Data privacy statementInformation according to the General Data Protection Regulation (DS-GVO)
We are very pleased about your interest in our company. Data privacy is particularly important to the Hotel Alpenhof Fischbacher GmbH.
The use of the Hotel Alpenhof Fischbacher GmbH websites is generally possible without giving any personal data. However, if an affected person wants to use our company's special services via our website, processing personal data may be necessary. If the processing of personal data is necessary and there is no legal basis for this kind of processing, we generally obtain the consent of the person concerned.
The processing of personal data, such as the name, address, email address or telephone number of the person concerned, is always carried out in accordance with the basic data protection regulation and in compliance with the country-specific data privacy policy applicable to the Hotel Alpenhof Fischbacher GmbH.
By means of this data privacy statement, our company would like to inform the public about the type, scope and purpose of the personal data collected, used and processed by us. Furthermore, the persons concerned are informed about their rights by means of this data privacy statement.
As the party responsible for processing personal data, the Hotel Alpenhof Fischbacher GmbH has implemented numerous technical and organisational measures to ensure that the personal data processed via this website is protected as completely as possible. Nevertheless, Internet-based data transmissions can always have security gaps, therefore absolute protection cannot be guaranteed. For this reason, each person concerned is free to provide us with personal data in alternative ways, for example, by telephone.
1. Definitions
The data privacy statement of the Hotel Alpenhof Fischbacher GmbH is based on the terms used by the European body issuing directives and regulations when issuing the General Data Protection Regulation (DS-GVO). Our data privacy statement should be easy to read and understand for the public as well as for our customers and business partners. To ensure this, we would like to explain the terms used in advance.
We use the following terms, among others, in this data privacy statement:
a) Personal data
Personal data is all information relating to an identified or identifiable natural person (hereinafter referred to as the “person concerned”). An identifiable person is a natural person who can be identified directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier or to one or more specific characteristics that are expressions of the physical, physiological, genetic, psychological, economic, cultural or social identity of that natural person.
b) Person concerned
The person concerned is any identified or identifiable natural person whose personal data is processed by the responsible party.
c) Processing
Processing is any procedure or series of procedures involving personal data, carried out with or without the help of automated methods, such as collection, capture, organisation, arrangement, storage, adaptation or alteration, selection, retrieval, use, disclosure by transmission, dissemination or any other form of provision, comparison or linkage, restriction, deletion or destruction.
d) Processing restriction
Processing restriction is the marking of stored personal data with a view to restricting its future processing.
e) Profiling
Profiling is any kind of automated processing of personal data, which consists of using this personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects of the natural person’s work performance, economic situation, health, personal preferences, interests, reliability, behaviour, place of residence or relocation.
f) Pseudonymisation
Pseudonymisation is the processing of personal data in such a way that the personal data can no longer be attributed to a specific person concerned without further information, provided that such additional information is stored separately and is subject to technical and organisational measures that ensure that the personal data is not attributed to an identified or identifiable natural person.
g) Responsible party or party responsible for processing
The responsible party or party responsible for processing is the natural or legal person, authority, institution or other body, which, alone or together with others, decides on the purposes and means of processing personal data. If the purposes and means of this processing are prescribed by EU law or by the law of the member states, the responsible party may, in accordance with EU law or the law of the member states, stipulate the specific criteria for its designation.
h) Assigned processor
An assigned processor is a natural or legal person, authority, institution or other body that processes personal data on behalf of the responsible party.
i) Recipient
A recipient is a natural or legal person, authority, institution or other body to which personal data is disclosed, regardless of whether or not it is a third party. However, authorities that may receive personal data in the context of a specific investigation mandate according to EU law or the law of a member state law shall not be considered to be recipients.
j) Third party
A third party is a natural or legal person, authority, institution or other body other than the person concerned, responsible party, assigned processor and those authorised to process personal data under the direct responsibility of the responsible party or assigned processor.
k) Consent
Consent is any declaration or other unambiguous and informed expression of intent given voluntarily by the person concerned in the form of a declaration or any other clear, unequivocal action by the person concerned that he or she agrees to the processing of personal data concerning him or her.
2. Name & address of the party responsible for processing
The responsible party within the meaning of the General Data Protection Regulation, other data protection laws in force in the member states of the European Union and other provisions dealing with data protection is the:
Hotel Alpenhof Fischbacher GmbH:
Family Fischbacher
Hotel Alpenhof
Flachauer Straße 98
5542 Flachau
Austria
Phone: +43 6457 2205
Fax: +43 6457 2205-18
E-Mail: hotel@alpenhof.info
Website: www.alpenhof.info
Hotel Mein Matteo
Flachauer Straße 353
5542 Flachau
Austria
Phone: +43 6457 2205-800
Fax: +43 6457 2205-802
E-Mail: info@meinmatteo.at
Website: www.meinmatteo.at
Restaurant Paularei
Flachauer Straße 353
5542 Flachau
Austria
Phone: +43 6457 2205-804
Fax: +43 6457 2205-802
E-Mail: info@paularei.at
Website: www.paularei.at
3. Cookies
4. Website analysis
This website uses Google Analytics, a web analytics service provided by Google Inc. ("Google"). Google Analytics uses "cookies", which are text files placed on your computer to help the website analyse how visitors use the site. The information generated by the cookie about your use of the website will normally be transmitted to and stored by Google on servers in the USA. If IP anonymisation is activated on this website, your IP address will be truncated beforehand within a member state of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the United States and truncated there. Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity for website operators and providing other services relating to website activity and internet usage. Google will not associate your IP address transferred within the framework of Google Analytics with any other data held by Google. You may refuse the use of cookies by selecting the appropriate settings on your browser, however, please note that if you do this you may not be able to use the full functionality of this website. Furthermore, you can prevent Google's collection and use of data generated by the cookie and related to your use of the website (including your IP address) by downloading and installing the browser plug-in or alternatively clicking on the following link to opt out of cookies: https://tools.google.com/dlpage/gaoptout?hl=de-DE.
You can prevent Google Analytics from collecting your user data on this website only by clicking on the following link. An opt out cookie is set that prevents any future acquisition of your data when visiting our website: Deactivate Google Analytics.
