Privacy Policy
Last updated: 30 August 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation is:
Knaust Operations GmbH
Vor dem Tore 6
99439 Am Ettersberg
Germany
Represented by Managing Director Steffen Knaust
Email: [email protected]
Registration court: Jena Local Court
Commercial register number: HRB 522070
VAT identification number: DE369881151
2. Scope
This Privacy Policy explains the processing of personal data when visiting kennerstays.com, when checking availability and making bookings, when making bookings through intermediary platforms, during online check-in and any identity verification offered, during payment processing, guest communication and the provision of digital access, in connection with statutory registration and retention obligations, and in connection with video surveillance of selected areas at the G1L property.
The German version of this Privacy Policy is the authoritative version. Translations into other languages are provided for information only. In the event of discrepancies or questions of interpretation, the German version shall prevail.
3. General legal bases
We process personal data in particular on the following legal bases:
- Art. 6(1)(a) GDPR for processing activities that require consent, in particular optional analytics functions and, where applicable, biometric identity data.
- Art. 6(1)(b) GDPR for pre-contractual measures and the performance of the accommodation contract, in particular availability, booking, stay, communication, payment and access.
- Art. 6(1)(c) GDPR for compliance with legal obligations, in particular tax, commercial, registration and municipal levy obligations.
- Art. 6(1)(f) GDPR for legitimate interests, in particular IT security, prevention of misuse, protection of property, enforcement of house rules and the establishment, exercise or defence of legal claims.
- Art. 9(2)(a) GDPR for biometric data used for unique identification, where explicit consent is required for this purpose.
Consent may be withdrawn at any time with effect for the future. The lawfulness of processing carried out before consent was withdrawn remains unaffected.
4. Visiting our website
4.1 Hosting, backend and server logs
Our website and the associated application programming interfaces are hosted by Uberspace. Caddy and a proprietary Fastify backend are used, among other technologies, for technical delivery.
When the website and its interfaces are accessed, the following data in particular may be processed:
- IP address and port
- date and time of access
- page, file or full URL accessed
- HTTP method, host and status code
- browser, device and operating system information
- referrer URL
- volume of data transferred
- technical error and security information
For availability and booking searches, the URLs accessed may also contain information about the destination, arrival, departure, adults and children.
The processing is carried out to provide the website securely, reliably and without errors, to analyse errors and to prevent abusive access, on the basis of Art. 6(1)(f) GDPR. Where the information is processed for a specific availability check or to take steps prior to entering into a contract, Art. 6(1)(b) GDPR also applies.
We have entered into a data processing agreement with Uberspace pursuant to Art. 28 GDPR. Processing takes place exclusively in Germany, another Member State of the European Union or a contracting state of the European Economic Area. Data may only be transferred to a third country with our prior consent and subject to the requirements of Art. 44 et seq. GDPR. The data will be deleted upon termination of the engagement or at our request. For technical reasons, deletion from backups may be delayed by up to seven weeks.
4.2 Cloudflare and country-based language selection
We use services provided by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, for the technical resolution of our domain, the protected forwarding of requests and the provision of a country code. When the Cloudflare proxy is enabled, requests are first routed through Cloudflare's global network and then forwarded to our server. In particular, Cloudflare may process the IP address, the URL accessed, HTTP headers including the language preferences transmitted by the browser, date and time, and technical routing and security information.
Cloudflare derives a two-letter country code from the IP address and transmits it to our server in the CF-IPCountry header. For the initial language selection, we combine this country code with the browser's language preferences. Our website uses only the country code as a geographic decision signal, not a city, coordinates or a precise location. If the country and language signals differ, a temporary prompt to switch between German and English may be displayed. The language can be changed manually at any time.
A manually selected language is stored locally in the browser under kenner-language and takes precedence over the automatic selection on subsequent visits. The IP address and country code are not stored in browser storage for this purpose. The temporary language prompt is dismissed automatically after 20 seconds. To prevent it from reappearing in the same tab, this is stored under kenner-language-suggestion-dismissed in session storage for the current browser session only.
