Privacy Policy
Privacy Information for Visitors to Our Website
When you visit our website, various data, including personal data, is collected. We treat your personal data (as defined in Art. 4(1) GDPR) confidentially and in accordance with statutory data protection provisions. This privacy policy explains what data we collect, what we use it for, and how and for what purpose this happens. This is done above all to give you comfortable and secure access to our information and offerings. Of course, with our website we also pursue economic interests intended to strengthen both our image and our revenue. For reasons of fairness and transparency, we are happy to inform you about this in detail below, in accordance with the EU GDPR (General Data Protection Regulation):
Who is responsible for data collection?
Responsible for data collection when you visit this website is Bürgermeister-Reuter-Stiftung (https://www.brst.de/impressum/) as the website operator.
How do we collect your data?
Your data is collected, on the one hand, automatically when you visit the website through the IT systems we use. This is primarily technical data (e.g., internet browser, operating system, or the time of the page access). This data is collected automatically as soon as you access our website. Other data is collected when you provide it to us yourself. This may, for example, be data you enter into a contact form.
What do we use your data for?
Part of the data is collected to ensure error-free provision of the website. Further details are explained in the following sections.
TLS Encryption
For security reasons and to protect the transmission of confidential content, such as orders or inquiries you send to us as the site operator, this site uses TLS encryption. You can recognize an encrypted connection by the fact that the browser’s address bar changes from “http://” to “https://” and by the lock symbol in your browser bar. When TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Your Contact for Our Data Protection Officer
We have appointed mb-datenschutz GmbH (https://mb-datenschutz.de/) as our Data Protection Officer. Please direct data protection inquiries to the email address dsb@brst.de. (For all other inquiries, please use the following email address: info@brst.de.)
Data Collection on Our Website
Cookies
Our website uses so-called cookies. These serve to make our offering more user-friendly, effective, and secure. Cookies are text files that are stored on your device via the browser.
Cookies do not cause any damage to your device and do not contain viruses. A distinction is made between so-called “session cookies” and “persistent cookies.” The former are automatically deleted once your visit ends. Other cookies remain stored on your device until they expire or are deleted. These cookies make it possible to recognize your browser on your next visit and to apply the settings you previously made. You can configure your browser to notify you when cookies are set and to allow cookies only in individual cases, to exclude their acceptance for certain cases or generally, and to activate automatic deletion of cookies when closing the browser. If cookies are disabled, the functionality of this website may be limited.
Session cookies, which are necessary to carry out the electronic communication process, are stored on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in storing cookies for the technically error-free and optimized provision of its services. Insofar as other cookies (e.g., for analyzing your browsing behavior) are stored, these are addressed separately in this privacy policy.
Server Log Files
The provider of our website automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. The log file data includes:
- the referrer URL (the website you came from),
- browser type, browser version, and language,
- the operating system used and its interface,
- the IP address (anonymized),
- estimated location (based on the network address),
- device type (PC or mobile),
- the time of the server request,
- the HTTP status code – access status,
- the amount of data transferred.
The storage period is a maximum of 90 days (for technical analysis purposes in the event of errors), otherwise a maximum of 30 days. This data is not merged with other data sources.
The legal basis for this data processing is Art. 6(1)(f) GDPR, which permits the processing of data for the optimal presentation and security of the website on the basis of our legitimate interest.
Matomo with Cookies
For anonymous reach measurement (website statistics), we use the open-source software Matomo. Matomo is self-hosted and self-evaluated by us. For Matomo to measure usage, it stores cookies on your device, which remain there until you delete them. Your IP address is anonymized for measurement purposes. Since, under the current, uncertain legal situation, even anonymous analysis techniques such as this presumably require your consent, we only start reach measurement once you activate it via the cookie banner.
GDPR legal basis: Art. 6(1)(a) GDPR – Your consent.