If you delete the cookies in this browser, you have to set the opt out cookie again.
You will find more information on Google Analytics provisions and privacy policy at https://www.google.com/analytics/terms/de.html.
5. ADDITIVE Online Marketing
Beside our website we do also operate optimized landingpages. To process your request, reservation, order, activation, registration or the transmission of other contact forms on our website as well as to save and store your data we use cloud services, CRM systems and software provided by ADDITIVE s.n.c., 39011 Lana (BZ), Italy (“ADDITIVE”). Through the use of these services and systems your data will be processed and stored, at least in part, also outside of the EU or the EEC. The adequate level of data protection is based on an adequacy decision taken by the European Commission (“Privacy Shield”) or on data processing agreements with the respective company. Our landingpages use Google Analytics, a web analytics service provided by Google Inc. (“Google”). For this functions cookies are used to analyse the use of the website. The information generated through the use of these cookies is transmitted to and stored by Google on its servers. If you do not wish to accept these cookies you can change the settings of your browser in order to prevent the saving of cookies or to get a notification anytime cookies are used, so you will be able to allow cookies in individual cases. Your IP address is collected but immediately anonymised (for example by deleting the last 8 bits). As a result the geolocation data is less accurate. The connection to the web analytics service provider Google is based on an adequacy decision taken by the European Commission (“Privacy Shield” in case of the USA). You can prevent the saving of cookies by changing the respective settings of your browser software. You can also prevent data collection connected to your use of our online services through cookies and the processing of this data by Google, by installing the browser-plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=en. Our landingpages also use functions provided by ADDITIVE for the multi-channel monitoring of the use of our websites as well as marketing and distribution strategies like landingpages, newsletter and social media presence. ADDITIVE has an insight into data gathered through Google Analytics. This data will be used only to analyse the use of our websites and to evaluate our marketing and distribution strategies. The data processing takes place in accordance with the requirements of art. 6 para. 1 lit f (legitimate interests) of the GDPR. Our objective in accordance with the GDPR (legitimate interests) is the improvement of our products and services and our web presence through the analysis of the use of our website as well as marketing and distribution strategies. Our landingpages also use remarketing functions provided by Google Inc. (“Google”) and by Facebook Inc. (“Facebook”). Therefore, Facebook and Google will know that you have visited our website. This way visitors of our website and of our landingpages will find ads adapted to their interests on Google’s advertising platforms and on the social media platforms Facebook and Instagram. The data processing takes place in accordance with the requirements of art. 6 para. 1 lit a (consent) of the GDPR. When you visit our landingpages a banner will inform you about the use of cookies for remarketing functions. If you continue using the website or click on the respective button you consent to the use of cookies. You can deny your consent anytime, by visiting the page containing the cookie information and denying the use in the banner that will be displayed.
6. Collecting general data and information
The website of the Hotel Alpenhof Fischbacher GmbH collects a range of general data and information each time a person concerned or automated system accesses the website. This general data and information is stored in the server’s log files. The following may be recorded: (1) the browser type and version used; (2) the operating system used by the accessing system; (3) the website from which an accessing system reaches our website (so-called “referrer”); (4) the sub-websites visited via an accessing system on our website; (5) the date and time of accessing the website; (6) an Internet protocol address (IP address); (7) the Internet service provider of the accessing system; (8) other similar data and information that is used to prevent threats in the event of attacks on our information technology systems.
When using this general data and information, the Hotel Alpenhof Fischbacher GmbH does not draw any conclusions about the person concerned. This information is in fact required in order to (1) deliver the content of our website correctly, (2) to optimise the content of our website and advertising, (3) to ensure the long-term functionality of our information technology systems and the technology of our website, and (4) to provide law enforcement authorities with the information necessary for prosecution in the event of a cyber attack. This anonymously collected data and information is therefore evaluated statistically by the Hotel Alpenhof Fischbacher GmbH on the one hand and then also with the aim of increasing data privacy and data security at our company in order to ultimately ensure an optimum level of protection for the personal data processed by us. The anonymous data of the server log files is stored separately from all personal data provided by a person concerned.
7. Subscribing to our newsletter
The Hotel Alpenhof Fischbacher GmbH website gives users the option of subscribing to our company newsletter. The input mask used for this purpose determines which personal data is transmitted to the party responsible for processing when the newsletter is ordered.
The Hotel Alpenhof Fischbacher GmbH informs its customers and business partners about the company’s offers at regular intervals by means of a newsletter. Our company newsletter can only be received by the person concerned if (1) the person concerned has a valid email address and (2) the person concerned has registered for the newsletter. For legal reasons, a confirmation email is sent to the email address entered by the person concerned for the first time for sending the newsletter in the double opt-in procedure. This confirmation email serves to check whether the owner of the email address has authorised the receipt of the newsletter as the person concerned.
When registering for the newsletter, we also store the IP address assigned by the Internet Service Provider (ISP) of the computer system used by the person concerned at the time of registration as well as the date and time of registration. The collection of this data is necessary in order to be able to trace the (possible) misuse of the email address of a person concerned at a later point in time and therefore serves as legal protection for the party responsible for processing.
The personal data collected when registering for the newsletter will be used exclusively for sending our newsletter. Furthermore, subscribers to the newsletter may be informed by email in the event of changes to the newsletter offer or changes in the technical conditions, if this is necessary for the operation of the newsletter service or for registration. The personal data collected in the context of the newsletter service will not be passed on to third parties. The subscription to our newsletter can be cancelled by the person concerned at any time. The consent to the storage of personal data, which the person concerned has given us for sending the newsletter, can be revoked at any time. You will find a corresponding link in every newsletter for the purpose of revoking your consent. It is also possible to unsubscribe directly from the newsletter at any time on the website of the party responsible for processing or to inform the party responsible for processing in any other way.
8. Newsletter tracking
The Hotel Alpenhof Fischbacher GmbH newsletter contains so-called “tracking pixels”. A tracking pixel is a miniature graphic embedded in emails sent in HTML format to enable log file recording and analysis. This allows a statistical evaluation of the success or failure of online marketing campaigns to be carried out. Using the embedded tracking pixel, the Hotel Alpenhof Fischbacher GmbH can recognise whether and when an email was opened by an person concerned and which links in the email were opened by the person concerned.