Our processing is based on our legitimate interest in providing the website securely, reliably and in a suitable language pursuant to Art. 6(1)(f) GDPR. Storage of a language expressly selected by the user on the end device is based on section 25(2) TDDDG. To the extent that Cloudflare processes personal data on our behalf, Cloudflare's data processing terms apply. Processing in third countries, in particular the United States, may take place and is carried out only in compliance with the requirements of Art. 44 et seq. GDPR, in particular on the basis of an applicable adequacy decision or standard contractual clauses.
4.3 Cookies, browser storage and PWA cache
Our website uses cookies and comparable technologies. Technically necessary storage is used to provide functions expressly requested by the user. Access to the end device is based on section 25(2) TDDDG. Subsequent processing of personal data, where applicable, is based on Art. 6(1)(b) or (f) GDPR.
Non-essential storage and analytics functions are only activated after consent has been given. The legal bases are section 25(1) TDDDG and Art. 6(1)(a) GDPR.
| Storage | Purpose | Duration |
|---|---|---|
| kenner-analytics-consent | Stores the analytics selection | 180 days |
_ga and _ga_<ID> | Google Analytics after consent | no more than 180 days |
| gstw_public_chat_user | Guestway chat with name, email address, Guestway ID and chat token | 31 days |
| Guestway notification count | Displays unread messages | 24 hours |
| Guestway draft | Temporarily stores a chat draft | 10 minutes |
| Guestway branding | Displays the chat widget | 10 minutes |
| kenner-language | Stores the language expressly selected by the user; it takes precedence over automatic language selection | until deleted in the browser |
| kenner-language-suggestion-dismissed | Prevents the language prompt from reappearing in the same tab after it has been dismissed manually or automatically | until the browser session in that tab ends |
| Anonymous apartment rating | Stores a local rating preference | until deleted in the browser |
| Service worker and image cache | Faster display and PWA functionality | images for up to 30 days, with a maximum of 40 images |
| App files | Offline and PWA functionality | until the next update or deletion in the browser |
Consent can be changed or withdrawn at any time through the website's privacy settings.
4.4 Google Analytics 4
We use Google Analytics 4 for statistical analysis of the website. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The measurement ID used is G-2JD1VZQN23.
After consent has been given, page views, apartments viewed or selected, the start of a checkout, the opening of a success page and, where applicable, price and currency may be recorded. In addition, a booking search may record the destination, whether travel dates are present, the length of stay and party size in grouped categories, the status and number of availability results, validation errors, booking buttons used, page sections viewed for longer, internal or external links clicked, the chat entry point used and the opening of the Guestway chat. Link tracking only sends a fixed link identifier, the placement and type of link and a reduced destination. When a link marked by us from a Google Business Profile, our Instagram profile or a parameter-free Apple Maps link address specified by us is opened, a valid campaign combination specified by us may initially be held solely in the volatile memory of the open page. Before analytics consent, it is neither stored in the browser nor transmitted to Google; it is deleted if consent is refused. After consent, only the campaign source “Google”, “Apple Maps” or “Instagram”, the approved medium “organic” or “social”, the associated campaign identifier “Google Business Profile”, “Apple Business Profile” or “Instagram Profile” and, as campaign content, the destination Leipzig or Erfurt or the profile link “bio” may be transmitted to Google Analytics. Link text, complete external URLs, raw URL query parameters, telephone numbers and email addresses are not transmitted. Specific travel dates, exact party sizes, free text and chat content are likewise not sent to Google Analytics through these additional events. Device and browser information, usage data, approximate location information and online identifiers may also be processed.
Google Analytics is activated exclusively after explicit consent has been given. The legal bases are section 25(1) TDDDG and Art. 6(1)(a) GDPR. Advertising signals, ad personalisation and Google Signals are disabled.
Processing by Google LLC in the United States may take place. Any transfer is made only in compliance with the requirements of Art. 44 et seq. GDPR.
4.5 Guestway website chat
Our website uses a chat service provided by Guestway BV, Soenenspark 1, 9051 Ghent, Belgium. When the chat is loaded, connections may be established to widget.guestway.io, api.guestway.io, wss.guestway.io and imagine.guestway.io.
