Skip to main content
Tomorrow, Sun 06.09. - Beergarden & Gelato Gustl open from 11 ☀️
Follow us!

Privacy Policy including Cookie Policy

Version: August 7, 2026



Weiß Hospitality GmbH
Menterschwaigstraße 4
81545 Munich
Germany
Tel.: +49 89 24881180

office@augustinermenterschwaige.de
www.augustinermenterschwaige.de

Managing Director: Till Weiß
Authorized Signatory: Pamela Weiß



Thank you for your interest in our hotel and restaurant operations. The protection of personal data is of particular importance to the management of Weiß Hospitality GmbH. Our website can generally be used without providing personal data. If a data subject wishes to use particular services offered by our establishment – such as booking a room, reserving a table, using our digital check-in or our WhatsApp concierge service – it may be necessary to process personal data. Where processing is necessary and there is no statutory basis for it, we generally obtain the data subject’s consent.

This Privacy Policy informs you about the nature, scope and purpose of the personal data we collect, use and process, as well as the rights available to you. Personal data is processed at all times in accordance with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), the German Telecommunications and Telemedia Data Protection Act (TTDSG) and the other data protection provisions applicable to our establishment.

We have implemented numerous technical and organisational measures to ensure that the personal data we process is protected as comprehensively as possible. Nevertheless, internet-based data transmissions may in principle have security vulnerabilities, meaning that absolute protection cannot be guaranteed. Every data subject is therefore free to provide us with personal data by alternative means, for example by telephone or in person at reception.

1. Controller

The controller within the meaning of Art. 4(7) GDPR and the other applicable data protection provisions is:

Weiß Hospitality GmbH
Menterschwaigstraße 4
81545 Munich, Germany
Tel.: +49 89 24881180
Email: office@augustinermenterschwaige.de

Weiß Hospitality GmbH operates the restaurant, beer garden and events business under the name “Augustiner Gutshof Menterschwaige”. The hotel business is operated under the name “Gutshotel Menterschwaige”. Weiß Hospitality GmbH is the controller responsible for processing personal data in all of the aforementioned business areas.

If you have any questions concerning data protection or wish to exercise your rights, you may contact us informally at any time using the contact details above.

2. Definitions

This Privacy Policy is based on the terminology used by the European legislature when adopting the GDPR. The most important terms are summarised below:

  • Personal data: any information relating to an identified or identifiable natural person (“data subject”).
  • Processing: any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, alteration, retrieval, use, disclosure, erasure or destruction.
  • Controller: the natural or legal person that, alone or jointly with others, determines the purposes and means of processing personal data.
  • Processor: a natural or legal person that processes personal data on behalf of the controller (Art. 28 GDPR).
  • Recipient/third party: any person or body to which personal data is disclosed, irrespective of whether that person or body is a third party.
  • Consent: any freely given, informed and unambiguous indication of the data subject’s wishes by which they signify agreement to the processing of personal data relating to them.

3. Legal bases for processing

Art. 6(1)(a) GDPR serves as our legal basis where we obtain consent for a particular processing purpose. Where processing is necessary for the performance of a contract to which the data subject is party – for example, in connection with a hotel accommodation agreement, a table reservation or the digital check-in process – processing is based on Art. 6(1)(b) GDPR. Where we are subject to a legal obligation requiring processing (e.g. tax or registration obligations), processing is based on Art. 6(1)(c) GDPR. Finally, processing operations may be based on Art. 6(1)(f) GDPR where processing is necessary for the purposes of a legitimate interest pursued by our company or a third party and the interests, fundamental rights and freedoms of the data subject do not override that interest. In this respect, our legitimate interest lies in conducting our business for the benefit of our guests, employees and shareholders.

4. Provision of the website and server log files

Each time our website is accessed, our system automatically collects data and information from the computer system of the accessing device. The data collected may include the browser type and version, operating system used, referrer URL, subpages accessed, date and time of access, IP address and internet service provider. This data is stored in server log files in order to ensure that the website is delivered correctly, to safeguard system security and stability, and to provide law-enforcement authorities with the information necessary in the event of a cyberattack. The legal basis is Art. 6(1)(f) GDPR. The data is deleted after no more than seven days unless further retention is required for evidentiary purposes.

