Privacy policy
DECLARATION ON INFORMATION OBLIGATION
We thank you for the trust you have placed in us and are aware of our responsibility to protect your data in the best possible way. We would therefore like to inform you about the data we collect when you use our products and services. We process your personal data exclusively within the framework of the provisions of the General Data Protection Regulation (DSGVO) and the Data Protection Act. In the following, we inform you about the most important aspects of data processing within the scope of our website.
1. DATA PROCESSING RESPONSIBILITY
The GDPR obliges data controllers in particular to comply with the provisions of the GDPR. The term “controller” refers to the natural or legal person, public authority, agency or other body which alone or jointly with others determines the purposes and means of the processing of personal data.
is responsible for the data processing in question:
ZIRBENNEST Martha
Helena Schennach
Nöbele 19
A-6632 Biberwier
Phone: 0043 650 412 53 63
E-mail: info@hausmartha.com
RESIDENCE Martha
Anette Schennach
Marienbergweg 17
A-6632 Biberwier
Phone: 0043 664 855 27 66
E-mail: info@hausmartha.com
2. COLLECTION AND PROCESSING OF DATA
We process the personal data that you provide to us as a user of our website, for example as part of an inquiry or registration or to conclude a contract. The following data processing may occur as part of interactions with our website:
a) Enquiry via contact form / email
If you send an inquiry via our contact form / email, the data you provide will be processed for the purpose of processing your inquiry. In this case, the data processing takes place on the legal basis of Art. 6 para. 1 lit. b) GDPR.
b) Subscription to the newsletter
If you subscribe to our newsletter, the data you provide will be processed for the purpose of marketing our products and services. In this case, the data processing takes place on the legal basis of Art. 6 para. 1 lit. a) GDPR.
In order to provide you with targeted information, we also collect and process the information you voluntarily provide on areas of interest, date of birth, postal code, etc. in particular. As soon as you have registered for our newsletter, we will send you a confirmation email with a link to confirm your registration. (= so-called double opt-in). You can unsubscribe from the newsletter at any time. The easiest way to do this is to use the “Unsubscribe newsletter” button, which is in each newsletter. Alternatively, you can informally revoke your declaration of consent at any time, and you are welcome to contact us concerning this. Afterwards, we will immediately delete all data in connection with the dispatch of our newsletter.
3. USE AND FURTHER PROCESSING OF PERSONAL DATA
If you have provided us with personal data as a user of our website, we will only use it to fulfill the respective purpose stated above, for example to answer your request, to process contracts and for technical administration.
Personal data will only be passed on or transmitted by us to third parties if this is necessary to fulfill the respective purpose mentioned above or for billing purposes, or if you as a user of the website have given your prior consent. As a user of the website, you have the right to withdraw your consent at any time with effect for the future.
Stored personal data will be deleted if you withdraw your consent to the storage of data, if your data is no longer required to fulfill the purpose for which it was stored, or if its storage is or becomes inadmissible for other legal reasons. Data that is required for billing and accounting purposes is not affected by a request for erasure.
4. INFORMATION, CORRECTION, DELETION
Upon written request, we will be happy to inform you at any time about the personal data stored about you. Our contact details can be found under point 1. controller for data processing of this privacy policy.
If your data processed by us is incorrect, please let us know. We will correct it immediately and inform you.
If you no longer wish us to process your data, please let us know informally. We will of course delete your data immediately and inform you accordingly. If there are compelling legal reasons for not deleting your data, we will inform you immediately.
5. COOKIES
Our website uses so-called “cookies”. When a website is visited, these small text files are sent and stored permanently or temporarily on the end device of the website user.
If the same website is accessed again by the website user at a later time, the website user’s browser (= software for opening and displaying websites) sends the previously received cookie back to the website. The website can use this procedure to evaluate the information it contains in various ways (e.g. the products viewed on the first visit to the website).
Cookies can be used, for example, to control the display of advertisements or to facilitate navigation on a website. If the user of the website wishes to prevent the use of cookies, they can do so by making local changes to their settings in the browser used on their end device.
Please note that the functionality of our website may be impaired if cookies are deactivated.
To manage the cookies and similar technologies used (tracking pixels, web beacons, etc.) and the corresponding consents, we use the consent tool “Real Cookie Banner”. For details on how Real Cookie Banner works, see https://devowl.io/de/rcb/datenverarbeitung/.
