resmio »
1. General Information
Thank you for your interest in resmio. Protecting your personal data is important to us.
Below you will find information on how we handle your personal data when you use our website https://www.resmio.com/en/ and related online services (app.resmio.com), social media presences (e.g., Facebook and Instagram), functions, and content.
Personal data includes all data that can personally identify you.
We process data in accordance with statutory data protection regulations, including the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
1.1 Contact details of the controller
This privacy policy applies to data processing by:
resmio GmbH
Katzwanger Straße 150
90461 Nuremberg
0911 3749230
support@resmio.com
The controller for the processing of personal data is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.
1.2 Contact details of the data protection officer
PROLIANCE GmbH / www.datenschutzexperte.de
Data Protection Officer
Leopoldstr. 21
80802 Munich
datenschutzbeauftragter@datenschutzexperte.de
1.3 Cooperation with processors and third parties
If we disclose, transmit, or grant access to data to processors or third parties, this is done solely on a legal basis – namely with your consent (Art. 6 (1) (a) GDPR), for the performance of a contract (lit. b, e.g., payment providers), to comply with a legal obligation (lit. c), or based on our legitimate interests (lit. f, e.g., web hosts, IT service providers).
We do not transmit data for purposes other than those stated in this policy. Internally, only persons who need your data to fulfill contractual and legal obligations receive it.
If we commission third parties to process data, this is done based on a data processing agreement under Art. 28 GDPR. We have concluded the necessary data protection agreements with all affected service providers.
1.4 Data transfer to third countries
If we process data in a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)) or if this occurs in the context of using third-party services or disclosing/transmitting data to third parties, this is only done to fulfill our (pre)contractual obligations, based on your consent, due to a legal obligation, or based on our legitimate interests.
We base the transfer of data to the USA on the EU Commission’s adequacy decision for the EU-US Data Privacy Framework (DPF). US companies certified under the DPF provide an adequate level of data protection. You can view the certification status of our service providers at https://www.dataprivacyframework.gov/.
If there is no adequacy decision for a third country or if a US service provider is not certified, we only process data or have it processed if the special requirements of Art. 44 et seq. GDPR are met. This means the processing occurs based on specific guarantees, such as the officially recognized standard contractual clauses (SCC) of the EU Commission or binding corporate rules.
2. Information about the processing of personal data
2.1 Data collection when visiting our website
When you simply visit our website, i.e., if you do not register or otherwise transmit information to us, we only process the data that your browser transmits to our server (“server log files”). This information is temporarily stored in a log file. When you visit our website, we automatically collect the following data to display the website:
- Our visited website
- Date and time of access
- Source or reference from which you reached the site (“referrer URL”)
- Access status (file transferred, file not found, etc.)
- Web browser and operating system used
- IP address of the requesting computer, anonymized if applicable
- Amount of data transferred
We collect the listed data to ensure a smooth connection to the website and to enable comfortable use of our site by users. Additionally, the log file serves to evaluate system security and stability as well as for administrative purposes.
The legal basis for the temporary storage of data and log files is Art. 6 (1) (f) GDPR.
Our legitimate interest follows from the data collection purposes listed above. Under no circumstances do we use the collected data to draw conclusions about your person.
For technical security reasons, especially to ward off attempted attacks on our web server, we may temporarily store this data. After a maximum of seven days, the data is anonymized by shortening the IP address at the domain level, making it impossible to establish a connection to the individual user. There is no evaluation of this data except for statistical purposes in anonymized form.
We do not merge this data with other data sources.
Furthermore, we use cookies and analysis services when you visit our website.
You will find more detailed explanations in sections 3, 5, and 7 of this privacy policy.
(1) Type of data processed
- Inventory data (e.g., names, addresses).
- Contact data (e.g., email, phone numbers).
- Content data (e.g., text input, photographs, videos).
- Usage data (e.g., visited websites, interest in content, access times).
- Meta/communication data (e.g., device information, IP addresses).
(2) Categories of data subjects
Visitors and users of the online service (hereinafter collectively referred to as “users”).
(3) Purpose of processing
- Providing the online service, its functions, and content.
- Answering contact requests and communicating with users.
- Security measures.
- Reach measurement/marketing.
(4) Retention period for personal data
The server log files generated during a mere website visit are anonymized after a maximum of seven days (see above). For general storage and deletion principles, see section 11.
2.2 Data disclosure
For the bases and requirements of disclosure to third parties, see section 1.3.
2.3 Data collection during the application process
We process applicant data only for the purpose of the application process in accordance with statutory requirements. Applicant data is processed to fulfill our (pre-)contractual obligations during the application process under Art. 6 (1) (b), (f) GDPR, § 26 BDSG.
The application process requires applicants to provide us with their applicant data. If we offer an online form, the necessary applicant data is marked and results from the job descriptions. Required details include personal information, postal and contact addresses, and documents belonging to the application, such as cover letter, CV, and certificates. Applicants may voluntarily provide us with additional information.
By submitting the application to us, applicants consent to the processing of their data for the purposes of the application process in the manner and scope set out in this privacy policy.
