Legal information

Privacy information

1. Controller

Karl Heinz
Einzelunternehmer (sole proprietor) trading as Property 360 Tour
Hollander Strasse 57
30629 Hannover
Deutschland
Email: hello@property360tour.com

2. General information

We process personal data only where necessary to operate the website, answer enquiries, review order requests, perform agreed services, process payments, deliver digital products or comply with legal obligations. The legal basis depends on the purpose and may be Article 6(1)(a), (b), (c) or (f) GDPR.

3. Hosting through Netlify

The website, server functions, form metadata and private project storage are provided through Netlify. Technical data such as IP address, requested URL, timestamp, browser information and security logs may be processed to deliver and protect the service. The legal basis is Article 6(1)(f) GDPR.

4. B2B enquiries and order requests

Orders are accepted only from businesses and professional vacation-rental operators. Forms may collect name, business email address, company, telephone number, property information, public listing links, product selection, branding instructions, permission confirmations and project notes. We process this information to answer the request, assess the supplied material and prepare or perform a business contract. The legal basis is Article 6(1)(b) GDPR and, for security and request management, Article 6(1)(f) GDPR.

5. Uploaded photographs and other material

Approved photographs and logos are stored under a generated order reference in private Netlify Blobs storage. Large images may be converted to an optimized working copy before transfer. Files are used only for intake review, production, quality control, customer review and delivery. Public portfolio use requires separate optional permission.

6. Project records and CRM

Order status, payment status, next actions and internal project notes are stored in a password-protected CRM. Access is limited to administration and production tasks. Public business contact data used for permitted outreach is kept separate from customer records.

7. Payments through Stripe

When Stripe is used, payment and fraud-prevention data is transmitted directly to Stripe. Property 360 Tour does not receive complete card details; we normally receive the payment status, transaction reference, amount, currency and limited customer information. The legal basis is Article 6(1)(b) GDPR and Article 6(1)(f) GDPR. Stripe may process data outside the European Economic Area using applicable transfer safeguards.

8. Optional website analytics

Google Tag Manager, container ID GTM-53N3PVV6, is used to load and manage optional measurement tools. The container is not loaded until a visitor selects “Allow analytics.” The container itself does not create user profiles; the data processing depends on the optional services configured in it and described in this section.

Google Analytics 4, measurement ID G-B3NHT2Y4XM, is loaded only after a visitor selects “Allow analytics.” The service measures sanitized page paths and selected interactions such as service selections, order-form steps and completed request types. Names, email addresses, form contents, uploaded files, file names and internal order references are not sent to Google Analytics.

With the same optional consent, Microsoft Clarity, project ID xo319kfawg, is loaded to help identify usability issues through aggregated interaction data, heatmaps and session recordings. Forms are explicitly masked and sensitive input fields are not intended to be captured. Clarity may process technical information such as device, browser, approximate location, page interactions and session identifiers.

The legal basis is consent under Article 6(1)(a) GDPR and the applicable telecommunications data-protection rules. Consent is stored locally and can be changed through “Analytics settings.” Advertising storage, advertising user data and advertising personalization remain disabled. Withdrawing consent removes the analytics cookies accessible to this website and reloads the page without the optional analytics scripts.

9. Email communication

We use our business mailbox for individual service communication. The newsletter form records the submitted email address, optional first name, selected interests, consent version, source page and submission time. A business contact is placed into an outreach campaign only after the contact's relevance, permitted outreach basis, supporting evidence, email verification and suppression status have been reviewed and Karl Heinz has given contact-specific approval. A public business email address alone is not treated as consent. Commercial email links may contain aggregate campaign parameters identifying the sending application, campaign, template and link placement. These links do not contain an email address, contact ID, company name or other recipient identifier, and the website sends campaign attribution to Google Analytics only after optional analytics consent. The current Thunderbird templates do not contain an email-open tracking pixel. Where an email delivery and outreach management provider is used, it may process delivery, clicks, replies, unsubscribes and suppression records on our behalf. Every commercial email must identify the sender, include the postal address and provide a working opt-out method. Marketing consent can be withdrawn and direct marketing can be objected to at any time using the unsubscribe option or by email. Transactional messages relating to an enquiry, contract, payment, project or delivery are not marketing messages.

10. Recipients and international transfers

Data is disclosed only where necessary to hosting, storage, payment, analytics, email, accounting, legal or technical service providers. Some providers may process data outside the European Economic Area. Where required, transfers rely on an adequacy decision, approved contractual clauses or another lawful safeguard.

11. Retention

Retention and deletion are managed by Karl Heinz. A redacted retention report is reviewed monthly and every review, deletion or exception decision is recorded in the manual deletion register. The report is read-only; deletion remains a deliberate provider-side action after the required checks.

  • An enquiry that does not become an accepted project is reviewed and normally deleted 12 months after the last substantive activity.
  • Delivered working and project files are reviewed and normally deleted 90 days after final delivery, unless the customer has agreed a longer support period or a documented exception applies. Final deliverables already received by the customer are not guaranteed to remain downloadable after that period.
  • An abandoned upload without a saved order is reviewed and normally deleted 30 days after the upload session expires or after the last upload activity, whichever is later, once the failed or unresolved submission state has been checked.
  • Contract, invoice, accounting and payment records are retained for the periods required by applicable tax, commercial and accounting law.
  • A documented legal hold overrides the normal deletion date until the matter and applicable limitation period are resolved.
  • Marketing consent records are retained while relied upon and as necessary to demonstrate compliance. Opt-out and suppression information is retained in the minimum form necessary to prevent future contact, reviewed annually and not erased while it is still required to honor the objection.
  • Provider logs and backups expire under the provider's own lifecycle. They are included in the monthly review where they can be controlled directly.

12. Your rights

Subject to the legal requirements, you may request access, correction, deletion, restriction, portability or object to processing based on legitimate interests. Consent may be withdrawn for the future at any time. Requests can be sent to hello@property360tour.com.

You may also lodge a complaint with the competent supervisory authority. For the controller's location this is the State Commissioner for Data Protection of Lower Saxony.

13. Security and automated decisions

We use technical and organizational measures appropriate to the risk, including access controls, signed upload sessions and protected administration. No decision producing legal or similarly significant effects is made solely by automated processing.

Last updated: July 2026