The legal basis for the processing of personal data in this context is Art. 6 para. 1 lit. c GDPR and Art. 6 para. 1 lit. f GDPR. Our legitimate interest is the management of the cookies and similar technologies used and the related consents.
The provision of personal data is neither contractually required nor necessary for the conclusion of a contract. You are not obliged to provide the personal data. If you do not provide the personal data, we will not be able to manage your consents.
6. MATOMO (FORMERLY PIWIK) WEB ANALYSIS Our website uses functions of the open source web application Matomo (formerly Piwik). With the help of Matomo, interactions of visitors on a website are recorded, in particular, with the help of cookies, which make it possible to analyse the visitor’s use of the website. To prevent this, you can deactivate the use of cookies on your terminal. Alternatively, by clicking on the following link, you can specifically prevent the use of Matomo web analysis services by placing a “Matomo deactivation cookie” in your browser: As we want to protect your data in the best possible way, your user data (in particular your IP address) will be pseudonymized. You can find more information about Matomo at https://www.matomo.org. Data processing is carried out for the purpose and in the legitimate interest of improving our services and our website, on the legal basis of Art. 6 para. 1 lit. f) GDPR.
7. GOOGLE MAPS
Our website uses functions of the map service Google Maps. The provider of this service is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
To use the functions of Google Maps, it is necessary to save your IP address. As a rule, the IP address is transmitted to the servers of the service provider in the USA and stored there. We have no influence on this data transfer and further data processing.
Google Maps is used for the purpose and in the legitimate interest of making our company easier to find, on the legal basis of Art. 6 para. 1 lit. f) GDPR.
You can find more information about Google Maps at https://policies.google.com/privacy?hl=de
8. BOOKING ROUTE AND ASSOCIATED SERVICES
Booking processing and reservation management
Purpose of the processing
Acceptance, management and confirmation of hotel reservations; preparation of the
accommodation contract; room allocation; management of cancelations and
changes.
Legal basis
Art. 6 para. 1 lit. b GDPR – contract fulfillment (accommodation contract) or
pre-contractual measures at the request of the data subject.
Legal basis
§ Section 6 para. 1 lit. b GDPR; §§ 1090 ff ABGB (existing contract).
Processed data types
First name, surname, title, e-mail, telephone, address, nationality, arrival
/departure date, room category, number of persons, booking amount, reservation
ID, booking channel, special requests.
Deletion period /
Storage
The booking data is stored for the duration of the stay and beyond for 7
years (retention obligation under tax law pursuant to Section 132 BAO).
Systems used: Apaleo PMS, Like Magic, SiteMinder (Channel Manager), booking portals
(Booking.com, Expedia, Airbnb etc. as independent responsible parties).
Online check-in, check-out and guest processes
Purpose of the processing
Digital handling of the check-in and check-out process; provision of the
digital guest directory; management of service requests and housekeeping tasks
during the stay.
Legal basis
Art. 6 para. 1 lit. b GDPR – fulfillment of the accommodation contract.
Legal basis
§§ 1090 ff ABGB.
Processed data types
First name, surname, date of birth, nationality, e-mail, telephone, room
/stay data, communication content (automated messages), upselling
preferences.
Deletion period /
Storage
For the duration of the stay; communication logs max. 6 months after departure;
deleted thereafter provided there are no further retention obligations.
Systems used: Like Magic (LikeMagic AG, Switzerland), Apaleo PMS.
Statutory guest registration (registration system)
Purpose of the processing
Electronic transmission of the registration data of all hotel guests and fellow travelers to the
responsible registration municipality; request and administration of registration numbers;
transmission of overnight stay statistics.
Legal basis
Art. 6 para. 1 lit. c GDPR – Compliance with a legal obligation to which the
controller is subject.
Legal basis
Registration Act 1991 (MeldeG), Federal Law Gazette No. 9/1992 as amended, in particular § 7
(accommodation provider), § 8 (registration form) and, where applicable, § 15 MeldeG (obligation to register at
accommodation establishments); Federal Statistics Act 2000; relevant
state registration regulations.
Processed data types
First name, surname, home address (street, town, country), date of birth, gender
(if collected), nationality, passport number, issuing country, expiration date of the
travel document, date of arrival, date of departure, number of nights, registration number (assigned by
municipality).
Deletion period /
Storage
Registration data is stored in accordance with the statutory retention periods
(7 years in accordance with §10(2) MeldeG 1991); then deleted in accordance with data protection regulations.