If you have already given consent via the cookie banner and have (hopefully not) changed your mind, you can object to our reach measurement by Matomo directly here:
Your objection creates an opt-out cookie in your browser that prevents Matomo from storing usage data. If you delete cookies, this will also result in the deletion of the Matomo opt-out cookie. Further information is available at: https://matomo.org/docs/privacy
Cookie Consent Management (Borlabs Cookie)
To obtain, manage, and document your consent to cookies and comparable technologies, we use the consent management tool Borlabs Cookie. The provider is Borlabs GmbH, Rübenkamp 32, 22307 Hamburg, Germany. The data collected in this process (including your consent decision, the time of consent, and your anonymized IP address) is needed in order to prove your choice and to display the correct settings to you upon a repeat visit. The legal basis is our statutory duty to demonstrate compliance under Art. 7(1) GDPR in conjunction with our legitimate interest under Art. 6(1)(f) GDPR. No transfer to third countries takes place in this context.
Google Tag Manager
We use Google Tag Manager to centrally manage various marketing and analytics tags on our website. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Tag Manager itself does not set any cookies of its own and does not collect personal data; however, when a page loads, a technical connection is established to Google’s servers, during which your IP address is transmitted.
Google Tag Manager is not permanently embedded in our website but is instead controlled via our cookie banner: it, and the marketing tags contained within it, are only loaded after you have consented to the corresponding category in the cookie banner. Without your consent, Google Tag Manager is not embedded and can therefore not execute any marketing tags. The legal basis is your consent under Art. 6(1)(a) GDPR in conjunction with Section 25(1) of the German Telecommunications and Digital Services Data Protection Act (TDDDG).
Google Ads Conversion Tracking
We use Google Ads Conversion Tracking (Google Tag) on our website, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. We run advertisements via Google Ads that link to our website, and we want to use this tool to understand whether visitors who arrived at our site via such an advertisement then take certain actions there (e.g., submit an inquiry). We only use this tool if you have given consent via our cookie banner.
The legal basis is your consent under Art. 6(1)(a) GDPR. The conversion tracking cookie set in this process, as well as the click ID (gclid) set upon an ad click, are stored in your browser for a period of 90 days.
Your data is transferred to Google’s servers in the United States in this context. Google LLC is certified under the EU-U.S. Data Privacy Framework (DPF), so appropriate safeguards within the meaning of Art. 45 GDPR are in place for this data transfer. In addition, we would like to note the following current development: the adequacy decision is currently valid, but has been under increased scrutiny by the European Commission since a recent U.S. Supreme Court ruling (June 29, 2026) concerning the independence of the U.S. Federal Trade Commission (FTC), the authority responsible for enforcing the DPF. A short-term update to this notice may become necessary. Further information on how Google handles your data can be found in Google’s privacy policy: https://policies.google.com/privacy
You can withdraw your consent at any time via our cookie banner, with effect for the future.
Google reCAPTCHA
To protect our website against abusive automated access and spam, we use the Google reCAPTCHA service on contact and booking forms. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
The service is only loaded after you have given consent via our cookie banner or have actively unblocked the relevant content. The legal basis is your consent under Art. 6(1)(a) GDPR in conjunction with Section 25(1) of the German Telecommunications and Digital Services Data Protection Act (TDDDG).
Your data is transferred to Google’s servers in the United States in this context. Google LLC is certified under the EU-U.S. Data Privacy Framework (DPF), so appropriate safeguards within the meaning of Art. 45 GDPR are in place for this data transfer. Further information on Google reCAPTCHA and Google’s privacy policy can be found at: https://policies.google.com/privacy
Visitor Interaction with Our Website
Contact Form
If you send us inquiries via the contact form, your information from the contact form, including the contact details you provide there, will be stored by us for the purpose of processing your inquiry and in case of follow-up questions. We do not pass this data on to third parties without your consent.
The processing of the data entered into the contact form is generally carried out on the legal basis of Art. 6(1)(b) GDPR (initiation or performance of a contract). Your data remains with us until you request its deletion or the purpose for data storage no longer applies (e.g., after your inquiry has been fully processed). If we are subject to statutory retention obligations, we delete the data after these periods expire.
Company Pages on Social Media
We maintain profiles on Facebook, Instagram, TikTok, YouTube, and Vimeo. The purposes of these presences are:
- direct contact with our online visitors with the aim of customer acquisition and retention, along with the associated offering of contemporary communication channels,
- notices about our posts and offerings,
- placement of advertisements directly within the respective platforms,
- statistical analyses for our own market research purposes.