5. Cookies and cookie consent management

Our website uses cookies and related technologies (collectively referred to below as “cookies”). It is available at www.augustinermenterschwaige.de. Cookies are also placed in part by third-party providers that we have commissioned. This section provides information about the use of cookies on our website and applies to citizens and permanent residents of the European Economic Area and Switzerland. The other sections of this Privacy Policy provide further information about the processing of personal data, in particular regarding our communications outside the website, your rights and our contact details.

5.1 What are cookies?

A cookie is a small file sent to your browser together with the pages of this website and stored on the hard drive of your computer or another device. The information stored in it may be transmitted back to our servers or to the servers of the relevant third-party providers during a subsequent visit.

5.2 What are scripts?

A script is a fragment of program code used to make our website function properly and interactively. This code is executed on our server or on your device.

5.3 What is a web beacon?

A web beacon (or pixel tag) is a small, invisible text or image element on a website that is used to monitor traffic. Various data concerning you is collected by means of web beacons.

5.4 Cookie categories

Technical or functional cookies ensure that particular parts of the website function properly and that your user preferences remain known. They make it easier for you to visit our website, for example by ensuring that you do not have to enter the same information repeatedly. We may place these cookies without your consent. The legal basis is Art. 6(1)(f) GDPR or Art. 6(1)(b) GDPR where they serve to initiate or perform a contract.

Statistics cookies help us understand how our website is used and optimise the user experience. Marketing/tracking cookies or comparable forms of local storage may be used to create user profiles, display advertising or track users across websites for marketing purposes. For cookies that are not technically necessary, we obtain your consent in advance in accordance with section 25(1) TTDSG in conjunction with Art. 6(1)(a) GDPR.

Content from Instagram and Facebook may be integrated into our website in order to promote content or share it on social networks. Such content may contain code from Meta Platforms Ireland Limited that places cookies and stores or processes information for personalised advertising. Please refer to these providers’ privacy notices, which may change regularly. Where possible, the data retrieved is anonymised.

5.5 Cookies and services used by us

In particular, we use the following cookies and services on our website:

  • WordPress – functional – consent to the WordPress service
  • Jetpack – functional/statistics – consent to the Jetpack service
  • Facebook / Instagram (Meta Platforms Ireland Limited) – marketing/tracking – consent to the Meta service
  • Google Maps – loaded only after an active click – consent to the Google Maps service
  • Google Fonts – functional/display – consent where applicable, unless hosted locally
  • Google Analytics – statistics – consent to the Google Analytics service
  • OpenTable widget – functional (table reservations) – provided by OpenTable as an independent controller
  • Other services identified in the cookie manager on a case-by-case basis – consent to the respective services

5.6 Consent and management of settings

When you visit our website for the first time, we display a cookie banner explaining the use of cookies. By clicking “Save settings”, you consent to our use of the categories of cookies and plug-ins you have selected. You can change your cookie settings at any time using the cookie manager on our website and choose between the categories Functional (always active), Statistics and Marketing. You may withdraw consent at any time with effect for the future.

5.7 Enabling, disabling and deleting cookies

You can use your internet browser to delete cookies automatically or manually, block particular cookies or receive a notification whenever a cookie is placed. Further information is available in your browser’s help section. Please note that our website may not function properly if cookies are disabled completely. After cookies have been deleted, they will be placed again during your next visit if you give your consent again.

The WhatsApp concierge service for digital check-in does not rely on website cookies but on separate, contract-related data processing. Details are provided in section 10. Your rights are described in section 20; the controller’s contact details can be found in section 1.

6. Contact by email or contact form

If you contact us by email or using a contact form, the personal data you provide (e.g. name, email address, telephone number and the content of your enquiry) is stored and used to process your enquiry. The legal basis is Art. 6(1)(b) GDPR where your enquiry concerns the initiation or performance of a contract; otherwise it is Art. 6(1)(f) GDPR (our legitimate interest in responding to enquiries). This data is not disclosed to third parties. It is deleted as soon as your enquiry has been answered conclusively and no statutory retention obligations prevent deletion.