Depending on how the chat is used, the following data in particular may be processed:
- IP address and browser and device data
- name and email address
- chat ID and chat token
- messages and attachments
- timestamps and real-time status
- technical usage and connection data
The chat is not loaded automatically. When first visiting the website, the user decides whether to allow the chat through the consent banner. If consent was refused there, consent is requested separately when the chat is opened. Only after consent has been given will the widget be loaded, connections to Guestway established and data stored in the browser. The legal bases for accessing the end device and loading the chat are section 25(1) TDDDG and Art. 6(1)(a) GDPR.
If a person deliberately opens the chat, the processing is carried out to handle the enquiry on the basis of Art. 6(1)(b) GDPR where it concerns a booking or stay. For other enquiries, we base the processing on Art. 6(1)(f) GDPR.
4.6 Smoobu availability check
For availability checks, our backend transmits travel dates, number of persons, destination and apartment allocation server-side to Smoobu GmbH, Pappelallee 78/79, 10437 Berlin, Germany. The responses are cached temporarily in working memory.
The processing serves to check available accommodation and to take steps prior to entering into a contract pursuant to Art. 6(1)(b) GDPR. Where technical logs are kept for security and error analysis, processing is additionally carried out on the basis of Art. 6(1)(f) GDPR.
4.7 Smoobu booking engine
For direct bookings, users are redirected through booking.kennerstays.com to booking.smoobu.com. The apartment, destination, arrival, departure, adults and children may be transmitted in the process. The remainder of the booking and payment process takes place in the Smoobu booking engine.
In particular, names, contact details, address, information about fellow travellers, booking and stay data, invoice data, payment information and messages may be processed there. Smoobu processes guest data for handling bookings, communication and payment transactions as well as for automated messages activated by the host. Where necessary, data may be passed on to subprocessors used by Smoobu. Processing is carried out to take steps prior to entering into a contract and to perform the contract pursuant to Art. 6(1)(b) GDPR.
4.8 External links and locally embedded content
The website contains external links, for example to Google Maps. A connection to the relevant provider is established only when the link is clicked. Links are opened with noreferrer.
Payment logos are delivered as local images. Merely displaying them does not establish a connection to the payment companies shown.
Average ratings and rating counts from Booking.com and Airbnb are retrieved server-side at regular intervals. When a visitor approaches the Leipzig city guide, our server retrieves the displayed average ratings live through Places API (New). For this purpose, our server sends only the name and address of each place to Google; Google does not receive the visitor's IP address or any other visitor details. The Google response is stored neither on our server nor in the browser. No guest names or review texts are processed on the website. Visiting the website does not establish a direct browser connection to Booking.com, Airbnb or Google. Content provided by Google Maps Platform is subject to the Google Maps Platform Terms and the Google Privacy Policy.
We do not use external web fonts, embedded YouTube or Vimeo videos, social media pixels, newsletter services, embedded Google Maps maps or public reCAPTCHA.
5. Enquiries and guest communication
If you contact us by email, telephone, WhatsApp, through a booking portal or through Guestway, we process the data you provide. This may include, in particular, your name, email address, telephone number, profile and account data, messages, attachments, timestamps, communication metadata and booking data.
Where the communication concerns a booking or stay, processing is carried out on the basis of Art. 6(1)(b) GDPR. We handle other enquiries on the basis of Art. 6(1)(f) GDPR.
Email is our standard communication channel. Our email inboxes are hosted by Webgo. During email communication, Webgo processes, in particular, sender and recipient addresses, message content, attachments, timestamps and technical connection and log data. Processing serves to handle enquiries and perform the accommodation contract pursuant to Art. 6(1)(b) GDPR. Other business communications are processed on the basis of Art. 6(1)(f) GDPR.
We use Telekom services for telephone communication. In particular, telephone numbers, connection times, connection duration and other technical traffic data may be processed. Depending on the reason for the communication, processing is carried out pursuant to Art. 6(1)(b) or (f) GDPR.
WhatsApp may be used as an optional channel. The provider is WhatsApp Ireland Limited, Merrion Road, Dublin 4, Ireland. Processing by affiliated companies in third countries, in particular the United States, may take place. Communication by email remains available.
