staedy for hotels
how it works
Check my hotel
How it worksCheck my hotel

How Staedy handles personal data

Privacy notice

Last updated: 31 August 2026

Help and legal
SupportCustomer rightsTermsPrivacyService providersSecurityImprint

In short

  • Controller: R&R Spiele UG (haftungsbeschränkt), Emeranstraße 23, 85622 Feldkirchen, Germany. Contact: privacy@staedy.com.
  • Staedy reviews public business information and produces additions for hotel websites. Please never send us guest, customer, patient or other unnecessary personal data.
  • This website runs no analytics or advertising. Cloudflare rate limiting protects the website check and project-request form from automated abuse.
  • As a production input, we may send guest-style questions and necessary public hotel information through our AI infrastructure. We never send your email address, payment data, access credentials or private project content to those models.
  • Card payments are processed directly by Mollie. Staedy never sees or stores full card details. Qonto is used for the business account and electronic invoice. The company-domain work email is used for the invoice, payment confirmation and private delivery.
  • You have rights of access, rectification, erasure, restriction, portability and objection, and can complain to the Bavarian data protection authority.

This summary is for orientation only. The full text below applies.

On this page

  • 1. Who is responsible
  • 2. Principles
  • 3. What you should not send us
  • 4. Visiting this website
  • 5. Cookies and local storage
  • 6. Businesses we research before contact
  • 7. Your website project
  • 8. Information about other businesses
  • 9. AI providers and measurement
  • 10. Payment and invoicing
  • 11. Email and correspondence
  • 12. Business post and QR codes
  • 13. Security logging
  • 14. Service providers and other recipients
  • 15. International transfers
  • 16. Retention
  • 17. Automated decisions and AI transparency
  • 18. Your rights
  • 19. Right to object
  • 20. Complaints to a supervisory authority
  • 21. Data breaches
  • 22. Changes to this notice

1. Who is responsible

The controller for the processing described here is:

Company
R&R Spiele UG (haftungsbeschränkt)
Address
Emeranstraße 23, 85622 Feldkirchen, Germany
Represented by
Rieke du Toit
Email
privacy@staedy.com
Fallback email
info@rouxdutoit.com

We are not required to appoint a data protection officer under Art. 37 GDPR or § 38 BDSG. Privacy requests are handled by the address above.

2. Principles

Staedy processes only the data needed to provide, secure, bill, deliver and improve the agreed service. We do not sell personal data, and we do not use it to build advertising profiles.

Staedy reviews publicly available business information and the material needed to produce and implement agreed website additions. The service is not designed to process guest, customer, patient, client or health data.

3. What you should not send us

Please do not submit to Staedy, in any field, email or attachment:

  • patient, client or guest records;
  • health data or any other special category data under Art. 9 GDPR;
  • customer lists or customer contact details;
  • employee personnel data;
  • passwords or login credentials in ordinary email or attachments.

If you send us such data anyway, we will delete it as soon as we identify it, unless we are legally required to retain it.

4. Visiting this website

This site is delivered by Cloudflare. When you load a page, Cloudflare processes technically necessary connection data on our behalf, in particular:

  • IP address;
  • date and time of the request;
  • the page requested;
  • browser and device information;
  • security and network characteristics;
  • error and abuse signals.

Purposes: delivery of the page, security, abuse prevention, error analysis and capacity management.

Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest is the secure and reliable operation of the website.

Cloudflare rate limiting protects the website-check and project-request endpoints from automated abuse. The limit uses connection data already processed to deliver and secure the service. Legal basis: Art. 6 (1) (f) GDPR, our legitimate interest in preventing automated abuse.

5. Cookies and local storage

Staedy uses no analytics, advertising cookies or cross-site behavioural tracking.

Staedy may store the following in your browser session storage, which is cleared when you close the tab:

  • your language preference;
  • a random checkout or post-payment onboarding reference, so a started flow survives a page change;
  • a security or verification session.

These are strictly necessary to provide the function you requested and are therefore exempt from the consent requirement under § 25 (2) no. 2 TDDDG. They are not used for advertising, cross-site tracking or behavioural profiling.

