Privacy policy
This privacy policy is a translation of the German version. In case of doubt, the German version shall prevail.
Table of contents
- ›1. Data controller
- ›2. Scope
- ›3. Principles of data processing
- ›4. Legal bases for processing
- ›5. Collection of personal data
- ›6. Cookies, tracking & consent management
- ›7. Cloudflare Turnstile (spam protection)
- ›8. Sending e-mails (Resend, USA)
- ›9. WhatsApp contact (optional)
- ›10. Audit log (activity logging)
- ›11. Hosting
- ›12. SSL/TLS encryption
- ›13. Disclosure of data to third parties / third countries
- ›14. Retention period
- ›15. No automated decisions
- ›16. Your rights as a data subject
- ›17. Right to lodge a complaint with a supervisory authority
- ›18. Objection to advertising e-mails
- ›19. Changes to this privacy policy
1. Data controller
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) of the European Union and the Swiss Federal Act on Data Protection (FADP, revised version of 1 September 2023) is:
J T Consulting LTD & EOOD
c/o Prime Residenz
10 Viktoria Leyks Nort str./blvd.
Mestnost Kosharite Distr.
Pomorie, 8200 Bulgaria
Represented by the Resort Managers: Thomas Hippin, Petya Hippin
E-mail: info@prime-residenz.ch
Phone: +41 79 899 44 33 (Switzerland)
Phone: +359 87 611 12 35 (Bulgaria)
Please address all requests under Art. 15–22 GDPR (access, rectification, erasure, restriction, objection, data portability) as well as complaints about the processing of your data exclusively to the controller named above.
External service providers: In the areas of marketing, online presence and business development, the controller is supported by external service providers, namely Mr Jens Herbst. These service providers process personal data exclusively on instruction and on behalf of J T Consulting LTD & EOOD (Art. 28 GDPR or in the capacity of auxiliary persons within the meaning of the Swiss FADP) and are not independent controllers within the meaning of Art. 4 no. 7 GDPR. Any personal liability of these external service providers under data protection law towards the data subjects is excluded; the party liable remains exclusively J T Consulting LTD & EOOD named above.
2. Scope
This privacy policy applies to the website prime-residenz.ch and all associated subpages. It provides information on the nature, scope and purpose of the collection and use of personal data.
As we address people in the DACH region (Germany, Austria, Switzerland), we are subject to both the EU GDPR and the Swiss FADP. The stricter rule in each case is applied.
3. Principles of data processing
We process personal data in accordance with the following principles:
- Lawfulness, fairness and transparency (Art. 5(1)(a) GDPR / Art. 6(2) and (3) FADP)
- Purpose limitation (Art. 5(1)(b) GDPR / Art. 6(3) FADP)
- Data minimisation (Art. 5(1)(c) GDPR / Art. 6(2) FADP)
- Accuracy (Art. 5(1)(d) GDPR / Art. 6(5) FADP)
- Storage limitation (Art. 5(1)(e) GDPR / Art. 6(4) FADP)
- Integrity and confidentiality (Art. 5(1)(f) GDPR / Art. 8 FADP)
4. Legal bases for processing
Your personal data is processed on the following legal bases:
- Consent (Art. 6(1)(a) GDPR / Art. 31(1) FADP): You have given your consent for one or more specific purposes.
- Performance of a contract and pre-contractual measures (Art. 6(1)(b) GDPR / Art. 31(2)(a) FADP): The processing is necessary for the performance of a contract or for the implementation of pre-contractual measures.
- Legal obligation (Art. 6(1)(c) GDPR): The processing is necessary for compliance with a legal obligation.
- Legitimate interest (Art. 6(1)(f) GDPR / Art. 31(1) FADP): The processing is necessary to safeguard our legitimate interests, unless your interests or fundamental rights and freedoms override them.