6. Bookings and performance of the contract
Depending on the booking channel, we process the following data in particular in connection with enquiries, bookings and stays:
- first and last name
- address
- email address and telephone number
- booking and stay data
- arrival and departure
- number and details of fellow travellers
- invoice and payment information
- language
- messages and special requests
- where applicable, information about pets or business bookings
- data relating to the granting of access
- information used to handle damage and claims
Processing is carried out to take steps prior to entering into, perform and administer the accommodation contract on the basis of Art. 6(1)(b) GDPR. Processing required by law is carried out pursuant to Art. 6(1)(c) GDPR. Where necessary, we process data for the establishment, exercise or defence of legal claims pursuant to Art. 6(1)(f) GDPR.
7. Booking platforms and data sources
Bookings may be made directly with us or through external booking platforms, in particular Booking.com, Airbnb and FeWo-direkt or Vrbo. These platforms process personal data in accordance with their own privacy policies and provide us with the data required to perform the booking.
In particular, we may receive master data, contact data, booking and stay data, communication data and payment status data. The legal basis for our subsequent processing is generally Art. 6(1)(b) GDPR.
Where data is not collected directly from the data subject, it originates in particular from the person making the booking, a fellow traveller or the booking platform used.
8. Guest portal, online check-in and Guestway
We use Guestway BV, Soenenspark 1, 9051 Ghent, Belgium, KBO/BCE 0798.195.974, VAT ID BE 0798.195.974, for the personal guest portal, online check-in, guest communication, automations and other operational processes. Privacy enquiries to Guestway may be sent to [email protected].
The following data in particular may be processed:
- master data and contact details
- booking and stay data
- data relating to fellow travellers
- communication content and attachments
- check-in data
- identity verification information
- technical usage and connection data
- data used to generate and transmit an access code
According to the provider, Guestway operates the platform on AWS in the European Union, region eu-west-1, Ireland. Guest data is stored there. Guestway processes the data as a processor on the basis of a data processing agreement pursuant to Art. 28 GDPR. Processing is carried out to provide the agreed services and in accordance with documented instructions.
Processing is generally carried out to perform the accommodation contract pursuant to Art. 6(1)(b) GDPR. Where legal obligations are fulfilled, Art. 6(1)(c) GDPR applies.
9. Digital identity verification, identity document and selfie
Where digital identity verification is offered as part of online check-in, identity document data, images of the front and back of the identity document, a selfie, technical device and connection data, liveness information, verification results and information relating to misuse or fraud prevention may be processed.
Where biometric features are derived from a facial image for the purpose of unique identification and compared with the photograph on the identity document, these constitute special categories of personal data. Such processing is carried out only after explicit consent has been given pursuant to Art. 6(1)(a) and Art. 9(2)(a) GDPR.
As an alternative that does not involve biometric selfie matching, identity verification by video call or manual verification is offered. Refusing the biometric procedure will not result in refusal of the stay if the person's identity can be reliably verified by an alternative method.
Guestway and Didit Identity Spain, S.L. may be involved in the technical implementation. According to the provider, Didit is used as a subprocessor of Guestway. According to the provider, the data is processed on AWS in the European Union. Identity document images and biometric data are intended to be processed only temporarily. As a general rule, only the verification result is intended to be stored.
10. Statutory registration requirements
For foreign guests, we process the registration form data required under sections 29 and 30 of the German Federal Registration Act (Bundesmeldegesetz). This may include, in particular, arrival, expected departure, first and last name, date of birth, nationality, address, information about foreign fellow travellers and the serial number of a recognised and valid passport or passport replacement document.
The required information is requested during online check-in through the registration form in Guestway described in section 8. The information is compared with the identity document. The legal basis is Art. 6(1)(c) GDPR in conjunction with sections 29 and 30 of the German Federal Registration Act.
Registration form data is retained for twelve months from the date of departure and destroyed or deleted within three months after this period expires. Access is restricted to authorised persons.
There is no general special registration form obligation for German guests under these provisions. Their data is processed where required for the contract, access, invoicing, municipal levies or other legal obligations.
11. Payment processing
For direct bookings, we currently offer PayPal and the following payment methods processed through Stripe Connect: credit card, iDEAL, Bancontact, EPS, Przelewy24 and Apple Pay. Other payment methods available in the Smoobu booking engine are currently not activated.
