Privacy Policy — PLAZA Hotels MCP Connector

Version: 1.1 Effective date: 2026-08-23 Publication URL: https://mcp.plazahotels.de/privacy

This policy covers the PLAZA Hotels connector for ChatGPT and Claude only. Bookings made by telephone, on a hotel website or at the hotel are covered by the respective hotel's own privacy notice.


0. At a glance — the five disclosures both directories require

Question Answer
What categories of data are collected? (a) Your free-text search/question and the hotel you asked about. (b) Only if you ask to book: first and last name, mobile telephone number, e-mail address, arrival/departure dates, number and ages of guests, the room and rate you chose, travel reason (business or private), and optionally a form of address and a free-text request to the hotel ("quiet room"). A postal address is not requested from you. (c) Technical operating metadata: timestamp, tool name, hotel, a derived pseudonymous session key, success/failure, duration, error code.
What are they used for? Answering your question from the hotel's knowledge base; retrieving live room availability and prices; creating the reservation or offer you asked for; re-sending a confirmation for that reservation; abuse prevention, rate limiting and operating the service. Nothing else. No advertising, no profiling, no training of AI models by us.
Who receives them? The hotel you are booking; HotelPartner (the booking system that holds the reservation); the SMS provider used for confirmations; OpenAI, as the provider of the text-embedding service used to search the hotel knowledge base; and the AI assistant platform you chose to use (OpenAI/ChatGPT or Anthropic/Claude), which processes the conversation under its own privacy policy. Details in §5.
How long are they kept? Technical operating logs: 90 days, then deleted. Detailed service records (§3.4(b)), which include your question text, your booking details and the source IP address: no automatic deletion period is currently set — they are kept for as long as needed for support and abuse prevention and are deleted on request (§9). Rate-limit counters: 5 minutes to 24 hours, in memory only. Short-lived offer tokens: 30 minutes. Reservation data: kept by the hotel and the booking system for the duration of the contract plus statutory retention periods (up to 10 years for accounting records under German tax and commercial law).
What controls do you have? You can simply not use the connector — nothing is sent to us until you invoke a tool. You choose whether to give booking data; without it no reservation is possible. You can disconnect or remove the connector in ChatGPT or Claude at any time. You have the GDPR rights of access, rectification, erasure, restriction, objection, data portability and complaint to a supervisory authority (§9).

No payment card data is ever processed by this connector. See §7.


1. Controller

Responsible for the data processing described here (controller within the meaning of Art. 4(7) GDPR):

PLAZA Hotelgroup GmbH
Lise-Meitner-Straße 4
74074 Heilbronn, Deutschland
Registergericht: Amtsgericht Stuttgart, HRB 747034
USt-IdNr.: DE 293010344
Vertreten durch die Geschäftsführung: Yonca Yalaz
Telefon:   +49 7131 264170
E-Mail:    info@plazahotels.de

PLAZA Hotelgroup GmbH operates all five hotels listed in §2 and is the controller for the processing described here, including the reservations created through the connector.

Operator of the technical service (processor):

mediaconstructor GmbH & Co. KG
Mecklenburgstraße 105, 19053 Schwerin, Deutschland
Registergericht: Amtsgericht Schwerin, HRA 3025
USt-IdNr.: DE258400609
Vertreten durch die Geschäftsführung: Martin Thalmann (mc Beteiligungs GmbH, HRB 97 08)
Telefon: 0385 760 50 94 · E-Mail: info@mc-kg.de

mediaconstructor GmbH & Co. KG develops and operates this connector on behalf of and on the documented instructions of PLAZA Hotelgroup GmbH, as a processor within the meaning of Art. 28 GDPR, and publishes the connector listing in the ChatGPT Plugin directory and the Claude Connectors Directory on the controller's behalf. It does not use the data described here for its own purposes.

A data processing agreement under Art. 28 GDPR between PLAZA Hotelgroup GmbH and mediaconstructor GmbH & Co. KG is in place.

Data protection officer / privacy contact:

DSKC Datenschutz-Arbeitssicherheit-Kompetenz-Center GmbH
Sielower Landstraße 68, 03044 Cottbus, Deutschland
E-Mail: info@dskc.de · Telefon: +49 355 48679410

You may contact the data protection officer directly about any processing described in this policy, without going through the controller.

2. What this connector is

The PLAZA Hotels MCP Connector is a software interface ("MCP server") that lets an AI assistant you already use — ChatGPT (OpenAI) or Claude (Anthropic) — answer questions about five hotels of the PLAZA group and, for all five, check live room availability and create a reservation:

Hotel City Booking possible via the connector
Plaza Premium Schwerin Schwerin yes
PLAZA INN Goslar Goslar yes
PLAZA INN Braunschweig City Süd Braunschweig yes
PLAZA INN Zwickau Zwickau yes
PLAZA Hotel Hanau Hanau yes

You do not need a PLAZA account and there is no login. The connector is used from inside your assistant; we do not operate the assistant itself.