5. Collection of personal data
a) Automatic data collection (server log files)
When you visit our website, your browser automatically transmits information to our server. This is stored in so-called server log files:
- Browser type and version
- Operating system used
- Referrer URL (previously visited page)
- Host name of the accessing computer
- Date and time of the server request
- IP address
This data is evaluated exclusively to ensure trouble-free operation of the website and to improve our offering. It is not combined with other data sources. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the security and optimisation of the website).
b) Contact forms
Our website offers various forms (brochure request, contact form, request for the video tour, reservation form). When you use these forms, the following data is collected:
- Title, first and last name
- E-mail address
- Phone number (optional, mandatory for reservations)
- For reservations, additionally: postal address (street, postcode, city, country), desired unit, confirmation of the reservation terms
- Message / enquiry (for the contact form)
- Preferred date and time (for consultations)
- Technical metadata: IP address, browser identifier, timestamp of submission
This data is used exclusively to process your enquiry and, for reservations, to initiate a contract, and is not passed on to third parties without your consent. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) and, for optional information and for the newsletter, Art. 6(1)(a) GDPR (consent).
c) Newsletter / promotional communication
When using a form, you can optionally consent to receiving promotional messages about our property projects (newsletter, updates, invitations to online events). We log the following for this purpose:
- Your e-mail address and, if provided, title and name
- Time of consent
- Source of consent (e.g. “brochure form”, “consultation pop-up”)
- In the event of later withdrawal: time of withdrawal
You can withdraw your consent at any time with effect for the future, informally by e-mail to info@prime-residenz.ch or via the unsubscribe link in every promotional e-mail. Legal basis: Art. 6(1)(a) GDPR / Art. 31(1) FADP.
d) Contact by e-mail, telephone or WhatsApp
If you contact us by e-mail, telephone or WhatsApp, your details (name, contact details, content of the enquiry) are stored in order to process the enquiry and in case of follow-up questions. We do not pass this data on without your consent. Legal basis: Art. 6(1)(b) GDPR. Information on the use of WhatsApp can be found in section 9.
7. Cloudflare Turnstile (spam protection)
To protect our forms against automated abuse (bots/spam), we use the Cloudflare Turnstile service of Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA).
When you use our forms, the following technical data is transmitted to Cloudflare:
- IP address
- Browser type and settings
- Interaction data (mouse movements, keyboard input)
- Date and time of access
This data is processed exclusively to distinguish human visitors from automated access. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in protection against abuse).
Data transfer to the USA: Cloudflare is certified under the EU-US Data Privacy Framework, which ensures an adequate level of data protection. Further information: Cloudflare privacy policy.
8. Sending e-mails (Resend, USA)
For the reliable sending of transactional e-mails (confirmation e-mails, brochure dispatch, reservation confirmations, newsletters) and for internal notification e-mails to our team, we use the Resend service of Resend Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA.
In this process, the following data is transmitted to Resend and processed there:
- E-mail address, title and name of the recipient
- Content of the respective e-mail
- Time of sending and technical delivery statistics (delivery, opening, bounce, spam complaints)
Resend is used solely to deliver the e-mails you have triggered or consented to. There is no further profiling, no advertising and no disclosure to third parties.
Processing on our behalf: We have concluded a data processing agreement (DPA) with Resend in accordance with Art. 28 GDPR.
Data transfer to the USA: Resend Inc. is certified under the EU-US Data Privacy Framework (active status can be verified in the official directory). This provides a level of data protection recognised by an adequacy decision of the EU Commission. In addition, we rely on EU standard contractual clauses.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) for transactional e-mails, Art. 6(1)(a) GDPR (consent) for promotional e-mails and Art. 6(1)(f) GDPR (legitimate interest) for internal notifications.
Further information: Resend privacy policy · Resend DPA.
