Legal

Privacy policy

This privacy policy is a translation of the German version. In case of doubt, the German version shall prevail.

1. Data controller

The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) of the European Union and the Swiss Federal Act on Data Protection (FADP, revised version of 1 September 2023) is:

J T Consulting LTD & EOOD

c/o Prime Residenz

10 Viktoria Leyks Nort str./blvd.

Mestnost Kosharite Distr.

Pomorie, 8200 Bulgaria

Represented by the Resort Managers: Thomas Hippin, Petya Hippin

E-mail: info@prime-residenz.ch

Phone: +41 79 899 44 33 (Switzerland)

Phone: +359 87 611 12 35 (Bulgaria)

Please address all requests under Art. 15–22 GDPR (access, rectification, erasure, restriction, objection, data portability) as well as complaints about the processing of your data exclusively to the controller named above.

External service providers: In the areas of marketing, online presence and business development, the controller is supported by external service providers, namely Mr Jens Herbst. These service providers process personal data exclusively on instruction and on behalf of J T Consulting LTD & EOOD (Art. 28 GDPR or in the capacity of auxiliary persons within the meaning of the Swiss FADP) and are not independent controllers within the meaning of Art. 4 no. 7 GDPR. Any personal liability of these external service providers under data protection law towards the data subjects is excluded; the party liable remains exclusively J T Consulting LTD & EOOD named above.

2. Scope

This privacy policy applies to the website prime-residenz.ch and all associated subpages. It provides information on the nature, scope and purpose of the collection and use of personal data.

As we address people in the DACH region (Germany, Austria, Switzerland), we are subject to both the EU GDPR and the Swiss FADP. The stricter rule in each case is applied.

3. Principles of data processing

We process personal data in accordance with the following principles:

  • Lawfulness, fairness and transparency (Art. 5(1)(a) GDPR / Art. 6(2) and (3) FADP)
  • Purpose limitation (Art. 5(1)(b) GDPR / Art. 6(3) FADP)
  • Data minimisation (Art. 5(1)(c) GDPR / Art. 6(2) FADP)
  • Accuracy (Art. 5(1)(d) GDPR / Art. 6(5) FADP)
  • Storage limitation (Art. 5(1)(e) GDPR / Art. 6(4) FADP)
  • Integrity and confidentiality (Art. 5(1)(f) GDPR / Art. 8 FADP)

4. Legal bases for processing

Your personal data is processed on the following legal bases:

  • Consent (Art. 6(1)(a) GDPR / Art. 31(1) FADP): You have given your consent for one or more specific purposes.
  • Performance of a contract and pre-contractual measures (Art. 6(1)(b) GDPR / Art. 31(2)(a) FADP): The processing is necessary for the performance of a contract or for the implementation of pre-contractual measures.
  • Legal obligation (Art. 6(1)(c) GDPR): The processing is necessary for compliance with a legal obligation.
  • Legitimate interest (Art. 6(1)(f) GDPR / Art. 31(1) FADP): The processing is necessary to safeguard our legitimate interests, unless your interests or fundamental rights and freedoms override them.

5. Collection of personal data

a) Automatic data collection (server log files)

When you visit our website, your browser automatically transmits information to our server. This is stored in so-called server log files:

  • Browser type and version
  • Operating system used
  • Referrer URL (previously visited page)
  • Host name of the accessing computer
  • Date and time of the server request
  • IP address

This data is evaluated exclusively to ensure trouble-free operation of the website and to improve our offering. It is not combined with other data sources. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the security and optimisation of the website).

b) Contact forms

Our website offers various forms (brochure request, contact form, request for the video tour, reservation form). When you use these forms, the following data is collected:

  • Title, first and last name
  • E-mail address
  • Phone number (optional, mandatory for reservations)
  • For reservations, additionally: postal address (street, postcode, city, country), desired unit, confirmation of the reservation terms
  • Message / enquiry (for the contact form)
  • Preferred date and time (for consultations)
  • Technical metadata: IP address, browser identifier, timestamp of submission

This data is used exclusively to process your enquiry and, for reservations, to initiate a contract, and is not passed on to third parties without your consent. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) and, for optional information and for the newsletter, Art. 6(1)(a) GDPR (consent).

