Which data arises when you visit this website, who receives it and what rights you have.
This is a translation for your convenience. The German version is the legally binding one.
Hotel Tusculum
Owner: Holger Möller
Gutenbergstrasse 25
35037 Marburg, Germany
Phone: +49 6421 22778
Email: info@tusculum.de
The controller is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data.
We take the protection of your personal data seriously and treat it confidentially and in accordance with the law. Please note that data transmission over the internet – for example when communicating by email – can have security gaps. Complete protection of data against access by third parties is not possible.
Where you have given consent, we process your data on the basis of Art. 6(1)(a) GDPR, and for the storage of cookies or access to information on your device additionally on the basis of section 25(1) TTDSG. Where your data is needed to perform a contract or for pre-contractual measures, we rely on Art. 6(1)(b) GDPR; for legal obligations on Art. 6(1)(c) GDPR; otherwise on our legitimate interest under Art. 6(1)(f) GDPR. Which basis applies in a particular case is stated in the relevant section.
Unless a more specific period is stated here, your personal data remains with us until the purpose of the processing no longer applies. If you make a legitimate request for deletion or withdraw your consent, your data will be deleted unless statutory retention periods prevent this; in that case deletion follows once they expire.
Some of the services named below may transfer data to the USA or other countries outside the EU. There, a level of data protection comparable to the EU cannot be guaranteed; in particular, authorities may under certain circumstances access data without you having an effective legal remedy against it. We have no influence on this processing. These services are loaded only after you have given your consent.
This site uses SSL or TLS encryption throughout. You can tell by the “https://” in the address bar and the padlock symbol in your browser. What you send us therefore cannot be read by third parties.
We hereby object to the use of the contact details published in the legal notice for sending advertising that has not been expressly requested. We expressly reserve the right to take legal action in the event of unsolicited advertising.
This website is hosted by IONOS SE, Elgendorfer Strasse 57, 56410 Montabaur, Germany. The servers are located in Germany. IONOS processes the data arising when these pages are called up on our behalf. The legal basis is our legitimate interest in providing the website securely and reliably (Art. 6(1)(f) GDPR). A data processing agreement under Art. 28 GDPR is in place with IONOS.
When the website is called up, data is automatically stored in log files: the address requested, date and time, amount of data transferred, notification of successful retrieval, browser type and version, operating system, the page visited before and the IP address. This data is not merged with other data sources and serves solely the operation and security of the website.
This website uses cookies – small packets of data stored on your device. They do no harm there. Session cookies are deleted automatically after your visit; permanent cookies remain until you delete them or your browser does it for you. The services named below may also set cookies (third-party cookies).
We store technically necessary cookies on the basis of our legitimate interest in providing the site without errors (Art. 6(1)(f) GDPR). All other cookies are stored only with your consent (Art. 6(1)(a) GDPR, section 25(1) TTDSG), which you can withdraw at any time. You can also set your browser to accept cookies only in individual cases or not at all; the functionality of this website may then be limited.
To manage your consent we use the consent technology of Usercentrics. The
provider is Usercentrics GmbH, Sendlinger Strasse 7, 80331 Munich, Germany. When the
page is called up, scripts are loaded from app.eu.usercentrics.eu and
sdp.eu.usercentrics.eu.
The following data is transmitted to Usercentrics: your consent or its withdrawal, your IP address, information about your browser and device, and the time of your visit. In addition, a cookie is stored in your browser so that your decision can be assigned to you. The legal basis is our legal obligation to be able to demonstrate consent (Art. 6(1)(c) GDPR). A data processing agreement is in place with Usercentrics.
If you contact us by email or telephone, we process your details in order to answer your enquiry. The legal basis is Art. 6(1)(b) GDPR where the enquiry relates to a contract, otherwise our legitimate interest in answering it (Art. 6(1)(f) GDPR). We delete the data as soon as it is no longer needed and no statutory retention obligations prevent this.
For room enquiries and bookings we use the hotel system igumbi. Both of them –
the enquiry form and the booking process – open in a layer on top of this
page. They are components provided by igumbi that load into our page; you stay on
tusculum.de while using them. Neither is loaded until you click on it, not
already when the page is opened. So if you neither enquire nor book, no contact with
igumbi takes place at all.
When they open, scripts are loaded from www.igumbi.net and the images of
the room categories from s3.amazonaws.com (Amazon Web Services); your IP
address is transmitted to these providers in the process.
What is transmitted is what you enter yourself: for an enquiry your travel dates, room category and number of people, plus form of address, name, email address, telephone number, postal address and your remarks; for a booking additionally the details required for the contract and the payment. We then handle the enquiry like any other contact. The legal basis is Art. 6(1)(b) GDPR.
The provider is igumbi (igumbi.com), based in Vienna, Austria. The
processing therefore takes place within the European Union; no transfer to a third
country is involved.