Systems used: Like Magic (recording of registration data), Apaleo PMS, FRIVA Digital Solutions GmbH
(transmission interface), Feratel Media Technologies AG (tourism data platform),
municipal program of the local registration municipality.
Payment processing
Purpose of the processing
Processing of all payment transactions in connection with the booking and the
stay; authorization, capture and chargeback of payments;
invoicing; fraud prevention; chargeback management.
Legal basis
Art. 6 para. 1 lit. b GDPR – contract fulfillment (accommodation contract); Art. 6 para. 1 lit.
c GDPR – fulfillment of tax obligations (obligation to provide supporting documents according to § 132a
BAO, UStG).
Legal basis
§§ 1090 ff ABGB; Value Added Tax Act 1994 (UStG); § 132 BAO (retention obligation
7 years); PCI-DSS standard (payment card industry standard).
Processed data types
Billing address, VAT ID (for corporate customers), booking amount, currency,
transaction history, payment status; via Adyen (PCI-DSS-certified):
credit card type, masked card number, expiration date, cardholder name, 3DS-
authentication data.
Deletion period /
Storage
Invoice data 7 years (§ 132 BAO); payment card data will be deleted or tokenized by Adyen after
completion of the transaction in accordance with PCI-DSS requirements;
CVV/CVC will not be stored after authorization.
Systems used: Adyen N.V. (Amsterdam, Netherlands) – PCI-DSS certified payment service provider;
Apaleo PMS.
Newsletter and marketing communication
Purpose of the processing
Sending personalized offers, special promotions and newsletters by e-mail
or WhatsApp; building customer loyalty; invitations to submit reviews.
Legal basis
Art. 6 para. 1 lit. a GDPR – consent of the data subject (voluntary, revocable at any time
). For existing customers (prior booking): Art. 6 para. 1 lit. f GDPR
in conjunction with. § Section 174 TKG 2021 (legitimate interest, direct advertising for similar
services, opt-out option required).
Legal basis
§ Section 174 TKG 2021 (Telecommunications Act – direct marketing by email); GDPR
Art. 7 (conditions for consent); UWG Section 107 (prohibition of unsolicited
messages).
Processed data types
First name, last name, e-mail address, telephone number, language, nationality (if
exists), booking amount, check-in/check-out date, room category,
consent status (opt-in/opt-out with time stamp).
Deletion period /
Storage
Until consent is withdrawn; after withdrawal, immediate deletion from the
distribution lists (max. within 30 days); proof of consent is retained for 3
years after withdrawal.
Systems used: Smartness / Smartpricing S.r.l. (Bolzano, Italy) – SmartConnect (newsletter,
WhatsApp, automatic messages), SmartChat (chatbot), SmartReputation/Revyoos
(evaluation requests).
Note on the right of withdrawal: Consent to receive marketing communication can be withdrawn at any time
without giving reasons – by e-mail to the controller (see above), via
the unsubscribe link in the newsletter or directly to the hotel. The revocation does not affect the
lawfulness of the processing carried out up to that point.
Revenue management and dynamic pricing
Purpose of the processing
Analysis of occupancy data, historical booking data and market data for
automated calculation and publication of optimized room rates on all
sales channels.
Legal basis
Art. 6 para. 1 lit. f GDPR – legitimate interest of the controller
(yield optimization, competitiveness). The processing primarily concerns aggregated
booking data; individual personal data is only used in
anonymized/aggregated form for price calculations.
Legal basis
Art. 6 para. 1 lit. f GDPR.
Processed data types
Aggregated booking data (occupancy, booking period, room category,
booking amount) – without direct personal reference in the price calculation.
Deletion period /
Storage
Aggregated evaluation data is stored for a maximum of 3 years.
Systems used: Smartness / Smartpricing S.r.l. (SmartPricing), SiteMinder (channel transmission
of updated prices), Apaleo PMS.
Evaluation management and online reputation
Purpose of the processing
Automated collection of guest reviews from OTA platforms (Booking.com,
Google, TripAdvisor etc.); sending of review requests after the stay;
Response to reviews.
Legal basis
Art. 6 para. 1 lit. f GDPR – Legitimate interest (reputation management,
quality assurance); for sending the evaluation request by e-mail additionally Art.
6 para. 1 lit. a GDPR (consent) or Section 174 TKG 2021 (existing customer regulation).
Legal basis
§ Section 174 TKG 2021; Art. 6 para. 1 lit. f GDPR.