7. Application procedure

If you apply for a position with us, we process the personal data you provide (e.g. by email or web form) for the purpose of conducting the application procedure. The legal basis is section 26 BDSG in conjunction with Art. 6(1)(b) GDPR. If an employment relationship is established, the data will continue to be processed in accordance with the statutory provisions governing the employment relationship. If your application is unsuccessful, your application documents will be deleted two months after notification of the rejection unless legitimate interests prevent deletion (e.g. evidentiary obligations under the German General Equal Treatment Act).

8. Newsletter

We use the Mailchimp service provided by The Rocket Science Group, LLC, 675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA, to send our free newsletter. When you subscribe, your email address and, optionally, your name and postal address are processed; we also store your IP address and the date and time of registration. The newsletter may contain a tracking pixel (web beacon) that allows us to evaluate whether and when the newsletter was opened and whether links within it were clicked. The legal basis is your consent under Art. 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future by using the unsubscribe link in the newsletter or by notifying us informally. Mailchimp’s privacy information is available at https://mailchimp.com/legal/privacy/.

9. Table reservations (OpenTable)

For online table reservations, we integrate a widget provided by OpenTable GmbH, Zeil 109, 60313 Frankfurt am Main, Germany. When the relevant page is accessed, a direct connection is established between your device and OpenTable’s servers. OpenTable, rather than Weiß Hospitality GmbH, is responsible for collecting data through the widget; OpenTable’s privacy notice is available at https://www.opentable.de/legal/privacy-policy. If you make a reservation, OpenTable transmits your reservation details (date, time, number of people, name and telephone number) to us so that we can process the reservation. The legal basis for integrating the widget is our legitimate interest in providing a convenient reservation option (Art. 6(1)(f) GDPR); the legal basis for our processing of the reservation data is taking steps prior to entering into the restaurant service contract (Art. 6(1)(b) GDPR).

10. WhatsApp Business – digital check-in and concierge service

10.1 Description of the service

We offer guests who have booked an overnight stay a digital check-in supported through the WhatsApp messaging service (“WhatsApp concierge service”). For this purpose, at approximately 2:00 p.m. on the day of arrival we automatically send exactly one WhatsApp message to the mobile telephone number provided by the guest during the booking process. This message contains a brief introduction to our WhatsApp concierge service, a link to an explanatory video produced by us about digital check-in (hosted on YouTube; see section 12), the guest’s booking number and a QR code for check-in on site. This is the only automatically generated WhatsApp message sent by our establishment; we do not automatically send advertising or other content via WhatsApp. Further individual messages (e.g. questions sent by the guest to reception) are answered personally by our employees.

10.2 Technical implementation and processing on our behalf

Messages are sent exclusively via the official WhatsApp Business Platform (Cloud API) provided by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (“Meta”). We have entered into the “WhatsApp Business Data Processing Terms” provided by Meta, which constitute a data processing agreement within the meaning of Art. 28 GDPR. Unlike the WhatsApp Messenger app intended for private users – whose use by businesses is discouraged, among others, by the Bavarian State Office for Data Protection Supervision (BayLDA), because third parties’ address-book data may be transmitted to WhatsApp without consent – the WhatsApp Business Platform does not synchronise with an address book. The mobile telephone number is transmitted specifically and exclusively via an application programming interface (API) for the guest’s particular booking.

We also use the Make automation platform to trigger and control delivery (linking booking data with the WhatsApp message, generating the QR code and scheduling delivery for 2:00 p.m.); further details are provided in section 11.

10.3 Data processed

As part of the WhatsApp concierge service, we process the following categories of data: mobile telephone number, first and last name, booking number, arrival date and content of the message sent (text, video link and QR code), as well as – on Meta’s side – message transmission metadata (e.g. time, delivery and read status, and device or connection data used).

10.4 Purposes and legal basis

The purpose of processing is to provide digital check-in as part of the accommodation service booked by the guest and to provide information about our concierge service. The legal basis is Art. 6(1)(b) GDPR (performance of a contract), as the message serves to prepare for and conduct the digital check-in provided for in the hotel accommodation agreement and has no advertising purpose.

