Legal
Privacy policy
This privacy policy is a translation of the German version. In case of doubt, the German version shall prevail.
1. Data controller
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) of the European Union and the Swiss Federal Act on Data Protection (FADP, revised version of 1 September 2023) is:
J T Consulting LTD & EOOD
c/o Residenz Victoria
10 Viktoria Leyks Nort str./blvd.
Mestnost Kosharite Distr.
Pomorie, 8200 Bulgaria
Represented by the Resort Managers: Thomas Hippin, Petya Hippin
Email: info@residenz-victoria.ch
Phone: +41 79 899 44 33 (Switzerland)
Phone: +359 87 611 12 35 (Bulgaria)
Please address all requests under Art. 15–22 GDPR (access, rectification, erasure, restriction, objection, data portability) as well as complaints about the processing of your data exclusively to the controller named above.
External service providers: In the areas of marketing, online presence and sales initiation, the controller is supported by external service providers, namely Mr Jens Herbst. These service providers process personal data exclusively on the instructions and on behalf of J T Consulting LTD & EOOD (Art. 28 GDPR or as auxiliary persons within the meaning of the Swiss FADP) and are not independent controllers within the meaning of Art. 4(7) GDPR. Any separate data protection liability of these external service providers towards the data subjects is excluded; the party responsible for liability remains solely J T Consulting LTD & EOOD as named above.
2. Scope
This privacy policy applies to the website residenz-victoria.ch and all associated subpages. It explains the nature, scope and purpose of the collection and use of personal data.
As we address people in the DACH region (Germany, Austria, Switzerland), we are subject to both the EU GDPR and the Swiss FADP. The stricter rule in each case is applied.
For linked pages outside residenz-victoria.ch, such as the programme on RTL+, the privacy policy of the respective site applies. We serve the RTL logo from our own server, so loading a page does not transmit any data to RTL. Trademark and image rights are set out in the legal notice.
3. Principles of data processing
We process personal data in accordance with the following principles:
- Lawfulness, fairness and transparency (Art. 5(1)(a) GDPR / Art. 6(2) and (3) FADP)
- Purpose limitation (Art. 5(1)(b) GDPR / Art. 6(3) FADP)
- Data minimisation (Art. 5(1)(c) GDPR / Art. 6(2) FADP)
- Accuracy (Art. 5(1)(d) GDPR / Art. 6(5) FADP)
- Storage limitation (Art. 5(1)(e) GDPR / Art. 6(4) FADP)
- Integrity and confidentiality (Art. 5(1)(f) GDPR / Art. 8 FADP)
4. Legal bases for processing
Your personal data is processed on the following legal bases:
- Consent (Art. 6(1)(a) GDPR / Art. 31(1) FADP): You have given your consent for one or more specific purposes.
- Performance of a contract and pre-contractual measures (Art. 6(1)(b) GDPR / Art. 31(2)(a) FADP): The processing is necessary for the performance of a contract or for the implementation of pre-contractual measures.
- Legal obligation (Art. 6(1)(c) GDPR): The processing is necessary for compliance with a legal obligation.
- Legitimate interest (Art. 6(1)(f) GDPR / Art. 31(1) FADP): The processing is necessary to safeguard our legitimate interests, unless your interests or fundamental rights and freedoms override them.
5. Collection of personal data
a) Automatic data collection (server log files)
When you visit our website, your browser automatically transmits information to our server. This is stored in so-called server log files:
- Browser type and version
- Operating system used
- Referrer URL (previously visited page)
- Host name of the accessing computer
- Date and time of the server request
- IP address
This data is evaluated exclusively to ensure trouble-free operation of the website and to improve our offering. It is not combined with other data sources. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the security and optimisation of the website).
