Recipients and processors
To provide our services we use carefully selected service providers with whom data processing agreements pursuant to Art. 28 GDPR are in place:
- Hosting / infrastructure: Operation in data centres within the EU.
- Stripe: Payment processing for subscriptions and transactions.
- fiskaly: Cloud TSS / fiscal signature for point-of-sale transactions.
- PostHog (EU hosting): privacy-friendly product analytics.
A transfer to third countries only takes place if appropriate safeguards (e.g. EU standard contractual clauses) are in place.
§ 6 Cookies & analytics
We use technically necessary cookies to provide basic functions. For product analytics we use PostHog with EU hosting. Analytics and convenience cookies are only set with your consent; you can withdraw this consent at any time with effect for the future. Where possible, IP addresses are processed in a shortened or pseudonymised form.
§ 7 Your rights as a data subject
You have the right at any time to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing (Art. 21 GDPR). You can withdraw any consent given at any time. To exercise your rights, an informal message to hello@guestelos.de is sufficient.
§ 8 Right to lodge a complaint with a supervisory authority
If you believe that the processing of your data violates data protection law, you have the right to lodge a complaint with a data protection supervisory authority. The responsible authority is that of the federal state in which our company is based (placeholder), or the authority of your usual place of residence.
See also: Legal notice · Terms · Home