Privacy notice
This notice covers auxapartment.de, bookings for AUX Lichtblick Göggingen and related guest assistance. Updated: 1 October 2026.
1. Controller and contact
Taras Serikov
Zieglerstraße 10
86199 Augsburg, Germany
Email: info@auxliving.de
Telephone: +49 1523 3924283
Both hosts handle the shared AUX Living contact channels and can access incoming messages on their linked devices. The accommodation provider named above is responsible for this website and the letting of Lichtblick.
2. Visiting the website
The website uses the website builder supplied by Smoobu GmbH, Pappelallee 78/79, 10437 Berlin, Germany. When you visit, technical information is processed, such as your IP address, requested page, access time, browser and device information and, where applicable, the referring page. This enables content delivery, reliable operation and investigation of technical problems or misuse. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is a secure, functioning website.
Smoobu's provider list includes Duda, Inc. for the builder (USA/EU) and AWS EMEA SARL for hosting (Germany/Ireland). Smoobu identifies the EU-US Data Privacy Framework for US transfers, or EU Standard Contractual Clauses where applicable. The linked list provides provider details and updates. See also Duda's privacy policy.
Technical-log retention depends on the operational and security purpose: the time needed to deliver the service and investigate faults, and, where relevant, to address specific security incidents and meet legal evidence obligations. Logs and booking records do not share one blanket retention period.
Map display: The apartment details page loads a map from Mapbox, Inc. (USA), using OpenStreetMap data. In particular, your IP address, browser information and technical usage data are transmitted to Mapbox. The purpose is to show the location; the basis is our legitimate interest in clear accommodation information (Article 6(1)(f) GDPR). Mapbox states that IP addresses are normally deleted after 30 days; investigations may require longer retention. Mapbox also processes certain data as an independent controller. For international transfers it cites the EU-US Data Privacy Framework and, where needed, EU standard contractual clauses. Details and contact for exercising your rights: Mapbox privacy.
3. Booking and online check-in through Smoobu
The embedded booking form connects to Smoobu when it loads. During a search or booking, we process travel dates, guest numbers, name, contact details, billing address and requests you provide. This also includes booking status, agreed services, total price and payment status. Smoobu is also used for confirmations, online check-in and arrival information.
We need this information to handle your booking enquiry and perform the accommodation contract (Article 6(1)(b) GDPR). Smoobu processes the guest data supplied for these purposes on our behalf under its contractual terms, including its data processing agreement.
Fields required for the relevant function are identified in the form. We cannot process a booking without the necessary contractual and contact details. Additional requests and voluntary information are not prerequisites for booking. Please contact us by email or telephone if you have questions about a required field.
Foreign guests are subject to the special registration requirements in sections 29 and 30 of Germany's Federal Registration Act (BMG). These require, in particular, name, birth, nationality, address, stay and identity-document information to the extent specified by law. The purpose is statutory guest registration, based on Article 6(1)(c) GDPR together with those provisions. Statutory registration cannot be completed without the required information. An online check-in does not automatically replace the legally required registration procedure.
4. Bank transfers and invoices
Direct bookings are payable by bank transfer. We process the payment amount, date, reference and account information communicated in the transfer to allocate payments and, where necessary, make refunds. Recipients include the banks involved. The legal basis is Article 6(1)(b) GDPR. Invoicing and statutory retention are based on Article 6(1)(c) GDPR, particularly in conjunction with tax law. Stripe and PayPal are not configured for this booking route.
5. Email and telephone
When you contact us, we use your contact details and enquiry to respond and assist you. Article 6(1)(b) GDPR applies to booking and stay-related matters. Other enquiries are handled under Article 6(1)(f) GDPR; our legitimate interest is responding appropriately to incoming requests.
Our mailbox uses Hosted Microsoft Exchange supplied by IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. IONOS also uses Fasthosts Internet Limited in the United Kingdom for this service. Transfers to the UK are covered by a European Commission adequacy decision. Emails are also available on our linked devices. Email and telephone links open the relevant function on your device; they do not make a booking.
6. Optional contact through WhatsApp Business
WhatsApp is optional. Email and telephone remain alternatives; neither booking nor access to the apartment requires WhatsApp. If you write to us there, we process your telephone number, visible profile name, messages and files you send. The purposes and legal bases described under “Email and telephone” apply. Please mention “Lichtblick” and your request; do not send access codes or identity documents.
The ordinary WhatsApp link does not load a chat window on this website or send a message. Opening it takes you to an external service. The EEA provider is WhatsApp Ireland Limited. WhatsApp independently processes usage and connection information. Contact access is enabled on our main device; contact synchronisation can transfer permitted contact numbers to WhatsApp. See the EEA WhatsApp privacy policy and WhatsApp Business privacy policy for processing and international transfers.
