PrivacyPolicy
Information pursuant to Art. 13 GDPR on the processing of personal data by GroomRoom Berlin GmbH, in the salon, on this website and when booking an appointment.
Table ofcontents
- Data Controller
- Introduction & Scope
- Types of Data Processed
- Categories of data subjects
- Purposes of processing
- Legal bases
- Retention period & deletion
- Data processing in third countries
- Security measures & TLS
- Cookies & consent management
- Web hosting & log files
- Contact & appointment booking (Alteg.io / Calendly)
- Web analytics: Google Analytics 4
- Google Ads & remarketing
- Meta Pixel (Facebook / Instagram)
- TikTok Pixel
- Elfsight widget (Google reviews)
- Social media profiles
- WhatsApp contact
- Google Maps (two-click solution)
- Video surveillance in the salon
- Photo & video recordings of your dog for social media
- Rights of data subjects
- Right to lodge a complaint with the supervisory authority
- Changes to this privacy policy
1. Data controller
The data controller within the meaning of the General Data Protection Regulation (GDPR) is:
GroomRoom Berlin GmbH
Managing Director: Jasper Hellmann
Mühlenstraße 8a · 14167 Berlin
Salon: Giesebrechtstraße 2 · 10629 Berlin · Charlottenburg
E-Mail: hallo@groomroom.net
Phone: +49 1525 4524113
A data protection officer is not legally required; if you have any questions about data protection, please contact us directly by E-Mail.
2. Introduction & scope
With this privacy policy, we want to inform you about the types of your personal data (hereinafter also referred to simply as "data") we process, for what purposes, and to what extent. This privacy policy applies to all processing of personal data carried out by us, both as part of providing our services and, in particular, on our website, in mobile applications, and within external online presences such as our social media profiles (hereinafter collectively referred to as "online offering").
The terms used are not gender-specific.
3. Types of data processed
- Basic data (e.g. names, addresses)
- Contact data (e.g. E-Mail, phone numbers)
- Content data (e.g. text entries, photos, videos)
- Usage data (e.g. visited websites, interest in content, access times)
- Meta-/communication data (e.g. device information, IP addresses)
- Contract data (e.g. subject of the contract, duration, customer category)
- Payment data (e.g. bank details, invoices, payment history)
- Pet data (e.g. breed, age, coat condition, special features, to provide the grooming service)
4. Categories of data subjects
- Customers (pet owners)
- Prospective customers contacting us
- Applicants for job vacancies
- Users of our online services
- Communication partners
5. Purposes of processing
- Providing our grooming services and fulfilling contractual obligations
- Contact enquiries, appointment booking and communication with customers
- Security measures to protect our IT systems and salon premises
- Reach measurement, direct marketing, remarketing
- Creation, evaluation and optimisation of our online presence
- Application process (execution, documentation, decision)
6. Legal basis
Below we share the legal bases of the General Data Protection Regulation (GDPR) on which we process personal data:
- Consent (Art. 6(1)(a) GDPR), the data subject has given consent to the processing of their personal data for one or more specific purposes.
- Performance of a contract and pre-contractual requests (Art. 6(1)(b) GDPR), processing is necessary for the performance of a contract.
- Legal obligation (Art. 6(1)(c) GDPR), processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Art. 6(1)(f) GDPR), processing is necessary to protect our legitimate interests or those of a third party, unless your interests, fundamental rights or freedoms override them.
In addition to the data protection regulations of the GDPR, national data protection regulations apply in Germany. This includes in particular the Federal Data Protection Act (BDSG) and, for telecommunications and telemedia, the Telecommunications and Telemedia Data Protection Act (TTDSG).
7. Storage duration & deletion of data
The data we process will be deleted in accordance with legal requirements as soon as the consent permitted for processing is revoked or other permissions cease to apply (e.g. if the purpose of the processing has ceased to apply or they are not required for the purpose). If data cannot be deleted due to tax or commercial retention obligations (e.g. invoices according to § 147 AO 10 years, commercial letters 6 years), its processing will be restricted.
8. Data processing in third countries
If we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or if this occurs in the context of using third-party services or disclosing or transferring data to other persons, bodies or companies, this is only done in accordance with legal requirements.
Subject to explicit consent or a contractually required transfer, we only process data or have it processed in third countries with a recognised level of data protection. This includes US processors certified under the EU-US Data Privacy Framework (DPF), or on the basis of special guarantees such as the EU Commission's standard contractual clauses (SCC).
9. Security measures & TLS encryption
In accordance with legal requirements and taking into account the state of the art, implementation costs, and the nature, scope, context and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we implement appropriate technical and organisational measures (TOM) to ensure a level of security appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical access to the data, as well as access, input, transfer, securing availability and its separation.