If special categories of personal data under Art. 9 (1) GDPR are voluntarily communicated during the application process, they are additionally processed under Art. 9 (2) (b) GDPR (e.g., health data, such as severe disability status or ethnic origin). If special categories of personal data are requested from applicants during the application process, they are additionally processed under Art. 9 (2) (a) GDPR (e.g., health data if necessary for the exercise of the profession).
If provided, applicants can submit their applications using an online form on our website. The data is transmitted to us using state-of-the-art encryption.
Applicants can also send us their applications via email.
Note that emails are not sent encrypted, and applicants themselves must ensure encryption. We assume no responsibility for the transmission path of the application between the sender and the receiver on our server.
Upon the applicant’s request, the data provided by them will be forwarded to our recruitment clients. Our clients are themselves responsible for careful data processing under the GDPR and are liable for any breaches.
Applicant data will be deleted after a period of six months, subject to a justified withdrawal by the applicant (e.g., an explicit request to be contacted for other potential vacancies via email or phone), so that we can answer any follow-up questions about the application and meet our evidence obligations under the Equal Treatment Act.
3. Cookies
Our website uses cookies that the browser stores on your device and that contain certain settings for using the website (e.g., for the current session). Cookies serve to make our offering more user-friendly, effective, and secure.
Cookies are small text files placed on your computer and stored by your browser. Most cookies we use are “session cookies”, which are automatically deleted after closing the browser. Other cookies remain on your device until you delete them or their storage period expires. These cookies allow us to recognize your browser on your next visit.
In some cases, cookies serve to simplify website processes by saving settings (e.g., remembering previously selected options). If personal data is also processed by individual cookies we implement, processing occurs under Art. 6 (1) (b) GDPR either to execute the contract or under Art. 6 (1) (f) GDPR to safeguard our legitimate interests in ensuring optimal website functionality and a customer-friendly, effective page visit.
We also use cookies to statistically record website usage and evaluate it to optimize our offering for you. These cookies enable us to automatically recognize that you have visited us before when you return to our site. These cookies are automatically deleted after a defined period.
You can configure your browser to inform you about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or generally, and activate the automatic deletion of cookies when closing the browser. Cookie settings can be managed via the following links for the respective browsers:
- Firefox: https://support.mozilla.org/de/kb/cookies-erlauben-und-ablehnen
- Internet Explorer: https://support.microsoft.com/de-de/help/17442/windows-internet-explorer-delete-manage-cookies
- Chrome: https://support.google.com/chrome/answer/95647?hl=de&co=GENIE.Platform=Desktop
- Safari: https://support.apple.com/de-de/guide/safari/sfri11471/mac
- Opera: https://help.opera.com/de/latest/web-preferences/
You can also individually manage the cookies of many companies and functions used for advertising. Use the corresponding user tools available at https://www.aboutads.info/choices/ or http://www.youronlinechoices.com/uk/your-ad-choices
Most browsers also offer a “Do Not Track” function, allowing you to indicate that you do not want to be “tracked” by websites. When this function is enabled, the respective browser informs advertising networks, websites, and applications that you do not want to be tracked for behavioral advertising and similar purposes.
Information and instructions on how to edit this function can be found via your browser provider at the following links:
- Google Chrome: https://support.google.com/chrome/answer/2790761?co=GENIE.Platform%3DDesktop&hl=de
- Mozilla Firefox: https://support.mozilla.org/de/kb/wie-verhindere-ich-dass-websites-mich-verfolgen
- Microsoft Edge: https://support.microsoft.com/de-de/microsoft-edge/weitere-informationen-zur-tracking-verhinderung-in-microsoft-edge-5ac125e8-9b90-8d59-fa2c-7f2e9a44d869
- Opera: https://help.opera.com/en/opera36/be-safe-and-private/#notrack
- Safari: https://support.apple.com/de-de/guide/safari/sfri40732/mac
Additionally, you can prevent the loading of scripts by default. NoScript allows JavaScript, Java, and other plugins to run only on trusted domains of your choice. Information and instructions on how to edit this function can be obtained from your browser provider (e.g., for Mozilla Firefox at: https://addons.mozilla.org/de/firefox/addon/noscript/).
Please note that disabling cookies may limit the functionality of this website.
4. Contact forms
When you contact us – via contact form, email, phone, or in-app chat – we process your information exclusively to handle and answer your request, including the associated technical administration. The data collected by a contact form is shown in the respective form. Your request is stored in our CRM system Odoo.
The legal basis is our legitimate interest in answering your request (Art. 6 (1) (f) GDPR). If your contact aims to initiate or conclude a contract, Art. 6 (1) (b) GDPR serves as an additional or alternative legal basis.
We delete the data as soon as your request is fully clarified and no statutory retention obligations prevent deletion.
5. Analysis tools
5.1 Tracking tools
We only use the following tracking measures if you have previously consented via our consent tool. Storing or accessing information on your device occurs based on your consent under § 25 (1) TDDDG; we base the subsequent processing of personal data on Art. 6 (1) (a) GDPR. You can withdraw your consent at any time with future effect via the cookie settings.