Personal data collected using tracking pixels contained in the newsletters are stored and evaluated by the party responsible for processing in order to optimise newsletter dispatch and to adapt the content of future newsletters even better to the interests of the person concerned. This personal data will not be passed on the third parties. Persons concerned are entitled to revoke the respective separate declaration of consent given via the double opt-in procedure at any time. This personal data will be deleted by the party responsible for processing after revocation. The Hotel Alpenhof Fischbacher GmbH automatically interprets cancelling the newsletter as revocation.
9. Contact options on the website
Due to legal regulations, the Hotel Alpenhof Fischbacher GmbH website contains information that enables fast electronic contact with our company and direct communication with us, which also includes a general address for so-called “electronic post” (email address). If a person concerned contacts the party responsible for processing via email or a contact form, the personal data transmitted by the person concerned will be stored automatically. Personal data voluntarily provided by a person concerned to the party responsible for processing will be stored for the purpose of processing or contacting the person concerned. This personal data is not passed on to third parties.
10. Routine deletion & blocking of personal data
The party responsible for processing shall only process and store the personal data of the person concerned for the time required to achieve the storage purpose or to the extent provided for by the European body issuing directives and regulations or another legislator in laws or regulations to which the party responsible for processing is subject.
If the storage purpose ceases to apply or if a storage period prescribed by the European body issuing directives and regulations or another competent legislator expires, the personal data is routinely blocked or deleted in accordance with the statutory provisions.
11. Rights of the person concerned
a) Right to confirmation
Every person concerned has the right granted by the European body issuing directives and regulations to ask the party responsible for processing to confirm whether personal data concerning him or her is being processed. If a person concerned wants to use this right of confirmation, he or she can contact our data protection officer at any time.
b) Right to information
Every person concerned with the processing of personal data has the right granted by the European body issuing directives and regulations to obtain, at any time and free of charge, information from the party responsible for processing on the personal data relating to him or her stored and a copy of that information. Furthermore, the European body issuing directives and regulations has granted the person concerned the following information:
c) Right to rectification
Any person concerned with the processing of personal data has the right granted by the European body issuing directives and regulations to request the immediate correction of inaccurate personal data concerning him or her. Furthermore, taking into account the purposes of the processing, the person concerned has the right to request the completion of incomplete personal data, including by means of a supplementary statement. If a person concerned wants to use this right to rectification, he or she can contact our data protection officer at any time.
d) Right to deletion (right to be forgotten)
Any person concerned with the processing of personal data has the right granted by the European body issuing directives and regulations to ask the responsible party to immediately delete any personal data concerning him or her, provided that one of the following reasons applies and insofar as the processing is not necessary:
If the personal data has been released by the Hotel Alpenhof Fischbacher GmbH and our company is responsible for deletion of the personal data as the responsible party according to Article 17 Para. 1 DS-GMO, the Hotel Alpenhof Fischbacher GmbH shall take appropriate measures, including technical measures, taking into account available technology and implementation costs, to inform other parties responsible for data processing who process the published personal data, that the person concerned has requested the deletion of all links to this personal data or of copies or replications of this personal data from those other responsible parties, insofar as processing is not necessary. The Hotel Alpenhof Fischbacher GmbH data protection officer or another employee will take the necessary steps in individual cases.
e) Right to restriction of processing
Any person concerned with the processing of personal data has the right granted by the European body issuing directives and regulations to request that the responsible party restricts the processing if one of the following conditions is met:
f) Right to data transferability
Any person concerned with the processing of personal data has the right granted by the European body issuing directives and regulations to receive personal data relating to him or her, which has been provided by the responsible party, in a structured, common and machine-readable format. They also have the right to transmit this data to another responsible party without any obstruction by the responsible party, to whom the personal data has been provided, provided that the processing is based on the consent according to Article 6 Para. 1 Letter a DS-GMO or Article 9 Para. 2 Letter a DS-GMO or on a contract according to Article 6 Para. 1 Letter b DS-GMO and processing is carried out by means of automated procedures, except where processing is necessary for the performance of a task in the public interest or in the exercise of official authority assigned to the responsible party.
Furthermore, in exercising his or her right to data transferability according to Article 20 Para. 1 DS-GMO, the person concerned has the right to effect that the personal data be transferred directly by a responsible party to another responsible party, provided this is technically feasible and provided that the rights and freedoms of other persons are not affected.
To assert the right to data transferability, the person concerned may contact the data protection officer appointed by the Hotel Alpenhof Fischbacher GmbH or another employee at any time.
g) Right to objection
Any person concerned with the processing of personal data shall has right granted by the European body issuing directives and regulations to enter an objection at any time to the processing of personal data concerning them according to Article 6 Para 1 Letters e or f DS-GMO for reasons arising from their particular situation. This also applies to profiling based on these provisions.
In the event of revocation, the Hotel Alpenhof Fischbacher GmbH will no longer process the personal data unless we can prove compelling legitimate reasons for processing, which outweigh the interests, rights and freedoms of the person concerned, or the processing serves to assert, exercise or defend legal claims.
If the Hotel Alpenhof Fischbacher GmbH processes personal data for direct advertising purposes, the person concerned has the right to object at any time to the processing of personal data for the purpose of this kind of advertising. This also applies to profiling if it is in connection with this kind of direct advertising. If the person concerned objects to the Hotel Alpenhof Fischbacher GmbH processing for direct advertising purposes, the Hotel Alpenhof Fischbacher GmbH will no longer process the personal data for these purposes.
In addition, the person concerned has the right to enter an objection against the processing of personal data concerning him or her carried out by the Hotel Alpenhof Fischbacher GmbH, which is done for academic or historical research purposes or for statistical purposes according to Article 89 Para. 1 DS-GMO for reasons arising from their particular situation, unless this processing is necessary to fulfil a task in the public interest.
