Autumn Flash Sale · 250€ off / month · Only in Berlin — ends soon
Legal
Last updated: 2 October 2026
This website is operated by The Base FOL Group GmbH. Handling the data of our website visitors responsibly and protecting it as well as possible is very important to us, and we make every effort to meet the requirements of the GDPR. Below we explain how we process your data on our website, using language that is as clear and transparent as possible so that you really understand what happens with your data.
2.1 Processing of personal data and other terms — Data protection applies to the processing of personal data. "Personal" means all data by which you can be personally identified, for example the IP address of the device (PC, laptop, smartphone, etc.) you are currently using. Such data is "processed" whenever something happens with it — for example when the IP address is transmitted by your browser to our provider and automatically stored there. This is processing (Art. 4 No. 2 GDPR) of personal data (Art. 4 No. 1 GDPR). These and further legal definitions can be found in Art. 4 GDPR.
2.2 Applicable rules and laws — GDPR, BDSG and TDDDG. The scope of data protection is governed by law: the GDPR (General Data Protection Regulation) as a European regulation and the BDSG (German Federal Data Protection Act) as national law. In addition, the TDDDG supplements the GDPR where the use of cookies is concerned.
2.3 The controller — Responsible for data processing on this website is the controller within the meaning of the GDPR: the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data. You can reach the controller at: The Base FOL Group GmbH, Pestalozzistraße 5-8, 13187 Berlin, datenschutz@jointhebase.co. The controller for guest data relating to stays at The Base Berlin ONE is theBASE Berlin ONE GmbH & Co. KG.
2.4 Data Protection Officer — We have appointed a data protection officer. You can reach them at: simply Legal GmbH, Sebastian Schenk, Burkarderstr. 36, 97082 Würzburg, dpo@dieter-datenschutz.de.
2.5 How data is generally processed on this website — As noted, some data (e.g. the IP address) is collected automatically and is mostly required for the technical provision of the website. Where we use personal data beyond this or collect other data, we inform you or ask for your consent. Other personal data you provide to us deliberately. Detailed information follows below.
2.6 Your rights — The GDPR gives you comprehensive rights, for example free information about the origin, recipients and purpose of your stored personal data. You can also request correction, blocking or deletion of this data, lodge a complaint with the competent supervisory authority, and withdraw a consent at any time. How these rights work in detail is set out in the final section of this policy.
2.7 Data protection — our view. For us, data protection is more than an obligation. Personal data has great value and a mindful approach to it should be a matter of course. You should be able to decide for yourself what happens with your data, when and by whom. We therefore comply with all statutory provisions, collect only the data we need, and treat it confidentially.
2.8 Disclosure and deletion — Data is only disclosed on a legal basis and only where unavoidable, in particular where a processor is involved and a data processing agreement under Art. 28 GDPR has been concluded. We delete your data once the purpose and legal basis for processing cease to apply and no other legal obligations prevent it (see also Art. 17 GDPR). For specific questions, please contact the controller.
2.9 Hosting — This website is hosted on our own servers. We store the personal data collected here on our own servers, including the automatically collected log files and all other data provided by visitors. The legal basis is Art. 6(1)(a), (b) and (f) GDPR and § 25(1) TDDDG, insofar as consent covers the storage of cookies or access to information on the visitor's device. We only process data necessary to fulfil our obligations.
2.10 Legal bases — Processing always requires a legal basis. Art. 6(1) GDPR provides: (a) consent for one or more specific purposes; (b) necessity for the performance of a contract with the data subject or pre-contractual steps at their request; (c) necessity for compliance with a legal obligation; (d) necessity to protect vital interests; (e) necessity for a task in the public interest or official authority; (f) necessity for the legitimate interests of the controller or a third party, unless overridden by the data subject's interests or fundamental rights, in particular for a child. The specific legal basis is named with each processing activity.
This section sets out, in detail, every data-processing activity on this website — server log files, cookies, analytics and third-party tools — together with the purpose, legal basis and storage period for each. This detailed part is currently maintained in the authoritative German version of our privacy policy. Please read it in full at /de/datenschutz. If you have any questions, contact datenschutz@jointhebase.co.
TheBase Coliving guest app. Guests and residents can use our app to open their room door, message our team (messages and support tickets) and receive notifications about their stay. For this we process your account details (name, email address, booking reference), the messages and tickets you send and your device token for push notifications. Legal basis: Art. 6(1)(b) GDPR (performance of the accommodation contract). Door credentials are transmitted via our property-management system (Mews) to the electronic locking system (Messerschmitt). The app and its database run on Amazon Web Services servers in Frankfurt, Germany; push notifications are delivered via your device manufacturer's push service (Apple or Google). Data is deleted once it is no longer needed for your stay and the handling of your request, unless statutory retention obligations apply.
Finally, we would like to inform you in detail about your rights and how you will be notified of changes to data-protection requirements.
4.1 Your rights in detail
4.1.1 Right of access (Art. 15 GDPR) — You can request confirmation of whether personal data concerning you is being processed and, if so, further information about how. A detailed list is in Art. 15(1)(a)–(h) GDPR.
4.1.2 Right to rectification (Art. 16 GDPR) — This covers the correction of inaccurate data and the completion of incomplete personal data.
4.1.3 Right to erasure (Art. 17 GDPR) — This "right to be forgotten" entitles you, under certain conditions, to request erasure of your personal data, generally where the purpose has ceased, a consent has been withdrawn, or processing had no legal basis. A detailed list of grounds is in Art. 17(1)(a)–(f) GDPR. It also corresponds to the controller's obligation under Art. 17(2) GDPR to take reasonable measures towards general erasure.
4.1.4 Right to restriction of processing (Art. 18 GDPR) — Subject to the conditions of Art. 18(1)(a)–(d) GDPR.
4.1.5 Right to data portability (Art. 20 GDPR) — The right to receive your own data in a common format and have it transmitted to another controller, for data processed on the basis of consent or a contract under Art. 20(1)(a) and (b), and only where technically feasible.
4.1.6 Right to object (Art. 21 GDPR) — In principle you can object to the processing of your personal data, in particular where your interest outweighs the controller's legitimate interest, and where processing relates to direct marketing and/or profiling.
4.1.7 Automated individual decisions (Art. 22 GDPR) — In principle you have the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects concerning you or similarly significantly affects you, subject to the restrictions and additions in Art. 22(2) and (4) GDPR.
4.1.8 Further rights — The GDPR includes rights to have third parties informed about how you have exercised rights under Art. 16, 17, 18 GDPR, insofar as feasible with reasonable effort. We also remind you of your right to withdraw consent under Art. 7(3) GDPR (without affecting the lawfulness of prior processing) and of your rights under §§ 32 et seq. BDSG, which are largely identical in content.
4.1.9 Right to lodge a complaint (Art. 77 GDPR) — You have the right to lodge a complaint with a data-protection supervisory authority if you believe the processing of your personal data infringes the GDPR.
The current version of this privacy policy is dated 2 October 2026. From time to time it is necessary to adapt this policy to respond to factual and legal changes. We therefore reserve the right to amend it at any time, will publish the amended version in the same place, and recommend that you read it regularly.