c) Newsletter / promotional communication

When using a form, you can optionally consent to receiving promotional messages about our property projects (newsletter, updates, invitations to online events). We log the following for this purpose:

  • Your e-mail address and, if provided, title and name
  • Time of consent
  • Source of consent (e.g. “brochure form”, “consultation pop-up”)
  • In the event of later withdrawal: time of withdrawal

You can withdraw your consent at any time with effect for the future, informally by e-mail to info@prime-residenz.ch or via the unsubscribe link in every promotional e-mail. Legal basis: Art. 6(1)(a) GDPR / Art. 31(1) FADP.

d) Contact by e-mail, telephone or WhatsApp

If you contact us by e-mail, telephone or WhatsApp, your details (name, contact details, content of the enquiry) are stored in order to process the enquiry and in case of follow-up questions. We do not pass this data on without your consent. Legal basis: Art. 6(1)(b) GDPR. Information on the use of WhatsApp can be found in section 9.

6. Cookies, tracking & consent management

We use cookies and similar technologies (e.g. localStorage, pixels, tags) on this website. For all technologies that are not strictly necessary, we obtain your explicit consent via our consent banner (Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG / Art. 31(1) FADP). As long as you have not given consent, only technically necessary cookies are set; all statistics and marketing tags remain deactivated via Google Consent Mode v2 (default setting “denied”).

You can withdraw or change your consent at any time with effect for the future, without giving reasons, via our Cookie settings page or via the corresponding link in our footer.

a) Categories

In the consent banner, you can decide for each category:

  • Technically necessary: always active (admin session cookie, Cloudflare Turnstile, storage of your cookie choice)
  • Statistics & reach: Google Analytics 4, Microsoft Clarity
  • Marketing & remarketing: Google Ads, Meta Pixel, LinkedIn Insight Tag
  • Personalisation: personalised ad delivery in the advertising networks mentioned above

b) Technically necessary cookies

Cookie / storagePurposeRetention period
pr_adminAuthentication in the internal admin area (staff only)30 days, HttpOnly, SameSite=Lax
cf_*Cloudflare Turnstile / spam protection for forms (see section 7)Session / short-term cookies
pr-consent-v1localStorage: stores your consent choice (categories, timestamp, source) so that the banner respects your decisionUntil withdrawal or manual deletion in the browser

Legal basis: Art. 6(1)(f) GDPR and § 25(2) no. 2 TDDDG (strictly necessary).

Server-side proof of consent (Art. 7(1) GDPR): In addition to local storage, we log your cookie decision in pseudonymised form on our server (selected categories, timestamp, source of the decision, truncated IP address, user agent, policy version). This serves solely to meet our obligation to provide proof and is not linked to you personally. Retention period: 3 years. Effect of withdrawal: If you withdraw consent previously given for “Statistics”, “Marketing” or “Personalisation”, the page reloads automatically so that any trackers already loaded are reliably stopped.

c) Google Tag Manager (container)

We use Google Tag Manager of Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Ireland). The Tag Manager is itself a container without a tracking function; however, it loads the tags activated in the statistics and marketing categories. The container is loaded exclusively after your consent to at least one of these categories. Recipient: Google Ireland Ltd.; in the case of transfer to the USA: Google LLC under the EU-US Data Privacy Framework (DPF). Legal basis: Art. 6(1)(a) GDPR. More: policies.google.com/privacy.

d) Google Analytics 4 (statistics)

If you consent to “Statistics”, we use Google Analytics 4 of Google Ireland Ltd. for pseudonymised analysis of reach and usage. We activate IP anonymisation as well as the Google Consent Mode default settings ads_data_redaction=true and url_passthrough=true. Data processed: IP address (truncated), device and browser information, pages visited, dwell time, approximate location (country/region). Retention period of the cookies (_ga, _ga_*): 14 months. US transfer: Google LLC under the EU-US DPF. Legal basis: Art. 6(1)(a) GDPR.

e) Microsoft Clarity (statistics)