11.1 Stripe
When a payment is made through Stripe, the required data is transmitted to Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. This may include name, contact details, invoice data, payment amount, payment information, IP address, device information and fraud prevention data.
11.2 PayPal
When a payment is made through PayPal, the required data is transmitted to PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg. This may include name, contact details, payment amount, transaction data and other information requested by PayPal.
Processing is carried out for payment processing pursuant to Art. 6(1)(b) GDPR. Where payment service providers comply with legal obligations, perform fraud prevention or carry out their own risk assessments, they process data under their own responsibility.
12. Digital access codes and locking system
We use Nuki to provide digital access. In particular, the booking reference, property, access period, access code, lock or device identifier and access and event data may be processed.
Processing is carried out to perform the accommodation contract pursuant to Art. 6(1)(b) GDPR. Where logs are required for security, misuse prevention or error analysis, processing is additionally carried out on the basis of Art. 6(1)(f) GDPR.
Access codes may be sent to guests through the guest portal or other communication channels.
13. Cleaning, maintenance and operational service providers
Data required to prepare for and carry out stays and to handle technical faults may be passed on to employees and cleaning and maintenance service providers. This generally concerns the property, stay period, occupancy status, cleaning status and specific operational information, and includes names or other details only where required for the assignment.
Processing is carried out to perform the contract pursuant to Art. 6(1)(b) GDPR and for proper organisation, security and maintenance pursuant to Art. 6(1)(f) GDPR. Access is restricted on a need-to-know basis.
14. Accounting, invoices and tax obligations
We process master data, booking data, invoice data, payment data and communication data to issue invoices, maintain accounts, allocate payments and comply with tax obligations. DATEV, Lexoffice, banks and tax advisers may be involved.
The legal basis is Art. 6(1)(c) GDPR in conjunction with the applicable tax and commercial law provisions. To the extent that processing serves to administer the contract or ensure proper business organisation, Art. 6(1)(b) and (f) GDPR also apply.
Documents subject to retention obligations are generally stored for six, eight or ten years, depending on their type. Longer storage may be required where documents are needed for ongoing tax, audit or legal proceedings.
15. Best price guarantee, damage and legal defence
When reviewing a best price guarantee claim, submitted links, screenshots, comparison offers, booking data and communications may be processed.
In the event of damage, special cleaning, claims or legal disputes, photographs, damage descriptions, booking and payment data, communications, witness statements and other evidence in particular may be processed.
Processing is carried out to perform the contract pursuant to Art. 6(1)(b) GDPR and for the establishment, exercise or defence of legal claims pursuant to Art. 6(1)(f) GDPR.
16. Wi-Fi
Where we provide guests with internet access, the router or internet provider used may process technical connection data. This may include, in particular, IP and MAC addresses, device names, connection times and technical error data.
Processing is carried out to provide and secure internet access pursuant to Art. 6(1)(b) and (f) GDPR.
17. Video surveillance at the G1L property
At the G1L property, we use visible video surveillance in selected areas of the hallway and courtyard. The interiors of apartments are not monitored. Public roads and third-party property are not recorded. Signs at the property draw attention to the video surveillance.
The purposes are to enforce house rules, protect guests, employees, property and technical equipment, prevent and investigate damage, unauthorised access and criminal offences, and reconstruct reported incidents.
The legal basis is Art. 6(1)(f) GDPR. We use UniFi Protect. Recordings are stored locally on a Dream Machine SE. Access to live images and recordings is restricted to authorised persons at Knaust Operations GmbH.
The regular storage period is 14 days. Recordings are then automatically deleted or overwritten. If a specific incident becomes known, necessary sequences may be stored separately until the handling, prosecution or defence of claims has been concluded.
Recipients of secured recordings may, where necessary, include the police, public prosecutor's office, courts, insurers or legal advisers.
18. Data relating to fellow travellers and minors
When a booking is made by a primary booker or through a platform, we may not receive data relating to fellow travellers directly from those individuals. We process only the information required for the stay, registration requirements, invoicing, access and security.
The primary booker is requested to inform fellow travellers of this Privacy Policy. For minors, only the information required for the relevant purpose is processed. Depending on the purpose, the legal bases are Art. 6(1)(b), (c) or (f) GDPR.
