Version: 1.1 Effective date: 2026-08-23 Publication URL: https://mcp.plazahotels.de/privacy
This policy covers the PLAZA Hotels connector for ChatGPT and Claude only. Bookings made by telephone, on a hotel website or at the hotel are covered by the respective hotel's own privacy notice.
| Question | Answer |
|---|---|
| What categories of data are collected? | (a) Your free-text search/question and the hotel you asked about. (b) Only if you ask to book: first and last name, mobile telephone number, e-mail address, arrival/departure dates, number and ages of guests, the room and rate you chose, travel reason (business or private), and optionally a form of address and a free-text request to the hotel ("quiet room"). A postal address is not requested from you. (c) Technical operating metadata: timestamp, tool name, hotel, a derived pseudonymous session key, success/failure, duration, error code. |
| What are they used for? | Answering your question from the hotel's knowledge base; retrieving live room availability and prices; creating the reservation or offer you asked for; re-sending a confirmation for that reservation; abuse prevention, rate limiting and operating the service. Nothing else. No advertising, no profiling, no training of AI models by us. |
| Who receives them? | The hotel you are booking; HotelPartner (the booking system that holds the reservation); the SMS provider used for confirmations; OpenAI, as the provider of the text-embedding service used to search the hotel knowledge base; and the AI assistant platform you chose to use (OpenAI/ChatGPT or Anthropic/Claude), which processes the conversation under its own privacy policy. Details in §5. |
| How long are they kept? | Technical operating logs: 90 days, then deleted. Detailed service records (§3.4(b)), which include your question text, your booking details and the source IP address: no automatic deletion period is currently set — they are kept for as long as needed for support and abuse prevention and are deleted on request (§9). Rate-limit counters: 5 minutes to 24 hours, in memory only. Short-lived offer tokens: 30 minutes. Reservation data: kept by the hotel and the booking system for the duration of the contract plus statutory retention periods (up to 10 years for accounting records under German tax and commercial law). |
| What controls do you have? | You can simply not use the connector — nothing is sent to us until you invoke a tool. You choose whether to give booking data; without it no reservation is possible. You can disconnect or remove the connector in ChatGPT or Claude at any time. You have the GDPR rights of access, rectification, erasure, restriction, objection, data portability and complaint to a supervisory authority (§9). |
No payment card data is ever processed by this connector. See §7.
Responsible for the data processing described here (controller within the meaning of Art. 4(7) GDPR):
PLAZA Hotelgroup GmbH
Lise-Meitner-Straße 4
74074 Heilbronn, Deutschland
Registergericht: Amtsgericht Stuttgart, HRB 747034
USt-IdNr.: DE 293010344
Vertreten durch die Geschäftsführung: Yonca Yalaz
Telefon: +49 7131 264170
E-Mail: info@plazahotels.de
PLAZA Hotelgroup GmbH operates all five hotels listed in §2 and is the controller for the processing described here, including the reservations created through the connector.
Operator of the technical service (processor):
mediaconstructor GmbH & Co. KG
Mecklenburgstraße 105, 19053 Schwerin, Deutschland
Registergericht: Amtsgericht Schwerin, HRA 3025
USt-IdNr.: DE258400609
Vertreten durch die Geschäftsführung: Martin Thalmann (mc Beteiligungs GmbH, HRB 97 08)
Telefon: 0385 760 50 94 · E-Mail: info@mc-kg.de
mediaconstructor GmbH & Co. KG develops and operates this connector on behalf of and on the documented instructions of PLAZA Hotelgroup GmbH, as a processor within the meaning of Art. 28 GDPR, and publishes the connector listing in the ChatGPT Plugin directory and the Claude Connectors Directory on the controller's behalf. It does not use the data described here for its own purposes.
A data processing agreement under Art. 28 GDPR between PLAZA Hotelgroup GmbH and mediaconstructor GmbH & Co. KG is in place.
Data protection officer / privacy contact:
DSKC Datenschutz-Arbeitssicherheit-Kompetenz-Center GmbH
Sielower Landstraße 68, 03044 Cottbus, Deutschland
E-Mail: info@dskc.de · Telefon: +49 355 48679410
You may contact the data protection officer directly about any processing described in this policy, without going through the controller.
The PLAZA Hotels MCP Connector is a software interface ("MCP server") that lets an AI assistant you already use — ChatGPT (OpenAI) or Claude (Anthropic) — answer questions about five hotels of the PLAZA group and, for all five, check live room availability and create a reservation:
| Hotel | City | Booking possible via the connector |
|---|---|---|
| Plaza Premium Schwerin | Schwerin | yes |
| PLAZA INN Goslar | Goslar | yes |
| PLAZA INN Braunschweig City Süd | Braunschweig | yes |
| PLAZA INN Zwickau | Zwickau | yes |
| PLAZA Hotel Hanau | Hanau | yes |
You do not need a PLAZA account and there is no login. The connector is used from inside your assistant; we do not operate the assistant itself.