7. Backing up WhatsApp communications
Our WhatsApp chats, including media, are backed up weekly to Google Drive so that they can be restored after device loss or technical problems. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is maintaining the availability and recoverability of guest communications. Google Ireland Limited supplies the Google service for EEA users.
Deleting a message from the active chat does not necessarily remove it immediately from an existing backup. Backup retention depends on backup and replacement cycles, recovery needs and any necessary retention obligations. See Google's privacy policy and Google's transfer frameworks for further information on processing, deletion and international processing.
8. Cookies and device storage
Cookies and similar storage can be necessary to provide website and booking functions securely. Where access to your device is strictly necessary for a service you explicitly request, it is based on section 25(2) of the German TDDDG. Subsequent processing of personal data relies on the legal bases described above. You can manage or delete stored website data in your browser settings; blocking necessary storage may limit functionality.
The Smoobu booking route also includes a measurement script supplied by Cloudflare, Inc. Cloudflare Web Analytics evaluates technical performance, such as loading times, for the page being viewed. Where personal data is processed for this purpose, the legal basis is the legitimate interest in reliable booking functions (Article 6(1)(f) GDPR).
Cloudflare describes this RUM process as collecting performance values, page and referral information without cookies or access to stored browser data. According to Cloudflare, the IP address necessarily received with the request is discarded at the processing data centre and not retained in central RUM databases or logs. This description concerns performance measurement, not every Cloudflare service.
Processing may take place internationally. Cloudflare identifies the EU-US Data Privacy Framework and, where applicable, EU Standard Contractual Clauses for US transfers. Further information and access to transfer safeguards: Cloudflare's privacy policy.
9. Recipients and international processing
The two hosts and technical providers involved in the relevant process have access. Where necessary, banks, our tax adviser, advisers or representatives handling legal matters, and legally authorised authorities receive the information they need. This serves contract performance, legal obligations or the establishment, exercise or defence of legitimate claims, under Article 6(1)(b), (c) or (f) GDPR.
The international services named above may process data outside the European Economic Area. WhatsApp and Google identify the EU-US Data Privacy Framework for transfers to appropriately certified US companies; EU Standard Contractual Clauses are used in particular for other cases. Provider links explain the safeguards. You may also request further information or a copy of applicable safeguards using our contact details above.
10. How long we keep information
We keep data only for as long as it is needed for its purpose. Our monthly manual deletion review distinguishes:
- Ordinary, finally resolved enquiries without a booking: deletion after 90 days as part of the monthly review, unless retention is legally required or there is a specific need for evidence.
- Check-in information needed only for practical arrangements: review no later than 30 days after departure and deletion of information no longer required.
- Statutory registration forms for foreign guests: retained for one year from departure, then destroyed or deleted within the following three months (section 30(4) BMG).
- Invoices and tax accounting vouchers: normally eight years; business correspondence subject to tax retention: normally six years. These periods generally start at the end of the relevant calendar year. Longer statutory retention, particularly for open tax proceedings, remains unaffected (section 14b UStG and section 147 AO).
- Evidence for outstanding claims or disputes: for as long as needed to resolve, pursue or defend the matter, taking applicable limitation periods and ongoing proceedings into account.
The 90-day rule and 30-day review are our operating rules, not blanket statutory deadlines. They do not automatically delete all booking data. The purpose-related criteria described above also apply to backups and technical logs.
11. Doorbell camera and noise-level measurement
The entrance area has a doorbell camera belonging to the building management. It is activated when the doorbell rings to see who is at the entrance, not by motion. It is separate from our Minut noise-level sensor. The building management is responsible for the camera.
We use Minut to measure noise levels in the apartment, detect significant disturbance and protect quiet enjoyment and neighbours. It measures decibel levels and associated times, not conversations or audio recordings. Readings may be personal data when linked to a stay. The legal basis is Article 6(1)(f) GDPR; the protective purposes described are our legitimate interests.
Recipients include Minut, Inc., its affiliates and technical providers. Minut states that it stores data in the EU, with possible third-country access subject to safeguards such as EU Standard Contractual Clauses. Available measurement history depends on the subscribed plan; necessity and the retention criteria above apply to incident-related evidence. Further information and a privacy contact: Minut's privacy policy.
12. Your rights
Subject to legal conditions, you have rights of access, rectification, erasure, restriction and data portability. Where processing relies on legitimate interests, you may object on grounds relating to your particular situation. You may withdraw consent at any time for the future, without affecting the lawfulness of processing before withdrawal.
Please contact info@auxliving.de. You may also complain to a supervisory authority, including the Bavarian State Office for Data Protection Supervision or the authority in your country of habitual residence.
For the purposes described here, we do not make solely automated decisions that produce legal or similarly significant effects within the meaning of Article 22 GDPR.