If you consent to “Statistics”, we use Microsoft Clarity of Microsoft Ireland Operations Ltd. (One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland) to create heatmaps and (anonymised) session recordings. Entries in form fields are masked by default. Retention period of the cookies (_clck, _clsk): up to 12 months. US transfer: Microsoft Corporation under the EU-US DPF. Legal basis: Art. 6(1)(a) GDPR. More: privacy.microsoft.com.

f) Google Ads: conversion tracking & remarketing (marketing)

If you consent to “Marketing”, we use Google Ads of Google Ireland Ltd. to measure the effectiveness of our advertisements (conversion tracking) and to reach website visitors again on advertising networks (remarketing). Cookies (_gcl_*, NID, IDE): up to 13 months (EU/EEA). Recipient: Google Ireland Ltd., in the case of US transfer Google LLC under the EU-US DPF. Legal basis: Art. 6(1)(a) GDPR.

g) Meta Pixel (Facebook/Instagram, marketing)

If you consent to “Marketing”, we use the Meta Pixel of Meta Platforms Ireland Ltd. (Merrion Road, Dublin 4, Ireland). The data processed includes the pixel ID, IP address, browser/device information, the page visited, conversion events and, where applicable, a pseudonymous Meta user ID. This data is used to measure advertising success and to create custom/lookalike audiences on the Meta platforms (Facebook, Instagram). Joint controllership exists for the collection and transmission of the data in accordance with Meta's joint controller agreement. Cookies (_fbp): up to 90 days. US transfer: Meta Platforms, Inc. under the EU-US DPF. Legal basis: Art. 6(1)(a) GDPR. More: facebook.com/policy.php.

h) LinkedIn Insight Tag (marketing)

If you consent to “Marketing”, we use the LinkedIn Insight Tag of LinkedIn Ireland Unlimited Company (Wilton Plaza, Wilton Place, Dublin 2, Ireland) for conversion tracking, retargeting and audience building on LinkedIn. The data processed includes the IP address, device/browser information, pages visited, timestamp and a cookie (li_sugr, UserMatchHistory): up to 90 days. US transfer: LinkedIn Corporation under the EU-US DPF. Legal basis: Art. 6(1)(a) GDPR.

i) Personalisation

If you additionally consent to “Personalisation”, we activate ad_personalization=granted and personalization_storage=granted in the Google services. This allows personalised ad delivery and recommendations based on your usage behaviour.

j) Note on transfers to third countries

The US services mentioned involve a transfer of data to the USA. All the providers listed are certified under the EU-US Data Privacy Framework (DPF); in addition, EU standard contractual clauses (SCC) and company-side protective measures are in place. Nevertheless, a residual risk remains with regard to access by US authorities without a comparable level of legal protection. By consenting to “Statistics”, “Marketing” or “Personalisation”, you also expressly agree to this third-country transfer pursuant to Art. 49(1)(a) GDPR.

7. Cloudflare Turnstile (spam protection)

To protect our forms against automated abuse (bots/spam), we use the Cloudflare Turnstile service of Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA).

When you use our forms, the following technical data is transmitted to Cloudflare:

  • IP address
  • Browser type and settings
  • Interaction data (mouse movements, keyboard input)
  • Date and time of access

This data is processed exclusively to distinguish human visitors from automated access. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in protection against abuse).

Data transfer to the USA: Cloudflare is certified under the EU-US Data Privacy Framework, which ensures an adequate level of data protection. Further information: Cloudflare privacy policy.

8. Sending e-mails (Resend, USA)

For the reliable sending of transactional e-mails (confirmation e-mails, brochure dispatch, reservation confirmations, newsletters) and for internal notification e-mails to our team, we use the Resend service of Resend Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA.

In this process, the following data is transmitted to Resend and processed there:

  • E-mail address, title and name of the recipient
  • Content of the respective e-mail
  • Time of sending and technical delivery statistics (delivery, opening, bounce, spam complaints)

Resend is used solely to deliver the e-mails you have triggered or consented to. There is no further profiling, no advertising and no disclosure to third parties.

Processing on our behalf: We have concluded a data processing agreement (DPA) with Resend in accordance with Art. 28 GDPR.