With the tracking measures used, we want to ensure a tailored design and the continuous optimization of our website.
We also use tracking measures to statistically record the use of our website and evaluate it for optimizing our offering for you. These interests are considered legitimate within the meaning of the aforementioned provision.
The respective data processing purposes and data categories can be found in the corresponding tracking tools.
(1) Google Analytics
This website uses Google Analytics, a web analysis service from Google Inc. (“Google”). The legal basis for using Google Analytics is Art. 6 (1) (f) GDPR.
Google Analytics uses “cookies”, text files stored on your computer that enable an analysis of your website use. The information generated by the cookie about your use of this website is transmitted to and processed by Google. Google Analytics 4 (GA4) does not log or store complete IP addresses. For visits from the EU, collection takes place via servers within the EU; the IP address is only used briefly to derive a rough, location-based indication and is then discarded before the data is logged.
On behalf of resmio GmbH, Google will use this information to evaluate your use of the website, compile reports on website activity, and provide other services related to website activity and internet usage to the website operator.
The IP address transmitted by your browser within the scope of Google Analytics is not merged with other Google data.
You can prevent Google Analytics collection by installing the browser plugin available at https://tools.google.com/dlpage/gaoptout?hl=de. General instructions for managing and disabling cookies are in section 3.
We use Google Analytics to analyze and regularly improve the use of our website. The statistics gained allow us to improve our offering and make it more interesting for you as a user.
If personal data is transferred to the USA, this transfer is based on the EU Commission’s adequacy decision for the EU-US Data Privacy Framework (DPF), under which Google LLC is certified (Art. 45 GDPR).
Third-party information: Google Dublin, Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, Fax: +353 (1) 436 1001. Terms of use: https://marketingplatform.google.com/about/analytics/terms/de/, privacy overview: https://support.google.com/analytics/answer/6004245?hl=de&ref_topic=2919631, and the privacy policy: https://policies.google.com/privacy?hl=de&gl=de.
(2) Google Ads
We use Google Ads on our website, a service from Google Ireland Limited, Google Building Gordon House, Barrow St, Dublin 4, Ireland.
Google Ads allows us to draw attention to our attractive offers with the help of advertising materials on external websites. This lets us determine how successful individual advertising measures are. These advertising materials are delivered by Google via “AdServers”. We use AdServer cookies for this, through which certain parameters for measuring success, such as ad impressions or user clicks, can be measured. If you access our website via a Google ad, Google Ads will store a cookie on your PC. These cookies usually expire after 30 days. They are not intended to identify you personally. For this cookie, the following analysis values are typically stored: unique cookie ID, number of ad impressions per placement (frequency), last impression (relevant for post-view conversions), opt-out information (marking that the user no longer wishes to be addressed). These cookies enable Google to recognize your web browser.
If a user visits certain pages of an Ads customer’s website and the cookie stored on their computer has not yet expired, Google and the customer can recognize that the user clicked on the ad and was redirected to this page. Each Ads customer is assigned a different cookie. Cookies therefore cannot be tracked across Ads customers’ websites. We do not collect or process any personal data ourselves in the aforementioned advertising measures. We only receive statistical evaluations from Google. Based on these evaluations, we can see which advertising measures used are particularly effective. We do not receive any further data from the use of advertising materials; in particular, we cannot identify users based on this information. Due to the marketing tools used, your browser automatically establishes a direct connection to Google’s server. We have no influence on the scope and further use of data collected by Google through Google Ads. To our knowledge, Google receives the information that you have accessed the relevant part of our website or clicked on an ad from us. If you have a Google user account and are registered, Google can associate the visit with your user account. Even if you are not registered with Google or have not logged in, Google may obtain and store your IP address.
We use Google Ads for marketing and optimization purposes, especially to display ads relevant and interesting to you, improve campaign performance reports, and achieve a fair calculation of advertising costs. The legal basis is your consent under Art. 6 (1) (a) GDPR in conjunction with § 25 (1) TDDDG.
You can disable interest-based Google ads in your Google ad settings at https://www.google.de/settings/ads or specifically block cookies from the domain “www.googleadservices.com”. For general cookie management in your browser, see section 3.
Third-party information: Google Ireland Limited, Google Building Gordon House, Barrow St, Dublin 4, Ireland.
For more information on data use by Google, settings, objection options, and data protection, please refer to the following Google websites:
Privacy Policy: https://policies.google.com/privacy?hl=de&gl=de
Google Website Statistics: https://services.google.com/sitestats/de.html
(3) Google Maps
On our website, we use Google Maps (API) from Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”). The legal basis is your consent under Art. 6 (1) (a) GDPR in conjunction with § 25 (1) TDDDG. Google Maps is a web service for displaying interactive maps to visualize geographical information. Using this service shows you our location and makes it easier to find us.
When accessing the subpages embedding the Google Maps map, information about your use of our website (such as your IP address) is transmitted to and stored on Google servers. This may also involve data transfer to Google LLC servers in the USA. This occurs regardless of whether Google provides a user account you are logged into or if a user account exists. If you are logged into Google, your data will be directly assigned to your account. If you do not wish to be associated with your Google profile, you must log out before activating the button. Google stores your data (even for unlogged users) as usage profiles and evaluates them.