10.5 Voluntary nature and alternatives

Providing a mobile telephone number and using the WhatsApp concierge service are voluntary. Guests who do not wish to receive a WhatsApp message may notify reception informally (e.g. when booking, by email or by telephone); digital check-in and all related information will then be made available to these guests by an alternative means (in person at reception or by email).

10.6 Transfers to third countries

Meta Platforms Ireland Limited may transfer personal data to its parent company, Meta Platforms, Inc., based in the USA. Such transfers are based on the European Commission’s EU Standard Contractual Clauses and – where applicable – the EU-U.S. Data Privacy Framework. Further information about data processing by WhatsApp/Meta is available in WhatsApp’s Privacy Policy at https://www.whatsapp.com/legal/privacy-policy and in the WhatsApp Business Data Processing Terms at https://www.whatsapp.com/legal/business-data-processing-terms.

10.7 Retention period

Data processed as part of the concierge service is deleted as soon as it is no longer required to provide the digital check-in service and, at the latest, once the statutory retention periods have expired (see section 18). Metadata held by Meta is subject to the deletion periods stated in the WhatsApp Business Data Processing Terms.

11. Automation of internal processes using Make (Celonis)

To automate internal workflows – in particular, to connect our booking or property-management system with the WhatsApp Business Platform, generate the QR code and schedule the message described in section 10 – we use the cloud-based Make automation platform, a service of Celonis, Inc., 600 Congress Avenue, Suite 1200, Austin, TX 78701, USA (accessible in the EU through the European group company; “Make”).

As part of this automation (a “Make scenario”), Make processes the guest’s booking number, mobile telephone number, name and arrival date on our behalf in order to generate the WhatsApp message and QR code and send them via the WhatsApp Business Platform. We have entered into a data processing agreement with Celonis/Make pursuant to Art. 28 GDPR. This agreement includes provisions on subprocessors, technical and organisational measures and deletion periods and is available at trust.make.com. For transfers to third countries (particularly the USA), Celonis, Inc. is certified under the EU-U.S. Data Privacy Framework; where required, EU Standard Contractual Clauses are used in addition.

Where processing serves to perform digital check-in for the guest, the legal basis is Art. 6(1)(b) GDPR. In all other respects, we base the automated and efficient design of this internal process on our legitimate interest pursuant to Art. 6(1)(f) GDPR. Execution records (logs) relating to the automation are deleted by Make in accordance with the periods configured in our account or the periods permitted by law.

12. Linked video content (YouTube)

In the WhatsApp message described in section 10, we link to an explanatory video about digital check-in produced by us and made available on the YouTube platform (provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; further processing may also involve its parent company Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA).

This is a link (hyperlink), not an embedding of the video on our website or directly in the WhatsApp message. A connection to YouTube/Google servers is established only when the guest actively clicks the link. Only as a result of this deliberate user action may personal data (e.g. IP address, device and browser information and, if the guest is signed into a Google account, usage data from that account) be transferred to Google and processed there – including in the USA. We have no control over the nature, scope or purpose of this processing.

The legal basis for providing the link is our legitimate interest in explaining the digital check-in procedure in a clear and accessible manner (Art. 6(1)(f) GDPR). Further information about data processing by Google/YouTube, including the bases for transfers to third countries, is available in Google’s Privacy Policy at https://policies.google.com/privacy and at https://policies.google.com/privacy/frameworks.

13. Social media: Facebook and Instagram

We maintain business profiles on Facebook and Instagram to promote our services and communicate with interested parties and guests. These platforms are operated by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. With regard to visitor statistics collected by Meta through these profiles (“Page Insights”), we and Meta Platforms Ireland Limited are joint controllers within the meaning of Art. 26 GDPR; the respective obligations are governed by the “Page Controller Addendum” provided by Meta and available at https://www.facebook.com/legal/terms/page_controller_addendum. The legal basis for processing is our legitimate interest in analysing, communicating and promoting our services (Art. 6(1)(f) GDPR) or the user’s consent given to Meta (Art. 6(1)(a) GDPR). Further details about data processing, options for objecting and deletion of data processed by Facebook or Instagram are available in the privacy policies at https://www.facebook.com/policy.php and https://help.instagram.com/519522125107875.

