Introduction
This privacy policy explains which personal data we process when operating this website, why we process it and which rights you have. Personal data means any information relating to an identified or identifiable person.
The controller responsible for data processing is Villa Mangifera LLC. The German management address shown above may also be used for privacy inquiries.
Overview of processing
Depending on how you use the website, we process contact, content, booking, contract, usage, metadata and log data in particular.
Data subjects
- Visitors to this website
- Prospective guests and people making inquiries
- Guests and contractual partners
Purposes of processing
- Providing, securing and maintaining the website
- Responding to inquiries
- Checking availability and arranging and fulfilling bookings
- Complying with legal obligations and preventing misuse
We currently do not use our own web analytics, advertising, remarketing or social-media tracking services on this website.
Legal bases
We process personal data primarily on the following legal bases:
- Article 6(1)(b) GDPR for pre-contractual inquiries, bookings and performance of the accommodation contract.
- Article 6(1)(c) GDPR for compliance with legal obligations.
- Article 6(1)(f) GDPR for secure, user-friendly and economical website operation and the prevention of misuse.
- Article 6(1)(a) GDPR where we ask for your consent to a specific processing activity.
Web hosting and server logs
This website is hosted by ALL-INKL.COM – Neue Medien Münnich, owner René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. When you access the website, the hosting provider processes technical data required to deliver content to your device and identify attacks.
Server data may include:
- IP address and date and time of access
- Requested URL or file, amount of data transferred and access status
- Referrer URL, browser, browser version and operating system
The legal basis is Article 6(1)(f) GDPR. Log files are generally deleted after no more than seven days. Longer storage may be required in individual cases, for example to investigate an attack.
ALL-INKL privacy information
Essential cookies and session
The website uses an essential PHP session. This usually sets a session cookie used to remember the selected language and protect forms against abusive requests with a security token. The cookie does not contain booking or payment data and is generally deleted when the browser is closed.
The legal basis is Article 6(1)(f) GDPR; storage on the device is necessary for the functions expressly requested. We currently do not set our own optional analytics or advertising cookies. Embedded booking services may use their own cookies or similar technologies; the section “Booking and Smoobu” provides additional information.
Contact and inquiry management
If you contact us through the contact form, question form, by email, telephone or post, we process the information you provide to handle and respond to your request. This includes your name, email address, message and, where applicable, your telephone number and other information provided voluntarily.
The legal basis is Article 6(1)(b) GDPR for pre-contractual or contractual matters and otherwise Article 6(1)(f) GDPR. We use the Resend email service operated by Plus Five Five, Inc., United States, to deliver form messages reliably. Sender and recipient addresses, subject, message content and technical delivery data are processed. The message is delivered to our booking@villa-mangifera.com mailbox hosted by ALL-INKL.
We delete inquiries once they are no longer required for processing and no legal retention obligations or legitimate interests require continued storage.
Availability, booking and Smoobu
The booking page embeds an availability calendar and direct booking tool provided by Smoobu GmbH, Pappelallee 78/79, 10437 Berlin, Germany. Opening the booking page establishes a connection to Smoobu servers. Essential connection data such as your IP address, browser information, referrer, date and time is transferred.
When you check availability or make a booking, Smoobu processes the travel, guest, contact, booking and, where applicable, payment data you enter. This processing is used to display available dates and prices, handle the booking and payment, communicate with you and manage your stay.
The legal bases are Article 6(1)(b) GDPR for pre-contractual measures and contract performance and Article 6(1)(f) GDPR for providing direct booking securely and efficiently. The privacy policies of Smoobu and connected payment services also apply to optional cookies they set and processing they perform as independent controllers.
To resize the embedded window correctly, the booking tool loads a technical library through Cloudflare’s cdnjs content delivery network. Cloudflare may process technical connection data, particularly your IP address.
Payment processing
Where online payment is offered during booking, you enter payment data directly into the interface provided by Smoobu or a connected payment service. The relevant payment service processes the data to authorise and complete the payment and prevent fraud. We generally receive only booking-related payment information and a payment status, not full credit-card details.
The legal basis is Article 6(1)(b) GDPR. The privacy information of the payment provider displayed during the booking process also applies.
Recipients and international transfers
Data is disclosed only to recipients that need it for the purposes described. These may include hosting, email, booking, payment, IT and administrative service providers, as well as authorities and advisers where required by law.
Because the villa is located in the United States and the controller is a US company, booking and contract data may be processed in the United States where necessary to arrange or fulfil your stay. For other transfers outside the EU or EEA, we rely on a lawful transfer mechanism, particularly an adequacy decision, suitable safeguards such as standard contractual clauses or a statutory exception required for contract performance.
Storage and deletion
We retain personal data only for as long as necessary for the relevant purpose. It is then deleted or anonymised unless legal retention duties, ongoing contractual relationships or legitimate interests—such as establishing, exercising or defending legal claims—require continued storage.
Commercial and tax retention periods may apply to booking, contract, invoice and payment records. Data stored in embedded services is also subject to each provider’s deletion periods.
Security measures
We use appropriate technical and organisational measures to protect personal data against loss, manipulation and unauthorised access. The website is transmitted over encrypted HTTPS connections. Contact forms use a server-side security token. Nevertheless, absolute security cannot be guaranteed for data transmitted over the internet.
Your privacy rights
Where the legal requirements are met, you have the following rights in particular:
- Access to your personal data
- Correction of inaccurate or incomplete data
- Deletion or restriction of processing
- Data portability
- Withdrawal of consent with effect for the future
- Objection to processing based on legitimate interests
- Lodging a complaint with a competent data-protection authority
To exercise your rights, contact booking@villa-mangifera.com.
Changes to this privacy policy
We update this privacy policy when the website, the services used or legal requirements change. The version published on this page is the current version.
This policy was adapted for Villa Mangifera from the existing privacy policy of WiMaB GbR. The source version was created with the support of the privacy policy generator by Dr. Thomas Schwenke.