If you do not agree to the future transmission of your data to Google when using Google Maps, you can completely deactivate the Google Maps web service by turning off JavaScript in your browser. Google Maps and the map display on this website can then no longer be used.
You can view Google’s terms of use at https://www.google.de/intl/de/policies/terms/regional.html. Additional terms of use for Google Maps can be found at https://www.google.com/intl/de_US/help/terms_maps.html
Detailed information on data protection in the context of using Google Maps can be found on Google’s website (“Google Privacy Policy”): https://www.google.de/intl/de/policies/privacy/.
(4) Meta Pixel, Custom Audiences, and Conversions
Within our online service, we use the “Meta Pixel” from Meta Platforms, Inc., 1 Hacker Way, Menlo Park, CA 94025, USA, or, if you are based in the EU, Meta Platform Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland, based on your consent for analysis, optimization, and reach measurement. The legal basis is Art. 6 (1) (a) GDPR in conjunction with § 25 (1) TDDDG.
Meta Platforms, Inc. is certified under the EU-US Data Privacy Framework (DPF) and thus offers a guarantee of compliance with European data protection law.
Using the Meta Pixel, Meta can determine the visitors to our online service as a target group for displaying ads (“Meta Ads”).
Accordingly, we use the Meta Pixel to display our Meta Ads only to users on Facebook and Instagram who have shown an interest in our online service or who share certain characteristics (e.g., interests in specific topics or products determined by visited websites) that we transmit to Meta (“Custom Audiences”).
Using the Meta Pixel, we also want to ensure our Meta Ads match potential user interest and are not annoying.
Furthermore, the Meta Pixel helps us track the effectiveness of Facebook ads for statistical and market research purposes by showing whether users were redirected to our website after clicking an ad on Facebook or Instagram (“conversion”).
Data processing by Meta Platforms, Inc. occurs within the framework of Meta’s data usage policy. Accordingly, general notes on displaying Meta Ads are in Meta’s data usage policy: https://www.facebook.com/privacy/policy/
Special information and details about the Meta Pixel and how it works can be found in the Meta Help Center: https://www.facebook.com/business/help/651294705016616.
You can object to the collection by the Meta Pixel and the use of your data to display ads on Facebook and Instagram or directly prevent this by disabling Meta tracking.
To set which types of ads are displayed to you within Facebook, you can access the page set up by Meta and follow the instructions on usage-based advertising settings: https://www.facebook.com/settings?tab=ads. The settings are platform-independent, meaning they are applied to all devices, such as desktop computers or mobile devices.
(5) GetResponse for web analysis and email marketing
For sending newsletters and evaluating them via GetResponse, see section 6.3.
6. Business-related processing
Additionally, we process
- Contract data (e.g., subject of the contract, term, customer category).
- Payment data (e.g., bank details, payment history) from our customers, prospects, and business partners to provide contractual services, customer service and care, marketing, advertising, and market research.
6.1 Provision of contractual services
We process the data of our contractual partners and prospects as well as other clients, customers, or partners (collectively referred to as “contractual partners”) in accordance with Art. 6 (1) (b) GDPR to provide them with our contractual or pre-contractual services. The data processed here, the type, scope, purpose, and necessity of their processing are determined by the underlying contractual relationship.
The processed data includes the master data of our contractual partners (e.g., names and addresses), contact data (e.g., email addresses and phone numbers), as well as contract data (e.g., services used, contract content, contractual communication, names of contact persons) and payment data (e.g., bank details, payment history).
We generally do not process special categories of personal data unless these are part of a commissioned or contractual processing.
We process data necessary to establish and fulfill contractual services and point out the necessity of providing them if this is not evident to the contractual partners. Disclosure to external persons or companies only occurs if required within the framework of a contract. When processing data provided to us within the scope of an order, we act according to the client’s instructions and legal requirements.
Within the scope of using our online services, we can store the IP address and the time of the respective user action. The storage is based on our legitimate interests and the users’ interests in protection against abuse and other unauthorized use. This data is generally not passed on to third parties unless required to pursue our claims under Art. 6 (1) (f) GDPR or if there is a legal obligation to do so under Art. 6 (1) (c) GDPR.
The data is deleted when it is no longer required to fulfill contractual or legal obligations of care or to deal with any warranty and comparable obligations, whereby the necessity of keeping the data is reviewed every three years; otherwise, statutory retention obligations apply.
6.2 Registration
(1) Creating a user profile:
You have the opportunity to register to use our online reservation system via app.resmio.com/signup and thereby create a user profile. During registration and setup, we collect and use the following (personal) data:
- Account holder name
- Account holder mobile number
- Email address
- Restaurant name
- Street and house number (restaurant location)
- City (restaurant location)
- Phone number (restaurant)
Your user account gives you the opportunity to use our online reservation system and related services and log in for the offers you have purchased. With your consent, the legal basis for data processing is Art. 6 (1) (a) GDPR or Art. 6 (1) (b) GDPR if the processing is necessary to provide the desired services (contract execution).