9. WhatsApp contact (optional)
We optionally offer you the opportunity to contact us via WhatsApp (provider: WhatsApp Ireland Ltd., 4 Grand Canal Square, Dublin, Ireland; parent group: Meta Platforms Ireland Ltd., based in Ireland, and Meta Platforms, Inc. in the USA). On our website you will find “click-to-chat” links for this purpose following the pattern https://wa.me/....
Important: No WhatsApp/Meta pixel and no social media plug-in is integrated on our website. No data is transferred to Meta unless you yourself click on a WhatsApp link. Only through your active click does your browser or the WhatsApp app open a conversation with us.
As soon as you contact us via WhatsApp, the privacy provisions of WhatsApp/Meta apply. In particular, the following is processed: telephone number, profile name, where applicable profile picture, content of the messages, timestamps and technical connection data. This processing lies outside our sphere of influence.
Data transfer to the USA: Meta Platforms, Inc. is certified under the EU-US Data Privacy Framework. We recommend reading the WhatsApp privacy policy before contacting us via WhatsApp.
Legal basis for providing the click-to-chat links: Art. 6(1)(f) GDPR (legitimate interest in a low-threshold contact channel). If you do not wish to use WhatsApp, e-mail and telephone are available to you as equivalent alternatives.
10. Audit log (activity logging)
For reasons of IT security, verifiability pursuant to Art. 5(2) GDPR (accountability) and protection against abuse, we operate an internal audit log. The following events are documented in it automatically and in an audit-proof manner:
- Creation, modification and deletion of enquiries and reservations (with before/after comparison of the changed fields)
- Granting, withdrawal and renewed granting of newsletter consents (with source and timestamp)
- Sending and failed attempts of each individual e-mail (with recipient, subject and Resend message ID)
- Logins, logouts and failed login attempts in the internal admin area
- Changes to system settings as well as GDPR access requests and erasures
For each entry, the date, time, IP address and browser identifier of the acting party are also stored.
Retention period / anonymisation: Audit entries are stored for a maximum of 12 months with IP address and browser identifier. After this period, the IP and browser are anonymised; the business transaction history is retained in anonymised form for evidentiary purposes. In the event of a GDPR erasure (see section 16, right to erasure), all data identifying the data subject in the associated audit entries is also anonymised immediately.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in IT security, prevention of abuse and fulfilment of the accountability obligation) and Art. 6(1)(c) GDPR in conjunction with Art. 5(2) GDPR.
11. Hosting
Our website is operated on the servers of an external hosting provider. Personal data collected on this website is stored on that provider's servers. This may include IP addresses, contact enquiries, metadata and communication data, contract data and other data.
We use the hosting provider in order to provide our website securely, quickly and efficiently. Legal basis: Art. 6(1)(f) GDPR (legitimate interest). A data processing agreement pursuant to Art. 28 GDPR is in place with that provider.
12. SSL/TLS encryption
For security reasons and to protect the transmission of confidential content, this website uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address bar of the browser changes from “http://” to “https://” and by the padlock symbol in your browser bar. When encryption is activated, the data you transmit to us cannot be read by third parties.
13. Disclosure of data to third parties / third countries
Your personal data is only transferred to third parties if:
- you have given your express consent (Art. 6(1)(a) GDPR / Art. 31(1) FADP)
- the disclosure is necessary for the performance of the contract (Art. 6(1)(b) GDPR)
- there is a legal obligation (Art. 6(1)(c) GDPR)
- the disclosure is necessary to safeguard legitimate interests and there is no reason to assume that your interest worthy of protection in non-disclosure prevails (Art. 6(1)(f) GDPR)
Overview of third-country transfers:
| Recipient | Country | Purpose | Safeguard |
|---|---|---|---|
| Resend Inc. | USA | E-mail sending (section 8) | EU-US DPF + DPA + SCC |
| Cloudflare, Inc. | USA | Spam protection (section 7) | EU-US DPF |
| WhatsApp Ireland Ltd. / Meta Platforms, Inc. | IE / USA | Only when contact is actively initiated by clicking (section 9) | EU-US DPF |
Switzerland: The EU Commission has issued an adequacy decision for Switzerland. No transfer beyond this to third countries without an adequate level of data protection takes place.