b) Contact forms
Our website offers various forms (brochure request, contact form, request for the video tour, reservation form). When you use these forms, the following data is collected:
- Title, first and last name
- E-mail address
- Phone number (optional, mandatory for reservations)
- For reservations, additionally: postal address (street, postcode, city, country), desired unit, confirmation of the reservation terms
- Message / enquiry (for the contact form)
- Preferred date and time (for consultations)
- Technical metadata: IP address, browser identifier, timestamp of submission
This data is used exclusively to process your enquiry and, in the case of reservations, to prepare a contract, and is not passed on to third parties without your consent. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) and, for optional details and the newsletter, Art. 6(1)(a) GDPR (consent).
c) Newsletter / promotional communication
When using a form, you can optionally consent to receiving promotional messages about our property projects (newsletter, updates, invitations to online events). We log the following for this purpose:
- Your email address and, if provided, title and name
- Time of consent
- Source of consent (e.g. “brochure form”, “consultation pop-up”)
- In the event of later withdrawal: time of withdrawal
You can withdraw your consent at any time with effect for the future, informally by email to info@residenz-victoria.ch or via the unsubscribe link in every marketing email. Legal basis: Art. 6(1)(a) GDPR / Art. 31(1) FADP.
d) Contact by e-mail, telephone or WhatsApp
If you contact us by e-mail, telephone or WhatsApp, your details (name, contact details, content of the enquiry) are stored in order to process the enquiry and in case of follow-up questions. We do not pass this data on without your consent. Legal basis: Art. 6(1)(b) GDPR. Information on the use of WhatsApp can be found in section 9.
7. Video tour (Vimeo)
For the video tour of the development, we embed a video from the Vimeo service (Vimeo.com, Inc., 330 West 34th Street, New York, NY 10001, USA). The player is only loaded when you expressly start the video tour; before that, there is no connection to Vimeo.
When the video starts, your browser transmits technical data to Vimeo, in particular your IP address, browser and device details and the page visited. We embed the player with the “dnt” (Do Not Track) parameter: Vimeo then sets no tracking cookies and does not analyse playback for advertising purposes.
The legal basis is your consent by starting the video (Art. 6(1)(a) GDPR). We provide the subtitles ourselves; they are not loaded from Vimeo.
Data transfer to the USA: Vimeo is certified under the EU-US Data Privacy Framework. Further information: Vimeo privacy policy.
8. Sending e-mails (Resend, USA)
For the reliable sending of transactional e-mails (confirmation e-mails, brochure dispatch, reservation confirmations, newsletters) and for internal notification e-mails to our team, we use the Resend service of Resend Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA.
In this process, the following data is transmitted to Resend and processed there:
- E-mail address, title and name of the recipient
- Content of the respective e-mail
- Time of sending and technical delivery statistics (delivery, opening, bounce, spam complaints)
Resend is used solely to deliver the e-mails you have triggered or consented to. There is no further profiling, no advertising and no disclosure to third parties.
Processing on our behalf: We have concluded a data processing agreement (DPA) with Resend in accordance with Art. 28 GDPR.
Data transfer to the USA: Resend Inc. is certified under the EU-US Data Privacy Framework (active status can be verified in the official directory). This provides a level of data protection recognised by an adequacy decision of the EU Commission. In addition, we rely on EU standard contractual clauses.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) for transactional e-mails, Art. 6(1)(a) GDPR (consent) for promotional e-mails and Art. 6(1)(f) GDPR (legitimate interest) for internal notifications.
Further information: Resend privacy policy · Resend DPA.
9. WhatsApp contact (optional)
We optionally offer you the opportunity to contact us via WhatsApp (provider: WhatsApp Ireland Ltd., 4 Grand Canal Square, Dublin, Ireland; parent group: Meta Platforms Ireland Ltd., based in Ireland, and Meta Platforms, Inc. in the USA). On our website you will find “click-to-chat” links for this purpose following the pattern https://wa.me/....
Important: No WhatsApp/Meta pixel and no social media plug-in is integrated on our website. No data is transferred to Meta unless you yourself click on a WhatsApp link. Only through your active click does your browser or the WhatsApp app open a conversation with us.