To exercise the right to objection, the person concerned may contact the Hotel Alpenhof Fischbacher GmbH data protection officer or another employee directly. The person concerned shall also be free to exercise his or her right of objection in relation to the use of information society services by means of automated procedures for which technical specifications are used, regardless of Directive 2002/58/EC.
h) Automated decisions in individual cases, including profiling
Every person concerned with the processing of personal data has the right granted by the European body issuing directives and regulations not to be subject to a decision based exclusively on automated processing, including profiling, which has legal effect against him or her or significantly affects him or her in a similar manner, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the person concerned and the responsible party, or (2) is admissible under the provisions of EU law or those of the member states to which the responsible party is subject and these provisions contain appropriate measures to safeguard the rights, freedoms and legitimate interests of the person concerned or (3) is made with the express consent of the person concerned.
If the decision (1) is required for the conclusion or performance of a contract between the person concerned and the responsible party or (2) is made with the express consent of the person concerned, the Hotel Alpenhof Fischbacher GmbH shall take appropriate measures to safeguard the rights, freedoms and legitimate interests of the person concerned, including at least the right to obtain the intervention of a person by the person responsible, to state his or her own position and to challenge the decision.
If the person concerned wishes to assert his or her right relating to automated decisions, he or she may contact our data protection officer at any time.
i) Right to withdraw consent relating to data privacy
Every person concerned with the processing of personal data has the right granted by the European body issuing directives and regulations to withdraw consent given to process personal data at any time.
If the person concerned wishes to assert his or her right to revoke his or her consent, he or she may contact our data protection officer at any time.
12. Data privacy for applications & in the application process
The party responsible for processing collects and processes the personal data of applicants for the purpose of processing the application procedure. Processing may also be carried out electronically. This applies, in particular, if an applicant sends corresponding application documents to the party responsible for processing electronically, for example, by email or via an online form on the website. If the party responsible for processing enters into an employment contract with an applicant, the data transmitted will be stored for the purpose of processing the employment contract in compliance with the statutory provisions. If the party responsible for processing does not enter into an employment contract with the applicant, the application documents shall be automatically deleted two months after notification of the refusal decision, provided that deletion does not obstruct other legitimate interests of the party responsible for processing. Other legitimate interest in this sense is, for example, a burden of proof in proceedings under the German General Act on Equal Treatment (AGG).
13. Legal basis for processing
Article 6 I lit. a DS-GVO serves our company as a legal basis for processing operations for which we obtain consent for a specific processing purpose. If processing personal data is necessary for the performance of a contract to which the person concerned is a party, as is the case, for example, with processing operations necessary for the delivery of goods or the provision of other services or consideration, processing is based on Article 6 I lit. b DS-GMO. The same applies to processing operations that are necessary to carry out precontractual measures, for example, in cases of enquiries about our products or services. If our company is subject to a legal obligation that requires the processing of personal data, for example, to fulfil tax obligations, processing is based on Article. 6 I lit. c DS-GMO. In rare cases, processing personal data may become necessary to protect the vital interests of the person concerned or another natural person. This would be the case, for example, if a visitor was injured at our company and his name, age, health insurance data or other vital information had to be passed on to a doctor, a hospital or other third parties. Processing would then be based on Article 6 I lit. d DS-GVO. Ultimately, processing operations could be based on Article 6 I lit. d DS-GVO. Processing operations that are not covered by any of the aforementioned legal bases are based on this legal basis if processing is necessary to safeguard a legitimate interest of our company or a third party, provided that the interests, fundamental rights and freedoms of the person concerned do not prevail. We are entitled to these kind of processing procedures in particular because they have been specifically mentioned by the European legislator. It advocates the view that a legitimate interest could be assumed if the person concerned is a customer of the responsible party (Recital 47, Sentence 2 DS-GMO).
14. Legitimate interests to processing pursued by the responsible party or a third party
If processing personal data is based on Article 6 I lit. f DS-GMO, it is in our legitimate interest to conduct our business activity for the good of all our employees and our shareholders.
15. Duration for which personal data is stored
The criterion for the duration of personal data storage is the respective legal retention period. After the expiry of this period, the corresponding data will be routinely deleted, provided that it is no longer necessary for the fulfilment or initiation of the contract.
16. Legal or contractual provisions for the provision of personal data; necessity for the conclusion of the contract; obligation of the person concerned to provide the personal data; possible consequences of failure to provide it
We inform you that the provision of personal data is partly required by law (e.g. tax regulations) or may also result from contractual regulations (e.g. information on the contractual partner). From time to time, it may be necessary for a contract to be concluded that a person concerned provides us with personal data that must subsequently be processed by us. For example, the person concerned shall undertake to provide us with personal data if our company enters into a contract with him or her. The only consequence of not providing personal information is that the contract will not be able to be concluded with the person concerned. Prior to the provision of personal data by the person concerned, the person concerned must contact our data protection officer. Our data protection officer will inform the person concerned on a case-by-case basis whether the provision of personal data is required by law or contract or necessary for the conclusion of the contract, whether there is an obligation to provide the personal data and what consequences the failure to provide the personal data would have.
17. Existence of automated decision-making
As a responsible company, we abstain from automatic decision-making or profiling.
18. Competent authority
Österreichische Datenschutzbehörde (Austrian Data Protection Authority)
Wickenburggasse 8
1080 Vienna
Austria
dsb@dsb.gv.at
This Privacy Policy - apart from the cookie information - has partly been provided by the privacy policy generator of the DGD Deutsche Gesellschaft für Datenschutz GmbH of the external data protection officer Freising in cooperation with the privacy lawyer Christian Solmecke.
The use of the Hotel Alpenhof Fischbacher GmbH websites is generally possible without giving any personal data. However, if an affected person wants to use our company's special services via our website, processing personal data may be necessary. If the processing of personal data is necessary and there is no legal basis for this kind of processing, we generally obtain the consent of the person concerned.
The processing of personal data, such as the name, address, email address or telephone number of the person concerned, is always carried out in accordance with the basic data protection regulation and in compliance with the country-specific data privacy policy applicable to the Hotel Alpenhof Fischbacher GmbH.
By means of this data privacy statement, our company would like to inform the public about the type, scope and purpose of the personal data collected, used and processed by us. Furthermore, the persons concerned are informed about their rights by means of this data privacy statement.
As the party responsible for processing personal data, the Hotel Alpenhof Fischbacher GmbH has implemented numerous technical and organisational measures to ensure that the personal data processed via this website is protected as completely as possible. Nevertheless, Internet-based data transmissions can always have security gaps, therefore absolute protection cannot be guaranteed. For this reason, each person concerned is free to provide us with personal data in alternative ways, for example, by telephone.