Data transfer to the USA: Resend Inc. is certified under the EU-US Data Privacy Framework (active status can be verified in the official directory). This provides a level of data protection recognised by an adequacy decision of the EU Commission. In addition, we rely on EU standard contractual clauses.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract) for transactional e-mails, Art. 6(1)(a) GDPR (consent) for promotional e-mails and Art. 6(1)(f) GDPR (legitimate interest) for internal notifications.

Further information: Resend privacy policy · Resend DPA.

9. WhatsApp contact (optional)

We optionally offer you the opportunity to contact us via WhatsApp (provider: WhatsApp Ireland Ltd., 4 Grand Canal Square, Dublin, Ireland; parent group: Meta Platforms Ireland Ltd., based in Ireland, and Meta Platforms, Inc. in the USA). On our website you will find “click-to-chat” links for this purpose following the pattern https://wa.me/....

Important: No WhatsApp/Meta pixel and no social media plug-in is integrated on our website. No data is transferred to Meta unless you yourself click on a WhatsApp link. Only through your active click does your browser or the WhatsApp app open a conversation with us.

As soon as you contact us via WhatsApp, the privacy provisions of WhatsApp/Meta apply. In particular, the following is processed: telephone number, profile name, where applicable profile picture, content of the messages, timestamps and technical connection data. This processing lies outside our sphere of influence.

Data transfer to the USA: Meta Platforms, Inc. is certified under the EU-US Data Privacy Framework. We recommend reading the WhatsApp privacy policy before contacting us via WhatsApp.

Legal basis for providing the click-to-chat links: Art. 6(1)(f) GDPR (legitimate interest in a low-threshold contact channel). If you do not wish to use WhatsApp, e-mail and telephone are available to you as equivalent alternatives.

10. Audit log (activity logging)

For reasons of IT security, verifiability pursuant to Art. 5(2) GDPR (accountability) and protection against abuse, we operate an internal audit log. The following events are documented in it automatically and in an audit-proof manner:

  • Creation, modification and deletion of enquiries and reservations (with before/after comparison of the changed fields)
  • Granting, withdrawal and renewed granting of newsletter consents (with source and timestamp)
  • Sending and failed attempts of each individual e-mail (with recipient, subject and Resend message ID)
  • Logins, logouts and failed login attempts in the internal admin area
  • Changes to system settings as well as GDPR access requests and erasures

For each entry, the date, time, IP address and browser identifier of the acting party are also stored.

Retention period / anonymisation: Audit entries are stored for a maximum of 12 months with IP address and browser identifier. After this period, the IP and browser are anonymised; the business transaction history is retained in anonymised form for evidentiary purposes. In the event of a GDPR erasure (see section 16, right to erasure), all data identifying the data subject in the associated audit entries is also anonymised immediately.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in IT security, prevention of abuse and fulfilment of the accountability obligation) and Art. 6(1)(c) GDPR in conjunction with Art. 5(2) GDPR.

11. Hosting

Our website is operated on the servers of an external hosting provider. Personal data collected on this website is stored on that provider's servers. This may include IP addresses, contact enquiries, metadata and communication data, contract data and other data.

We use the hosting provider in order to provide our website securely, quickly and efficiently. Legal basis: Art. 6(1)(f) GDPR (legitimate interest). A data processing agreement pursuant to Art. 28 GDPR is in place with that provider.

12. SSL/TLS encryption

For security reasons and to protect the transmission of confidential content, this website uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address bar of the browser changes from “http://” to “https://” and by the padlock symbol in your browser bar. When encryption is activated, the data you transmit to us cannot be read by third parties.

13. Disclosure of data to third parties / third countries

Your personal data is only transferred to third parties if:

  • you have given your express consent (Art. 6(1)(a) GDPR / Art. 31(1) FADP)
  • the disclosure is necessary for the performance of the contract (Art. 6(1)(b) GDPR)
  • there is a legal obligation (Art. 6(1)(c) GDPR)
  • the disclosure is necessary to safeguard legitimate interests and there is no reason to assume that your interest worthy of protection in non-disclosure prevails (Art. 6(1)(f) GDPR)

Overview of third-country transfers:

RecipientCountryPurposeSafeguard
Resend Inc.USAE-mail sending (section 8)EU-US DPF + DPA + SCC
Cloudflare, Inc.USASpam protection (section 7)EU-US DPF
WhatsApp Ireland Ltd. / Meta Platforms, Inc.IE / USAOnly when contact is actively initiated by clicking (section 9)EU-US DPF

Switzerland: The EU Commission has issued an adequacy decision for Switzerland. No transfer beyond this to third countries without an adequate level of data protection takes place.