14. Google Maps

We use the Google Maps API on our website to display geographical information (provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). The map is loaded only after the user actively clicks it; only then is a connection established to Google’s servers, as a result of which personal data (in particular the IP address) may be transmitted to Google, including to the USA in some circumstances. The legal basis is our legitimate interest in displaying our location clearly (Art. 6(1)(f) GDPR), unless separate consent is obtained, in which case Art. 6(1)(a) GDPR applies. Further information is available at https://policies.google.com/privacy.

15. Google Fonts

We use external fonts from Google Fonts, a service provided by Google Ireland Limited. If the fonts are loaded from Google’s servers, personal data (in particular the IP address) may be transmitted to Google. Where consent is obtained for this purpose, the legal basis is Art. 6(1)(a) GDPR; otherwise, we base their use on our legitimate interest in presenting our website consistently and attractively (Art. 6(1)(f) GDPR). Further information is available at https://developers.google.com/fonts/faq and https://policies.google.com/privacy.

16. Jetpack for WordPress

We use the Jetpack WordPress plug-in (provider: Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA), which provides us with a visitor overview and security functions to protect against brute-force attacks, among other features. For this purpose, Jetpack places a cookie and transfers usage data to Automattic for analytical purposes. The data collected is not used to identify the user without separate, express consent. The legal basis is Art. 6(1)(a) GDPR (consent through the cookie manager) or Art. 6(1)(f) GDPR (our legitimate interest in the security and functionality of our website). Automattic’s privacy information is available at https://automattic.com/privacy/.

17. Shariff (social media buttons)

We use the Shariff component (developer: GitHub, Inc., 88 Colin P. Kelly Junior Street, San Francisco, CA 94107, USA) to integrate social media buttons in a privacy-friendly manner. Unlike conventional buttons, Shariff does not transfer data to the relevant social network until the user actively clicks a button. The legal basis is our legitimate interest in providing links to social networks in compliance with data protection requirements (Art. 6(1)(f) GDPR). Further information is available at https://help.github.com/articles/github-privacy-policy/.

18. Retention and deletion of personal data

We process and store personal data only for the period required to achieve the relevant storage purpose or where required by European or national legislation (e.g. commercial and tax-law retention periods of up to ten years for booking and accounting documents). If the storage purpose ceases to apply or a prescribed retention period expires, the personal data is routinely blocked or deleted.

19. Automated decision-making, including profiling

We do not use solely automated decision-making within the meaning of Art. 22 GDPR or profile our guests. The automated WhatsApp message described in section 10 does not constitute an automated decision producing legal or similarly significant effects; it is purely service-related or contract-related information.

20. Rights of data subjects

As a data subject, you have the following rights in accordance with the GDPR:

  • Right to confirmation and access regarding the data stored about you (Art. 15 GDPR);
  • Right to rectification of inaccurate data and completion of incomplete data (Art. 16 GDPR);
  • Right to erasure (“right to be forgotten”), Art. 17 GDPR;
  • Right to restriction of processing, Art. 18 GDPR;
  • Right to data portability, Art. 20 GDPR;
  • Right to object to processing, in particular to direct marketing, Art. 21 GDPR;
  • Right not to be subject to a decision based solely on automated processing, including profiling, Art. 22 GDPR;
  • Right to withdraw consent with effect for the future, Art. 7(3) GDPR;
  • Right to lodge a complaint with a data protection supervisory authority, Art. 77 GDPR. The supervisory authority responsible for our establishment is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 27, 91522 Ansbach, Germany, https://www.lda.bayern.de.

To exercise these rights, it is sufficient to send an informal notification using the contact details provided in section 1.

21. Currency and amendment of this Privacy Policy

This Privacy Policy is currently valid and was last updated in August 2026. It may become necessary to amend this Privacy Policy due to the further development of our website and services (e.g. new communication channels or service providers) or changes in statutory or regulatory requirements. The current Privacy Policy is available on our website.

Follow us!

Book now