Legal
Privacy Notice
(Version: 2026-09-22; applicable to the online service “N824”)
1. Controller
The controller responsible for processing personal data under the General Data Protection Regulation (GDPR) is:
N824 GmbH i. G.operating under the brand N824
Ettlinger Straße 22
76337 Waldbronn
Germany
Managing Director: Rico J. Anderer
E-mail (general contact & privacy): mail@n824.com
Phone: +49 172 6333600
2. Scope
This Privacy Notice applies to:
- the websites and web apps of N824,
- the use of the N824 PMS & Channel Manager as a SaaS service,
- the processing of personal data of
- Hosts (our B2B customers and their staff), and
- Guests of our Hosts, insofar as their data is processed within the N824 service,
- communication with us via email, phone, contact form or support ticket.
Separate privacy information may apply to the rental of apartments under N824 Apartments Waldbronn / w724 UG.
3. Overview of Data Processing
We process personal data in particular:
- to provide and secure our websites and web apps,
- to register and support Hosts (B2B customers),
- for billing and payment processing,
- to technically and organisationally provide the PMS & Channel Manager,
- to process Guest data on behalf of Hosts,
- for error analysis, support and product improvement.
Legal bases are in particular Article 6(1)(b), (c) and (f) GDPR and – for consent-based processing – Article 6(1)(a) GDPR.
4. Visiting our Websites and Web Apps
Data categories:
IP address, date/time, requested URL, referrer URL, browser type/version, operating system, session ID where applicable, error logs.
Purposes:
Provision of content, technical stability and security (e.g. detection of attacks), error analysis.
Legal basis:
Article 6(1)(f) GDPR (legitimate interest in a secure, stable and usable online service).
Storage period:
Server logs are usually stored for 7–30 days; longer storage only occurs in specific cases, e.g. for investigation of security incidents.
Error reports:
When the web app hits an unexpected error, it sends a report to our error tracking provider (see section 10). A report holds the error, the page or request it occurred on, your browser and operating system, internal account identifiers and, for server errors, your IP address. A report is not built to hold cookies, what you typed, booking contents, names or email addresses. Reports are kept for 30 days.
5. Registration and Use of the N824 Service (Hosts / B2B)
Data categories:
Company name, address, VAT ID, contact person, business contact details, login data, roles/permissions, contract and communication data.
Purposes:
Contract initiation and performance, creation and administration of user accounts, provision of the PMS/Channel Manager, support and customer care, billing, documentation of contractual processes.
Legal bases:
- Article 6(1)(b) GDPR (performance of a contract / pre-contractual measures),
- Article 6(1)(c) GDPR (statutory retention duties),
- Article 6(1)(f) GDPR (legitimate interest in efficient support and product improvement).
Storage period:
For the duration of the contractual relationship; thereafter for the period required by commercial and tax law (typically 6–10 years), then deletion or anonymisation.
6. Payment Processing
Data categories:
Name/company, billing address, invoice amount, invoice and booking references, payment status; when using external payment providers additional payment data at the respective provider (e.g. tokenised card data).
Purposes:
Billing of our services, payment processing, accounting.
Legal bases:
Article 6(1)(b) GDPR (performance of a contract),
Article 6(1)(c) GDPR (tax and commercial law obligations).
External payment providers generally act as their own controllers; their privacy notices apply in addition.
7. Processing of Guest Data on Behalf of Hosts
We provide a technical service to Hosts; Guest data processed in this context falls under the responsibility of the respective Host.
Roles:
- Host: controller within the meaning of Article 4(7) GDPR.
- N824 / N824 GmbH i. G.: processor within the meaning of Article 28 GDPR.
Typical data categories:
Name, contact details, stay period, booked unit, number of guests, prices/payments, registration data, communication history between Host and Guest, internal notes.
Purposes:
Management of bookings and stays, synchronisation with booking portals and connected systems, reporting and analytics for Hosts.
A separate data processing agreement (DPA) under Article 28 GDPR is concluded with each Host, defining scope, duration, technical and organisational measures, sub-processors and third-country transfers.
8. Support, Communication and Feedback
Data categories:
Email address, name, content of support requests, technical metadata (e.g. timestamp, system environment), support logs.
Purposes:
Handling of enquiries, error analysis, improvement of the service, documentation of support cases.
Legal bases:
Article 6(1)(b) GDPR (contractual communication),
Article 6(1)(f) GDPR (legitimate interest in support and product optimisation).
For voluntary feedback or optional surveys, Article 6(1)(a) GDPR (consent) may additionally apply.
9. Cookies and Similar Technologies
We use a common cookie setup on our websites and in the web app:
a) Strictly necessary cookies
- Purpose: login status, session management, security functions (e.g. CSRF protection), basic usability, interface preferences and unsent form drafts (local storage).
- Legal basis: Section 25(2) TDDDG in conjunction with Article 6(1)(f) GDPR (legitimate interest in a secure and functional service).
- These cookies cannot be disabled without significantly impairing use of the service.
b) Statistics, analytics and marketing cookies
We currently do not use statistics, analytics or marketing cookies and therefore do not display a cookie banner. Should this change, we will obtain your prior consent (Article 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG), which you may withdraw at any time with effect for the future.
10. Recipients and Service Providers
To operate N824 and N824 GmbH i. G. we use carefully selected service providers, including:
- Hosting provider (Cloudflare, Inc., USA): operation of servers, databases, file storage, backups and email sending. Databases, files and backups are stored in the EU. Requests are processed at the Cloudflare data centre closest to where they arrive, for visitors in the EU/EEA normally one within the EU/EEA. Image processing, outbound email and connection logs run on the provider’s global network (see section 11).
- Email provider (webgo GmbH, Germany): receipt and storage of emails sent to us.