We run no analytics, no heat mapping, no session recording and no advertising pixels. If this ever changes, we will update this notice and put consent controls in place before the change takes effect.

6. Businesses we research before contact

Staedy sometimes researches a business before that business has contacted us, in order to post it a single measured finding. Where we do this, we process:

  • the domain and its publicly reachable pages;
  • the publicly identifiable organisation, location and services;
  • publicly available information about that business;
  • one measured question and the answers four named AI assistants gave to it;
  • technical retrieval data and the postal address the letter was sent to.

Purpose: to establish whether a measured finding is worth sending, and to prepare and post it.

Legal basis: Art. 6 (1) (f) GDPR, our legitimate interest in direct business-to-business approach. We do not rely on Art. 6 (1) (b) here, because the business has not asked us for anything.

Receiving a letter from Staedy creates no contract and no payment obligation. If you would prefer not to be researched or contacted again, write to privacy@staedy.com and we will record that and stop.

7. Your website project

If you commission website work, Staedy stores, for the duration of the contract and the applicable retention periods:

  • the confirmed business identity, website and work contact details;
  • the accepted scope, platform, publishing route, price and document versions;
  • guest-style questions used as research inputs, provider answers and public evidence references;
  • copy, designs, assets, feedback and approvals created or supplied for the project;
  • private preview, staging, code-handoff and delivery records;
  • named project accounts, access invitations and security events, but not passwords stored in ordinary project records;
  • the contract and document versions you accepted.

Legal basis: Art. 6 (1) (b) GDPR, performance of the contract.

Private preview and staging links are not public profiles. Please share them only with people who are authorised to see them. You can ask us to revoke or replace a link at any time.

8. Information about other businesses

Internal project research may identify businesses named by AI systems and may therefore contain publicly available information about businesses that are not our customers. Where that information is personal data not collected from the person concerned, this section is our notice under Art. 14 GDPR.

Most of those businesses are legal persons, and information about a legal person is not personal data. Where a business is a sole trader, a partnership or is named after a person, the information can be personal data, and this section applies to it. Our legal basis is Art. 6 (1) (f) GDPR: the legitimate interest of our customer in understanding a market they compete in, balanced against interests that are limited here because we use only information those businesses have themselves published.

Categories of data
Business name, location, services, publicly visible web content, publicly visible review patterns, and (only where necessary for a documented business point) the name and role of a publicly listed representative.
Source
Publicly accessible websites, public directories, publicly visible review platforms and the answers of the AI providers listed in section 9.
Purpose
Evidence-based prioritisation of useful additions for our customer’s website.
Legal basis
Art. 6 (1) (f) GDPR. Our legitimate interest, and that of our customer, is understanding the publicly visible competitive picture in a documented and correctable way.

To keep this proportionate, Staedy:

  • does not record patient, client or guest names;
  • summarises review patterns rather than reproducing reviews in full;
  • does not include the names of individual reviewers in customer-facing website content;
  • uses employee information only where it is necessary for an evidenced business point;
  • records the original source and the time it was retrieved;
  • corrects or removes entries on substantiated request.

If you are named in Staedy project material and want that reviewed, write to privacy@staedy.com. You can object at any time under section 19.

9. AI providers and measurement

As one input to the website production process, Staedy may test how AI assistants answer guest-style questions relevant to the customer’s hotel and market. Staedy routes those questions and necessary public business information through Cloudflare AI Gateway to selected providers, currently:

  • OpenAI;
  • Anthropic;
  • Google;
  • Perplexity.

Staedy does not send these providers:

  • customer email addresses;
  • payment data;
  • private project feedback, unpublished customer assets or website access credentials;
  • patient, client or guest data;
  • any personal data that is not necessary for the measurement.

For each research run we may record the provider, model, settings, timestamp, answer, cited sources and error status so the production decision can be checked. These records are working evidence and are not a separate purchased report unless the order says otherwise.