As soon as you contact us via WhatsApp, the privacy provisions of WhatsApp/Meta apply. In particular, the following is processed: telephone number, profile name, where applicable profile picture, content of the messages, timestamps and technical connection data. This processing lies outside our sphere of influence.
Data transfer to the USA: Meta Platforms, Inc. is certified under the EU-US Data Privacy Framework. We recommend reading the WhatsApp privacy policy before contacting us via WhatsApp.
Legal basis for providing the click-to-chat links: Art. 6(1)(f) GDPR (legitimate interest in a low-threshold contact channel). If you do not wish to use WhatsApp, e-mail and telephone are available to you as equivalent alternatives.
10. Audit log (activity logging)
For reasons of IT security, verifiability pursuant to Art. 5(2) GDPR (accountability) and protection against abuse, we operate an internal audit log. The following events are documented in it automatically and in an audit-proof manner:
- Creation, modification and deletion of enquiries and reservations (with before/after comparison of the changed fields)
- Granting, withdrawal and renewed granting of newsletter consents (with source and timestamp)
- Sending and failed attempts of each individual e-mail (with recipient, subject and Resend message ID)
- Logins, logouts and failed login attempts in the internal admin area
- Changes to system settings as well as GDPR access requests and erasures
For each entry, the date, time, IP address and browser identifier of the acting party are also stored.
Retention period / anonymisation: Audit entries are stored for a maximum of 12 months with IP address and browser identifier. After this period, the IP and browser are anonymised; the business transaction history is retained in anonymised form for evidentiary purposes. In the event of a GDPR erasure (see section 16, right to erasure), all data identifying the data subject in the associated audit entries is also anonymised immediately.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in IT security, prevention of abuse and fulfilment of the accountability obligation) and Art. 6(1)(c) GDPR in conjunction with Art. 5(2) GDPR.
11. Hosting
This website is hosted by Vercel Inc. (440 N Barranca Ave #4133, Covina, CA 91723, USA). The pages are delivered via Vercel's global delivery network; the server functions that process your enquiries run in the Frankfurt am Main data centre.
We store enquiries and reservation requests in a database at Neon Inc. (USA), in an Amazon Web Services data centre in Frankfurt am Main. Both providers process the data on our behalf under their data processing terms (Art. 28 GDPR).
They are used in the interest of providing our online services securely, quickly and efficiently. Legal basis: Art. 6(1)(f) GDPR (legitimate interest).
12. SSL/TLS encryption
For security reasons and to protect the transmission of confidential content, this website uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address bar of the browser changes from “http://” to “https://” and by the padlock symbol in your browser bar. When encryption is activated, the data you transmit to us cannot be read by third parties.
13. Disclosure of data to third parties / third countries
Your personal data is only transferred to third parties if:
- you have given your express consent (Art. 6(1)(a) GDPR / Art. 31(1) FADP)
- the disclosure is necessary for the performance of the contract (Art. 6(1)(b) GDPR)
- there is a legal obligation (Art. 6(1)(c) GDPR)
- the disclosure is necessary to safeguard legitimate interests and there is no reason to assume that your interest worthy of protection in non-disclosure prevails (Art. 6(1)(f) GDPR)
Overview of third-country transfers:
| Recipient | Country | Purpose | Safeguard |
|---|---|---|---|
| Resend Inc. | USA | E-mail sending (section 8) | EU-US DPF + DPA + SCC |
| Vercel Inc. | USA | Hosting and delivery (section 11) | EU-US DPF + DPA |
| Neon Inc. | USA (data in Frankfurt) | Database for enquiries (section 11) | DPA + SCC |
| Vimeo.com, Inc. | USA | Video tour, only after a click (section 7) | EU-US DPF |
| WhatsApp Ireland Ltd. / Meta Platforms, Inc. | IE / USA | Only when contact is actively initiated by clicking (section 9) | EU-US DPF |
Switzerland: The EU Commission has issued an adequacy decision for Switzerland. No transfer beyond this to third countries without an adequate level of data protection takes place.