1. Definitions
The data privacy statement of the Hotel Alpenhof Fischbacher GmbH is based on the terms used by the European body issuing directives and regulations when issuing the General Data Protection Regulation (DS-GVO). Our data privacy statement should be easy to read and understand for the public as well as for our customers and business partners. To ensure this, we would like to explain the terms used in advance.
We use the following terms, among others, in this data privacy statement:
a) Personal data
Personal data is all information relating to an identified or identifiable natural person (hereinafter referred to as the “person concerned”). An identifiable person is a natural person who can be identified directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier or to one or more specific characteristics that are expressions of the physical, physiological, genetic, psychological, economic, cultural or social identity of that natural person.
b) Person concerned
The person concerned is any identified or identifiable natural person whose personal data is processed by the responsible party.
c) Processing
Processing is any procedure or series of procedures involving personal data, carried out with or without the help of automated methods, such as collection, capture, organisation, arrangement, storage, adaptation or alteration, selection, retrieval, use, disclosure by transmission, dissemination or any other form of provision, comparison or linkage, restriction, deletion or destruction.
d) Processing restriction
Processing restriction is the marking of stored personal data with a view to restricting its future processing.
e) Profiling
Profiling is any kind of automated processing of personal data, which consists of using this personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects of the natural person’s work performance, economic situation, health, personal preferences, interests, reliability, behaviour, place of residence or relocation.
f) Pseudonymisation
Pseudonymisation is the processing of personal data in such a way that the personal data can no longer be attributed to a specific person concerned without further information, provided that such additional information is stored separately and is subject to technical and organisational measures that ensure that the personal data is not attributed to an identified or identifiable natural person.
g) Responsible party or party responsible for processing
The responsible party or party responsible for processing is the natural or legal person, authority, institution or other body, which, alone or together with others, decides on the purposes and means of processing personal data. If the purposes and means of this processing are prescribed by EU law or by the law of the member states, the responsible party may, in accordance with EU law or the law of the member states, stipulate the specific criteria for its designation.
h) Assigned processor
An assigned processor is a natural or legal person, authority, institution or other body that processes personal data on behalf of the responsible party.
i) Recipient
A recipient is a natural or legal person, authority, institution or other body to which personal data is disclosed, regardless of whether or not it is a third party. However, authorities that may receive personal data in the context of a specific investigation mandate according to EU law or the law of a member state law shall not be considered to be recipients.
j) Third party
A third party is a natural or legal person, authority, institution or other body other than the person concerned, responsible party, assigned processor and those authorised to process personal data under the direct responsibility of the responsible party or assigned processor.
k) Consent
Consent is any declaration or other unambiguous and informed expression of intent given voluntarily by the person concerned in the form of a declaration or any other clear, unequivocal action by the person concerned that he or she agrees to the processing of personal data concerning him or her.
2. Name & address of the party responsible for processing
The responsible party within the meaning of the General Data Protection Regulation, other data protection laws in force in the member states of the European Union and other provisions dealing with data protection is the:
Hotel Alpenhof Fischbacher GmbH:
Family Fischbacher
Hotel Alpenhof
Flachauer Straße 98
5542 Flachau
Austria
Phone: +43 6457 2205
Fax: +43 6457 2205-18
E-Mail: hotel@alpenhof.info
Website: www.alpenhof.info
Hotel Mein Matteo
Flachauer Straße 353
5542 Flachau
Austria
Phone: +43 6457 2205-800
Fax: +43 6457 2205-802
E-Mail: info@meinmatteo.at
Website: www.meinmatteo.at
Restaurant Paularei
Flachauer Straße 353
5542 Flachau
Austria
Phone: +43 6457 2205-804
Fax: +43 6457 2205-802
E-Mail: info@paularei.at
Website: www.paularei.at
3. Cookies
4. Website analysis
This website uses Google Analytics, a web analytics service provided by Google Inc. ("Google"). Google Analytics uses "cookies", which are text files placed on your computer to help the website analyse how visitors use the site. The information generated by the cookie about your use of the website will normally be transmitted to and stored by Google on servers in the USA. If IP anonymisation is activated on this website, your IP address will be truncated beforehand within a member state of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the United States and truncated there. Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity for website operators and providing other services relating to website activity and internet usage. Google will not associate your IP address transferred within the framework of Google Analytics with any other data held by Google. You may refuse the use of cookies by selecting the appropriate settings on your browser, however, please note that if you do this you may not be able to use the full functionality of this website. Furthermore, you can prevent Google's collection and use of data generated by the cookie and related to your use of the website (including your IP address) by downloading and installing the browser plug-in or alternatively clicking on the following link to opt out of cookies: https://tools.google.com/dlpage/gaoptout?hl=de-DE.
You can prevent Google Analytics from collecting your user data on this website only by clicking on the following link. An opt out cookie is set that prevents any future acquisition of your data when visiting our website: Deactivate Google Analytics.
If you delete the cookies in this browser, you have to set the opt out cookie again.
You will find more information on Google Analytics provisions and privacy policy at https://www.google.com/analytics/terms/de.html.
