top of page

Privacy Policy

Last updated: 01.06.2026
Effective globally for all visitors to www.hommyconsulting.com and all individuals communicating with Hommy Consulting from any country.

Hommy Consulting respects your privacy and is committed to protecting your personal data with the same care, transparency, and seriousness we bring to every aspect of our consulting work.

This privacy policy explains how we collect, use, share, and protect your personal information when you visit our website, complete our intake conversation, contact us by any channel, or otherwise interact with Hommy Consulting from anywhere in the world.

This policy has been written to meet the strictest global privacy standards, including the European Union's General Data Protection Regulation (GDPR), and to respect the additional rights granted to individuals under the laws of specific jurisdictions, including the United Kingdom (UK GDPR), Switzerland (FADP), Brazil (LGPD), South Africa (POPIA), California (CCPA/CPRA), and other applicable national laws.

If you do not agree with the practices described here, please do not use this website or share personal information with us.

The data controller responsible for the processing of personal data under this policy is:

Gabriel Cadenas - Hommy Consulting

70195 Stuttgart

Email: info@hommyconsulting.com
Website: www.hommyconsulting.com

For all matters relating to your personal data, including any of the rights described in this policy, please contact us at the email address above.

We only collect the personal data we genuinely need to serve you. Specifically:

a) Information you give us directly
When you contact us through our website, complete our intake conversation, send us an email, message us on professional platforms, or speak with us by phone, we may collect:

  • Your full name

  • Your professional or business email address

  • Your hotel, property, or company name

  • Your country and city

  • Your role or position

  • Your phone number (only if you provide it)

  • The information you share about your business situation, challenges, or goals

  • Your preferred language and time for communication

  • Any other information you voluntarily provide during our interactions

b) Information we collect automatically when you visit our website

  • Your IP address (anonymized where technically possible)

  • Browser type and version

  • Operating system and device type

  • Date, time, and duration of your visit

  • Pages you visited

  • Referring website or source

  • General geographic location at country or region level

c) Cookies and similar technologies
Our website uses cookies and similar technologies. A cookie is a small text file stored on your device. We use:

  • Essential cookies — required for the website to function. These cannot be disabled and do not require your consent.

  • Analytics cookies — to understand how visitors use our site, used only with your explicit consent.

  • Functional cookies — to remember your preferences, used only with your explicit consent.

You can accept, decline, or manage cookies through the cookie banner shown on your first visit, or at any later time through your browser settings or our cookie preferences panel.

We do not use advertising cookies, tracking pixels for third-party advertising, or behavioral profiling cookies.#

We process your personal data for the following purposes:

  • To respond to your inquiry and the questions or requests you have shared with us

  • To provide the consulting services, advisory work, and analysis you have requested

  • To schedule, conduct, and follow up on discovery calls, meetings, and project conversations

  • To send you communications directly related to your inquiry or our work together

  • To maintain accurate business records as required by law

  • To improve our website, services, and the quality of our interactions

  • To comply with applicable legal, tax, and regulatory obligations

 

We will never:

  • Sell your personal data to any third party

  • Share your data with parties for their own marketing purposes

  • Use your data for automated decision-making that produces legal or similarly significant effects

  • Send you marketing communications without your explicit consent

Depending on your location and the specific data, we rely on one or more of the following legal bases:

  • Your consent — when you voluntarily share information through our forms, accept cookies, or agree to specific data uses

  • Contractual necessity — when processing is required to deliver the services you have engaged us to provide

  • Legitimate business interests — to operate our website, respond to professional inquiries, and protect our business, where these interests are not overridden by your fundamental rights

  • Legal obligation — to fulfill applicable record-keeping, tax, and regulatory requirements

You may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before your withdrawal.

We keep your personal data only for as long as we genuinely need it:

  • Contact form submissions and unconverted inquiries: retained for up to 24 months after our last meaningful contact, then deleted

  • Active client project data: retained for the duration of the engagement plus the legally required retention period in our jurisdiction (typically 6 to 10 years for tax and commercial records in Germany)

  • Concluded client engagements: retained according to applicable legal retention requirements, then deleted or fully anonymized

  • Website analytics data: retained for up to 14 months

  • Cookies: vary by type, with most expiring within 12 months

  • Email correspondence: retained according to professional and legal record-keeping standards

When the retention period ends, your data is either securely deleted or irreversibly anonymized.

Your personal data is accessed only by:

  • Hommy Consulting personnel directly involved in serving your inquiry or project

  • Trusted third-party service providers that help us operate our business (data processors)

Our data processors may include:

  • Website hosting and platform provider 

  • Email and productivity services

  • Customer relationship management 

  • Scheduling and meeting tools 

  • Communication platforms 

  • Cloud storage 

  • Accounting and invoicing software 

  • Analytics services 

All data processors are bound by formal Data Processing Agreements that require them to protect your data with at least the same standards we apply.

We do not share, transfer, sell, or lease your personal data to any other third party for their own purposes.

Hommy Consulting operates internationally. Some of our service providers may be located outside your country, including in the European Economic Area, the United Kingdom, the United States, and elsewhere.