14. Retention period
Personal data is stored only for as long as is necessary for the respective purpose of processing:
| Data category | Retention period |
|---|---|
| Enquiries from contact forms, without follow-up business | Until processed, then max. 6 months |
| Reservations and contract data | Duration of the business relationship + statutory retention (usually 6 to 10 years under the German Commercial Code (HGB) and Fiscal Code (AO)) |
| Newsletter consents and withdrawals | Until withdrawal; proof of withdrawal beyond that for evidentiary purposes |
| Server log files | Max. 30 days |
| Audit log with IP/browser | 12 months, then anonymisation |
| Audit log, business transaction history (anonymised) | As long as necessary to fulfil the accountability obligation |
After the respective period has expired, the data is routinely deleted or anonymised.
15. No automated decisions
We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR / Art. 21 FADP. All decisions on reservations, conclusion of contracts or the answering of enquiries are made personally by our staff.
16. Your rights as a data subject
Under the EU GDPR (Art. 15–22) and the Swiss FADP (Art. 25–29), you have the following rights with regard to your personal data:
Right of access (Art. 15 GDPR / Art. 25 FADP)
You can request information at any time, free of charge, about your personal data stored by us, its origin, recipients and the purpose of the data processing. On request, we will provide you with a machine-readable file (JSON) containing all data stored about you and the complete processing history from the audit log.
Right to rectification (Art. 16 GDPR / Art. 32(1) FADP)
You have the right to request the rectification of inaccurate data or the completion of incomplete data.
Right to erasure (Art. 17 GDPR / “right to be forgotten” / Art. 32(2)(c) FADP)
You can request the immediate erasure of your data, provided that no statutory retention obligations or overriding legitimate interests of the controller stand in the way. When you exercise this right, all data identifying you in our audit log is also anonymised immediately.
Right to restriction of processing (Art. 18 GDPR)
You can request the restriction of processing, e.g. if the accuracy of the data is contested.
Right to data portability (Art. 20 GDPR / Art. 28 FADP)
You have the right to receive your data in a structured, commonly used and machine-readable format or to request its transmission to another controller.
Right to object (Art. 21 GDPR)
You can object to the processing of your data at any time if the processing is based on a legitimate interest (Art. 6(1)(f) GDPR). In the event of an objection, we will cease the processing unless we can demonstrate compelling legitimate grounds.
Right to withdraw consent (Art. 7(3) GDPR / Art. 31(3) FADP)
You can withdraw consent you have given at any time with effect for the future. The lawfulness of the processing carried out until the withdrawal remains unaffected.
Response time: We process your request within the statutory period of one month (Art. 12(3) GDPR). An informal message is sufficient to exercise your rights: info@residenz-victoria.ch. We may request suitable proof to verify your identity.
17. Right to lodge a complaint with a supervisory authority
If you believe that the processing of your personal data violates data protection provisions, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR / Art. 49 FADP):
Switzerland
Federal Data Protection and Information Commissioner (FDPIC)
Feldeggweg 1, 3003 Bern
Bulgaria (seat of the controller)
Commission for Personal Data Protection (CPDP)
2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia
Germany / Austria
The competent data protection supervisory authority of your federal state or the Austrian Data Protection Authority (www.dsb.gv.at).
18. Objection to advertising e-mails
The use of contact data published within the scope of the legal notice obligation for sending advertising and information materials that have not been expressly requested is hereby expressly objected to. The operators of the pages expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, for example by spam e-mails.
19. Changes to this privacy policy
We reserve the right to amend this privacy policy at any time so that it always complies with current legal requirements or to reflect changes to our services in the privacy policy. The privacy policy in force at the time will then apply to your next visit.
As of: September 2026