Processed data types
E-mail address, first name, location data (for personalized evaluation request);
public evaluation content from platforms (aggregated, without personal reference in the
evaluation).
Deletion period /
Storage
Evaluation request logs: max. 6 months; aggregated evaluation data: max. 3
years.
Systems used: Smartness / Smartpricing S.r.l. (Smart Reputation, Revyoos).
System automation and workflow integration
Purpose of the processing
Automated transfer of non-personal or pseudonymized
operational data between the systems (e.g. daily order lists to suppliers,
operational notifications). Insofar as personal data is processed in individual cases by
automation, the respective processing purpose from
sections 2.1 to 2.7 applies.
Legal basis
Art. 6 para. 1 lit. b or lit. f GDPR – depending on the specific automation process.
Legal basis
Art. 6 para. 1 lit. b, f GDPR.
Processed data types
Depending on the specific workflow; mainly operational data without
direct personal reference. For workflows with personal reference: booking data,
room numbers, guest name.
Deletion period /
Storage
Temporary processing data is deleted after the workflow is completed (max.
30 days log storage).
Systems used: Make / Celonis Inc (New York, USA) – automation platform; Celonis SE
(Munich, Germany) – EU contracting party.
Recipients and categories of recipients (Art. 13 para. 1 lit. e
GDPR)
Your personal data will be passed on to the following recipients:
Recipient / Category
Purpose of the transfer
Legal basis
apaleo GmbH, Munich (DE)
Operation of the central PMS,
data storage, automation
Art. 28 GDPR (order processing)
LikeMagic AG, Dübendorf (CH)
Guest journey, check-in/out,
Registration data capture
Art. 28 GDPR
(order processing);
Third country transfer:
Adequacy decision CH
SiteMinder Ltd, Sydney (AU)
Transmission of bookings via
sales channels
Art. 28 GDPR; third country transfer: SCC
according to EU 2021/914
Smartpricing S.r.l. (Smartness),
Bolzano (IT)
Newsletter, Marketing, Revenue
Management, Reviews
Art. 28 GDPR (order processing)
Adyen N.V., Amsterdam (NL)
Payment processing (PCI-DSS-
certified)
Art. 28 GDPR (order processing)
FRIVA Digital Solutions GmbH,
Gerasdorf (AT)
Electronic guest registration
Art. 28 GDPR (order processing)
Recipient / Category
Purpose of the transfer
Legal basis
Feratel Media Technologies
AG, Innsbruck (AT)
Forwarding of registration data to
Municipality
Art. 28 GDPR; Art. 6 para. 1 lit. c
(Registration Act)
Registration municipality (Austrian
municipal administration)
Fulfillment of the statutory reporting obligation
Art. 6 para. 1 lit. c GDPR; Section 7 MeldeG
1991
Celonis Inc / Make, New York
(USA)
System automation and
workflow integration
Art. 28 GDPR; third country transfer: DPF
/ SCC according to EU 2021/914
Booking platforms
(Booking.com, Expedia, Airbnb
etc.)
Booking agency; acting as an independent
manager
Art. 6 para. 1 lit. b GDPR; own
data protection declarations of the
platforms
Transfers to third countries (Art. 13 para. 1 lit. f GDPR)
The following transfers of personal data to countries outside the European
Economic Area (EEA) take place:
Receiver
Third country
Transfer mechanism
Primary source
LikeMagic AG
Switzerland
Adequacy decision of the EU-
Commission (initial decision 26.07.2000;
confirmed under GDPR on 15.01.2024)
edoeb.admin.ch/en/adequacy;
EUR-Lex 32000D0518
SiteMinder Ltd.
Australia
EU Standard Contractual Clauses (SCC) pursuant to
Implementing Decision (EU) 2021/914 of
4. June 2021 – no
adequacy decision for Australia
siteminder.com/legal/privacy/
and
siteminder.com/legal/data-
security/
Celonis Inc.
