PRIVACY POLICY
1. Controller
The controller responsible for the processing of personal data on this website is:
Fürst von Hohenzollern Group of Companies
Karl-Anton-Platz 2
72488 Sigmaringen
Germany
Phone: +49 7571 729-0
Email:
The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.
2. Data Protection Officer
We have appointed a Data Protection Officer for our company:
Ulrike Eben
Panoramastraße 17
88271 Wilhelmsdorf
Germany
Phone: +49 151 17640968
Email:
3. General Information on Data Processing
We process personal data only insofar as this is necessary to provide our website and services, there is a legal basis for the processing, or you have consented to the processing.
Personal data means any information relating to an identified or identifiable natural person.
In particular, the following legal bases may apply:
- Art. 6(1)(a) GDPR – consent,
- Art. 6(1)(b) GDPR – performance of a contract and pre-contractual measures,
- Art. 6(1)(c) GDPR – compliance with legal obligations,
- Art. 6(1)(f) GDPR – legitimate interests.
Personal data is generally stored only for as long as necessary for the respective purpose of processing. Statutory retention obligations remain unaffected.
4. Hosting and Server Log Files
This website is hosted by an external service provider. When you access our website, information is automatically collected by the web server in so-called server log files.
This may include in particular:
- IP address,
- date and time of access,
- page or file accessed,
- referrer URL,
- browser type and browser version,
- operating system used,
- hostname of the accessing device.
The processing is carried out to ensure the secure, technically error-free and efficient provision of our website, as well as for error analysis and the prevention of misuse.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and technically reliable provision of our online services.
Where our hosting provider processes personal data on our behalf, such processing is carried out on the basis of a data processing agreement pursuant to Art. 28 GDPR.
5. Contact by Email or Telephone
If you contact us by email or telephone, we process the personal data you provide in order to deal with your enquiry.
If your enquiry relates to the initiation or performance of a contract, the processing is carried out on the basis of Art. 6(1)(b) GDPR.
In all other cases, processing is carried out on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in the appropriate handling of enquiries addressed to us.
The data will be deleted once the purpose of the processing no longer applies and no statutory retention obligations or other legal grounds require further storage.
6. Cookies and Similar Technologies
Our website uses cookies and similar technologies. Cookies are small data records that are stored on your device or enable access to information already stored on your device.
Where the storage of information on your device or access to information already stored on your device is strictly necessary to provide a digital service expressly requested by you, this is carried out on the basis of Section 25(2) of the German Telecommunications Digital Services Data Protection Act (TDDDG).
For cookies and similar technologies that are not strictly necessary, we obtain your consent before they are used. In this case, information is stored on your device or accessed on the basis of Section 25(1) TDDDG. Any associated processing of personal data is carried out, where applicable, on the basis of Art. 6(1)(a) GDPR.
You may withdraw or change your consent at any time with effect for the future via the cookie settings on our website.
7. CookieFirst – Consent Management
We use the consent management service CookieFirst to manage cookie settings and consent.
The provider is:
Digital Data Solutions B.V.
Plantage Middenlaan 42a
1018 DH Amsterdam
The Netherlands
CookieFirst enables us to store your decisions regarding the use of cookies and similar technologies and to document whether consent has been given or refused.
In particular, the following information may be processed:
- consent status and any changes to or withdrawal of consent,
- anonymised IP address,
- information about the browser used,
- information about the device used,
- date and time of consent or changes to your settings,
- URL of the page on which consent was saved or changed,
- approximate location, and
- a unique identifier (UUID) used to associate the stored consent.
The processing is carried out in order to comply with our legal obligations to obtain and document consent on the basis of Art. 6(1)(c) GDPR.
Where Digital Data Solutions B.V. processes personal data on our behalf, such processing is carried out on the basis of a data processing agreement pursuant to Art. 28 GDPR.
Cookies and Similar Technologies Currently in Use
Below you will find an up-to-date overview of the cookies and similar technologies used on our website. The overview is provided via CookieFirst and is updated regularly.