When personal data is transferred outside your jurisdiction, we ensure that one of the following safeguards is in place:

  • The destination country has been recognized as offering an adequate level of data protection by the relevant authority (such as the European Commission's adequacy decisions)

  • Standard Contractual Clauses approved by the European Commission or the relevant authority are signed with the recipient

  • Other lawful safeguards apply, such as your explicit consent for a specific transfer or the necessity of the transfer for performing a contract with you

You may request more information about the specific safeguards in place for any transfer by contacting us at the email address in Section 2.

Regardless of where you live, you have the following rights with respect to your personal data:

  • Right to know what personal data we hold about you

  • Right to access that data in a readable form

  • Right to correct inaccurate or incomplete data

  • Right to delete your data ("right to be forgotten"), subject to legal retention requirements

  • Right to restrict how we process your data in certain circumstances

  • Right to object to processing based on legitimate interest

  • Right to data portability — to receive your data in a structured, commonly used format

  • Right to withdraw consent at any time, where consent is the legal basis for processing

  • Right to file a complaint with the data protection authority in your jurisdiction

To exercise any of these rights, please contact us at [your email]. We will respond within 30 days, or sooner where required by your local law.

The following sections describe additional rights that apply if you are in a specific jurisdiction. Universal rights described in Section 9 always apply to you regardless of location.

If you are in the EU, EEA, or UK, the General Data Protection Regulation (GDPR) and the UK GDPR apply to our processing of your personal data. In addition to the rights in Section 9, you have the right to:

  • Lodge a complaint with your national supervisory authority

  • Receive specific information about the recipients of your personal data

  • Be informed of any automated decision-making (we do not currently conduct any)

UK residents may contact the Information Commissioner's Office (ICO) at www.ico.org.uk.

If you are in Switzerland, the Swiss Federal Act on Data Protection (FADP) applies in addition to the rights described above. You may contact the Federal Data Protection and Information Commissioner (FDPIC) at www.edoeb.admin.ch.

If you are in Brazil, the Lei Geral de Proteção de Dados (LGPD) applies. You have additional rights including the right to confirmation of processing and the right to know with which public or private entities we have shared your data. You may contact the Autoridade Nacional de Proteção de Dados (ANPD) at www.gov.br/anpd.

10.4 Argentina, Mexico, Colombia, Uruguay, Chile, Peru, and other Latin American countries

If you are in any of these countries, the national data protection law applicable to you may grant additional rights. You may contact your national data protection authority or write to us at the email address in Section 2 and we will respect your rights under your applicable law.

If you are in South Africa, the Protection of Personal Information Act (POPIA) applies to our processing of your personal information. Your additional rights include the right to object to processing for direct marketing and the right to be notified of unauthorized access. You may contact the Information Regulator (South Africa) at www.justice.gov.za/inforeg.

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you specific rights, including:

  • The right to know what personal information we collect, use, and share about you

  • The right to delete personal information

  • The right to correct inaccurate personal information

  • The right to opt out of the "sale" or "sharing" of personal information (we do not sell or share personal information as defined by the CCPA)

  • The right to limit use of sensitive personal information

  • The right not to be discriminated against for exercising your privacy rights

To exercise these rights, contact us at the email in Section 2. We will not deny services, charge different prices, or provide different quality based on your exercise of these rights.

If you are located in a jurisdiction not specifically mentioned above, you may still have specific data protection rights under your local law. We respect these rights and invite you to contact us to discuss any specific concerns. We aim to extend GDPR-equivalent protections to all visitors regardless of location.

We apply appropriate technical and organizational measures to protect your personal data, including:

  • Encrypted transmission of data via SSL/TLS protocols

  • Access controls, authentication, and role-based permissions for our systems

  • Confidentiality obligations binding all personnel and contractors

  • Vetted, contractually bound third-party service providers

  • Regular review of our security practices

  • Secure deletion or anonymization of data when retention periods end

While we apply industry-standard security practices, no electronic transmission or storage system is 100% secure. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within the timeframes required by applicable law.

Our website and services are intended for hotel owners, executives, and professionals. We do not knowingly collect personal data from children under the age of 16 (or the age of digital consent in your jurisdiction). If you believe we have inadvertently collected personal data from a child, please contact us immediately and we will delete it.

Our website may contain links to external websites operated by third parties, such as trusted partners, vendors we recommend, or platforms like LinkedIn, Instagram, or Calendly. We are not responsible for the privacy practices of these external sites. We encourage you to read their privacy policies before sharing personal data with them.

We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or other reasons. The most recent version will always be available on our website with the "Last updated" date at the top.

For material changes that affect how we use your data, we will notify active clients directly. For minor changes, the updated policy is effective from the date it is posted.

We encourage you to review this policy periodically.

If you have any questions, concerns, or requests regarding this privacy policy or how we handle your data, please contact us:

Hommy Consulting
Email: gabriel@hommyconsulting.com
Address: 70195 Stuttgart

We are committed to responding to all genuine privacy inquiries within 30 days, or sooner where required by your local law.

This policy was last updated on 01.06.2026.

bottom of page