For security reasons and to protect the transmission of personal data, this website uses TLS/SSL encryption. You can recognise an encrypted connection when the browser's address bar changes from "http://" to "https://".
10. Cookies & consent management
Cookies are small text files or other storage markers that save information on devices and read information from them. We distinguish between:
- Technically necessary cookies (session ID, consent storage): Legal basis Art. 6 (1) (f) GDPR, § 25 (2) No. 2 TTDSG.
- Statistics cookies (e.g. Google Analytics 4): only with consent, Art. 6 (1) (a) GDPR, § 25 (1) TTDSG.
- Marketing cookies (e.g. Google Ads, Meta Pixel, TikTok Pixel): only with consent, Art. 6 (1) (a) GDPR, § 25 (1) TTDSG.
We use our own custom-built consent banner. Your consent is stored locally in your browser under the key groomroom-consent-v1 saved. You can withdraw your consent at any time by deleting your browser data for this website; the banner will then reappear on your next visit.
Without your consent, no statistics or marketing tools will be loaded.
11. Web hosting & log files
To host our website, we use services that make the site available on servers. The data processed in this context can include technical access data in particular: your IP address, the time of your request, the amount of data transferred, a notification of successful retrieval, your browser type and version, your operating system, and the referrer URL.
For IT security reasons (e.g. to defend against denial-of-service attacks), the server log files are stored for a maximum of 30 days and then deleted. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the security of our website).
12. Contact & appointment booking (Alteg.io / Calendly)
When you contact us (e.g. via contact form, E-Mail, phone, or social media) and when you book appointments through our online booking systems, your details are processed to the extent necessary to answer your enquiries and carry out any requested actions.
For appointment bookings, we use the online platform Alteg.io (Alteg.io OÜ, Tallinn, Estonia) at the endpoint https://n1335300.alteg.io. Alteg.io opens in a pop-up window when you click on an appointment button. Your name, E-Mail, phone number, as well as details about your dog and the requested service, are transmitted to Alteg.io.
For selected calendar widgets, we additionally use Calendly (Calendly LLC, USA). Calendly is only loaded when you first click on a booking button (click-to-load) and transmits data including your IP address and browser information to Calendly servers in the USA.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract / pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in efficient appointment organisation).
13. Web analytics: Google Analytics 4
We use Google Analytics 4 by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), a web analytics service that helps us anonymously analyse and improve how our website is used. The measurement ID is G-QBLHFB9NXJ.
Google Analytics uses cookies and similar technologies that allow us to analyse how users interact with the website. The information collected is transferred to a Google server and stored there. We have activated IP anonymisation (anonymize_ip:true) so that your IP address is processed in a shortened form.
Processing takes place exclusively on the basis of your consent (Art. 6(1)(a) GDPR, § 25(1) TTDSG). Data transfer to the US: Google LLC is certified under the EU-US Data Privacy Framework.
Storage duration: 14 months by default. You can withdraw your consent at any time via our consent banner (clear your browser data and select again).
14. Google Ads & Remarketing
We use the advertising service Google Ads (Conversion ID AW-11051089562) by Google Ireland Limited. Google Ads uses cookies to measure the success of our advertising campaigns, especially if you reached our site via a Google ad and then take an action (e.g. send a contact request or book an appointment).
Legal basis: Art. 6(1)(a) GDPR (consent). Can be withdrawn via the consent banner. Google privacy policy: policies.google.com/privacy.
15. Meta Pixel (Facebook / Instagram)
We use the Meta Pixel (Pixel ID 403469430045387) of Meta Platforms Ireland Limited, Dublin, Ireland. In addition, with your consent, we send the same events server-side via the Meta Conversions API (including IP address, browser ID, Meta cookies, and hashed contact details for bookings) so that events are only counted once. The pixel tracks interactions with our website (page views, conversion events) and sends them to Meta. Meta uses this information to provide us with reports on ad performance and, if you have a Meta account, to show you personalised ads on Facebook and Instagram.
Legal basis: Art. 6(1)(a) GDPR (consent). Can be revoked via the consent banner. Meta privacy policy: facebook.com/privacy/policy.
16. TikTok Pixel
We use the TikTok Pixel (SDK ID CDGOEMJC77U1SA0STPF0) from TikTok Technology Limited, Dublin, Ireland. Purpose: measuring and optimising our TikTok ad campaigns. Processed data includes, among others, IP address, device information, browser details, and interactions with our website.
Legal basis: Art. 6(1)(a) GDPR (consent). Can be revoked via the consent banner. TikTok privacy policy: tiktok.com/legal/privacy-policy-eea.