Your data will be deleted as soon as the user account on our website is deleted and provided no statutory retention obligations exist. You can usually change and/or delete your user account, including the data you provided, directly in your user account after logging in, or have this done by sending a corresponding message to the controller named in the introduction.
(2) Log in with Google
We allow you to log in to our service via your Google account. An additional registration is then not required.
To log in, you will be redirected to the Google Inc. site, where you can log in with your usage data. This links your Google profile with our resmio service. Through this link, we automatically receive data from your profile from Google Inc. The following information is transmitted to us:
- Your public profile (everything that third parties can easily see and learn when viewing your Google profile),
- Your email address.
We only use your email address from this data.
For more information and privacy settings, please refer to the Privacy Policy and the Terms of Service of Google Inc.
(3) Sign in with Apple
We allow you to register and log in with your Apple account. An additional registration is then not required.
To log in, use your Apple ID and the password stored with Apple. As part of such registration, Apple, represented by Apple Inc., Infinite Loop, Cupertino, CA 95014, USA, processes data about you.
resmio stores the information that you registered via “Sign in with Apple”. The following information is transmitted to us: Your public profile (everything that third parties can easily see and ask when viewing your Apple profile) and your email address. We only use your email address from this data.
For more information and privacy settings, please refer to the Privacy Policy and Terms of Service of Apple Inc.
6.3 Newsletter
If you want to receive our newsletter with information about our offers and products, we require your email address as a mandatory detail. You can subscribe via the forms on this website or when registering for our online reservation system; in both cases, your explicit consent is required.
We use the double opt-in process for sending: You will first receive an email with a confirmation link and will only be added to the mailing list after clicking it. By confirming, you give us your consent under Art. 6 (1) (a) GDPR. As proof of subscription and to clarify potential abuse, we store the IP address as well as the date and time of registration and confirmation alongside the email address.
We use GetResponse for dispatch and evaluation (GetResponse Sp. z o.o., ul. Arkonska 6/A3, 80-387 Gdansk, Poland). Subscription data is stored on GetResponse servers. Our newsletters allow us to evaluate user behavior – e.g., if and when a message was opened and which links were clicked, and via conversion tracking, whether a predefined action occurred. We can optimize the send time based on the open time and time zone; we can also group recipients by interest to deliver more relevant content. We have concluded a data processing agreement with GetResponse under Art. 28 GDPR.
You can withdraw your consent at any time with future effect – via the unsubscribe link in every newsletter email or by sending a message to the controller named above. The legality of the processing carried out until the withdrawal remains unaffected. After unsubscribing, your email address will be deleted from our mailing list and from GetResponse servers, unless you have expressly consented to continued use. Data stored for other purposes remains unaffected by this.
6.4 Third-party providers
To reliably provide our services, we rely on selected third-party providers. This may require processing certain personal data, such as IP addresses, usage, or contact data, within the scope of the respective service.
We use the third-party providers listed below to reliably provide our services. Legal bases and requirements for any third-country transfer result from sections 1.3 and 1.4; specific details per provider (purpose, data types, storage location, and duration) can be found in the following overview.
Below is an overview of the third-party providers used:
| Provider name | Processing purpose | Type of data | Legal basis | Storage location | Storage duration | Privacy Policy |
|---|---|---|---|---|---|---|
| Aircall | VoIP telephony | Phone numbers, name, meta/connection data | Art. 6 (1) (f) GDPR | EU, USA (DPF-certified) | Max. 6 months | Link |
| Amazon SES / SNS | Email and push communication (auto guest notifications) | Email address, communication content, meta/connection data | Art. 6 (1) (f) GDPR | EU (Frankfurt), possibly USA (DPF-certified) | As long as necessary to fulfill the purpose | Link |
| AWS (Amazon Web Services) | Server hosting, data processing | Usage data, customer data, IP address | Art. 6 (1) (f) GDPR | EU (Frankfurt), possibly USA (DPF-certified) | As long as necessary to fulfill the purpose | Link |
| CloudAMQP | Message Queuing (RabbitMQ) | Meta and communication data | Art. 6 (1) (f) GDPR | EU, USA | As long as necessary to fulfill the purpose | Link |
| Cloudflare | Content Delivery Network, security | IP address, access and security data | Art. 6 (1) (f) GDPR | Worldwide (Anycast, DPF-certified) | 24 hours up to max. 7 days | Link |
| Coralogix | Logging and system monitoring | Log files, system data, IP address | Art. 6 (1) (f) GDPR | Israel (EU adequacy decision) | Max. 30 days | Link |
| Crashlytics (Fabric) | App error analysis | Device information, error logs | Art. 6 (1) (f) GDPR | USA (DPF-certified via Google) | Max. 90 days | Link |
| DigitalOcean | Hosting of individual services | IP address, usage data | Art. 6 (1) (f) GDPR | EU, possibly USA (DPF-certified) | Max. 30 days (log data) | Link |
| Firebase (Google) | App hosting, analytics, push services | Usage data, app metrics, IP address | Art. 6 (1) (f) GDPR | USA (DPF-certified) | Max. 14 months | Link |