The editorial use of these social media channels is based on our legitimate interest under Art. 6(1)(f) GDPR. For the placement of advertisements, we do not upload any of our own customer data (e.g., email lists) for Custom Audience or Lookalike purposes; ad delivery takes place exclusively within the respective platform on its own legal basis.
Joint Controllership (Art. 26 GDPR):
For certain processing activities, in particular page statistics, we are joint controllers together with the respective platform operators. You can find the essential content of the respective agreements under the links listed below.
Transfer of Data to Third Countries:
For all of the services listed, your data may be transferred to the United States, based on the EU-U.S. Data Privacy Framework (adequacy decision under Art. 45 GDPR) or, as a fallback, on Standard Contractual Clauses (Art. 46 GDPR). Note: the adequacy decision is currently valid, but has been under increased scrutiny by the European Commission since a recent U.S. Supreme Court ruling concerning the independence of the U.S. Federal Trade Commission. A short-term update to this notice may become necessary.
When you visit our Facebook page, Meta Platforms Ireland Limited collects, among other things, your IP address as well as other cookie-based information, and provides us, as the page operator, with statistical evaluations (Page Insights). In this respect, we are joint controllers together with Meta under Art. 26 GDPR. The essential content of this agreement: https://www.facebook.com/legal/terms/page_controller_addendum General privacy policy: https://www.facebook.com/privacy/explanation You can object to this processing by logging out of Facebook, disabling the “stay logged in” feature, and configuring your browser accordingly.
Instagram also belongs to Meta Platforms Ireland Limited. The explanations under “Facebook” regarding joint controllership and third-country transfers apply accordingly. Privacy policy: https://privacycenter.instagram.com/policy
TikTok
For our TikTok Ads account, we are joint controllers together with TikTok Technology Limited (Dublin, Ireland) under Art. 26 GDPR for processing activities related to advertisements and analytics functions. The essential content on this can be found in the “Jurisdiction Specific Terms,” Part B (EEA/UK): https://ads.tiktok.com/i18n/official/policy/jurisdiction-specific-terms Privacy policy: https://www.tiktok.com/legal/page/eea/privacy-policy/en
YouTube
Google/YouTube’s privacy policy applies to our YouTube channel. The controller for visitor data collected in connection with the use of the channel is Google Ireland Limited. Videos are published exclusively via our YouTube channel and are not embedded on our website.
Vimeo
Vimeo, Inc. (555 West 18th Street, New York, NY 10011, USA) processes the data of visitors to our Vimeo channel as an independent controller. We do not enter into a data processing agreement with Vimeo, as Vimeo does not act as a processor in this context but as its own independent controller. For third-country transfers, Vimeo provides Standard Contractual Clauses. Privacy policy: https://vimeo.com/privacy
What Rights Do You Have Under the EU GDPR?
The EU GDPR aims to give you, as the data subject, the greatest possible control over your personal data. Personal data is any data that relates to you as a person, whether directly or indirectly. To enable you to effectively exercise control over your data, you have the following rights against us:
- the right of access under Art. 15 GDPR,
- the right to rectification under Art. 16 GDPR,
- the right to erasure under Art. 17 GDPR,
- the right to restriction of processing under Art. 18 GDPR, and
- the right to object under Art. 21 GDPR, as well as
- the right to lodge a complaint with a supervisory authority under Art. 77 GDPR, if you believe that we are processing your data unlawfully. You can find the supervisory authority responsible for our company here: https://www.bfdi.bund.de/DE/Home/home_node.html
The right to data portability under Art. 20 would only be relevant when visiting our website if you had the option of creating a profile (e.g., an applicant profile, membership profile, or similar) or entering corresponding information about yourself.