Payments in connection with a booking are handled through the payment service Stripe. For customers within the EU the provider is Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. Stripe processes the data required for the payment, such as name, amount and means of payment.
Since the booking process is embedded in our page (see section 7), you enter your
payment details in a form displayed on tusculum.de. The input fields for
the card details are provided by Stripe itself (“Stripe Elements”). Your full card
number is transmitted to Stripe only; neither we nor the hotel system igumbi
receive it. What is passed on to igumbi is only the last four digits, the card brand,
the expiry date, the cardholder’s name and an identifier for the payment issued by
Stripe. The legal basis is the performance of the contract under Art. 6(1)(b) GDPR and
our legitimate interest in a secure payment process (Art. 6(1)(f) GDPR). Stripe’s own
privacy terms apply in addition:
stripe.com/privacy.
Where data is transferred to the USA, Stripe relies on the standard contractual clauses
of the European Commission.
In the section “What our guests say” we embed reviews from review portals. Content is loaded from the following servers, and your IP address is transmitted to the respective provider:
apps.elfsight.com,
core.service.elfsight.com, service-reviews-ultimate.elfsight.com,
static.elfsight.com, universe-static.elfsightcdn.comapps.expediapartnercentral.comwww.jscache.com, www.tripadvisor.de,
static.tacdn.comThis content is only loaded once you have given your consent. The legal basis is your consent under Art. 6(1)(a) GDPR. You can withdraw it at any time via the privacy settings.
The figure “4.4 from 244 Google reviews” is fetched from Google once a day by our server and stored as a small file on this website. Your browser does not contact Google; it loads the figure from our own server. No data about you is therefore transmitted to Google, and no consent is required for this.
On the “Parking” page we show the current occupancy figures for Marburg’s car parks.
The display is loaded from pls.marburg.de, a service of the University Town
of Marburg and Stadtwerke Marburg. Your IP address is transmitted there in the process.
The content is only loaded once you have given your consent (Art. 6(1)(a) GDPR).
The button at the bottom of the screen takes you to a chat assistant. It is operated
at workflow.zollhaus-ki.de. You are writing to an automated system there,
not to a person. When you open and use the chat, your messages are transmitted there in
order to answer your question; IP address, time and the course of the conversation may
also be recorded. The legal basis is Art. 6(1)(b) GDPR where it concerns initiating or
handling a booking, and otherwise your consent given by opening the chat
(Art. 6(1)(a) GDPR).
The answers are generated in the background by an AI language model (GPT-4o) which we use via Microsoft Azure. It runs in European data centres; your chat input does not leave the European Union. The messages are passed to this model so that it can answer your question.
When you call us, your call may be answered by an AI-supported voice assistant (“Lena”). You are then speaking to an automated application, not to a person. The service is provided via voicemind.de. At the beginning of the call we point this out: “This call is processed with AI support.”
What is processed is your spoken input (converted into text in real time), the content of the conversation including details you give such as name, telephone number, your request or a desired appointment, and technical connection data such as telephone number, time and duration of the call. The purpose is the automated handling of your request, in particular arranging appointments and giving simple information.
Where the data is required to arrange or carry out an appointment, the legal basis is Art. 6(1)(b) GDPR. The call is recorded and transcribed only with your consent under Art. 6(1)(a) GDPR. If you do not want this, please hang up and use another way of contacting us, for example email. Transcripts are stored for a maximum of 30 days and then deleted automatically, unless longer statutory retention periods or a documented dispute prevent this. You can withdraw your consent at any time with effect for the future.
The fonts used on this website are held on our own server. There is no connection to Google Fonts or any other font service, so no data is transmitted there either.
You have the right to free information about the data stored about you, its origin, its recipients and the purpose of the processing (Art. 15 GDPR), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18) and to data portability (Art. 20). Simply write to info@tusculum.de.
Many processing operations are only possible with your express consent. You can withdraw consent you have given at any time with effect for the future. The lawfulness of the processing carried out until then remains unaffected.
Where processing is based on Art. 6(1)(e) or (f) GDPR, you have the right at any time to object to the processing of your personal data on grounds relating to your particular situation; this also applies to profiling based on those provisions. If you object, we will no longer process your data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.
If your data is processed for direct marketing, you have the right to object to that processing at any time; your data will then no longer be used for that purpose.
You can request the restriction of processing if you dispute the accuracy of your data and we are checking it, if the processing is unlawful and you want restriction instead of erasure, if we no longer need the data but you need it for legal claims, or for as long as the balancing of interests following an objection is still pending. Apart from being stored, restricted data may only be processed with your consent or for legal claims.
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your residence, your place of work or the place of the alleged infringement. The authority responsible for us is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
(Hessian Commissioner for Data Protection and Freedom of Information)
Postfach 3163
65021 Wiesbaden, Germany
Version: 30 August 2026