14. Retention period

Personal data is stored only for as long as is necessary for the respective purpose of processing:

Data categoryRetention period
Enquiries from contact forms, without follow-up businessUntil processed, then max. 6 months
Reservations and contract dataDuration of the business relationship + statutory retention (usually 6 to 10 years under the German Commercial Code (HGB) and Fiscal Code (AO))
Newsletter consents and withdrawalsUntil withdrawal; proof of withdrawal beyond that for evidentiary purposes
Server log filesMax. 30 days
Audit log with IP/browser12 months, then anonymisation
Audit log, business transaction history (anonymised)As long as necessary to fulfil the accountability obligation

After the respective period has expired, the data is routinely deleted or anonymised.

15. No automated decisions

We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR / Art. 21 FADP. All decisions on reservations, conclusion of contracts or the answering of enquiries are made personally by our staff.

16. Your rights as a data subject

Under the EU GDPR (Art. 15–22) and the Swiss FADP (Art. 25–29), you have the following rights with regard to your personal data:

Right of access (Art. 15 GDPR / Art. 25 FADP)

You can request information at any time, free of charge, about your personal data stored by us, its origin, recipients and the purpose of the data processing. On request, we will provide you with a machine-readable file (JSON) containing all data stored about you and the complete processing history from the audit log.

Right to rectification (Art. 16 GDPR / Art. 32(1) FADP)

You have the right to request the rectification of inaccurate data or the completion of incomplete data.

Right to erasure (Art. 17 GDPR / “right to be forgotten” / Art. 32(2)(c) FADP)

You can request the immediate erasure of your data, provided that no statutory retention obligations or overriding legitimate interests of the controller stand in the way. When you exercise this right, all data identifying you in our audit log is also anonymised immediately.

Right to restriction of processing (Art. 18 GDPR)

You can request the restriction of processing, e.g. if the accuracy of the data is contested.

Right to data portability (Art. 20 GDPR / Art. 28 FADP)

You have the right to receive your data in a structured, commonly used and machine-readable format or to request its transmission to another controller.

Right to object (Art. 21 GDPR)

You can object to the processing of your data at any time if the processing is based on a legitimate interest (Art. 6(1)(f) GDPR). In the event of an objection, we will cease the processing unless we can demonstrate compelling legitimate grounds.

Right to withdraw consent (Art. 7(3) GDPR / Art. 31(3) FADP)

You can withdraw consent you have given at any time with effect for the future. The lawfulness of the processing carried out until the withdrawal remains unaffected.

Response time: We process your request within the statutory period of one month (Art. 12(3) GDPR). To exercise your rights, an informal notification to info@prime-residenz.ch is sufficient. To verify your identity, we may request suitable proof.

17. Right to lodge a complaint with a supervisory authority

If you believe that the processing of your personal data violates data protection provisions, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR / Art. 49 FADP):

Switzerland

Federal Data Protection and Information Commissioner (FDPIC)

Feldeggweg 1, 3003 Bern

www.edoeb.admin.ch

Bulgaria (seat of the controller)

Commission for Personal Data Protection (CPDP)

2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia

www.cpdp.bg

Germany / Austria

The competent data protection supervisory authority of your federal state or the Austrian Data Protection Authority (www.dsb.gv.at).

18. Objection to advertising e-mails

The use of contact data published within the scope of the legal notice obligation for sending advertising and information materials that have not been expressly requested is hereby expressly objected to. The operators of the pages expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, for example by spam e-mails.

19. Changes to this privacy policy

We reserve the right to amend this privacy policy at any time so that it always complies with current legal requirements or to reflect changes to our services in the privacy policy. The privacy policy in force at the time will then apply to your next visit.

As of: May 2026

© 2026 Prime Residenz · prime-residenz.ch