When you ask about a hotel, the assistant sends us your question (or a reformulation of it) and the hotel it concerns. The question text is converted into a numerical representation ("embedding") in order to search the hotel's knowledge base; see §5 on OpenAI as recipient.
We ask you not to include personal data in a question that does not need it. If you do, it is processed only to answer that question.
Arrival and departure date, number of adults, ages of children, number of rooms. This is sent to the booking system to obtain real prices. On its own, it is not linked to your identity.
Nothing in this category is collected in order to "have" it. It is requested at the moment you ask for a reservation, because the booking system requires it:
| Data | Required? | Why it is needed |
|---|---|---|
| First and last name | yes | the reservation is made in your name |
| Mobile telephone number | yes | confirmation by SMS; the hotel must be able to reach you |
| E-mail address | yes | the booking system sends the confirmation, or the offer link, to it |
| Arrival / departure date, number and ages of guests, room and rate chosen | yes | the content of the contract |
| Travel reason (private or business) | yes | required field of the booking system; used for statistics and rate eligibility |
| Form of address (Frau / Herr) | optional | how the reservation record and the confirmation address you |
| Free-text request to the hotel (e.g. "quiet room", "late arrival around 23:00") | optional | forwarded to the hotel as a note on the booking |
No postal address is requested from you. The address field required by the booking system is filled from the hotel's own address, not from you. (Verified against the booking payload builder: the street, house number, postal code, city and country fields sent to the booking system are taken from a fixed per-hotel constant, never from anything you type.)
We do not request, and you should never enter, payment card details, health data, government identification numbers, passwords or API keys.
We keep two separate records of each tool call.
(a) The operating log. For each tool call: timestamp, hotel, tool name, a pseudonymous
session key derived by our server (from the MCP session identifier, or failing that a hashed IP
address), whether the call succeeded, how long it took, a short non-content summary of the
parameters, and an error code if any. In that summary, names and addresses are replaced by
[dropped], e-mail addresses and telephone numbers are masked, and all free text is reduced to
its character count ([len:52]). Any parameter type not explicitly recognised is treated as
free text, so a field added in future cannot begin recording content by accident.
(b) The service record. Since 23 August 2026 we additionally keep, per conversation, a detailed record of what was requested and answered:
Purposes: handling support enquiries about a booking made through the connector (Art. 6(1)(b) GDPR, and Art. 6(1)(f) for enquiries by someone other than the guest), and detecting and preventing abuse of a service that has no login — see §4. The legitimate interest is concrete: the connector is openly reachable, every booking it creates is a real obligation for the hotel, and without the source address an abusive or fraudulent booking cannot be attributed or stopped.
Never recorded, in either record: payment card data (§7), and the signed offer token used
internally to carry a price quote — it is a credential and is replaced by [redacted].
We do not receive the conversation between you and the assistant. We receive the parameters of the tools the assistant calls, and we record our own answers to them — not the surrounding chat.
The detailed record can be switched off in configuration, in which case only (a) is kept.
| Processing | Legal basis |
|---|---|
| Answering questions from the hotel knowledge base, sights and events search | Art. 6(1)(b) GDPR (steps prior to a contract at your request) and Art. 6(1)(f) GDPR (legitimate interest in informing prospective guests) |
| Availability and price enquiry | Art. 6(1)(b) GDPR — pre-contractual measure at your request |
| Creating a reservation or an offer, sending the confirmation by SMS/e-mail, re-sending it | Art. 6(1)(b) GDPR — performance of, or steps towards, the accommodation contract |
| Technical operating metadata, rate limiting, abuse prevention, IT security | Art. 6(1)(f) GDPR — legitimate interest in a functioning, non-abused service. Our balancing test: the data is pseudonymous operational metadata, retained briefly, and no less intrusive means exists to detect abuse of an unauthenticated public interface |
| Statutory retention of booking and accounting records | Art. 6(1)(c) GDPR together with § 147 AO and § 257 HGB |
Consent (Art. 6(1)(a) GDPR) is not used as a legal basis by the connector, and none is therefore required from you for the functions described here. The AI assistant platform you use may rely on its own legal bases for its own processing; see §5.4.