14. Retention period
Personal data is stored only for as long as is necessary for the respective purpose of processing:
| Data category | Retention period |
|---|---|
| Enquiries from contact forms, without follow-up business | Until processed, then max. 6 months |
| Reservations and contract data | Duration of the business relationship + statutory retention (usually 6 to 10 years under the German Commercial Code (HGB) and Fiscal Code (AO)) |
| Newsletter consents and withdrawals | Until withdrawal; proof of withdrawal beyond that for evidentiary purposes |
| Server log files | Max. 30 days |
| Audit log with IP/browser | 12 months, then anonymisation |
| Audit log, business transaction history (anonymised) | As long as necessary to fulfil the accountability obligation |
After the respective period has expired, the data is routinely deleted or anonymised.
15. No automated decisions
We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR / Art. 21 FADP. All decisions on reservations, conclusion of contracts or the answering of enquiries are made personally by our staff.
16. Your rights as a data subject
Under the EU GDPR (Art. 15–22) and the Swiss FADP (Art. 25–29), you have the following rights with regard to your personal data:
Right of access (Art. 15 GDPR / Art. 25 FADP)
You can request information at any time, free of charge, about your personal data stored by us, its origin, recipients and the purpose of the data processing. On request, we will provide you with a machine-readable file (JSON) containing all data stored about you and the complete processing history from the audit log.
Right to rectification (Art. 16 GDPR / Art. 32(1) FADP)
You have the right to request the rectification of inaccurate data or the completion of incomplete data.
Right to erasure (Art. 17 GDPR / “right to be forgotten” / Art. 32(2)(c) FADP)
You can request the immediate erasure of your data, provided that no statutory retention obligations or overriding legitimate interests of the controller stand in the way. When you exercise this right, all data identifying you in our audit log is also anonymised immediately.
Right to restriction of processing (Art. 18 GDPR)
You can request the restriction of processing, e.g. if the accuracy of the data is contested.
Right to data portability (Art. 20 GDPR / Art. 28 FADP)
You have the right to receive your data in a structured, commonly used and machine-readable format or to request its transmission to another controller.
Right to object (Art. 21 GDPR)
You can object to the processing of your data at any time if the processing is based on a legitimate interest (Art. 6(1)(f) GDPR). In the event of an objection, we will cease the processing unless we can demonstrate compelling legitimate grounds.
Right to withdraw consent (Art. 7(3) GDPR / Art. 31(3) FADP)
You can withdraw consent you have given at any time with effect for the future. The lawfulness of the processing carried out until the withdrawal remains unaffected.
Response time: We process your request within the statutory period of one month (Art. 12(3) GDPR). To exercise your rights, an informal notification to info@prime-residenz.ch is sufficient. To verify your identity, we may request suitable proof.
17. Right to lodge a complaint with a supervisory authority
If you believe that the processing of your personal data violates data protection provisions, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR / Art. 49 FADP):
Switzerland
Federal Data Protection and Information Commissioner (FDPIC)
Feldeggweg 1, 3003 Bern
Bulgaria (seat of the controller)
Commission for Personal Data Protection (CPDP)
2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia
Germany / Austria
The competent data protection supervisory authority of your federal state or the Austrian Data Protection Authority (www.dsb.gv.at).
18. Objection to advertising e-mails
The use of contact data published within the scope of the legal notice obligation for sending advertising and information materials that have not been expressly requested is hereby expressly objected to. The operators of the pages expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, for example by spam e-mails.
19. Changes to this privacy policy
We reserve the right to amend this privacy policy at any time so that it always complies with current legal requirements or to reflect changes to our services in the privacy policy. The privacy policy in force at the time will then apply to your next visit.
As of: May 2026