3. Categories of personal data, and when they are processed

3.1 Question and search data — whenever you use a search tool

When you ask about a hotel, the assistant sends us your question (or a reformulation of it) and the hotel it concerns. The question text is converted into a numerical representation ("embedding") in order to search the hotel's knowledge base; see §5 on OpenAI as recipient.

We ask you not to include personal data in a question that does not need it. If you do, it is processed only to answer that question.

3.2 Availability requests

Arrival and departure date, number of adults, ages of children, number of rooms. This is sent to the booking system to obtain real prices. On its own, it is not linked to your identity.

3.3 Reservation data — only if you actually ask to book

Nothing in this category is collected in order to "have" it. It is requested at the moment you ask for a reservation, because the booking system requires it:

Data Required? Why it is needed
First and last name yes the reservation is made in your name
Mobile telephone number yes confirmation by SMS; the hotel must be able to reach you
E-mail address yes the booking system sends the confirmation, or the offer link, to it
Arrival / departure date, number and ages of guests, room and rate chosen yes the content of the contract
Travel reason (private or business) yes required field of the booking system; used for statistics and rate eligibility
Form of address (Frau / Herr) optional how the reservation record and the confirmation address you
Free-text request to the hotel (e.g. "quiet room", "late arrival around 23:00") optional forwarded to the hotel as a note on the booking

No postal address is requested from you. The address field required by the booking system is filled from the hotel's own address, not from you. (Verified against the booking payload builder: the street, house number, postal code, city and country fields sent to the booking system are taken from a fixed per-hotel constant, never from anything you type.)

We do not request, and you should never enter, payment card details, health data, government identification numbers, passwords or API keys.

3.4 Technical operating metadata

We keep two separate records of each tool call.

(a) The operating log. For each tool call: timestamp, hotel, tool name, a pseudonymous session key derived by our server (from the MCP session identifier, or failing that a hashed IP address), whether the call succeeded, how long it took, a short non-content summary of the parameters, and an error code if any. In that summary, names and addresses are replaced by [dropped], e-mail addresses and telephone numbers are masked, and all free text is reduced to its character count ([len:52]). Any parameter type not explicitly recognised is treated as free text, so a field added in future cannot begin recording content by accident.

(b) The service record. Since 23 August 2026 we additionally keep, per conversation, a detailed record of what was requested and answered:

Purposes: handling support enquiries about a booking made through the connector (Art. 6(1)(b) GDPR, and Art. 6(1)(f) for enquiries by someone other than the guest), and detecting and preventing abuse of a service that has no login — see §4. The legitimate interest is concrete: the connector is openly reachable, every booking it creates is a real obligation for the hotel, and without the source address an abusive or fraudulent booking cannot be attributed or stopped.

Never recorded, in either record: payment card data (§7), and the signed offer token used internally to carry a price quote — it is a credential and is replaced by [redacted].

We do not receive the conversation between you and the assistant. We receive the parameters of the tools the assistant calls, and we record our own answers to them — not the surrounding chat.

The detailed record can be switched off in configuration, in which case only (a) is kept.

3.5 What we do not do

4. Legal bases

Processing Legal basis
Answering questions from the hotel knowledge base, sights and events search Art. 6(1)(b) GDPR (steps prior to a contract at your request) and Art. 6(1)(f) GDPR (legitimate interest in informing prospective guests)
Availability and price enquiry Art. 6(1)(b) GDPR — pre-contractual measure at your request
Creating a reservation or an offer, sending the confirmation by SMS/e-mail, re-sending it Art. 6(1)(b) GDPR — performance of, or steps towards, the accommodation contract
Technical operating metadata, rate limiting, abuse prevention, IT security Art. 6(1)(f) GDPR — legitimate interest in a functioning, non-abused service. Our balancing test: the data is pseudonymous operational metadata, retained briefly, and no less intrusive means exists to detect abuse of an unauthenticated public interface
Statutory retention of booking and accounting records Art. 6(1)(c) GDPR together with § 147 AO and § 257 HGB

Consent (Art. 6(1)(a) GDPR) is not used as a legal basis by the connector, and none is therefore required from you for the functions described here. The AI assistant platform you use may rely on its own legal bases for its own processing; see §5.4.

5. Recipients

5.1 The hotel

The reservation is transmitted to the hotel you selected, which is operated by PLAZA Hotelgroup GmbH — the controller named in §1. Passing the reservation to the hotel is therefore an internal step within the controller, not a disclosure to a separate controller. The hotel processes it for the purposes of the accommodation contract.