17. Elfsight widget (Google reviews)
We embed an Elfsight widget (Elfsight Ltd., Limassol, Cyprus) on our homepage to show real Google reviews from our customers. The widget only loads after you give your marketing consent; before that, you'll just see a placeholder.
When it loads, technical data (IP address, browser fingerprint) is sent to Elfsight and Google to fetch the reviews. Legal basis: Art. 6(1)(a) GDPR (consent). Elfsight privacy policy: elfsight.com/privacy-policy.
18. Social media profiles
We maintain profiles on social networks (Instagram, TikTok, Facebook). When you visit our profiles, the respective providers regularly process user data. This includes, in particular, meta/communication data and usage data.
Processing is based on our legitimate interest in effectively informing and communicating with you (Art. 6(1)(f) GDPR) or on the basis of joint controllership with the platform operators (Art. 26 GDPR). For details, please see the respective platform's privacy policy.
19. WhatsApp contact
We offer the option to contact us via WhatsApp (Meta Platforms Ireland Limited). When you open a WhatsApp link, you'll be redirected to the WhatsApp app/website and leave our site. Meta then processes the message content and metadata sent between you and us.
Legal basis: Art. 6(1)(b) GDPR (communication with prospective or existing customers). WhatsApp privacy policy: whatsapp.com/legal/privacy-policy-eea.
20. Google Maps (two-click solution)
We use Google Maps by Google Ireland Limited to show our location. To protect your privacy, we use a two-click solution: the map is only loaded after you explicitly click on the placeholder. Only then is data (IP address, browser information) sent to Google.
Legal basis: Art. 6 (1) (a) GDPR (consent by clicking). Google privacy policy: policies.google.com/privacy.
21. Video surveillance in the salon
For quality assurance and evidence purposes, we monitor the treatment areas in the salon with video cameras. The recordings are used exclusively to clarify any subsequent misunderstandings between us and our clients regarding the treatment provided.
All video recordings are irretrievably deleted after 30 calendar days at the latest. Access to the recordings is restricted to management.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in preserving evidence and documentation). Visible signs in the salon inform about the video surveillance. Data subjects are clients and their dogs/cats.
22. Photo & video recordings of the dog for social media
Before and after the grooming treatment, we occasionally take photos and videos of the dog, which we publish on our social media profiles (Instagram, TikTok, Facebook) and our Google Business profile. By booking an appointment, the pet owner accepts this use (see Terms and Conditions point 5).
If the client objects to the publication, this must be communicated in writing before the treatment. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in marketing/public relations); for identifiable persons in the recordings: Art. 6 (1) (a) GDPR (consent).
23. Rights of data subjects
As a data subject, you have the following rights under the GDPR, which you can assert against us (E-Mail to hallo@groomroom.net):
- Right to object (Art. 21 GDPR), you have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data based on Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions.
- Right to withdraw consent (Art. 7(3) GDPR), you have the right to withdraw any consent you have given at any time.
- Right of access (Art. 15 GDPR), you have the right to request confirmation as to whether your data is being processed, to access this data, and to receive further information and a copy of the data.
- Right to rectification (Art. 16 GDPR), you have the right to request the completion of incomplete data or the correction of inaccurate data concerning you.
- Right to erasure (Art. 17 GDPR), you have the right to request that your data be deleted without undue delay ('right to be forgotten').
- Right to restriction of processing (Art. 18 GDPR), you have the right to request that the processing of your data be restricted.
- Right to data portability (Art. 20 GDPR), you have the right to receive your data in a structured, commonly used and machine-readable format, or to request its transfer to another controller.
24. Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, especially in the Member State where you live, work, or where the alleged infringement took place, if you believe that the processing of your personal data violates the GDPR (Art. 77 GDPR).
Berlin Commissioner for Data Protection and Freedom of Information
Friedrichstraße 219 · 10969 Berlin
Phone: +49 30 13889-0
E-Mail: mailbox@datenschutz-berlin.de
Web: datenschutz-berlin.de
25. Changes to this privacy policy
We ask you to regularly check the content of our privacy policy. We update the privacy policy whenever changes to our data processing make it necessary. We'll let you know as soon as the changes require your active cooperation (e. g. consent) or any other individual notification.
Where we provide addresses and contact information of companies and organisations in this privacy policy, please note that these addresses may change over time. We ask you to check the details before getting in touch.
Questions about data protection? Send us an email, we usually reply within one working day.
E-Mail to data protectionLast updated: April 2026 · This privacy policy replaces all previous versions.
