| GitHub | Code management, version control | Development-related meta and content data | Art. 6 (1) (f) GDPR | USA (DPF-certified) | Depending on project duration | Link |
| Gmail (Google) | Email communication | Email address, communication content, attachments | Art. 6 (1) (f) GDPR | EU, possibly USA (DPF-certified) | According to statutory retention periods | Link |
| Heroku / Salesforce | Hosting of the resmio web app | Usage data, possibly personal data of users | Art. 6 (1) (f) GDPR | EU, USA (DPF-certified) | As long as necessary to fulfill the purpose | Link |
| Hetzner | Web hosting resmio.com | IP address, log files | Art. 6 (1) (f) GDPR | Germany | Log data typically 7 days | Link |
| Intercom | Customer communication, live chat | Communication content, usage data, IP address | Art. 6 (1) (f) GDPR | USA (DPF-certified) | Max. 9 months | Link |
| Odoo | CRM, invoicing, customer management | Personal master data, contact data, contract master data, business-related communication, customer history, planning and control data | Art. 6 (1) (b), (f) GDPR | EU | Contractual or statutory retention periods | Link |
| OpenRedis | Cache system (Redis) | Temporary session data | Art. 6 (1) (f) GDPR | EU | Session-based, temporary | Link |
| Pusher | Real-time communication | Meta and usage data | Art. 6 (1) (f) GDPR | UK (adequacy decision) | Max. 30 days | Link |
| Sentry | Error tracking, stability analysis | Error messages, log data, IP address | Art. 6 (1) (f) GDPR | USA (DPF-certified) | Max. 90 days | Link |
| Smartlook | User experience & session recording | Mouse movements, click behavior, IP address | Art. 6 (1) (f) GDPR | EU | 30 days | Link |
| Vonage | Sending SMS guest notifications | Phone number, content data, meta/connection data | Art. 6 (1) (b), (f) GDPR | USA (DPF-certified), EU | Max. 13 months | Link |
| Zapier | Process automation | Data-dependent: e.g., contact data, IP address | Art. 6 (1) (b), (f) GDPR | USA (DPF-certified) | Until deleted by admin | Link |
7. Social media links
We currently use the following social media plugins: Facebook, Instagram, X, Xing, LinkedIn, and YouTube.
We use the so-called two-click solution. This means that when you visit our site, generally no personal data is initially passed on to the plugin providers. You can identify the plugin provider by the marking on the box with their initial or logo.
We offer you the possibility to communicate directly with the plugin provider via the button. Only if you click on the marked field and activate it, the plugin provider receives the information that you have accessed the corresponding website of our online service. In addition, the data mentioned under section 2.1 of this statement is transmitted. In the case of Facebook/Instagram and Xing, the IP address is anonymized immediately after collection according to the respective providers in Germany.
By activating the plugin, personal data is transmitted from you to the respective plugin provider and stored there (for US providers, in the USA). Since the plugin provider primarily collects data via cookies, we recommend deleting all cookies via your browser’s security settings before clicking on the grayed-out box.
We have no influence on the collected data and data processing operations, nor are we aware of the full extent of data collection, the purposes of processing, and storage periods. We also have no information on the deletion of collected data by the plugin provider.
The plugin provider stores the data collected about you as usage profiles and uses them for advertising, market research, and/or tailored website design. Such an evaluation takes place in particular (even for unlogged users) to display tailored advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles; you must contact the respective plugin provider to exercise this right. Through the plugins, we allow you to interact with social networks and other users so we can improve our offer and make it more interesting for you. The legal basis for using plugins is Art. 6 (1) (f) GDPR.
Data transfer occurs regardless of whether you have an account with the plugin provider and are logged in there. If you are logged into the plugin provider, the data we collect will be directly assigned to your existing account with the plugin provider. If you click the activated button and, for example, link the page, the plugin provider also stores this information in your user account and shares it publicly with your contacts. We recommend logging out regularly after using a social network, especially before activating the button, as this helps avoid assignment to your profile with the plugin provider.
For more information on the purpose and scope of data collection and its processing by the plugin provider, please refer to the privacy policies of these providers below. They will also provide further information on your rights and settings options to protect your privacy.
Addresses of the respective plugin providers and URLs with their privacy notices:
a) Facebook/Instagram (Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Parent company: Meta Platforms, Inc., 1 Hacker Way, Menlo Park, CA 94025, USA); Privacy Policy: https://www.facebook.com/privacy/policy/; Meta Platforms is certified under the EU-US Data Privacy Framework (DPF); any transfer to the USA occurs on this basis.
b) X (X Internet Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland) Privacy Policy: https://x.com/de/privacy, Opt-Out: https://x.com/personalization
c) Xing (XING AG, Dammtorstraße 29-32, 20354 Hamburg, Germany), Privacy Policy: https://privacy.xing.com/de/datenschutzerklaerung, Opt-Out: https://nats.xing.com/optout.html?popup=1&locale=de_DE
d) LinkedIn Corporation (LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland; LinkedIn Corporation, 1000 W Maude Ave, Sunnyvale, CA 94085, USA); http://www.linkedin.com/legal/privacy-policy. LinkedIn is certified under the EU-US Data Privacy Framework (DPF); any transfer to the USA occurs on this basis.