Last updated: July 22, 2026
Privacy Information Regarding the Collection of Personal Data in Connection with the Initiation and Processing of Lease Agreements
Dear prospective tenant, dear tenant,
In connection with the EU General Data Protection Regulation (EU GDPR), we, as the controller responsible for the processing of personal data, are subject to certain information obligations. In accordance with Art. 13 and Art. 14 of the EU GDPR, we therefore inform you of the following:
Controller
The controller responsible for this processing is:
Bürgermeister-Reuter-Stiftung
Marburger Str. 10
10789 Berlin,
Germany Phone: +49 30 491022-0
Email: info@brst.de
Website
On our homepage www.brst.de, you can find further information about our organization, details of the persons authorized to represent it, and additional contact options in our legal notice (Impressum). Website: https://www.brst.de/impressum
Contact Person / Data Protection Officer
Our Data Protection Officer is mb-datenschutz GmbH. dsb@brst.de
Legal Bases and Purposes for the Processing of Your Data:
- EU GDPR Art. 6(1)(a) permits us to process your data based on your consent for certain purposes, e.g., subscribing to our newsletter.
- EU GDPR Art. 6(1)(b) covers data processing that is necessary for the performance of a contract (lease agreement) as well as for pre-contractual measures.
- EU GDPR Art. 6(1)(c) permits us to process your data on the basis of a legal obligation, e.g., due to retention obligations under financial and tax law.
- Art. 6(1)(f) EU GDPR permits us to process your personal data where we or a third party have legitimate interests in such processing, provided your interests, fundamental rights, or fundamental freedoms do not override these interests, for example for:
- internal evaluations and marketing analyses,
- the prevention of damage to and/or liability of the organization through appropriate measures,
- the assertion, exercise, or defense of legal claims,
- video surveillance and the issuance of tenant ID cards in the exercise of our right as property owner (Hausrecht).
Duration of Data Storage:
General storage period:
Your personal data will be deleted once the purpose of the data processing no longer applies and the statutory retention periods have expired. Retention obligations for organizations are generally 6 or 10 years.
Special storage period:
- for video recordings: 72 hours
Where storage is based on your consent, we will delete your personal data if you withdraw your consent.
Processing of Your Applicant Data in the Reservation Portal home-in-berlin.de
For booking inquiries as well as for all process steps up to the conclusion of the digital lease agreement, we use the functionalities of the software company Immomio GmbH on our website www.home-in-berlin.de. Specific information on Immomio’s data protection practices can be found on Immomio’s website at: www.immomio.com/datenschutz-mieter/. This also includes information on the digital contract signature via DocuSign.
Immomio also provides us with convenient functionality and various options for transferring the security deposit and first month’s rent via the payment provider Mangopay.
For the booking portal to function, we must set two cookies (ARAffinity and ARAffinitySameSite). These cookies serve only to correctly assign your browser session and expire automatically at the end of the session.
Recipients of Your Personal Data:
Within our organization, only employees who require access to your personal data to perform their duties are granted such access, and only to the extent necessary.
Service providers we engage may receive your data for the purposes described above, provided they meet the confidentiality requirements under data protection law. These may, for example, include companies in the following categories: IT services, printing and mailing services, market research firms, call centers, logistics companies, and companies that handle data destruction on our behalf. These service providers are so-called data processors, who are contractually bound by special obligations in accordance with statutory requirements.
If, in our assessment, a creditworthiness check is required prior to concluding the lease agreement, data will be transmitted to corresponding credit reporting agencies in Germany.
If you have granted us a SEPA direct debit mandate for the collection of your rent, our bank will receive your data in order to carry out the direct debit collection from your account.
Your data will be disclosed to public authorities only where there is a legal obligation to do so.
Your data will only be disclosed to recipients outside the EU/EEA in cases where this is necessary for communication with you (e.g., if your service provider is based outside the European Union) or if you have named a bank outside the EU/EEA for the repayment of your security deposit.
Data We Receive About You From Others:
If a creditworthiness check is carried out prior to the start of the contract, we receive data about you from the relevant credit reporting agency.
If you booked your apartment through an online portal, we receive data about you from that portal.
Your Data Protection Rights:
You have:
- the right of access under Art. 15 EU GDPR,
- the right to rectification under Art. 16 EU GDPR,
- the right to erasure under Art. 17 EU GDPR,
- the right to restriction of processing under Art. 18 EU GDPR, and
- the right to object under Art. 21 EU GDPR.
In addition, you have the right to lodge a complaint with a data protection supervisory authority under Art. 77 EU GDPR.
Last updated: March 20, 2026