1. Controller and contact
Controller responsible for processing:
House of Tales GmbH, Zimmerstraße 90, 10117 Berlin, Germany
Phone: +49 (0)30 20888765,
Email: info@houseoftales.de
We have not appointed a data protection officer; you may contact us at any time regarding data protection matters using the contact details above.
2. Which data do we process?
Depending on use, we may process in particular:
- Master and contact data (e.g. name, address, email, telephone number)
- Contract, booking and payment data
- Communication data (e.g. messages by email, form, social media)
- Application data (e.g. cover letter, CV, references)
- Usage, meta and log data (e.g. IP address, device information, pages visited)
- Consent data (e.g. timing, scope and status of your cookie consent)
3. Purposes and legal bases
We process your data in particular for the following purposes:
- Provision, security and stability of our website
- Handling enquiries and customer communication
- Performance of bookings and contracts, including payment processing
- Newsletter delivery
- Analysis, optimisation and marketing (e.g. reach measurement, advertising)
- Social media presence and public relations
- Recruitment
- Fulfilling legal obligations and enforcing rights
Depending on the processing activity, the legal bases include in particular Article 6(1)(a), (b), (c) and (f) GDPR, as well as Sections 25(1)–(2) of the German Telecommunications Telemedia Data Protection Act (TDDDG). For recruitment, additionally Section 26 of the German Federal Data Protection Act (BDSG) and, where relevant, Article 9(2)(b) GDPR.
4. Website, hosting and server logs
When you visit our website, we automatically process data including your IP address, date and time of access, pages requested, referrer URL, and browser and device information.
Processing serves technical provision, security, error analysis and protection against misuse. Legal basis is our legitimate interests in secure and stable operation (Article 6(1)(f) GDPR).
We use hosting and infrastructure services provided by Hetzner Online GmbH (Germany) and Vercel Inc. (United States).
5. Cookies, consent management and tracking
Our website uses cookies, local/session storage and similar technologies:
- Strictly necessary technologies (e.g. for security, booking, consent management) are used on the basis of Section 25(2) TDDDG together with Article 6(1)(b) / (f) GDPR.
- Non-essential technologies (e.g. analytics, marketing, remarketing, social-media pixels) are used only if you consent under Section 25(1) TDDDG and Article 6(1)(a) GDPR.
We use the CookieScript consent management tool to collect and manage your choices. Data processed may include your IP address (possibly truncated), timing and status of consent, consent ID, and browser and device information. Legal bases are Article 6(1)(c) / (f) GDPR and Section 25 TDDDG.
You may withdraw or adjust your consent at any time with effect for the future via the cookie settings.
6. Services used
Depending on necessity or consent we use in particular:
- Google Tag Manager (Google Ireland Limited) to administer tags; legal basis Article 6(1)(f) GDPR and, where tags require consent, Article 6(1)(a) GDPR plus Section 25(1) TDDDG.
- Google Analytics for reach analytics, only after consent.
- Google Ads / conversion tracking to measure advertising performance, only after consent.
- Meta pixel (Facebook/Instagram) for measuring and optimising Meta ads, only after consent.
- TikTok pixel for measuring and optimising TikTok ads, only after consent.
- Google Fonts loaded locally for typography; data is not transferred to Google in this implementation.
7. Newsletter
We use Mailjet (Mailjet SAS and companies in the Mailjet/Sinch group) for our newsletter.
Processed data may include your email address, name if provided, signup and confirmation times, IP address and consent records. Where tracking is enabled, open and click data may be processed.
Sending the newsletter and any tracking rely on your consent (Article 6(1)(a) GDPR; Section 25(1) TDDDG); documentation of consent is based on Article 6(1)(c) / (f) GDPR. You may unsubscribe at any time via the link in each email.
8. Bookings, payment providers and QuinBook
When you book we process data required to perform the contract (e.g. name, contact data, booking data, payment status, services booked, communication). Legal bases are Article 6(1)(b) GDPR and Article 6(1)(c) GDPR for statutory retention obligations.
For bookings we use QuinBook (Woizzer AG, Germany), which may process booking, contact, payment and usage data.
Payments are handled by external providers, notably PayPal (Europe) S.Ã r.l. et Cie and Stripe Payments Europe Ltd. These providers process payment data independently (e.g. name, billing address, transaction amount and details) for payment processing, fraud prevention and statutory compliance.
9. Job applications
We process application materials (contact details, CV, certificates, qualifications) solely for the recruitment procedure.
Legal bases include Article 6(1)(b) GDPR and Section 26 BDSG, and where relevant Article 9(2)(b) GDPR and Section 26 BDSG for special categories of personal data.
Application data is routinely deleted within six months after the procedure ends unless longer retention is legally permissible or necessary.
10. Social media
We operate profiles on Facebook, Instagram, TikTok and X (formerly Twitter).
When you visit our profiles or interact with us we process information you share for communication and public relations. Legal basis is Article 6(1)(f) GDPR or, for contract-related enquiries, Article 6(1)(b) GDPR.
The platform operators alone are responsible for processing on those platforms under their respective privacy policies.
11. Recipients, third-country transfers and retention
We transfer personal data only where permitted by law or necessary for our duties. Recipients may include hosting and IT vendors, payment and booking providers, newsletter services, analytics and marketing vendors, social networks, advisers, regulators and courts.
Some processors are located outside the EU/EEA, including the United States. We ensure safeguards under Articles 44 et seq. GDPR apply, including adequacy decisions, EU‑US Data Privacy Framework certification where applicable or standard contractual clauses.
Data is retained only as long as needed for the respective purposes or as required by statutory retention periods; typical horizons are six or ten years for tax and commercial-law records.
12. Your rights
Under the GDPR you have in particular the right to:
- Access your personal data (Article 15 GDPR)
- Rectification (Article 16 GDPR)
- Erasure (Article 17 GDPR) and restriction of processing (Article 18 GDPR)
- Data portability (Article 20 GDPR)
- Object to processing based on legitimate interests or to direct marketing (Article 21 GDPR)
- Withdraw consent at any time with future effect (Article 7(3) GDPR)
- Lodge a complaint with a supervisory authority (Article 77 GDPR); notably the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit)
To exercise your rights please contact us using the details above.
13. Changes
We will update this policy when our website, services or legal obligations change. The version published on our website applies.