e) Google/YouTube (Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA), Privacy Policy: https://policies.google.com/privacy, Opt-Out: https://adssettings.google.com/authenticated?hl=de,
8. Embedding YouTube videos
We embed videos from the “YouTube” platform provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, on our websites. When playing the video, YouTube sets cookies to collect information on user behavior. This is used, for example, to improve the user-friendliness of YouTube’s service and prevent misuse. If you have a Google account and are logged in, the videos you watch are assigned to your Google account.
Data processing by Google is based on any contractual relationship existing between you and Google or Google’s privacy policy, which you can access at https://www.google.de/intl/de/policies/privacy. There you will also find information about your legal right to object to processing.
A contract was concluded with Google based on the EU Standard Contractual Clauses to ensure an adequate level of data protection when transferring personal data to third countries.
By clicking the play button of a YouTube video embedded on our websites, you consent to the one-time data processing to play the corresponding video. The legal basis is Art. 6 (1) (a) GDPR.
You can withdraw your consent at any time. To end data processing by YouTube, please contact Google directly. Further information can be found at https://www.google.de/intl/de/policies/privacy.
9. Analysis and market research
To run our business economically and identify market trends, customer, and user preferences, we analyze the data available to us on business transactions, contracts, inquiries, etc. We process master data, communication data, contract data, payment data, usage data, and metadata based on Art. 6 (1) (f) GDPR. Data subjects include customers, prospects, business partners, visitors, and users of the online service.
Analyses are conducted for business evaluations, marketing, and market research. We may consider registered users’ profiles with information such as their purchasing history. Analyses help us increase user-friendliness, optimize our offering, and improve business efficiency. The analyses are processed exclusively by resmio and are not disclosed externally unless they are anonymous analyses with aggregated values.
If these analyses or profiles are personally identifiable, they will be deleted or anonymized upon termination by the user, or otherwise two years after termination. In all other respects, general business analyses and general trend determinations are created anonymously where possible.
10. Payment providers
10.1 PayPal
We enable our customers’ guests (i.e., restaurant operators) to process payments via the payment provider PayPal (PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg). Payments can be collected via resmio for reservations, online orders, or ticket purchases, for example.
This aligns with our legitimate interest in offering an efficient and secure payment method (Art. 6 (1) (f) GDPR). In this context, technically necessary connection data (e.g., IP address) as well as data-related transaction details (e.g., purchase amount, currency, reservation reference) are transmitted to PayPal, provided this is necessary for payment processing (Art. 6 (1) (b) GDPR).
Processing the data specified in this section is neither legally nor contractually required. Without transmitting your personal data, we cannot process a payment via PayPal.
PayPal conducts a credit check for various services such as direct debit payments to ensure your willingness and ability to pay. This corresponds to PayPal’s legitimate interest and serves contract execution (under Art. 6 (1) (b) GDPR). For this purpose, your data (name, address, date of birth, bank account details) is passed on to credit agencies. We have no influence on this process and only receive the result of whether the payment was made, rejected, or is pending review.
Further information on objection and removal options concerning PayPal can be found at: https://www.paypal.com/de/webapps/mpp/ua/privacy-full
10.2 Stripe
If you pay by credit card, your credit card data is not stored by us but is encrypted and forwarded to the payment provider Stripe Payments Europe Ltd., Block 4, Harcourt Centre, Harcourt Road, Dublin 2, Ireland, and processed by Stripe.
Stripe processes the following information:
Regarding all transactions:
- Date of the transaction,
- Monetary amount of the transaction.
- Transaction status (accepted/declined)
When paying with a credit card:
- Credit card origin (only the last four digits are visible to us and stored by Stripe),
- The IP address from which the order was placed to identify fraud
- Card expiration date (month and year)
- Credit card country of origin
- Type of credit card (credit or debit)
- Credit card company name (Visa, American Express, Mastercard…)
When paying via SEPA:
- IBAN
- First and last name of the account holder
The current Stripe privacy information and supplementary details can be found on this website: https://stripe.com/de/privacy. We also use the above data for statistical evaluation of our website. Processing occurs under Art. 6 (1) (b) GDPR to execute a contract with you or based on legitimate interests under Art. 6 (1) (f) GDPR.
Data is only processed as long as necessary for the stated purposes. Financial information is stored exclusively by Stripe. We have no access to it.
If data is transferred to Stripe in the USA, this occurs based on the EU-US Data Privacy Framework (DPF), under which Stripe is certified.
10.3 Adyen
We use Adyen to process payments via resmio. For example, if you opt for a paid plan at resmio or book an add-on/service and choose a payment method from the payment provider Adyen (e.g., SEPA direct debit), payment processing is handled by the Dutch service Adyen B.V., Simon Carmiggeltstraat 6 – 50, 1011 DJ Amsterdam, Netherlands.