8. Vimeo Background Video
On our homepage, we use a background video provided by Vimeo.
The provider is:
Vimeo.com, Inc.
330 West 34th Street, 10th Floor
New York, NY 10001
USA
The video is embedded as a background element on the homepage and is automatically loaded and played when the page is accessed. For technical reasons, this establishes a connection to Vimeo servers. In particular, your IP address and technical information about your browser, device and page access may be transmitted to Vimeo.
The Vimeo player is embedded with the Do Not Track (DNT) function enabled. This restricts or prevents the collection of session data and analytics by the Vimeo player. Vimeo states that certain technically necessary security cookies may nevertheless be used even when DNT is enabled. These are used in particular for the secure operation of the player, bot prevention and securing data traffic.
The background video is embedded and the associated data processing is carried out on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in the high-quality multimedia and visual presentation of Hohenzollern Castle and its services.
Where storage or access operations on your device are strictly necessary to provide the digital service expressly requested by you, they are carried out on the basis of Section 25(2) TDDDG.
Vimeo is a provider based in the United States. Where personal data is transferred to the United States or other third countries, such transfer is carried out in accordance with the requirements of Art. 44 et seq. GDPR.
Further information on the processing of personal data can be found in Vimeo's privacy information.
9. External Links and Google Maps
Our website contains links to external websites. These include, in particular, links to Google Maps.
Where Google Maps or another external service is provided solely by means of an external link, no personal data is transmitted by us to the operator of the linked website when you access our website. Only when you click on such a link do you leave our website and establish a connection to the respective provider.
The respective provider's privacy policy applies to any subsequent processing of personal data.
10. Online Ticket Booking via bookingkit
We use the bookingkit booking and ticketing system for online bookings, the purchase of admission tickets and the booking of events.
The provider is:
bookingkit GmbH
Sonnenallee 223
12059 Berlin
Germany
As part of a booking, the personal data required to carry out and process the booking is processed. This may include in particular:
- first and last name,
- address,
- email address,
- telephone number, where provided or required,
- event or service booked,
- date and number of tickets,
- booking and transaction data,
- billing information,
- payment information, and
- technical data.
The processing is carried out for the purpose of taking pre-contractual measures and performing the contract concluded with you on the basis of Art. 6(1)(b) GDPR.
Where data must be retained due to statutory commercial or tax retention obligations, further processing is carried out on the basis of Art. 6(1)(c) GDPR.
Where bookingkit processes personal data on our behalf, such processing is carried out on the basis of a data processing agreement pursuant to Art. 28 GDPR.
bookingkit may use technically necessary cookies and similar technologies as part of the booking process. Other services, such as mapping services, may also be integrated within the booking environment provided by bookingkit. The bookingkit privacy information additionally applies to data processing within the environment provided by bookingkit.
11. Payment Processing via Stripe
Online payments within our booking system are processed via Stripe.
For users in the European Economic Area, payment processing involves companies of the Stripe group based in Ireland. These include in particular:
Stripe Payments Europe, Limited
1 Grand Canal Street Lower
Grand Canal Dock
Dublin D02 H210
Ireland
Depending on the type of payment service, other companies of the Stripe group may also be involved.
In connection with payment processing, the following data in particular may be processed:
- name,
- contact details,
- billing information,
- payment data,
- selected payment method,
- amount and currency,
- transaction data, and
- IP address and other technical data.
The processing is carried out in order to process the payment requested by you and therefore to perform the contract pursuant to Art. 6(1)(b) GDPR.
Stripe may also process certain personal data under its own responsibility as a data controller, in particular where this is necessary for payment processing, fraud prevention, security or compliance with legal obligations.
Depending on the payment method selected, additional payment service providers and card or payment networks may be involved in processing the payment.
12. Card Payments
If you select card payment, the payment is processed via Stripe and the respective card and payment networks involved.
The payment and transaction data required to authorise and process the payment is processed for this purpose.