The reservation is transmitted to the hotel you selected, which is operated by PLAZA Hotelgroup GmbH — the controller named in §1. Passing the reservation to the hotel is therefore an internal step within the controller, not a disclosure to a separate controller. The hotel processes it for the purposes of the accommodation contract.
| Recipient | Role | What it receives | Basis |
|---|---|---|---|
| HotelPartner — operator of the WBE booking system used by the PLAZA hotels (the reservation system of record) | booking system of record | availability requests, and the complete reservation data of §3.3 | Contractually governed data processing under Art. 28 GDPR. The exact contracting entity can be obtained from the contact in §1 |
| seven communications GmbH & Co. KG (seven.io), Willestraße 4–6, 24103 Kiel, Deutschland | SMS delivery (booking confirmation, and re-sending it to a corrected number) | mobile number and the confirmation text | Art. 28 GDPR processor agreement |
| — no separate e-mail provider — | — | — | Your booking confirmation and offer link are sent by the booking system (row 1), not by this connector. The connector's re-send function is SMS only, so no e-mail provider receives your data from us |
| OpenAI (OpenAI Ireland Limited for customers in the EEA) | text-embedding service used to search the hotel knowledge base | the text of your question, as an API request | Art. 28 GDPR processor agreement under OpenAI's API data processing addendum. Inputs sent through the API are not used to train OpenAI's models |
| Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Deutschland — server located in Germany | hosting | all of the above in transit; the operating log at rest | Art. 28 GDPR processor agreement |
Note on OpenAI as an embedding provider: the knowledge-base search uses OpenAI embedding models. This applies regardless of which assistant you use — if you use Claude, your question text is still sent to OpenAI for embedding, because that is how the hotel knowledge base is indexed. We consider this material and therefore state it explicitly.
We do not sell personal data and we do not pass it to third parties for their own advertising. Disclosure to authorities occurs only where legally required.
You reach this connector through ChatGPT (OpenAI) or Claude (Anthropic). That platform processes your conversation — including what you type and what our tools return — under its own privacy policy and as its own controller. We have no control over it and it is not a processor for us. Before you enter booking data, be aware that the assistant platform sees it:
Data stays within the EU/EEA wherever the provider allows it. Transfers to the USA or other third countries can occur with the AI/embedding providers named in §5. Where they do, they are based on:
You may request details of the mechanism relied upon for a specific provider, and a copy of the relevant safeguards, from the contact in §1.
This connector never processes payment card data. There is no payment inside ChatGPT or Claude.
Card data is therefore entered only in the booking system's environment, is never transmitted to or through this connector, and is not visible to the AI assistant. We also never request card numbers, CVCs or bank details in the chat; if an assistant ever asks you for them, do not provide them and contact us at the address in §1.
| Data | Retention |
|---|---|
| Technical operating log (§3.4) | 90 days, then automatically deleted |
| Rate-limit counters | held in memory for the length of the window (5 minutes to 24 hours); not persisted |
| Signed offer token linking an availability quote to a reservation | 30 minutes, single use; contains the quote, not your identity |
| Detailed service record (§3.4(b)): source IP, client identifier, full tool parameters, guest contact details, answer text | no automatic deletion period is currently set. Kept for support on bookings made through the connector and for abuse prevention; deleted on request under §9, and reviewed when a fixed period is set |
| Question / search text | stored as written in the detailed service record (§3.4(b)); the operating log records only its character count; transiently processed by the embedding provider under §5.2 |
| Reservation data | stored in the booking system and by the hotel for the duration of the contract and thereafter under statutory retention duties — generally 6 years (§ 257 HGB) to 10 years (§ 147 AO) for accounting-relevant records. Contact the hotel for its own retention schedule |
| Data of an offer that expires unused | deleted or anonymised by the booking system according to its own retention schedule |
Under the GDPR you have, in relation to the processing described here, the right to:
Send requests to the contact in §1. Please tell us the hotel and the approximate date, and the phone number or e-mail address you used — for an unauthenticated connector this is usually the only way we can locate a record. We may ask for proof of identity where there is reasonable doubt (Art. 12(6) GDPR).
Right to complain (Art. 77 GDPR). You may lodge a complaint with a supervisory authority, in particular the authority of your habitual residence or of our establishment:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Lautenschlagerstraße 20, 70173 Stuttgart, Deutschland
https://www.baden-wuerttemberg.datenschutz.de
(Competent authority for the controller's registered office in Heilbronn, Baden-Württemberg.)
Measures in place for this connector (each verified against the running code):
No internet service is absolutely secure; we cannot guarantee absolute security, but we maintain the above as state of the art and review it when the service changes.
We will update this policy when the connector changes — for example if a tool is added that processes additional data. The current version is always available at the URL at the top of this document, with its version number and effective date. Material changes will be noted here with the date of the change.
This policy is published in German, English and Dutch. In case of any discrepancy between the language versions, the German version prevails.