5. ADDITIVE Online Marketing
Beside our website we do also operate optimized landingpages. To process your request, reservation, order, activation, registration or the transmission of other contact forms on our website as well as to save and store your data we use cloud services, CRM systems and software provided by ADDITIVE s.n.c., 39011 Lana (BZ), Italy (“ADDITIVE”). Through the use of these services and systems your data will be processed and stored, at least in part, also outside of the EU or the EEC. The adequate level of data protection is based on an adequacy decision taken by the European Commission (“Privacy Shield”) or on data processing agreements with the respective company. Our landingpages use Google Analytics, a web analytics service provided by Google Inc. (“Google”). For this functions cookies are used to analyse the use of the website. The information generated through the use of these cookies is transmitted to and stored by Google on its servers. If you do not wish to accept these cookies you can change the settings of your browser in order to prevent the saving of cookies or to get a notification anytime cookies are used, so you will be able to allow cookies in individual cases. Your IP address is collected but immediately anonymised (for example by deleting the last 8 bits). As a result the geolocation data is less accurate. The connection to the web analytics service provider Google is based on an adequacy decision taken by the European Commission (“Privacy Shield” in case of the USA). You can prevent the saving of cookies by changing the respective settings of your browser software. You can also prevent data collection connected to your use of our online services through cookies and the processing of this data by Google, by installing the browser-plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=en. Our landingpages also use functions provided by ADDITIVE for the multi-channel monitoring of the use of our websites as well as marketing and distribution strategies like landingpages, newsletter and social media presence. ADDITIVE has an insight into data gathered through Google Analytics. This data will be used only to analyse the use of our websites and to evaluate our marketing and distribution strategies. The data processing takes place in accordance with the requirements of art. 6 para. 1 lit f (legitimate interests) of the GDPR. Our objective in accordance with the GDPR (legitimate interests) is the improvement of our products and services and our web presence through the analysis of the use of our website as well as marketing and distribution strategies. Our landingpages also use remarketing functions provided by Google Inc. (“Google”) and by Facebook Inc. (“Facebook”). Therefore, Facebook and Google will know that you have visited our website. This way visitors of our website and of our landingpages will find ads adapted to their interests on Google’s advertising platforms and on the social media platforms Facebook and Instagram. The data processing takes place in accordance with the requirements of art. 6 para. 1 lit a (consent) of the GDPR. When you visit our landingpages a banner will inform you about the use of cookies for remarketing functions. If you continue using the website or click on the respective button you consent to the use of cookies. You can deny your consent anytime, by visiting the page containing the cookie information and denying the use in the banner that will be displayed.
6. Collecting general data and information
The website of the Hotel Alpenhof Fischbacher GmbH collects a range of general data and information each time a person concerned or automated system accesses the website. This general data and information is stored in the server’s log files. The following may be recorded: (1) the browser type and version used; (2) the operating system used by the accessing system; (3) the website from which an accessing system reaches our website (so-called “referrer”); (4) the sub-websites visited via an accessing system on our website; (5) the date and time of accessing the website; (6) an Internet protocol address (IP address); (7) the Internet service provider of the accessing system; (8) other similar data and information that is used to prevent threats in the event of attacks on our information technology systems.
When using this general data and information, the Hotel Alpenhof Fischbacher GmbH does not draw any conclusions about the person concerned. This information is in fact required in order to (1) deliver the content of our website correctly, (2) to optimise the content of our website and advertising, (3) to ensure the long-term functionality of our information technology systems and the technology of our website, and (4) to provide law enforcement authorities with the information necessary for prosecution in the event of a cyber attack. This anonymously collected data and information is therefore evaluated statistically by the Hotel Alpenhof Fischbacher GmbH on the one hand and then also with the aim of increasing data privacy and data security at our company in order to ultimately ensure an optimum level of protection for the personal data processed by us. The anonymous data of the server log files is stored separately from all personal data provided by a person concerned.
7. Subscribing to our newsletter
The Hotel Alpenhof Fischbacher GmbH website gives users the option of subscribing to our company newsletter. The input mask used for this purpose determines which personal data is transmitted to the party responsible for processing when the newsletter is ordered.
The Hotel Alpenhof Fischbacher GmbH informs its customers and business partners about the company’s offers at regular intervals by means of a newsletter. Our company newsletter can only be received by the person concerned if (1) the person concerned has a valid email address and (2) the person concerned has registered for the newsletter. For legal reasons, a confirmation email is sent to the email address entered by the person concerned for the first time for sending the newsletter in the double opt-in procedure. This confirmation email serves to check whether the owner of the email address has authorised the receipt of the newsletter as the person concerned.
When registering for the newsletter, we also store the IP address assigned by the Internet Service Provider (ISP) of the computer system used by the person concerned at the time of registration as well as the date and time of registration. The collection of this data is necessary in order to be able to trace the (possible) misuse of the email address of a person concerned at a later point in time and therefore serves as legal protection for the party responsible for processing.
The personal data collected when registering for the newsletter will be used exclusively for sending our newsletter. Furthermore, subscribers to the newsletter may be informed by email in the event of changes to the newsletter offer or changes in the technical conditions, if this is necessary for the operation of the newsletter service or for registration. The personal data collected in the context of the newsletter service will not be passed on to third parties. The subscription to our newsletter can be cancelled by the person concerned at any time. The consent to the storage of personal data, which the person concerned has given us for sending the newsletter, can be revoked at any time. You will find a corresponding link in every newsletter for the purpose of revoking your consent. It is also possible to unsubscribe directly from the newsletter at any time on the website of the party responsible for processing or to inform the party responsible for processing in any other way.
8. Newsletter tracking
The Hotel Alpenhof Fischbacher GmbH newsletter contains so-called “tracking pixels”. A tracking pixel is a miniature graphic embedded in emails sent in HTML format to enable log file recording and analysis. This allows a statistical evaluation of the success or failure of online marketing campaigns to be carried out. Using the embedded tracking pixel, the Hotel Alpenhof Fischbacher GmbH can recognise whether and when an email was opened by an person concerned and which links in the email were opened by the person concerned.
Personal data collected using tracking pixels contained in the newsletters are stored and evaluated by the party responsible for processing in order to optimise newsletter dispatch and to adapt the content of future newsletters even better to the interests of the person concerned. This personal data will not be passed on the third parties. Persons concerned are entitled to revoke the respective separate declaration of consent given via the double opt-in procedure at any time. This personal data will be deleted by the party responsible for processing after revocation. The Hotel Alpenhof Fischbacher GmbH automatically interprets cancelling the newsletter as revocation.
9. Contact options on the website
Due to legal regulations, the Hotel Alpenhof Fischbacher GmbH website contains information that enables fast electronic contact with our company and direct communication with us, which also includes a general address for so-called “electronic post” (email address). If a person concerned contacts the party responsible for processing via email or a contact form, the personal data transmitted by the person concerned will be stored automatically. Personal data voluntarily provided by a person concerned to the party responsible for processing will be stored for the purpose of processing or contacting the person concerned. This personal data is not passed on to third parties.