As a general rule, we receive only the information required to process and allocate the payment and do not receive your complete card details.
The legal basis is Art. 6(1)(b) GDPR.
13. PayPal
PayPal is available as a payment method within our online ticket shop.
The provider for users in Germany is:
PayPal (Europe) S.à r.l. et Cie, S.C.A.
22–24 Boulevard Royal
L-2449 Luxembourg
If you select PayPal as your payment method, the data required to process the payment will be transmitted to or processed by PayPal.
This may include, in particular, your name, contact details, payment information, transaction amount and other information required to process the payment.
The processing is carried out in order to provide the payment method selected by you and to perform the contract pursuant to Art. 6(1)(b) GDPR.
PayPal's privacy policy additionally applies to the further processing of personal data by PayPal.
14. Transfers of Data to Third Countries
When individual services are used, personal data may be processed outside the European Union or the European Economic Area.
Where personal data is transferred to a third country, this is carried out in accordance with the requirements of Art. 44 et seq. GDPR. Such transfers may in particular be based on an adequacy decision by the European Commission, appropriate safeguards such as the European Commission's Standard Contractual Clauses, or other transfer mechanisms provided for by law.
15. Video Surveillance
For the protection of visitors, employees, buildings, works of art and cultural assets and other property, as well as for the exercise of our domiciliary rights, appropriately signposted areas of Hohenzollern Castle are subject to video surveillance.
Video surveillance serves in particular:
- the protection of persons,
- the protection of works of art, cultural assets and other property,
- the exercise of our domiciliary rights, and
- the prevention and, where appropriate, investigation of criminal offences.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interests include, in particular, the protection of persons, cultural assets and other property and the exercise of our domiciliary rights.
Areas subject to video surveillance are identified by appropriate notices.
Recordings are generally deleted or overwritten after no more than 72 hours, unless they are required for a longer period due to a specific incident for investigation, for the establishment, exercise or defence of legal claims, or for disclosure to competent authorities. In such cases, the relevant recordings will be retained only for as long as necessary for the respective purpose.
16. Retention Period
Unless a more specific retention period is stated in this Privacy Policy, we retain personal data only for as long as necessary for the respective purpose of processing.
Where statutory retention obligations apply, in particular under commercial or tax law, the relevant data will be retained for the duration of the statutory retention period and subsequently deleted unless there is another legal basis for further processing.
17. Your Rights
Subject to the applicable statutory requirements, you have in particular the following rights:
- right of access pursuant to Art. 15 GDPR,
- right to rectification pursuant to Art. 16 GDPR,
- right to erasure pursuant to Art. 17 GDPR,
- right to restriction of processing pursuant to Art. 18 GDPR,
- right to data portability pursuant to Art. 20 GDPR,
- right to object pursuant to Art. 21 GDPR.
Where processing is based on your consent, you may withdraw that consent at any time with effect for the future pursuant to Art. 7(3) GDPR. The lawfulness of processing carried out before the withdrawal of consent remains unaffected.
18. Right to Object
Where we process personal data on the basis of Art. 6(1)(f) GDPR, you have the right pursuant to Art. 21 GDPR to object to the processing at any time on grounds relating to your particular situation.
Where personal data is processed for direct marketing purposes, you have the right to object to processing for such purposes at any time.
19. Right to Lodge a Complaint with a Supervisory Authority
Pursuant to Art. 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes the GDPR.
In particular, you may contact the supervisory authority of your habitual residence, your place of work or the place of the alleged infringement.
For companies based in Baden-Württemberg, the competent supervisory authority is in particular:
The State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (LfDI Baden-Württemberg)
20. SSL/TLS Encryption
For security reasons and to protect the transmission of confidential information, this website uses SSL/TLS encryption.
You can recognise an encrypted connection, in particular, by the fact that the address line of your browser begins with “https://”.
21. Current Version of this Privacy Policy
Last updated: August 2026
We reserve the right to amend this Privacy Policy if the services used, the processing of personal data or legal requirements change.