19. Recipients of personal data
Depending on the process, personal data may be transmitted in particular to the following recipients:
- booking and intermediary platforms
- Smoobu as a booking and channel management service
- Guestway for the guest portal, communication, check-in and identity verification, and Didit Identity Spain, S.L. as a subprocessor for identity verification
- payment service providers and banks
- providers of digital locking and access systems
- hosting, IT, communication and analytics service providers
- tax advisers, accounting service providers and legal advisers
- cleaning, maintenance and other service providers
- public authorities and municipal bodies where required by law
- police, public prosecutor's offices, courts or insurers in connection with specific incidents
Processors are engaged on the basis of an agreement pursuant to Art. 28 GDPR where required by law. Other recipients process data under their own responsibility.
20. Processing outside the European Economic Area
Some service providers or their subprocessors may process data outside the European Union or the European Economic Area, in particular in the United States.
Such a transfer is made only where the requirements of Art. 44 et seq. GDPR are met. In particular, this may be based on an adequacy decision, a valid certification under the EU-US Data Privacy Framework, standard contractual clauses of the European Commission or a statutory derogation. Where required, we assess additional safeguards.
According to the provider, Guestway operates the platform on AWS in the European Union, region eu-west-1, Ireland. According to information provided by Guestway, Didit is also intended to store data on AWS in the European Union.
21. Storage periods and deletion
We store personal data only for as long as required for the relevant purpose or for as long as statutory retention obligations apply. The relevant factors include, in particular, the purpose of processing, the duration of the contract, statutory retention periods and the need to establish or defend claims.
| Data category | Period or criterion |
|---|---|
| Registration forms for foreign guests | 12 months from departure, followed by destruction or deletion within 3 months |
| G1L video recordings | normally 14 days; secured incident recordings until handling is concluded |
| Booking records and invoices | generally 8 years |
| Other business documents subject to retention obligations | generally 6 or 10 years, depending on their type |
| Google Analytics cookies | no more than 180 days |
| Google Analytics event and user data | up to 14 months |
| Guestway browser data | 10 minutes, 24 hours or 31 days, depending on the entry |
| PWA image cache | up to 30 days |
| Claim and damage data | until the matter has been concluded and applicable limitation periods have expired |
| Records of consent | for as long as required to demonstrate lawfulness |
Where no fixed period is specified for an individual data category, the data will be deleted as soon as the purpose of processing no longer applies and there are no statutory retention obligations or legitimate grounds for continued storage.
22. Obligation to provide data
You are required to provide only the personal data necessary to enter into and perform the accommodation contract or required by law. Without the required information, we may be unable to process a booking or payment, verify identity, grant access or complete a registration required by law.
Consent to biometric selfie matching is not mandatory if identity can be reliably established through the video call offered or through manual verification.
23. Automated decision-making and profiling
We do not make decisions based solely on automated processing that produce legal effects or similarly significantly affect a person within the meaning of Art. 22 GDPR.
24. Data security
We take appropriate technical and organisational measures to protect personal data. These include, in particular, role-based access, secure passwords, two-factor authentication, encrypted transmission, regular reviews of authorisations, restricted disclosure to service providers and documented deletion and incident response processes.
Paper registration forms are stored securely under lock and key and destroyed securely after the statutory retention period expires.
25. Rights of data subjects
Subject to the statutory requirements, you have the right of access pursuant to Art. 15 GDPR, rectification pursuant to Art. 16 GDPR, erasure pursuant to Art. 17 GDPR, restriction of processing pursuant to Art. 18 GDPR, data portability pursuant to Art. 20 GDPR, objection pursuant to Art. 21 GDPR and withdrawal of consent pursuant to Art. 7(3) GDPR.
To exercise your rights, please contact [email protected].
Where we process data on the basis of legitimate interests, you may object on grounds relating to your particular situation.
You also have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority responsible for the company's registered office is generally the Thuringian State Commissioner for Data Protection and Freedom of Information. You may also contact the supervisory authority for your place of residence.
26. Updates to this Privacy Policy
We update this Privacy Policy when our services, systems used, data flows or legal requirements change.
Last updated: 30 August 2026