We pass on the information you provided during the order process, along with details about your order (name, address, IBAN, BIC, invoice amount, currency, and transaction number) to Adyen in accordance with Art. 6 (1) (b) GDPR.
Your data is passed on exclusively for payment processing with Adyen and only to the extent necessary for this purpose.
Adyen’s privacy policy with further details can be found at: https://www.adyen.com/de_DE/privacy-policy
11. Retention period for personal data
We only store personal data for as long as required for the respective processing purpose. If statutory retention obligations exist – especially under commercial and tax law (e.g., HGB, AO) – the data is kept until the respective period expires and then routinely deleted.
Furthermore, we may retain data if you have consented or if we need it to assert, exercise, or defend legal claims within the statutory limitation periods (usually three years, up to thirty years in certain cases).
If data is necessary for contract execution/initiation or based on legitimate interest, we delete it once this purpose ceases to apply or if you effectively exercise your right of withdrawal or objection.
12. Data subject rights
Data protection law grants you comprehensive data subject rights regarding the controller’s processing of your personal data, which we inform you about below. You have the right:
- under Art. 15 GDPR, to request information about your personal data processed by us. In particular, you can request information on processing purposes, the category of personal data, categories of recipients to whom your data has been or will be disclosed, planned retention periods, the existence of a right to rectification, deletion, restriction of processing or objection, the existence of a right to complain, the source of your data if not collected by us, and the existence of automated decision-making including profiling and, if applicable, meaningful information about the logic involved and the scope and intended effects of such processing, as well as your right to be informed about guarantees under Art. 46 GDPR when data is transferred to third countries;
- under Art. 16 GDPR, to immediately demand the correction of incorrect data and/or completion of your personal data stored by us;
- under Art. 17 GDPR, to request the deletion of your personal data stored by us, unless processing is necessary to exercise the right to freedom of expression and information, to fulfill a legal obligation, for reasons of public interest, or to assert, exercise, or defend legal claims;
- under Art. 18 GDPR, to request the restriction of processing your personal data, provided you dispute the accuracy of the data, the processing is unlawful but you reject its deletion and we no longer need the data, but you require it to assert, exercise, or defend legal claims, or you have objected to processing under Art. 21 GDPR as long as it has not been determined whether our legitimate grounds prevail;
- under Art. 19 GDPR, to assert the right to rectification, deletion, or restriction of processing against the controller, who is obliged to notify all recipients to whom the personal data was disclosed of this rectification, deletion, or restriction, unless this proves impossible or involves a disproportionate effort. You have the right to be informed about these recipients;
- under Art. 20 GDPR, to receive your personal data that you provided to us in a structured, common, and machine-readable format or request its transfer to another controller, where technically feasible;
- under Art. 7 (3) GDPR, to withdraw your given consent at any time with future effect. In the event of withdrawal, we will immediately delete the data concerned, provided further processing cannot be based on a legal foundation for processing without consent. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal;
- under Art. 77 GDPR, if you believe the processing of your personal data violates the GDPR, without prejudice to any other administrative or judicial remedy, the right to lodge a complaint with a supervisory authority, particularly in the member state of your residence, workplace, or the place of the alleged infringement.
13. Right to object
If we process your personal data based on legitimate interests under Art. 6 (1) (f) GDPR, you have the right to object to processing your personal data at any time under Art. 21 GDPR with future effect, provided there are reasons arising from your particular situation.
If you wish to exercise your right to object, we will stop processing the affected data. However, further processing remains reserved if we can demonstrate compelling legitimate grounds for processing that override your interests, fundamental rights, and freedoms, or if processing serves to assert, exercise, or defend legal claims.
If we process your personal data for direct marketing, you have the right to object at any time to the processing of personal data concerning you for such marketing. You can exercise the objection as described above. If you exercise your right to object, we will stop processing the affected data for direct marketing purposes.
Please send your objection to support@resmio.com.
14. Data security
For security reasons and to protect the transmission of personal data and other confidential content (e.g., inquiries to the controller), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the “https://” string and the lock icon in your browser line.
We otherwise use appropriate technical and organizational security measures to protect your data against loss, destruction, or unauthorized access by third parties. Our security measures are continuously improved in line with technological developments.
15. Links to other providers
Our website also contains – clearly recognizable – links to the websites of other companies. Where links to websites of other providers exist, we have no influence on their content. Therefore, no guarantee or liability can be assumed for this content. The respective provider or operator of the pages is always responsible for the content of these pages.
The linked pages were checked for potential legal violations and recognizable infringements at the time of linking. Illegal content was not identifiable at the time of linking. However, permanent content control of the linked pages is not reasonable without concrete evidence of an infringement. Upon becoming aware of legal violations, such links will be removed immediately.
16. Currency and changes to this privacy policy
This privacy policy is currently valid and was last updated in July 2026.
Due to the further development of our website and offers on it or due to changed legal or regulatory requirements, it may become necessary to change this privacy policy.
You can access and print the current privacy policy at any time on the website at https://www.resmio.com/en/privacy-policy/.
***