Legal basis: Art. 6 (1) (b) GDPR for performing the service, and where necessary Art. 6 (1) (f) GDPR for quality assurance and auditability.

Where these providers process data outside the EEA, see section 15. The current provider list, including regions and safeguards, is published under Subprocessors.

10. Payment and invoicing

Staedy collects company and billing details on its own checkout, then redirects you to Mollie Hosted Checkout, where card data is entered directly with Mollie. The amount settles to Staedy's business account and Qonto is used to issue the electronic invoice. Depending on the transaction, Staedy receives and stores:

  • payment status;
  • amount and currency;
  • Mollie payment and Qonto invoice references;
  • the company-domain work email supplied at checkout, for identity checks, the invoice, payment correspondence and private delivery;
  • billing address, company and optional VAT details supplied at checkout;
  • the contract and consent versions accepted;
  • refund and dispute status.

Staedy does not receive or store full card numbers. Card data is entered directly with the payment provider.

Legal bases: Art. 6 (1) (b) GDPR for performing the contract; Art. 6 (1) (c) GDPR for statutory accounting and record-keeping duties; Art. 6 (1) (f) GDPR for fraud and abuse prevention.

11. Email and correspondence

Staedy uses Cloudflare Email Service for verification, order, delivery and service messages. Invoices are handled by the separately identified invoicing process, not inferred from an email delivery event.

When you write to us, we process the sender and recipient addresses, the subject, the content, any attachments, delivery and authentication results, and the link to your order.

Replies are read and handled by a person. Full customer replies and attachments are not automatically forwarded to AI providers.

Legal bases: Art. 6 (1) (b) GDPR where the correspondence concerns a contract or a request you made, and Art. 6 (1) (f) GDPR for general business correspondence and for verifying that mail is authentic.

Email is not an inherently confidential channel. Please do not send sensitive personal data by email. If you need a secure route for something specific, ask us at support@staedy.com.

12. Business post and QR codes

For addressed business post, Staedy may process the business name and address, the website, publicly identifiable business information, the mailer version and dispatch batch, a pseudonymous QR or short code, and the resulting scan, verification and purchase events.

The QR code contains no email address and no personal name.

Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest is targeted business-to-business outreach and measuring whether it works. Objections and suppression lists are respected. See section 19.

13. Security logging

Staedy processes security logs in order to detect unauthorised access, prevent abusive requests, protect payments and webhooks, investigate errors and handle security incidents.

Logs are designed not to contain full project content, payment data, email bodies, passwords or private link tokens.

Legal basis: Art. 6 (1) (f) GDPR, our legitimate interest in the security and integrity of the service.

14. Service providers and other recipients

Personal data is disclosed to the following categories of recipient:

  • Cloudflare, for hosting, storage, security functions, browser execution and email;
  • Mollie for card payment processing and Qonto for the business account and invoicing;
  • the documented AI providers, for public measurement only;
  • legal, tax and security advisors, where necessary;
  • website service providers you explicitly choose, for released implementation views;
  • public authorities, where we are legally obliged to disclose.

Where a provider is our processor, it acts on documented instructions under an agreement pursuant to Art. 28 GDPR. Payment institutions may instead act as independent controllers for payment, fraud-prevention, regulatory and anti-money-laundering duties. The current list states each role, location and transfer safeguard.

15. International transfers

Some of our providers process data outside the European Economic Area, in particular in the United States.

Where that happens, the transfer is based on one of the following:

  • an adequacy decision of the European Commission, including certification under the EU–US Data Privacy Framework where the provider is certified;
  • the European Commission Standard Contractual Clauses under Art. 46 (2) (c) GDPR, together with a transfer impact assessment and supplementary technical and organisational measures;
  • EU or EEA data residency options where the provider offers them.

The safeguard applying to each provider is stated in the Subprocessors list. You can request a copy of the relevant safeguards from privacy@staedy.com.

16. Retention

We keep personal data only as long as it is needed for the purpose it was collected for, or as long as a statutory retention period requires.