(Make)
USA
Primary: EU-U.S. Data Privacy Framework
(DPF) – adequacy decision of the EU-
Commission of 10.07.2023 (for DPF-
certified US companies). Subsidiary: SCC
in accordance with (EU) 2021/914, Module 2
make.com/data-processing-
agreement.pdf;
make.com/standard-
contractual-clauses.pdf
Duration of data storage (Art. 13 para. 2 lit. a GDPR)
Personal data is not stored for longer than is necessary for the respective processing purpose
. The specific retention periods are based on the statutory minimum and
maximum retention periods:
Data category
Storage period
Legal basis of the retention obligation
Booking and
invoice data
7 years
§ Section 132 BAO (Federal Fiscal Code)
Registration data (guest registration)
7 years
§ 10 MeldeG 1991; BAO
Payment card details
After transaction completion
tokenized/deleted in accordance with PCI-DSS
;
CVV/CVC not saved
PCI DSS standard; Adyen guidelines
Communication data (e-mails,
messages)
Max. 6 months after departure
Art. 5 para. 1 lit. e GDPR (data minimization)
Marketing consent
(proof)
3 years after revocation
Art. 7 para. 1 GDPR (obligation to provide evidence)
Contract data (hotel operator)
10 years after the end of the contract
§ 1489 ABGB (general statute of limitations)
Technical logs / protocols
Max. 30-90 days
Art. 5 para. 1 lit. e GDPR
Data category
Storage period
Legal basis of the retention obligation
Applicant data (if collected
)
6 months after rejection
Art. 6 para. 1 lit. f GDPR
Automated decision-making and profiling (Art. 13 para. 2 lit. f
GDPR)
There is no exclusively automated decision-making within the meaning of Art. 22 GDPR, which
has a legal effect on you or significantly affects you in a similar way.
Note: Adyen uses automated risk analysis systems
(RevenueProtect) as part of fraud prevention. These are used exclusively for payment security and may trigger a manual
check, but do not make any final legal decisions vis-à-vis the
persons concerned.
Cookies and tracking (website / online booking engine)
Cookies and similar technologies are used on the hotel website and in the online booking engine (operated by SiteMinder / Like Magic)
:
Cookie category
Purpose
Provider
Legal basis
Technically necessary
Cookies
Operation of the website, session
management, security
Own systems,
SiteMinder, Like
Magic
Art. 6 para. 1 lit. b/f
GDPR; Section 165 TKG 2021
Analysis cookies
(pseudonymized)
Performance monitoring,
User behavior analysis
Datadog, Hotjar
Art. 6 para. 1 lit. a GDPR
(consent via cookie
banner)
Analysis cookies
(anonymized)
User behavior analysis
No relevance due to anonymization
Marketing/tracking cookies
Retargeting,
Conversion optimization
Google Ads if applicable (via
SiteMinder Demand
Plus)
Art. 6 para. 1 lit. a GDPR
(consent)
You can adjust your cookie settings at any time via the cookie banner on our website.
Rights of the data subjects (Art. 13 para. 2 lit. b-d GDPR)
You have the following rights vis-à-vis the controller in accordance with the GDPR:
Law
content
Restrictions
Information (Art. 15
GDPR)
You can request information about the data stored about you at
, its origin,
recipients and the purpose of processing
.
Third-party rights; trade and
business secrets
Rectification (Art. 16
GDPR)
You can have incorrect or incomplete data corrected at any time at
.
–
Erasure (Art. 17
GDPR)
Under certain circumstances,
may request the erasure of your data
(‘right to be forgotten’).
Statutory retention obligations (§
132 BAO, MeldeG) may prevent
immediate deletion.
Law
content
Restrictions
Restriction (Art.
18 GDPR)
You may request the restriction of
processing of your data (e.g.
during the verification of a rectification).
–
Data portability
(Art. 20 GDPR)
You may receive your data in a structured,
machine-readable format or request
its transfer to another
controller.
Applies only to automatically processed
data based on consent or contract.
Objection (Art. 21
GDPR)
You can object to the processing of your data on
basis of Art. 6 para. 1 lit. f GDPR
(legitimate interest) at any time
, in particular against
direct advertising.
Revocation of the
consent (Art. 7
para. 3 GDPR)
Consent (e.g. for newsletters) can be revoked at any time without giving reasons
. The revocation does not affect
the legality of the processing carried out up to that point
.
–
Complaint to the
supervisory authority
(Art. 77 GDPR)
You have the right to lodge a complaint with the
Austrian data protection authority at
.
Austrian Data Protection Authority,
Barichgasse 40-42, 1030 Vienna; dsb.gv.at
Contact data protection and data protection authority
If you have any questions about data protection or the exercise of your rights, please contact:
Contact us
Details
Data protection contact hotel
See contact information at the top (data controller)
Austrian
Data Protection Authority
Barichgasse 40-42, 1030 Vienna | Tel: +43 1 531 15-202525 | E-mail: dsb@dsb.gv.at |
Website: www.dsb.gv.at