- Channel manager (Channex Ltd, United Kingdom): connection to booking portals, receipt of bookings and guest data.
- Error tracking provider (Functional Software, Inc., trading as Sentry, USA): receipt and storage of error reports from the web app (see section 4), stored in the EU.
- Map and geocoding provider (Stadia Maps, Inc., USA, EU servers): address search and map tiles when a Host sets a property location. Map tiles are loaded directly by your browser, which transmits your IP address to the provider.
- Advisers and professional service providers: tax advisers, lawyers, auditors.
- Authorities and public bodies: where there is a statutory obligation to disclose data (e.g. tax authorities).
We conclude data processing agreements under Article 28 GDPR with processors, especially covering purpose limitation, data security and sub-processing.
An up-to-date overview of sub-processors is provided in the DPA and on request. We inform Hosts at least 30 days before changes to sub-processors take effect.
11. Transfers to Third Countries (including USA)
Personal data is stored within the EU/EEA. As a rule, it is also processed there. Where we cannot enforce EU-only processing (e.g. for certain cloud or payment providers, see section 10), the following principles apply:
Legal bases for transfers:
- adequacy decision under Article 45 GDPR (e.g. for companies certified under the EU-US Data Privacy Framework), or
- appropriate safeguards under Article 46 GDPR (in particular Standard Contractual Clauses (SCCs)), possibly combined with additional technical and organisational measures, or
- in exceptional cases, Article 49 GDPR (e.g. explicit consent or necessity for contract performance).
When using US-based service providers we check:
- whether the provider is certified under the EU-US Data Privacy Framework, or
- whether Standard Contractual Clauses have been concluded.
A copy of the safeguards in place is available on request at mail@n824.com.
Even with such safeguards, a residual risk may remain that authorities in third countries access data and that data subject rights cannot be enforced to the same extent as in the EU. We inform about this transparently.
12. Storage Periods and Deletion
We store personal data only for as long as necessary for the respective purposes or as required by statutory retention duties:
- Contract and billing data: typically 6–10 years (commercial and tax law).
- Server logs and security logs: usually up to 30 days, unless a specific case requires longer retention.
- Database backups: 30 days. Deleted data may therefore remain in backups for up to 30 days.
As processor, we delete or anonymise Guest data in accordance with the Host’s instructions and the contractual arrangements in the DPA.
13. Your Rights (GDPR)
Data subjects have, where the statutory conditions are met, in particular the following rights:
- Right of access to personal data (Article 15 GDPR),
- Right to rectification of inaccurate data (Article 16 GDPR),
- Right to erasure (“right to be forgotten”, Article 17 GDPR),
- Right to restriction of processing (Article 18 GDPR),
- Right to data portability (Article 20 GDPR),
- Right to object to certain processing (Article 21 GDPR), especially where processing is based on Article 6(1)(f) GDPR,
- Right to withdraw consent at any time with effect for the future (Article 7(3) GDPR).
To exercise your rights, you can contact us at mail@n824.com at any time.
Where we act as processor for a Host, we support the Host in handling data subject requests.
14. Obligation to Provide Data
Certain data is required in order to use the N824 service (e.g. account, billing and access data). Without such data we cannot set up a user account or provide our service.
For Guests, the required data follows from the contractual relationship with the Host; without such data a booking or stay is generally not possible.
15. Automated Decision-Making / AI Features
We do not carry out automated individual decision-making within the meaning of Article 22 GDPR that produces legal effects concerning data subjects or similarly significantly affects them.
Where we offer AI-based functions (e.g. forecasts, price recommendations, text suggestions), these are only tools supporting Hosts. Decisions on prices, bookings or other measures are taken by Hosts themselves.
16. Data Security
We implement technical and organisational measures to ensure an appropriate level of security (Article 32 GDPR), including in particular:
- encrypted data transmission (TLS),
- access controls and role/permission systems,
- regular backups,
- logging of security-relevant events,
- internal policies and staff awareness.
17. Right to Lodge a Complaint with a Supervisory Authority
Data subjects have the right to lodge a complaint with a data protection supervisory authority (Article 77 GDPR).
For our seat in Baden-Württemberg, the competent authority is in particular:
State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (LfDI BW).
Contact details are available on the authority’s website.
18. Additional Information for California Residents (CCPA/CPRA)
This section applies in addition to the above for natural persons residing in California, to the extent the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) apply to our processing.
Categories of personal information (examples):
- Identifiers: name, email address, IP address, account ID,
- Commercial information: product/service usage, transaction data,
- Internet or other electronic network activity information: log and usage data of our web app,
- Geolocation data (on a coarse level, e.g. via IP address),
- Professional or employment-related information: role at a Host/B2B customer.
We generally do not process sensitive personal information within the meaning of the CPRA.
Sale / sharing of data:
We do not sell personal information as defined by CCPA/CPRA and currently do not engage in “sharing” for cross-context behavioural advertising. If this changes, we will update this Privacy Notice and provide the legally required opt-out options (“Do Not Sell or Share My Personal Information”).
Rights under CCPA/CPRA:
California residents have, among others, the following rights:
- Right to know / access: information about personal information collected, used or disclosed,
- Right to deletion: deletion of personal information, subject to applicable exceptions,
- Right to correct inaccurate personal information,
- Right to non-discrimination: no disadvantage for exercising these rights.
To exercise these rights, you can contact us at mail@n824.com (subject: “CCPA Request”). We may request additional information to verify your identity.
19. Changes to this Privacy Notice
We may update this Privacy Notice if the legal framework, technical conditions or our data processing activities change. The current version is always available on our websites.
We will notify you of material changes within the N824 service (e.g. by a notice in the app or by email).
(End of Privacy Notice – version 2026-09-22)