Unverified started flows
Deleted after 30 days.
Verification tokens
Minutes to hours, then deleted.
Outbound research and unanswered letters
Deleted after 90 days unless a contract follows.
Paid website projects and working evidence
Kept for the contract, warranty and applicable limitation periods; working copies and access records are removed earlier when they are no longer needed.
Invoices and booking documents
8 years where they are booking documents under § 147 AO and § 257 HGB; other records follow the period applicable to their legal category.
Security logs
Risk-based, generally up to 90 days, longer only where an incident is under investigation.
Customer correspondence
As long as needed for support, contract performance and evidence; commercial letters are subject to statutory retention of 6 years under § 257 HGB.
Public source material
No longer than needed to substantiate a finding and resolve any dispute about it.
Outreach suppression list
Kept indefinitely, because deleting it would mean contacting you again.

Where erasure is not possible because of a statutory retention duty, we restrict processing instead: the data is blocked from ordinary use and kept only for the legal purpose.

17. Automated decisions and AI transparency

Staedy does not make decisions based solely on automated processing that produce legal effects concerning a natural person or similarly significantly affect them, within the meaning of Art. 22 GDPR.

You should still know how the service uses AI, so:

  • AI systems can be used to collect research inputs and assist drafting, but they do not approve or publish customer website changes;
  • material factual claims are checked against public sources, customer material or direct customer confirmation;
  • a person reviews the proposed website work before it is presented for customer approval;
  • the customer decides whether the finished work may be published;
  • AI provider answers change over time, so no research observation is treated as a permanent state of the world.

Where the EU AI Act applies to how we use these systems, we follow the applicable transparency obligations, including making clear that content was produced with AI assistance.

18. Your rights

Where the statutory conditions are met, you have the right to:

Access (Art. 15)
Confirmation of whether we process your data, and a copy of it.
Rectification (Art. 16)
Correction of inaccurate data and completion of incomplete data.
Erasure (Art. 17)
Deletion of your data.
Restriction (Art. 18)
Blocking of processing in defined cases.
Portability (Art. 20)
Receipt of data you provided, in a structured, commonly used, machine-readable format.
Objection (Art. 21)
Objection to processing based on legitimate interests. See section 19.
Withdrawal of consent (Art. 7 (3))
Withdrawal at any time with effect for the future, where processing is based on consent.
Complaint (Art. 77)
Complaint to a supervisory authority. See section 20.

Requests go to privacy@staedy.com. We answer within one month and will tell you if we need to extend that under Art. 12 (3) GDPR. We may need additional information to verify your identity before we act.

Exercising these rights is free of charge.

19. Right to object

Where we process personal data on the basis of legitimate interests under Art. 6 (1) (f) GDPR, you have the right to object at any time on grounds relating to your particular situation. We will then stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

Where data is processed for direct marketing, including our addressed business post, you can object at any time and without giving reasons. We will then stop, and add you to a suppression list so it does not happen again.

Objections to business post: support@staedy.com. All other objections: privacy@staedy.com.

20. Complaints to a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, place of work or the place of the alleged infringement.

The authority responsible for us is:

Authority
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Address
Promenade 18, 91522 Ansbach, Germany
Online complaint form
www.lda.bayern.de

We would prefer you raise it with us first at privacy@staedy.com, but you are under no obligation to do so.

21. Data breaches

Staedy documents personal data breaches and, where required, reports them to the competent supervisory authority without undue delay and where feasible within 72 hours under Art. 33 GDPR.

Where a breach is likely to result in a high risk to the rights and freedoms of natural persons, we inform the affected people in clear language under Art. 34 GDPR, unless a statutory exception applies.

22. Changes to this notice

We publish the current version, language and date of this notice at the top of this page.

If we make a material change that affects an existing contract or introduces a new purpose, we will inform affected customers in good time and by a route they will actually see, normally email.

Questions about this page

support@staedy.com

staedy for hotels

Staedy finds and fixes missing information and technical gaps on hotel websites—without redesigning the site.

HomeHow it worksSupportCustomer rightsTermsPrivacyService providersSecurityImprint
© 2026 Staedy · staedy.com