5.2 Processors and service providers

Recipient Role What it receives Basis
HotelPartner — operator of the WBE booking system used by the PLAZA hotels (the reservation system of record) booking system of record availability requests, and the complete reservation data of §3.3 Contractually governed data processing under Art. 28 GDPR. The exact contracting entity can be obtained from the contact in §1
seven communications GmbH & Co. KG (seven.io), Willestraße 4–6, 24103 Kiel, Deutschland SMS delivery (booking confirmation, and re-sending it to a corrected number) mobile number and the confirmation text Art. 28 GDPR processor agreement
— no separate e-mail provider — Your booking confirmation and offer link are sent by the booking system (row 1), not by this connector. The connector's re-send function is SMS only, so no e-mail provider receives your data from us
OpenAI (OpenAI Ireland Limited for customers in the EEA) text-embedding service used to search the hotel knowledge base the text of your question, as an API request Art. 28 GDPR processor agreement under OpenAI's API data processing addendum. Inputs sent through the API are not used to train OpenAI's models
Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Deutschland — server located in Germany hosting all of the above in transit; the operating log at rest Art. 28 GDPR processor agreement

Note on OpenAI as an embedding provider: the knowledge-base search uses OpenAI embedding models. This applies regardless of which assistant you use — if you use Claude, your question text is still sent to OpenAI for embedding, because that is how the hotel knowledge base is indexed. We consider this material and therefore state it explicitly.

5.3 No other disclosure

We do not sell personal data and we do not pass it to third parties for their own advertising. Disclosure to authorities occurs only where legally required.

5.4 The AI assistant platform you chose

You reach this connector through ChatGPT (OpenAI) or Claude (Anthropic). That platform processes your conversation — including what you type and what our tools return — under its own privacy policy and as its own controller. We have no control over it and it is not a processor for us. Before you enter booking data, be aware that the assistant platform sees it:

6. Transfers to third countries

Data stays within the EU/EEA wherever the provider allows it. Transfers to the USA or other third countries can occur with the AI/embedding providers named in §5. Where they do, they are based on:

You may request details of the mechanism relied upon for a specific provider, and a copy of the relevant safeguards, from the contact in §1.

7. No payment card data

This connector never processes payment card data. There is no payment inside ChatGPT or Claude.

Card data is therefore entered only in the booking system's environment, is never transmitted to or through this connector, and is not visible to the AI assistant. We also never request card numbers, CVCs or bank details in the chat; if an assistant ever asks you for them, do not provide them and contact us at the address in §1.

8. Retention

Data Retention
Technical operating log (§3.4) 90 days, then automatically deleted
Rate-limit counters held in memory for the length of the window (5 minutes to 24 hours); not persisted
Signed offer token linking an availability quote to a reservation 30 minutes, single use; contains the quote, not your identity
Detailed service record (§3.4(b)): source IP, client identifier, full tool parameters, guest contact details, answer text no automatic deletion period is currently set. Kept for support on bookings made through the connector and for abuse prevention; deleted on request under §9, and reviewed when a fixed period is set
Question / search text stored as written in the detailed service record (§3.4(b)); the operating log records only its character count; transiently processed by the embedding provider under §5.2
Reservation data stored in the booking system and by the hotel for the duration of the contract and thereafter under statutory retention duties — generally 6 years (§ 257 HGB) to 10 years (§ 147 AO) for accounting-relevant records. Contact the hotel for its own retention schedule
Data of an offer that expires unused deleted or anonymised by the booking system according to its own retention schedule

9. Your rights

Under the GDPR you have, in relation to the processing described here, the right to:

Send requests to the contact in §1. Please tell us the hotel and the approximate date, and the phone number or e-mail address you used — for an unauthenticated connector this is usually the only way we can locate a record. We may ask for proof of identity where there is reasonable doubt (Art. 12(6) GDPR).

Right to complain (Art. 77 GDPR). You may lodge a complaint with a supervisory authority, in particular the authority of your habitual residence or of our establishment:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Lautenschlagerstraße 20, 70173 Stuttgart, Deutschland
https://www.baden-wuerttemberg.datenschutz.de

(Competent authority for the controller's registered office in Heilbronn, Baden-Württemberg.)

10. Security

Measures in place for this connector (each verified against the running code):

No internet service is absolutely secure; we cannot guarantee absolute security, but we maintain the above as state of the art and review it when the service changes.

11. Changes to this policy

We will update this policy when the connector changes — for example if a tool is added that processes additional data. The current version is always available at the URL at the top of this document, with its version number and effective date. Material changes will be noted here with the date of the change.

12. Language

This policy is published in German, English and Dutch. In case of any discrepancy between the language versions, the German version prevails.