10. Routine deletion & blocking of personal data
The party responsible for processing shall only process and store the personal data of the person concerned for the time required to achieve the storage purpose or to the extent provided for by the European body issuing directives and regulations or another legislator in laws or regulations to which the party responsible for processing is subject.
If the storage purpose ceases to apply or if a storage period prescribed by the European body issuing directives and regulations or another competent legislator expires, the personal data is routinely blocked or deleted in accordance with the statutory provisions.
11. Rights of the person concerned
a) Right to confirmation
Every person concerned has the right granted by the European body issuing directives and regulations to ask the party responsible for processing to confirm whether personal data concerning him or her is being processed. If a person concerned wants to use this right of confirmation, he or she can contact our data protection officer at any time.
b) Right to information
Every person concerned with the processing of personal data has the right granted by the European body issuing directives and regulations to obtain, at any time and free of charge, information from the party responsible for processing on the personal data relating to him or her stored and a copy of that information. Furthermore, the European body issuing directives and regulations has granted the person concerned the following information:
- the purpose of processing
- the categories of personal data being processed
- the recipients or categories of recipients to whom the personal data has been or are still being disclosed, in particular recipients in third countries or international organisations
- if possible, the planned storage duration of the personal data or, if this is not possible, the criteria for determining this duration
- the existence of a right to rectification or deletion of personal data concerning a person or of a restriction on processing by the party responsible or of a right of opposition to this processing
- the existence of a right of appeal to a supervisory authority
- if the personal data is not collected from the person concerned: all available information about the origin of the data
- the existence of automated decision-making, including profiling in accordance with Article 22 Para. 1 and 4 DS-GMO and, at least in these cases, meaningful information on the logic involved and the scope and intended effects of this kind of processing for the person concerned
c) Right to rectification
Any person concerned with the processing of personal data has the right granted by the European body issuing directives and regulations to request the immediate correction of inaccurate personal data concerning him or her. Furthermore, taking into account the purposes of the processing, the person concerned has the right to request the completion of incomplete personal data, including by means of a supplementary statement. If a person concerned wants to use this right to rectification, he or she can contact our data protection officer at any time.
d) Right to deletion (right to be forgotten)
Any person concerned with the processing of personal data has the right granted by the European body issuing directives and regulations to ask the responsible party to immediately delete any personal data concerning him or her, provided that one of the following reasons applies and insofar as the processing is not necessary:
- personal data has been collected or otherwise processed for purposes for which it is no longer necessary.
- the person concerned withdraws his or her consent on which the processing was based according to Article 6 Para. 1 Letter a DS-GMO or Article 9 Para. 2 Letter A DS-GMO and there is no other legal basis for the processing.
- the person concerned enters an objection against processing according to Article 21 Para. 1 DS-GMO and there are no overriding legitimate grounds for processing or the person concerned enters and objection against processing according to Article 21 Para. 2 DS-GMO.
- the personal data has been processed unlawfully.
- the deletion of personal data is necessary is required to fulfil a legal obligation under EU law or the law of the member states to which the responsible party is subject.
- the personal data was collected in relation to information society services offered according to Article 8 Para. 1 DS-GMO.
If the personal data has been released by the Hotel Alpenhof Fischbacher GmbH and our company is responsible for deletion of the personal data as the responsible party according to Article 17 Para. 1 DS-GMO, the Hotel Alpenhof Fischbacher GmbH shall take appropriate measures, including technical measures, taking into account available technology and implementation costs, to inform other parties responsible for data processing who process the published personal data, that the person concerned has requested the deletion of all links to this personal data or of copies or replications of this personal data from those other responsible parties, insofar as processing is not necessary. The Hotel Alpenhof Fischbacher GmbH data protection officer or another employee will take the necessary steps in individual cases.
e) Right to restriction of processing
Any person concerned with the processing of personal data has the right granted by the European body issuing directives and regulations to request that the responsible party restricts the processing if one of the following conditions is met:
- the accuracy of the personal data is disputed by the person concerned for a period that enables the party responsible to verify the accuracy of the personal data.
- the processing is unlawful, the person concerned refuses deletion of the personal data and instead requests that the use of the personal data be restricted.
- the party responsible no longer needs the personal data for the purposes of the processing, but the person concerned needs them to assert, exercise or defend legal claims.
- the person concerned has entered an objection against the processing according to Article. 21 Para. 1 DS-GMO and it has not yet been determined whether the legitimate reasons of the responsible party outweigh those of the person concerned.
f) Right to data transferability
Any person concerned with the processing of personal data has the right granted by the European body issuing directives and regulations to receive personal data relating to him or her, which has been provided by the responsible party, in a structured, common and machine-readable format. They also have the right to transmit this data to another responsible party without any obstruction by the responsible party, to whom the personal data has been provided, provided that the processing is based on the consent according to Article 6 Para. 1 Letter a DS-GMO or Article 9 Para. 2 Letter a DS-GMO or on a contract according to Article 6 Para. 1 Letter b DS-GMO and processing is carried out by means of automated procedures, except where processing is necessary for the performance of a task in the public interest or in the exercise of official authority assigned to the responsible party.
Furthermore, in exercising his or her right to data transferability according to Article 20 Para. 1 DS-GMO, the person concerned has the right to effect that the personal data be transferred directly by a responsible party to another responsible party, provided this is technically feasible and provided that the rights and freedoms of other persons are not affected.
To assert the right to data transferability, the person concerned may contact the data protection officer appointed by the Hotel Alpenhof Fischbacher GmbH or another employee at any time.
g) Right to objection
Any person concerned with the processing of personal data shall has right granted by the European body issuing directives and regulations to enter an objection at any time to the processing of personal data concerning them according to Article 6 Para 1 Letters e or f DS-GMO for reasons arising from their particular situation. This also applies to profiling based on these provisions.
In the event of revocation, the Hotel Alpenhof Fischbacher GmbH will no longer process the personal data unless we can prove compelling legitimate reasons for processing, which outweigh the interests, rights and freedoms of the person concerned, or the processing serves to assert, exercise or defend legal claims.
