Kiripotib Guest Farm
Kiripotib Guest Farm
Online booking

Privacy Policy

Information on the processing of personal data pursuant to Art. 13 GDPR.

1. Controller

The controller for data processing on this website is:

Hans Georg von Hase t/a Kiripotib Guest Farm
Private Bag 13036
Windhoek
Namibia
Phone: +264 (62) 58 1419
E-Mail: reservations@kiripotib.com

2. Purposes and legal bases of processing

We process your personal data exclusively for the following purposes:

  • Booking handling: receiving, reviewing and confirming your booking request, contract performance, invoicing and any cancellations — based on Art. 6(1)(b) GDPR (contract) and — for accounting obligations — Art. 6(1)(c) GDPR (legal obligation).
  • Communication: follow-up questions, confirmation e-mails, travel information — based on Art. 6(1)(b) and (f) GDPR (contract or legitimate interest).
  • Dietary information (voluntary): Details you provide about dietary preferences or intolerances are voluntary and are used solely to plan the catering during your stay. As such details may constitute health-related data within the meaning of Art. 9 GDPR, we process them on the basis of your explicit consent (Art. 9(2)(a) GDPR), which you give by voluntarily providing the information. You may withdraw this consent at any time with effect for the future.
  • Membership proof (optional): If you indicate an astro-society membership and upload proof, we process this solely to verify the 10 % discount. Legal basis Art. 6(1)(b) GDPR. The proof is stored together with the rest of your booking record and deleted once the statutory retention periods expire (see section 4).
  • Abuse prevention: To protect against automated login attempts and bulk requests we briefly keep your IP address in the server's memory (rate-limit bucket). There is explicitly NO persistent logging to log files; the IP is discarded from memory automatically after a few minutes — Art. 6(1)(f) GDPR (legitimate interest in abuse-free operation).

3. Recipients / processors

We share your data only where necessary for contract performance or required by law. Service providers used:

  • Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany) — hosting of the server and database. A data processing agreement (DPA) under Art. 28 GDPR is in place.
  • Resend (Resend, Inc., USA) — sending transactional e-mails (booking receipt and confirmation, invoices, cancellation documents). Resend is certified under the EU-U.S. Data Privacy Framework (DPF), which is covered by an adequacy decision of the European Commission; processing is additionally governed by a data processing agreement (DPA) under Art. 28 GDPR.

No further sharing with third parties takes place. Any transfer to third countries outside the EEA only happens to the extent necessary for contract performance (e.g. communication with the guest) or where appropriate safeguards exist (EU-U.S. Data Privacy Framework, Standard Contractual Clauses).

4. Storage period

Booking-related data is stored as long as it is required for contract handling and as long as statutory retention periods apply (in particular § 257 HGB or Namibian tax law — typically 6–10 years). Once these periods expire, the data is deleted. Uploaded membership proofs are part of the booking record and follow the same retention period. IP addresses used for abuse prevention are held exclusively in volatile server memory (see section 2) and are NOT written to log files.

5. Your rights

You have the right at any time to:

  • access your stored data (Art. 15 GDPR)
  • rectification of inaccurate data (Art. 16 GDPR)
  • erasure ("right to be forgotten", Art. 17 GDPR), unless statutory retention periods prevent this
  • restriction of processing (Art. 18 GDPR)
  • data portability (Art. 20 GDPR)
  • object to processing based on legitimate interests (Art. 21 GDPR)
  • withdraw any consent given with effect for the future (Art. 7(3) GDPR)

To exercise your rights, simply send an e-mail to reservations@kiripotib.com.

6. Right to lodge a complaint

You have the right to lodge a complaint with a supervisory authority about the processing of your personal data — in particular the data protection authority of your usual place of residence or of the controller's country of establishment.

7. Cookies and comparable technologies

We only use the technically necessary storage that is required for the operation of the website and does not require consent:

  • Session cookie for the admin and owner login — HTTP-only, signed, used solely to authenticate logged-in staff and equipment owners. It is removed automatically on logout or once the session expires.
  • Browser localStorage for your chosen language (DE/EN). It is kept purely locally in your browser and is never transmitted to the server.

We do not use tracking, analytics or marketing cookies. The only embedded third-party script is the cookieless web-analytics tool described in section 8.

8. Web analytics (Umami)

On the public pages of this website we use the analytics tool "Umami" (provider: Umami Software, Inc.) to evaluate the use of our website on a statistical, aggregated basis and to improve our services. The data is processed on the provider's servers.

Umami works without cookies and does not store or read any information on your device. No personal data is collected and no cross-device or cross-site profiles are created. Your IP address is not stored; any same-day recognition relies solely on an anonymous, daily-rotating hash that does not allow conclusions about your identity. Only aggregated, anonymous usage data is recorded — in particular pages viewed, referring source, approximate region/country, browser/operating system/device type and time on page. Information you enter into forms (e.g. booking details) is NOT recorded, and no analytics takes place in the internal administration area.

The legal basis is our legitimate interest in a needs-based and statistically sound design of our website (Art. 6(1)(f) GDPR). As Umami sets no cookies and does not store or read information on your device, no consent under Section 25 TDDDG (formerly TTDSG) is required. The processing is carried out on our behalf under a data processing agreement (Art. 28 GDPR). Umami stores no personal data; an IP address transmitted to the provider when the connection is established is used solely for anonymous evaluation (region/country) and is not stored. Where data is processed outside the EEA, this is covered by appropriate safeguards. You may object at any time (Art. 21 GDPR) and can additionally prevent the script from loading via your browser settings ("Do Not Track") or a content blocker.

9. Encryption

The website uses TLS encryption (HTTPS) throughout — recognisable by the lock icon in your address bar. All transmitted data — including the booking forms — is therefore transferred in encrypted form.

10. No automated decision-making

No automated decision-making within the meaning of Art. 22 GDPR takes place. Booking requests are reviewed manually by our team before confirmation.

11. Currency of this policy

This privacy policy applies in the version currently published on this page. We reserve the right to amend it as necessary to reflect changes in the law or features of the website.