If the Hotel Alpenhof Fischbacher GmbH processes personal data for direct advertising purposes, the person concerned has the right to object at any time to the processing of personal data for the purpose of this kind of advertising. This also applies to profiling if it is in connection with this kind of direct advertising. If the person concerned objects to the Hotel Alpenhof Fischbacher GmbH processing for direct advertising purposes, the Hotel Alpenhof Fischbacher GmbH will no longer process the personal data for these purposes.
In addition, the person concerned has the right to enter an objection against the processing of personal data concerning him or her carried out by the Hotel Alpenhof Fischbacher GmbH, which is done for academic or historical research purposes or for statistical purposes according to Article 89 Para. 1 DS-GMO for reasons arising from their particular situation, unless this processing is necessary to fulfil a task in the public interest.
To exercise the right to objection, the person concerned may contact the Hotel Alpenhof Fischbacher GmbH data protection officer or another employee directly. The person concerned shall also be free to exercise his or her right of objection in relation to the use of information society services by means of automated procedures for which technical specifications are used, regardless of Directive 2002/58/EC.
h) Automated decisions in individual cases, including profiling
Every person concerned with the processing of personal data has the right granted by the European body issuing directives and regulations not to be subject to a decision based exclusively on automated processing, including profiling, which has legal effect against him or her or significantly affects him or her in a similar manner, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the person concerned and the responsible party, or (2) is admissible under the provisions of EU law or those of the member states to which the responsible party is subject and these provisions contain appropriate measures to safeguard the rights, freedoms and legitimate interests of the person concerned or (3) is made with the express consent of the person concerned.
If the decision (1) is required for the conclusion or performance of a contract between the person concerned and the responsible party or (2) is made with the express consent of the person concerned, the Hotel Alpenhof Fischbacher GmbH shall take appropriate measures to safeguard the rights, freedoms and legitimate interests of the person concerned, including at least the right to obtain the intervention of a person by the person responsible, to state his or her own position and to challenge the decision.
If the person concerned wishes to assert his or her right relating to automated decisions, he or she may contact our data protection officer at any time.
i) Right to withdraw consent relating to data privacy
Every person concerned with the processing of personal data has the right granted by the European body issuing directives and regulations to withdraw consent given to process personal data at any time.
If the person concerned wishes to assert his or her right to revoke his or her consent, he or she may contact our data protection officer at any time.
12. Data privacy for applications & in the application process
The party responsible for processing collects and processes the personal data of applicants for the purpose of processing the application procedure. Processing may also be carried out electronically. This applies, in particular, if an applicant sends corresponding application documents to the party responsible for processing electronically, for example, by email or via an online form on the website. If the party responsible for processing enters into an employment contract with an applicant, the data transmitted will be stored for the purpose of processing the employment contract in compliance with the statutory provisions. If the party responsible for processing does not enter into an employment contract with the applicant, the application documents shall be automatically deleted two months after notification of the refusal decision, provided that deletion does not obstruct other legitimate interests of the party responsible for processing. Other legitimate interest in this sense is, for example, a burden of proof in proceedings under the German General Act on Equal Treatment (AGG).
13. Legal basis for processing
Article 6 I lit. a DS-GVO serves our company as a legal basis for processing operations for which we obtain consent for a specific processing purpose. If processing personal data is necessary for the performance of a contract to which the person concerned is a party, as is the case, for example, with processing operations necessary for the delivery of goods or the provision of other services or consideration, processing is based on Article 6 I lit. b DS-GMO. The same applies to processing operations that are necessary to carry out precontractual measures, for example, in cases of enquiries about our products or services. If our company is subject to a legal obligation that requires the processing of personal data, for example, to fulfil tax obligations, processing is based on Article. 6 I lit. c DS-GMO. In rare cases, processing personal data may become necessary to protect the vital interests of the person concerned or another natural person. This would be the case, for example, if a visitor was injured at our company and his name, age, health insurance data or other vital information had to be passed on to a doctor, a hospital or other third parties. Processing would then be based on Article 6 I lit. d DS-GVO. Ultimately, processing operations could be based on Article 6 I lit. d DS-GVO. Processing operations that are not covered by any of the aforementioned legal bases are based on this legal basis if processing is necessary to safeguard a legitimate interest of our company or a third party, provided that the interests, fundamental rights and freedoms of the person concerned do not prevail. We are entitled to these kind of processing procedures in particular because they have been specifically mentioned by the European legislator. It advocates the view that a legitimate interest could be assumed if the person concerned is a customer of the responsible party (Recital 47, Sentence 2 DS-GMO).
14. Legitimate interests to processing pursued by the responsible party or a third party
If processing personal data is based on Article 6 I lit. f DS-GMO, it is in our legitimate interest to conduct our business activity for the good of all our employees and our shareholders.
15. Duration for which personal data is stored
The criterion for the duration of personal data storage is the respective legal retention period. After the expiry of this period, the corresponding data will be routinely deleted, provided that it is no longer necessary for the fulfilment or initiation of the contract.
16. Legal or contractual provisions for the provision of personal data; necessity for the conclusion of the contract; obligation of the person concerned to provide the personal data; possible consequences of failure to provide it
We inform you that the provision of personal data is partly required by law (e.g. tax regulations) or may also result from contractual regulations (e.g. information on the contractual partner). From time to time, it may be necessary for a contract to be concluded that a person concerned provides us with personal data that must subsequently be processed by us. For example, the person concerned shall undertake to provide us with personal data if our company enters into a contract with him or her. The only consequence of not providing personal information is that the contract will not be able to be concluded with the person concerned. Prior to the provision of personal data by the person concerned, the person concerned must contact our data protection officer. Our data protection officer will inform the person concerned on a case-by-case basis whether the provision of personal data is required by law or contract or necessary for the conclusion of the contract, whether there is an obligation to provide the personal data and what consequences the failure to provide the personal data would have.
17. Existence of automated decision-making
As a responsible company, we abstain from automatic decision-making or profiling.
18. Competent authority
Österreichische Datenschutzbehörde (Austrian Data Protection Authority)
Wickenburggasse 8
1080 Vienna
Austria
dsb@dsb.gv.at
This Privacy Policy - apart from the cookie information - has partly been provided by the privacy policy generator of the DGD Deutsche Gesellschaft für Datenschutz GmbH of the external data protection officer Freising in cooperation with the privacy lawyer Christian Solmecke.